Guidance for Microsoft Security Copilot - the generative-AI security platform that helps analysts investigate, hunt, summarise, and respond using natural language, plugins, promptbooks, and embedded…

MITAuto-check passedSecurity

Install Security Copilot

skills CLI
$ npx skills add vinayaklatthe/microsoft-security-skills --skill security-copilot -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vinayaklatthe/microsoft-security-skills security-copilot --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security-copilot .claude/skills/security-copilot && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-copilot
GitHub stars
175
Token cost
~1.8k tokens
SKILL.md length
812 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Guidance for Microsoft Security Copilot - the generative-AI security platform that helps analysts investigate, hunt, summarise, and respond using natural language, plugins, promptbooks, and embedded…

  • Works in 7 steps: Provision capacity - Set up Security… → Assign roles - Configure Security… → Enable plugins - Turn on the Microsoft… → …
  • The goal is configuring autonomous triage
  • SKILL.md covers When to use, Pick the right experience for…, Approach and Guardrails, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Security Copilot is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for Microsoft Security Copilot - the generative-AI security platform that helps analysts investigate, hunt, summarise, and respond using natural language, plugins, promptbooks, and embedded experiences. Covers SCU provisioning, plugins, promptbooks, governance, and the standalone vs embedded experience choice. WHEN: Microsoft Security Copilot, AI for SOC, security copilot units SCU, promptbooks, Copilot plugins, natural language investigation, summarise incident with AI, Copilot for Security setup, how…

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Prompt injection and agent security. It works with Microsoft Sentinel and Microsoft Defender. The repository describes itself as: Curated Microsoft Security skills for AI agents - Defender, Sentinel, Entra, Purview, Intune, Security Copilot. The licence is MIT.

When your agent uses it

  • The goal is configuring autonomous triage
  • Remediation agents (use security-copilot-agents)

Example prompts

  • “/security-copilot”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Provision capacity - Set up Security Compute Units (SCUs) in Azure (provisioned
  2. Assign roles - Configure Security Copilot owner and contributor roles in Entra,
  3. Enable plugins - Turn on the Microsoft plugins you need (Defender XDR, Sentinel, Intune,
  4. Choose the experience per workflow - Use the standalone portal for multi-step
  5. Build promptbooks - Identify your top 5 repeatable workflows (incident summary for exec,
  6. Govern usage and consumption - Monitor SCU consumption per workload, audit Copilot
  7. Measure value - Track time-to-first-answer, analyst satisfaction, and SCU per resolved

What it can do on your machine

Read from SKILL.md and the folder at commit 15f16df. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Copilot loads about 1.8k tokens when it runs. Until then it costs about 184 tokens; SKILL.md has 812 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~184
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vinayaklatthe/microsoft-security-skills at commit 15f16df, republished under its MIT licence (© vinayaklatthe). 812 words, ~1,812 tokens.

Download SKILL.mdSave it as .claude/skills/security-copilot/SKILL.md (or your agent's skills folder).
name
security-copilot
description
Guidance for Microsoft Security Copilot - the generative-AI security platform that helps analysts investigate, hunt, summarise, and respond using natural language, plugins, promptbooks, and embedded experiences. Covers SCU provisioning, plugins, promptbooks, governance, and the standalone vs embedded experience choice. WHEN: Microsoft Security Copilot, AI for SOC, security copilot units SCU, promptbooks, Copilot plugins, natural language investigation, summarise incident with AI, Copilot for Security setup, how do I use AI in my SOC, explain a KQL query with AI, summarise an alert for a stakeholder. DO NOT USE when the goal is configuring autonomous triage or remediation agents (use security-copilot-agents).
license
MIT
metadata.author
Microsoft
metadata.version
0.1.0

Microsoft Security Copilot

Microsoft Security Copilot is a generative-AI security platform that helps security and IT teams investigate incidents, hunt threats, summarise findings, and respond at machine speed using natural language, grounded in your security data and Microsoft threat intelligence.

When to use

Accelerating SOC investigation, reporting, and analyst productivity across Microsoft and third-party security data using natural-language workflows.

Do not use this skill for:

  • Configuring autonomous triage/remediation agents (use security-copilot-agents)
  • Building a SIEM analytics rule (use sentinel)
  • Configuring Defender XDR investigations or actions (use defender-xdr)

Pick the right experience for the task

TaskUse this experienceWhy
Multi-step investigation across productsStandalone portalCross-plugin reasoning, promptbooks
Summarise this specific incidentEmbedded in Defender XDRContext already loaded
Explain or translate a KQL queryEmbedded in SentinelInline in the query editor
Explain a Conditional Access policyEmbedded in EntraPolicy already in scope
Repeatable investigation patternPromptbookSaved, shareable, parameterised
Daily ad-hoc analyst questionStandalone or embeddedEither; pick by where you start

Rule of thumb: start embedded for single-product questions, switch to standalone the moment you need to correlate across two or more products. Promptbook anything you do more than twice.

Approach

  1. Provision capacity - Set up Security Compute Units (SCUs) in Azure (provisioned capacity model), assign the Azure subscription and resource group, choose the geographic region, and configure overage settings. SCUs are the meter; underprovisioning throttles, overprovisioning wastes spend. Verify: Security Copilot → Owner settings → Capacity shows SCUs reserved and the region matches your data residency requirement.
  2. Assign roles - Configure Security Copilot owner and contributor roles in Entra, align to least privilege, set the default environment, and decide on the data sharing toggle (model improvement opt-in/out). Verify: a non-owner test account can use Copilot but cannot change capacity settings.
  3. Enable plugins - Turn on the Microsoft plugins you need (Defender XDR, Sentinel, Intune, Entra, Threat Intelligence, Purview, Defender for Cloud) and add non-Microsoft or custom plugins where you have third-party data. Copilot respects the underlying product RBAC of the calling user - it never elevates privilege. Verify: a query that requires Sentinel data from a user without Sentinel access returns a permission error, not an answer.
  4. Choose the experience per workflow - Use the standalone portal for multi-step cross-product investigations, and the embedded experiences inside Defender XDR, Sentinel, Intune, Entra, and Purview for single-product context. Verify: analysts know which surface to start in for their top 5 daily tasks.
  5. Build promptbooks - Identify your top 5 repeatable workflows (incident summary for exec, reverse-engineer a script, KQL explanation, phishing email triage, CA policy explanation) and turn each into a promptbook with parameters. Verify: each promptbook runs end-to-end on a sample input without manual editing.
  6. Govern usage and consumption - Monitor SCU consumption per workload, audit Copilot activity, and set alerts on SCU utilisation > 80% to control cost. Review prompt logs for sensitive data exposure. Verify: a usage dashboard exists; alerting fires when SCUs trend high.
  7. Measure value - Track time-to-first-answer, analyst satisfaction, and SCU per resolved incident before and after rollout. If the metric does not move, the promptbooks or plugins are wrong, not the platform.
Show full SKILL.md (295 more words)Show less

Guardrails

  • Treat AI output as assistive - analysts must validate findings before acting. Copilot is not the source of truth; the underlying product is.
  • Apply least-privilege plugin access; Copilot inherits the user's product RBAC, so over- permissioning a user over-permissions Copilot for that user.
  • Monitor SCU consumption to control cost; tune capacity to demand and set utilisation alerts. Surprises in capacity bills are a configuration problem, not a platform problem.
  • Data residency is set at capacity creation - changing region later means rebuild. Decide up front based on regulatory scope.
  • Sensitive prompts are still data. Treat the prompt history as audit-relevant; do not paste credentials, customer PII, or unsanitised raw data into prompts.
  • Promptbooks are code. Version-control them, review changes, and remove unused ones.

Common anti-patterns

  • "Buy SCUs, give everyone access, see what happens." Burns budget, produces no measurable value, and trains analysts to distrust AI output.
  • Skipping promptbooks. Without them, every investigation is a snowflake and the platform feels like a chatbot, not a workflow.
  • Treating Copilot as a fact source. It synthesises from the products' data - if the data is wrong, the answer is wrong. Always pivot to the source product for action.
  • Pasting raw incident data into the standalone prompt when the embedded experience already has it. Wastes SCUs and adds risk.
  • No SCU utilisation alerts. First sign of a problem is the invoice.

Example prompts

  • Set up Microsoft Security Copilot and provision SCUs.
  • Use promptbooks to summarise an incident for a stakeholder.
  • How do I use AI to speed up incident investigation in my SOC?
  • Explain a KQL query with Security Copilot.
  • Pick between standalone and embedded experiences for my analysts.

Microsoft Learn

© vinayaklatthe, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/security-copilot of vinayaklatthe/microsoft-security-skills.

Open the folder on GitHubat commit 15f16df

Compare with similar skills

Security Copilot next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Copilot compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Copilot this skillvinayaklatthe/microsoft-security-skills175—~1.8kAutomated safety check: PassMIT
Incident InvestigationSCStelz/security-investigator250—~13kAutomated safety check: PassMIT
Azure External Attack Surface ManagementMicrosoftDocs/Agent-Skills777—~935Automated safety check: PassCC-BY-4.0
Kql Query AuthoringSCStelz/security-investigator250—~5.7kAutomated safety check: PassMIT
Detection AuthoringSCStelz/security-investigator250—~17kAutomated safety check: PassMIT
Azure Content SafetyMicrosoftDocs/Agent-Skills777—~1.8kAutomated safety check: PassCC-BY-4.0

Similar skills

  • Incident Investigation

    SCStelz/security-investigator

    A skill your agent uses when asked to investigate a security incident by ID from Microsoft Defender XDR or Microsoft Sentinel.

    250 GitHub stars~13k tokensUpdated yesterday
    SecurityAuto-check passed
  • Official

    Expert knowledge for Azure External Attack Surface Management development including configuration.

    777 GitHub stars~935 tokensUpdated 4 days ago
    SecurityAuto-check passed
  • Kql Query Authoring

    SCStelz/security-investigator

    A skill your agent uses when asked to write, create, or help with KQL (Kusto Query Language) queries for Microsoft Sentinel, Defender XDR, or Azure Data Explorer.

    250 GitHub stars~5.7k tokensUpdated yesterday
    Data & AnalyticsAuto-check passed
  • Detection Authoring

    SCStelz/security-investigator

    Create, deploy, update, and manage custom detection rules in Microsoft Defender XDR via the Graph API (/beta/security/rules/detectionRules).

    250 GitHub stars~17k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Azure Content Safety

    MicrosoftDocs/Agent-Skills

    Official

    Expert knowledge for Content Safety in Foundry Control Plane development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security…

    777 GitHub stars~1.8k tokensUpdated 4 days ago
    DevelopmentAuto-check passed
  • Skill Inspector

    NVIDIA/SkillSpector

    Official

    Decides whether an agent skill is safe to install by combining a SkillSpector static scan with the agent's own source review, ending in APPROVE, CAUTION or REJECT.

    20k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check passed

More from vinayaklatthe/microsoft-security-skills

All 50 skills in this repo
  • API Security Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure App Service Security

    vinayaklatthe/microsoft-security-skills

    Guidance for securing Azure App Service web apps and APIs — managed identity, Easy Auth with Microsoft Entra ID, network isolation via private endpoints + VNet integration, HTTPS / TLS hardening…

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Arc

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management.

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Bastion Jit

    vinayaklatthe/microsoft-security-skills

    Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Confidential Computing

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Confidential Computing — protecting data in use through hardware-based Trusted Execution Environments (TEEs).

    175 GitHub stars~2.4k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Ddos Protection

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure DDoS Protection — Network Protection (per-VNet) and IP Protection (per public IP) tiers built on the same always-on Microsoft platform.

    175 GitHub stars~2k tokensUpdated 3 mo ago
    Auto-check passed

Categories

Questions about Security Copilot

What does Security Copilot do?

Guidance for Microsoft Security Copilot - the generative-AI security platform that helps analysts investigate, hunt, summarise, and respond using natural language, plugins, promptbooks, and embedded…. Security Copilot is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for Microsoft Security Copilot - the generative-AI security platform that helps analysts investigate, hunt, summarise, and respond using natural language, plugins, promptbooks, and embedded experiences.

When should I use Security Copilot?

Security Copilot fits situations like: the goal is configuring autonomous triage; remediation agents (use security-copilot-agents).

How do I install Security Copilot in Claude Code?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill security-copilot -a claude-code`. Or copy the skill folder (skills/security-copilot in vinayaklatthe/microsoft-security-skills) into .claude/skills/security-copilot in your project. Claude Code loads it when a task matches its description.

How do I install Security Copilot in Codex?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill security-copilot -a codex`. Or copy the skill folder (skills/security-copilot in vinayaklatthe/microsoft-security-skills) into .agents/skills/security-copilot in your project. Codex loads it when a task matches its description.

Can I use Security Copilot in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vinayaklatthe/microsoft-security-skills --skill security-copilot -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-copilot, .gemini/skills/security-copilot, .github/skills/security-copilot and .opencode/skills/security-copilot in your project.

What does Security Copilot need to run?

SKILL.md names no scripts, command-line tools or credentials: Security Copilot is instructions for the agent only.

Does Security Copilot access the network?

SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.

Is Security Copilot safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Copilot use?

Security Copilot is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Copilot use?

About 1.8k tokens (SKILL.md is roughly 7.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Copilot?

Skills that share tags, products or a category with Security Copilot: Incident Investigation (SCStelz/security-investigator, 250 stars), Azure External Attack Surface Management (MicrosoftDocs/Agent-Skills, 777 stars), Kql Query Authoring (SCStelz/security-investigator, 250 stars) and Detection Authoring (SCStelz/security-investigator, 250 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Copilot?

vinayaklatthe (a GitHub user) maintains it in vinayaklatthe/microsoft-security-skills, which has 175 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on June 18, 2026.

Source: vinayaklatthe/microsoft-security-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.