mcpbeat

Secure By Design

microsoft/secure-by-design

Secure by Design principles knowledge base for assessing security-first design, development, and deployment across the software lifecycle.

13k tokens
context cost
the whole folder, loaded on every use
13
files
instructions only
0
copies elsewhere
how many repositories repackaged it
1313
stars on the repo
on the repository, not the skill itself

Install

one command, takes just this skill from the repository
npx skills add https://github.com/microsoft/hve-core --skill secure-by-design

What comes with it

48 244 bytes besides the instruction
references/00-principle-index.md
references/01-security-governance.md
references/02-risk-driven-approach.md
references/03-secure-product-development.md
references/04-supply-chain-security.md
references/05-usable-security-controls.md
references/06-detect-and-respond.md
references/07-flexible-architecture.md
references/08-minimize-attack-surface.md
references/09-defense-in-depth.md
references/10-continuous-assurance.md
references/11-secure-deprecation.md

The instruction itself

6 sections, as written by the author

Secure by Design — Skill Entry

This SKILL.md is the entrypoint for the Secure by Design skill.

The skill synthesizes the UK Government Secure by Design Principles (10 principles) and the

Australian ASD/ACSC Secure by Design Foundations (6 foundations) into structured,

machine-readable references that an agent can query to identify, assess, and improve adherence to

secure-by-design practices across the software lifecycle.

Normative references (Secure by Design)

  • 00 Principle Index
  • 01 Security Governance
  • 02 Risk-Driven Approach
  • 03 Secure Product Development
  • 04 Supply Chain Security
  • 05 Usable Security Controls
  • 06 Detect and Respond
  • 07 Flexible Architecture
  • 08 Minimize Attack Surface

10. 09 Defense in Depth

11. 10 Continuous Assurance

12. 11 Secure Deprecation

Skill layout

  • SKILL.md — this file (skill entrypoint).
  • references/ — the Secure by Design normative documents.
  • 00-principle-index.md — index of all principle identifiers, categories, source mappings, and cross-references.
  • 01 through 11 — one document per synthesized principle area merging UK and AU guidance.

Third-Party Attribution

UK Government Secure by Design Principles

  • Copyright: Crown Copyright, UK Government Security Group
  • License: Open Government Licence v3.0 (OGL-UK-3.0)
  • Source: <https://www.security.gov.uk/policy-and-guidance/secure-by-design/principles/>
  • Modifications: Synthesized into structured principle-checklist format with cross-references; merged with Australian guidance into unified principle areas
  • Trademark: Use of UK Government content does not imply endorsement

Australian ASD/ACSC Secure by Design Foundations

  • Copyright: © Commonwealth of Australia, Australian Signals Directorate
  • License: Creative Commons Attribution 4.0 (CC-BY-4.0)
  • Source: <https://www.cyber.gov.au/business-government/secure-design/secure-by-design/secure-by-design-foundations>
  • Modifications: Synthesized into structured principle-checklist format with cross-references; merged with UK guidance into unified principle areas
  • Trademark: Use of ASD/ACSC content does not imply endorsement

How to use it

Copy the folder

Take microsoft/secure-by-design from the repository into ~/.claude/skills for personal use, or into .claude/skills inside a project.

Check the name does not clash

The agent identifies a skill by the name field in its header. Two skills with the same name cannot sit side by side — one of them will be ignored.