Agent skill

Security Copilot Agents

by vinayaklatthe in vinayaklatthe/microsoft-security-skills

Guidance for Microsoft Security Copilot agents — autonomous, purpose-built AI agents (e.g., phishing triage, alert triage, conditional access optimization, vulnerability remediation) that work…

MITAuto-check passedSecurity

Install Security Copilot Agents

skills CLI
$ npx skills add vinayaklatthe/microsoft-security-skills --skill security-copilot-agents -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vinayaklatthe/microsoft-security-skills security-copilot-agents --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security-copilot-agents .claude/skills/security-copilot-agents && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-copilot-agents
GitHub stars
175
Token cost
~2.1k tokens
SKILL.md length
977 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Guidance for Microsoft Security Copilot agents — autonomous, purpose-built AI agents (e.g., phishing triage, alert triage, conditional access optimization, vulnerability remediation) that work…

  • Works in 7 steps: Provision capacity and licensing first —… → Set up the agent identity — Each agent… → Scope permissions to least privilege —… → …
  • Basic Security Copilot setup
  • SKILL.md covers When to use, Pick the right agent for the job, Approach and Guardrails, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Security Copilot Agents is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for Microsoft Security Copilot agents — autonomous, purpose-built AI agents (e.g., phishing triage, alert triage, conditional access optimization, vulnerability remediation) that work within Security Copilot. Covers available agents, identity/permissions, and supervision. WHEN: Security Copilot agents, autonomous SOC agent, phishing triage agent, alert triage agent, agent identity, supervise AI agent, agentic security, Copilot agent permissions, automate phishing triage, AI agent for SOC, autonomous…

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security operations and Prompt injection and agent security. The repository describes itself as: Curated Microsoft Security skills for AI agents - Defender, Sentinel, Entra, Purview, Intune, Security Copilot. The licence is MIT.

When your agent uses it

  • Basic Security Copilot setup
  • SCU provisioning
  • Promptbooks (use security-copilot)

Example prompts

  • “/security-copilot-agents”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Provision capacity and licensing first — Each agent consumes **Security Copilot Compute
  2. Set up the agent identity — Each agent has its own Entra Agent ID (workload identity).
  3. Scope permissions to least privilege — Built-in agents request a set of Graph / product
  4. Configure supervision mode per action — Each agent has actions with different blast
  5. Pilot on a slice — Scope the agent to one team, one mailbox, one site, or one device
  6. Wire to your SOC tooling — Agent activity logs flow to Defender XDR and Sentinel via
  7. Lifecycle the agent identity — When you decommission an agent (or a workflow), disable

What it can do on your machine

Read from SKILL.md and the folder at commit 15f16df. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Copilot Agents loads about 2.1k tokens when it runs. Until then it costs about 173 tokens; SKILL.md has 977 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~173
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vinayaklatthe/microsoft-security-skills at commit 15f16df, republished under its MIT licence (© vinayaklatthe). 977 words, ~2,084 tokens.

Download SKILL.mdSave it as .claude/skills/security-copilot-agents/SKILL.md (or your agent's skills folder).
name
security-copilot-agents
description
Guidance for Microsoft Security Copilot agents — autonomous, purpose-built AI agents (e.g., phishing triage, alert triage, conditional access optimization, vulnerability remediation) that work within Security Copilot. Covers available agents, identity/permissions, and supervision. WHEN: Security Copilot agents, autonomous SOC agent, phishing triage agent, alert triage agent, agent identity, supervise AI agent, agentic security, Copilot agent permissions, automate phishing triage, AI agent for SOC, autonomous alert triage, hands-off triage of high-volume alerts. DO NOT USE for basic Security Copilot setup, SCU provisioning, or promptbooks (use security-copilot).
license
MIT
metadata.author
Microsoft
metadata.version
0.1.0

Microsoft Security Copilot Agents

Security Copilot agents are purpose-built, semi-autonomous AI agents that operate within Security Copilot to take on high-volume security workflows, learn from analyst feedback, and act inside the Microsoft Security products. Each agent has its own Entra Agent ID, scoped permissions, and a supervision model.

When to use

Use this skill when the user wants to offload a high-volume, repetitive triage or remediation workflow to an agent and is ready to govern an autonomous workload identity.

Do not use this skill for:

  • Basic Security Copilot setup, SCU provisioning, promptbooks (use security-copilot)
  • General Entra Agent ID design (use entra-id + Entra Agent ID guidance)
  • Building a custom agent from scratch (this skill is operating built-in agents)

Pick the right agent for the job

If the team is drowning in...AgentOwning productRecommended first mode
User-reported phishing ticketsPhishing TriageDefender for Office 365Recommendation - human approves verdicts for 2 weeks
DLP / Insider Risk alert backlogAlert Triage (Purview)PurviewRecommendation - measure precision before autonomy
Stale or duplicate Conditional Access policiesConditional Access OptimizationEntra IDRecommendation only - never autonomous in production
Patch / vuln backlog for endpointsVulnerability RemediationIntune + Defender Vuln MgmtRecommendation; deploy patches via existing change control
Threat-landscape briefings for leadershipThreat Intelligence BriefingDefender Threat IntelligenceAutonomous (read-only)
SOC analyst onboarding / context lookupsConditional Access / IR partner agentsPartner ecosystemRecommendation - third-party data path

Rule of thumb: start every agent in Recommendation mode for 2-4 weeks. Measure agreement rate between agent verdict and human verdict. Only graduate to autonomous when agreement > 90% on the relevant queue.

Approach

  1. Provision capacity and licensing first — Each agent consumes Security Copilot Compute Units (SCUs). Most built-in agents need ~1-2 SCUs per concurrent workflow. Confirm SCU commitment and the owning product licence (e.g. Phishing Triage needs Defender for Office 365 P2). Without both, the agent surfaces in UI but fails at execution. Verify: Security Copilot → Owner settings → Capacity shows enough SCUs reserved for the agents you plan to enable.
  2. Set up the agent identity — Each agent has its own Entra Agent ID (workload identity). Treat it as a privileged service principal: name it predictably (e.g. sc-agent-phishingtriage-prod), document its owner, register it in your identity inventory, and enable sign-in monitoring. Verify: Entra → Enterprise applications shows the agent identity with the expected API permissions and no extras.
  3. Scope permissions to least privilege — Built-in agents request a set of Graph / product permissions. Review and remove anything not needed for your scenario. For example, Alert Triage does not need Mail.Send even if the consent flow offers it. Verify: a test action in the agent succeeds; a deliberately out-of-scope action (e.g. sending mail when only triage is intended) fails.
  4. Configure supervision mode per action — Each agent has actions with different blast radius. Set the mode per action, not per agent:
    • Recommendation = agent suggests, human approves (always for blocking, deleting, password reset, MFA reset, policy change)
    • Autonomous = agent acts without approval (acceptable for labelling, classification, read-only enrichment, briefing generation) Verify: an irreversible action in test data prompts for human approval; a reversible action proceeds without.
  5. Pilot on a slice — Scope the agent to one team, one mailbox, one site, or one device group for 2-4 weeks. Measure: agreement rate, time-to-decision, false positive/negative count, override rate. Verify: pilot dashboard shows >90% agent-human agreement before expanding scope.
  6. Wire to your SOC tooling — Agent activity logs flow to Defender XDR and Sentinel via the AuditLogs and agent-specific tables. Build a workbook tracking agent decisions vs human overrides so drift is visible.
  7. Lifecycle the agent identity — When you decommission an agent (or a workflow), disable the Entra Agent ID, revoke its API permissions, and remove it from your privileged identity inventory. Agent identities that outlive their use case are tomorrow's blast radius.
Show full SKILL.md (348 more words)Show less

Guardrails

  • Human-in-the-loop for consequential actions, always. Password reset, MFA reset, account disable, message purge, policy change, device wipe - never autonomous.
  • Govern agent identities like privileged service principals. They are not service accounts to forget. Apply Conditional Access (where supported), monitor sign-ins, review API permissions quarterly, rotate any agent secrets, and audit consented permissions.
  • Measure agreement rate before graduating to autonomous. A high-volume agent acting at 85% accuracy is a 15% incident factory at scale. Use the 90% threshold or higher.
  • Watch SCU consumption. Agents can burn through SCU capacity unexpectedly during incident spikes; set alerts on SCU utilisation > 80%.
  • Do not pile agents on the same identity. Each built-in agent has its own Entra Agent ID; consolidating is not supported and breaks the audit chain.
  • Agent prompts can be poisoned. Phishing-Triage reads user-submitted email content; treat agent inputs as untrusted. Microsoft has built-in mitigations - do not add your own unsanitised data sources.

Common anti-patterns

  • "Enable in autonomous mode on day one." No baseline of accuracy; first false positive becomes a real outage (blocked exec mailbox, disabled VIP account).
  • "Use Global Admin for the agent identity." Catastrophic blast radius. Use the agent's default scoped permissions and trim further.
  • "Treat the agent as the SOC analyst." Agents augment, not replace. Without a human review loop you lose the feedback that improves the agent.
  • "Forget to disable retired agent identities." Inactive agent IDs sit in Entra with consented Graph permissions - prime supply-chain target.
  • "Skip the pilot." Org-wide rollout exposes a queue-specific failure mode you would have caught in a 2-week pilot.

Example prompts

  • Deploy the Phishing Triage agent in Security Copilot.
  • Which Security Copilot agent should I pilot first for my SOC?
  • How do I supervise an autonomous alert triage agent and set permissions?
  • What permissions does the Conditional Access Optimization agent need?
  • Configure agent identity for an agentic SOC.
  • Measure the accuracy of the Alert Triage agent before going autonomous.

Microsoft Learn

© vinayaklatthe, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/security-copilot-agents of vinayaklatthe/microsoft-security-skills.

Open the folder on GitHubat commit 15f16df

Compare with similar skills

Security Copilot Agents next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Copilot Agents compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Copilot Agents this skillvinayaklatthe/microsoft-security-skills175—~2.1kAutomated safety check: PassMIT
Threat Database UpdateFlorianBruniaux/claude-code-ultimate-guide6.1k—~680Automated safety check: PassCC-BY-SA-4.0
Defending Applicationstelagod/code-abyss243—~777Automated safety check: PassMIT
Skill Scannergetsentry/skills1k4 repos~2.5kAutomated safety check: WarnApache-2.0
Security Alert Triageelastic/agent-skills5921 repos~3.5kAutomated safety check: NotesApache-2.0
Kubernetes Network Security Auditkubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0

Similar skills

  • Threat Database Update

    FlorianBruniaux/claude-code-ultimate-guide

    Refreshes the guide's coding-agent and MCP security threat data through AgentSec Triage: research advisories, add tested records and synchronize the public feed.

    6.1k GitHub stars~680 tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Defending Applications

    telagod/code-abyss

    Application security defense knowledge for builders. An agent skill from telagod/code-abyss.

    243 GitHub stars~777 tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    SecurityAuto-check: warnings
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    SecurityAuto-check: notes
  • Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

    12k GitHub stars~7.3k tokensUpdated 2 days ago
    SecurityAuto-check: notes
  • Official

    Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint).

    592 GitHub starsUsed in 1 repo~3.9k tokens
    SecurityAuto-check: notes

More from vinayaklatthe/microsoft-security-skills

All 50 skills in this repo
  • API Security Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure App Service Security

    vinayaklatthe/microsoft-security-skills

    Guidance for securing Azure App Service web apps and APIs — managed identity, Easy Auth with Microsoft Entra ID, network isolation via private endpoints + VNet integration, HTTPS / TLS hardening…

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Arc

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management.

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Bastion Jit

    vinayaklatthe/microsoft-security-skills

    Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Confidential Computing

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Confidential Computing — protecting data in use through hardware-based Trusted Execution Environments (TEEs).

    175 GitHub stars~2.4k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Ddos Protection

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure DDoS Protection — Network Protection (per-VNet) and IP Protection (per public IP) tiers built on the same always-on Microsoft platform.

    175 GitHub stars~2k tokensUpdated 3 mo ago
    Auto-check passed

Categories

Questions about Security Copilot Agents

What does Security Copilot Agents do?

Guidance for Microsoft Security Copilot agents — autonomous, purpose-built AI agents (e.g., phishing triage, alert triage, conditional access optimization, vulnerability remediation) that work…. Security Copilot Agents is an agent skill from vinayaklatthe/microsoft-security-skills., phishing triage, alert triage, conditional access optimization, vulnerability remediation) that work within Security Copilot.

When should I use Security Copilot Agents?

Security Copilot Agents fits situations like: basic Security Copilot setup; SCU provisioning; promptbooks (use security-copilot).

How do I install Security Copilot Agents in Claude Code?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill security-copilot-agents -a claude-code`. Or copy the skill folder (skills/security-copilot-agents in vinayaklatthe/microsoft-security-skills) into .claude/skills/security-copilot-agents in your project. Claude Code loads it when a task matches its description.

How do I install Security Copilot Agents in Codex?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill security-copilot-agents -a codex`. Or copy the skill folder (skills/security-copilot-agents in vinayaklatthe/microsoft-security-skills) into .agents/skills/security-copilot-agents in your project. Codex loads it when a task matches its description.

Can I use Security Copilot Agents in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vinayaklatthe/microsoft-security-skills --skill security-copilot-agents -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-copilot-agents, .gemini/skills/security-copilot-agents, .github/skills/security-copilot-agents and .opencode/skills/security-copilot-agents in your project.

What does Security Copilot Agents need to run?

SKILL.md names no scripts, command-line tools or credentials: Security Copilot Agents is instructions for the agent only.

Does Security Copilot Agents access the network?

SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.

Is Security Copilot Agents safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Copilot Agents use?

Security Copilot Agents is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Copilot Agents use?

About 2.1k tokens (SKILL.md is roughly 8.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Copilot Agents?

Skills that share tags, products or a category with Security Copilot Agents: Threat Database Update (FlorianBruniaux/claude-code-ultimate-guide, 6.1k stars), Defending Applications (telagod/code-abyss, 243 stars), Skill Scanner (getsentry/skills, 1k stars) and Security Alert Triage (elastic/agent-skills, 592 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Copilot Agents?

vinayaklatthe (a GitHub user) maintains it in vinayaklatthe/microsoft-security-skills, which has 175 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on June 18, 2026.

Source: vinayaklatthe/microsoft-security-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.