HVE Core is a collection of agents, prompts, coding instructions, and skills for building repeatable software-development workflows with GitHub Copilot. It is intended for individuals and teams that want structured AI-assisted research, planning, implementation, and review, while the catalogue entries provide many of its reusable workflow components.
Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add microsoft/hve-core --skill engagement-reportinggit clone --depth 1 https://github.com/microsoft/hve-coreWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/microsoft/hve-core/engagement-reporting)<a href="https://agentmods.dev/skills/microsoft/hve-core/engagement-reporting"><img src="https://agentmods.dev/badge/skills/microsoft/hve-core/engagement-reporting.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00022 | $0.01827 |
| Opus 5 | $0.00011 | $0.00914 |
| Sonnet 5 | $0.00004 | $0.00365 |
| Haiku 4.5 | $0.00002 | $0.00183 |
Grade A, and why
engagement-reporting scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 185 lines — stays where its author put it; the contents beside it link to each section on GitHub.
engagement-reporting
Goal
Produce an audience-calibrated engagement report whose factual claims trace to primary sources. Preserve source coverage, review decisions, and retention state without publishing or sending the report.
This skill and its bundled references are the single runtime authority whether the skill is invoked directly or through the Engagement Report Generator. A parent may coordinate interaction, state, and bounded subagent dispatch, but it must not replace or restate this workflow.
Read the bundled references when entering their phase:
- Research contract for source discovery, WorkIQ retrieval, board normalization, and coverage gates
- Report contract for synthesis, traceability, review, output, and talk tracks
- Distribution contract for optional Outlook draft creation
Use the engagement template to scaffold engagement configuration and the weekly standard template for the default weekly report contract. Render Outlook draft bodies as faithful HTML; never manually flatten Markdown or substitute plain text.
Flow
- Confirm the report type, reporting period, audience, and output format. For
an ordinary weekly request, use
weekly-standardand do not invent a consolidated or executive format. Ask before using an unsupported report type. - Read
engagement.yaml; validate required engagement and stakeholder fields, require workspace-relative confined local paths, then load optional canonical terminology and report options - Before any artifact write, verify that
.working/,reports/,transcripts/, andengagement.yamlare protected by effective ignore rules. Stop withNeeds ignore protectionwithout creating any artifact when a path is unprotected - Before the first source query, display the required data sensitivity notice below
- Before the first WorkIQ query, obtain explicit user confirmation and accept the WorkIQ EULA when acceptance is required
- Create
.working/{date}-{report-type}/using the structure inreferences/report-contract.md - Follow
references/research.mdto collect and normalize configured source evidence - Ask for manual context only when a material coverage gap remains; do not interrupt a routine run when current evidence is sufficient
- Draft against the selected template and enforce its exact audience-facing layout; preserve claim-level source references only in working artifacts
- Run the review gate in
references/report-contract.md. Apply it inline for routine weekly reports; dispatch the Engagement Report Reviewer only for high-stakes, complex, or explicitly requested independent review - When Council validation is explicitly enabled, run at least two isolated
Council Critic evaluations. Dispatch the Council Arbiter in
proposalmode, obtain user decisions on material edits, then dispatch it inpersistencemode with the validated reporting date, report-type slug, and approved decision set. Use the manual Council prompt in separate model sessions when independent agent runs are unavailable - Present the final draft for explicit user approval and save the approved output
- When Outlook distribution is configured, ask separately for approval to
create the draft, then follow
references/distribution.mdthrough the Engagement Report Outlook Drafter - Complete the retention handoff
What ships with it
5 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 185 lines · 22 tokens per session scan A 04413dc4b7c5
engagement-reporting is a skill published in the GitHub repository microsoft/hve-core (1,436 stars, last pushed yesterday), licensed MIT. It adds 22 tokens to every session and 1,827 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-05.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
local-ai-agents
Build local-first AI agents that run entirely on a developer workstation with Microsoft Foundry Local and Qwen function-calling models. Covers Small Language Models (SLMs), the OpenAI-compatible local endpoint, sandboxed local tools, local RAG with Chroma, local MCP servers, hybrid cloud/local routing, and the…
next-cache-components-adoption
Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…
next-partial-prefetching-adoption
Turn on Partial Prefetching in a Next.js app and work through the insights it surfaces. Use when the user wants to enable or adopt Partial Prefetching, flip the partialPrefetching flag, opt routes in with export const prefetch = 'partial', audit Link prefetch={true} behavior, preserve existing prefetched UI with…
chronicle
Analyze Copilot session history for standup reports, usage tips, session search, and session reindexing. Use when the user asks for a standup, daily summary, usage tips, workflow recommendations, wants to search or find past sessions by keyword/file/PR, wants to reindex their session store, or asks about deleting…
babysit-pr
Babysit a GitHub pull request after creation by continuously polling review comments, CI checks/workflow runs, and mergeability state until the PR is merged/closed or user help is required. Diagnose failures, retry likely flaky failures up to 3 times, auto-fix/push branch-related issues when appropriate, and keep…