Agent skills

Security skills

Read straight from the source repositories, not from submitted listings. Every skill shows what it does, what is inside, where it came from — and whether attention around its source is actually growing.

Toolclaude-code 29,140codex 4,755cursor 3,111copilot 976windsurf 55cline 34
CategoryWorkflow & Productivity 4,979AI & Agents 3,037Data & Analytics 2,345Code Review & Quality 1,376Backend & API 1,244Security 1,194Design & Presentation 1,154Documentation 965Content & Marketing 916Testing & QA 777DevOps & Cloud 576Databases 550Frontend 469Business & Finance 328Media & Video 257Other 9,833
2,762 found
529576 · page 12 / 58
azure-virtual-machinesExpert knowledge for Azure Virtual Machines development including troubleshooting, best practices, decision making, architecture…MicrosoftDocsbuilding-api-authenticationBuild secure API authentication systems with OAuth2, JWT, API keys, and session management. Use when implementing secure…jeremylongshorewritesbuilding-gitops-workflowsExecute use when constructing GitOps workflows using ArgoCD or Flux. Trigger with phrases like "create GitOps workflow", "setup…jeremylongshorewriteschecking-hipaa-complianceCheck HIPAA compliance for healthcare data security requirements. Use when auditing healthcare applications. Trigger with 'check…jeremylongshorewritescis-controlsExpert CIS Controls v8 (CIS Top 18) advisor — implementation group scoping (IG1/IG2/IG3), control gap assessments…Sushegaadclaude-md-improverAudit and improve CLAUDE.md files in repositories. Use when user asks to check, audit, update, improve, or fix CLAUDE.md files.…anthropicsclone-audit-mrlv3nl4Audit cloned or reimplemented websites for fidelity gaps, tracking scripts, source-brand and language residue, placeholders, and…nexu-iocmmcExpert CMMC 2.0 (Cybersecurity Maturity Model Certification) advisor for US defense contractors and subcontractors in the Defense…Sushegaadcode-review-webReview web application code for bugs, security issues, performance problems, and stack-specific anti-patterns. Use this skill…rampstackcocontainer-security-hardeningHarden Docker/container images and runtime deployments with secure base images, non-root users, CVE scanning, SBOM/signing…sickn33dependabotComprehensive guide for configuring and managing GitHub Dependabot. Use this skill when users ask about creating or optimizing…githubdeps-vetRecord a vetted Hex package version in hex_vet.exs after a security review — manages the audit ledger, not the scanner. Use to…oliver-kriskadesign-systemBuild or audit a design system including component library, design tokens, naming conventions, contribution model, and…rampstackcofirebase-apk-scannerScans Android APKs for Firebase security misconfigurations including open databases, storage buckets, authentication issues, and…trailofbitsfounder-agreement-drafting-stephane-boghossianA drafting-and-review copilot for a founders' / co-founders' agreement — the terms fixing equity, vesting, IP, roles, control…lawve-aiwritesgame-feelGame feel ("juice") for Apple apps — celebration choreography, haptic vocabulary design, sound-effect layers, and the…rshankrasgolang-how-toGolang skills orchestrator — always active on any Golang coding, review, debug, or setup task. Reads the task context and loads…samberwritesgroq-install-authInstall and configure Groq SDK authentication for TypeScript or Python. Use when setting up a new Groq integration, configuring…jeremylongshorehtml-ppt-zhangzara-retro-windowsAn IT security-awareness training on spotting phishing — the tells, the drill, and what to do in the first 60 seconds. Built as a…nexu-iohuashu-takram-soft-techOpen Design procurement & security leave-behind: the one-pager-plus a buying committee can forward and approve internally. Built…nexu-ioimproveSurvey any codebase as a senior advisor and produce prioritized, self-contained implementation plans for OTHER models/agents to…shobcoderinsecure-defaultsDetects fail-open insecure defaults (hardcoded secrets, weak auth, permissive security) that allow apps to run insecurely in…trailofbitswritesintercom-install-authInstall and configure Intercom API authentication with access tokens or OAuth. Use when setting up a new Intercom integration…jeremylongshorewritesismExpert Australian Information Security Manual (ISM) advisor for government entities and their supply chains. Use for ISM control…lawve-aiiso27001Expert ISO 27001 compliance assistant for security and compliance teams. Use this skill whenever a user asks about ISO 27001 or…Sushegaadklingai-install-authSet up Kling AI API authentication with JWT tokens. Use when starting a new Kling AI integration or troubleshooting auth issues.…jeremylongshorewritesgoogle-ads-landingScore and diagnose Google Ads landing pages. Use when asked to audit a landing page, check landing page quality, diagnose…nowork-studiolinkedin-post-writerDraft a new LinkedIn post from scratch using one of 16 2026 hook formulas (anaphora, R.I.P., year-pivot, time-anchor…sergebulaevlogging-api-requestsMonitor and log API requests with correlation IDs, performance metrics, and security audit trails. Use when auditing API requests…jeremylongshorewritesmsbuild-antipatternsDetect and fix MSBuild anti-patterns in project and build files. USE WHEN asked to review, audit, lint, clean up, or code-review…dotnetmsgraph-sdkIntegrate Microsoft Graph SDK into any project — .NET, TypeScript/JavaScript, or Python. Covers auth patterns (client…githubnis2EU NIS2 Directive (Directive (EU) 2022/2555) compliance advisor for essential and important entities: entity classification, Art.…Sushegaadnist-800-53NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT…Sushegaadnotion-security-basicsApply Notion API security best practices for integration tokens, OAuth2 flows, least-privilege capabilities, and page-level…jeremylongshorewritesnzismExpert New Zealand Information Security Manual (NZISM) advisor for NZ government agencies and their supply chains. Use for NZISM…Sushegaadoma-scmSCM (software configuration management) and Git: branching, merges, conflicts, worktrees, baselines, audit readiness, plus…first-flukeopenrouter-install-authSet up OpenRouter API authentication and configure API keys. Use when starting a new OpenRouter integration, rotating keys, or…jeremylongshorewritesacademic-paper-verifyThoroughly verify all code, tables, figures, modeling decisions, and quantitative claims in an academic paper against its source…brycewang-stanfordpci-complianceExpert PCI DSS compliance advisor covering PCI DSS v4.0.1 (current) and v4.0. Use this skill whenever a user asks about PCI DSS…Sushegaadperformance-optimizationDiagnose and fix web performance issues including Core Web Vitals (LCP, INP, CLS), bundle size, asset optimization, render…rampstackcophx-deps-vetRecord a vetted Hex package version in hex_vet.exs after a security review — manages the audit ledger, not the scanner. Use to…oliver-kriskaproposition-audit-anthony-searlePost-hoc verification and trust audit of AI-generated factual and interpretive claims. Classifies claims by type and salience…lawve-aiscanning-api-securityDetect API security vulnerabilities including injection, broken auth, and data exposure. Use when scanning APIs for security…jeremylongshorewritesscanning-database-securityProcess use when you need to work with security and compliance. This skill provides security scanning and vulnerability detection…jeremylongshorewritesscanning-for-secretsDetect exposed secrets, API keys, and credentials in code. Use when auditing for secret leaks. Trigger with 'scan for secrets'…jeremylongshorewritessdk-docs-auditorAudits any SDK documentation site and produces a fully scored, downloadable HTML report. Use this skill whenever a user provides…Infrasity-Labssecret-scanningGuide for configuring and managing GitHub secret scanning, push protection, custom patterns, and secret alert remediation. For…githubsecurity-threat-modelRepository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and…tech-leads-club
← Prev12 / 58Next →
How the catalog works
What is an agent skill?

A folder with a SKILL.md inside — instructions, and often scripts and assets, that an AI agent loads when the task matches. Claude Code, Codex, Cursor and Copilot all read the same format, so one skill usually works across them.

Where does this catalog come from?

We read 660 source repositories straight from their file trees rather than from submitted listings — what you see is what is actually published. 98 repositories were rejected because they advertise skills but contain none: link lists, not folders.

Why is there no install counter?

Because install counts live in the registry that serves `npx skills add`, and that is not ours — publishing a number we cannot verify would be worse than showing none. Instead we show where a skill comes from and whether attention around its source is actually growing, measured from our own weekly snapshots.

Do you deduplicate?

Yes, and it matters more than expected. Aggregator repositories republish the same skill in several places — one source carried 6,317 SKILL.md files for 2,001 actual skills. We collapse by folder name and keep the canonical copy, so the catalog counts things, not copies.

Keep going