securityOfficial
Official Provider SkillView repo
Assess codebase for CWE credentials & secrets vulnerabilities (CWE-259, CWE-321, CWE-732, CWE-778, CWE-798)
Files1 files
SKILL.md111 lines
Loading editor…
Install
RecommendedOne command — your agent picks it up automatically.
Select an AI agent above to see the install command.
or
Manual Install
More stepsDownload the file and paste it into your agent's system prompt.
Skill details
Versionv1.0.0
AuthorMicrosoft
Categorysecurity
Skill IDmicrosoft/github-copilot-modernization/plugins/github-copilot-modernization/skills/cwe-credentials-secrets
Related skills
Analyzing ArchitectureArchitect analysis for rewrite/migration: produces structured architecture artifacts plus global prose research views (project-structure, tech-stack, data-model) for planning, implementation, feature-inventory, and gates. This is the single architect task.
Triggers: "analyze architecture", "analyze existing application", "analyze the codebase", "codebase architecture analysis", "analyze for migration", "prepare migration analysis", "produce migration artifacts", "analyze before rewrite".
NOT forApi Service ContractsGenerate API and service communication contracts with sequence diagramAppmod HooksLifecycle hooks for the modernize-rearchitecture coordinator. Defines hook points, registered actions, and execution rules.Architecture DiagramGenerate architecture diagram with component relationship details from project analysisAssessmentRun a fully local application assessment for one Java, .NET, or JavaScript/TypeScript repositoryAssessment Report ConverterConvert an arbitrary CSV report (e.g. a Black Duck export or a custom migration-issue inventory) into
a schema-valid assessment `report.json` the modernization pipeline can consume — so it appears in the
assessment UI and migration solutions resolve automatically.
This skill is LLM-driven: you read and interpret the CSV yourself and author `report.json` by hand against
the schema. A small helper script only does deterministic lookups (migration solutions, the ruleId for a
solution) and validates