Agent skills

Security skills

Read straight from the source repositories, not from submitted listings. Every skill shows what it does, what is inside, where it came from — and whether attention around its source is actually growing.

Toolclaude-code 29,140codex 4,755cursor 3,111copilot 976windsurf 55cline 34
CategoryWorkflow & Productivity 4,979AI & Agents 3,037Data & Analytics 2,345Code Review & Quality 1,376Backend & API 1,244Security 1,194Design & Presentation 1,154Documentation 965Content & Marketing 916Testing & QA 777DevOps & Cloud 576Databases 550Frontend 469Business & Finance 328Media & Video 257Other 9,833
2,762 found
625672 · page 14 / 58
clickhouse-enterprise-rbacConfigure ClickHouse enterprise RBAC — SQL-based users, roles, row policies, column-level grants, and quota management. Use when…jeremylongshorewritesclickhouse-install-authInstall @clickhouse/client and configure authentication to ClickHouse Cloud or self-hosted. Use when setting up a new ClickHouse…jeremylongshorewritesclickhouse-security-basicsSecure ClickHouse with user management, network restrictions, TLS, and audit logging. Use when hardening a ClickHouse deployment…jeremylongshorecomfyui-gatewayREST API gateway for ComfyUI servers. Workflow management, job queuing, webhooks, caching, auth, rate limiting, and image…sickn33competitor-experience-auditAudit the brand, UX, and site design of the leading sites in a vertical as a set of observable cross-site patterns, producing the…rampstackcocompetitor-profilingWhen the user wants to research, profile, or analyze competitors from their URLs. Also use when the user mentions 'competitor…Infrasity-Labscompliance-checkerCheck affiliate content for FTC compliance and platform rules. Triggers on: "check my content for compliance", "FTC disclosure…Affitorconsent-flowGenerates GDPR/CCPA/DPDP privacy consent flows with granular category preferences, consent state persistence, audit logging, and…rshankraswritescriticism-self-criticism触发:当一项工作已经完成、进入阶段验收、收到批评反馈,或反复出现同类错误需要系统纠偏时调用;常见信号包括 review、audit、retrospective、quality check、纠错与复盘。HughYaucryptotokenkitAccess security tokens and smart cards using CryptoTokenKit. Use when building TKTokenDriver or TKSmartCardTokenDriver…dpearson2699cursor-install-authInstall Cursor IDE and configure authentication across macOS, Linux, and Windows. Triggers on "install cursor", "setup cursor"…jeremylongshorewritescustomerio-security-basicsApply Customer.io security best practices. Use when implementing secure credential storage, PII handling, webhook signature…jeremylongshorewritesdata-validateRun declarative data quality checks and generate a codebook. Checks completeness, distributions, impossible values, duplicates…brycewang-stanforddeployment-pipeline-designDesign multi-stage CI/CD pipelines with approval gates, security checks, and deployment orchestration. Use this skill when…wshobsonec2AWS EC2 virtual machine management — instances, security groups, key pairs, AMIs, EBS volumes, Auto Scaling Groups, Spot…itsmostafaelevenlabs-install-authInstall and configure ElevenLabs SDK authentication for Node.js or Python. Use when setting up a new ElevenLabs project…jeremylongshorewriteselevenlabs-security-basicsApply ElevenLabs security best practices for API keys, webhook HMAC validation, and voice data protection. Use when securing API…jeremylongshorewritesfintel-dataQuery Fintel (fintel.io) institutional market intelligence via the REST API at https://api.fintel.io/v1 with FINTEL_API_KEY…himself65flowstudio-power-automate-debugDebug failing Power Automate cloud flows using the FlowStudio MCP server. The Graph API only shows top-level status codes. This…githubfreshie-inventoryManage the freshie ecosystem inventory database \u2014 a CMDB tracking\ \ all plugins,\nskills, packs, and compliance grades…jeremylongshorewritesfrontend-quality-auditorAudit frontend websites and apps before launch. Use for production-readiness reviews, visual polish checks, responsive QA…TheGoat395fsi-compliance-checkerMaps code, architecture, and infrastructure changes to specific control IDs in PCI-DSS v4.0 and MAS TRM (Singapore financial…sickn33gdpr-compliantApply GDPR-compliant engineering practices across your codebase. Use this skill whenever you are designing APIs, writing data…githubpair-programming结对编程搭档。当用户要求"边写边审"、"结对编程"、"写完自己 review 一遍"、"高可靠地实现",或明确希望代码交付时附带自我审查意见时使用。交付代码的同时输出结构化审查(正确性/安全/性能/可读性/健壮性五维度),重点捕捉 AI…staruhubgeo-optimizerGenerative Engine Optimization (GEO) — make content rank in AI search answers from ChatGPT, Claude, Perplexity, Gemini, and…nowork-studiogithub-codespaces-efficiencyAudit and improve GitHub Codespaces efficiency. Use this skill when a user wants faster Codespaces startup, lower Codespaces…githubgolang-swaggerGolang OpenAPI/Swagger documentation with swaggo/swag — annotation comments (@Summary, @Param, @Success, @Router, @Security)…samberwritesgroq-data-handlingUse when you need to keep PII out of Groq API calls, filter model responses, audit-log conversations, or track token cost and…jeremylongshorewritesgroq-security-basicsApply Groq security best practices for API key management and data protection. Use when securing API keys, implementing least…jeremylongshorewritesguidewire-core-workflow-aAutomate the PolicyCenter account→submission→quote→bind→issue→endorse→renew pipeline including the failure paths — underwriting…jeremylongshorewritesguidewire-install-authAuthenticate production Guidewire Cloud API integrations and survive the auth-side failures — token expiry storms, scope drift…jeremylongshorewritesguidewire-security-and-rbacLock down a Guidewire Cloud API integration so it survives a SOC 2 audit, an NAIC Model Audit Rule review, and a real-world…jeremylongshorewriteshubspot-agency-multi-portalManage 10-100 HubSpot portals for agency clients with credential isolation that prevents cross-portal data contamination…jeremylongshorewriteshubspot-authAuthenticate production HubSpot integrations and survive the auth-side failures — 30-min token expiry storms, 500K daily…jeremylongshorewriteshubspot-deal-pipeline-automationAutomate and audit HubSpot deal pipeline operations without destroying real pipeline — covering stage automation loops…jeremylongshorewritesimprove-reactSurvey a whole React codebase as a senior React engineer, using React Doctor's scan as evidence, then produce a prioritized audit…millioncoincident-reporting-navigatorUse when a security incident, data breach, or actively exploited vulnerability raises the question "who must we notify, where…lawve-aiintercom-debug-bundleCollect Intercom debug evidence for support tickets and troubleshooting. Use when encountering persistent Intercom API issues…jeremylongshoreintercom-enterprise-rbacConfigure Intercom enterprise OAuth, admin roles, and app-level access control. Use when implementing OAuth integration, managing…jeremylongshorewritesintercom-security-basicsApply Intercom security best practices for tokens, webhook verification, and scopes. Use when securing access tokens…jeremylongshorewritesios-simulatorManages iOS Simulator devices and app tests with xcrun simctl: lifecycle, install/launch, push and location simulation, privacy…dpearson2699ismExpert Australian Information Security Manual (ISM) advisor for government entities and their supply chains. Use for ISM control…Sushegaadk8s-security-policiesComprehensive guide for implementing NetworkPolicy, PodSecurityPolicy, RBAC, and Pod Security Standards in Kubernetes.sickn33k8s-security-policiesImplement Kubernetes security policies including NetworkPolicy, PodSecurityPolicy, and RBAC for production-grade security. Use…wshobsonkicad-reviewDesign review and validation workflow for KiCAD projects via MCP tools. Triggers on: "review my design", "check for errors"…mixelpixxklaviyo-install-authInstall and configure Klaviyo Node.js SDK with API key authentication. Use when setting up a new Klaviyo integration, configuring…jeremylongshorewritesklaviyo-security-basicsApply Klaviyo security best practices for API key management and access control. Use when securing API keys, configuring OAuth…jeremylongshorewriteslindy-enterprise-rbacConfigure enterprise role-based access control for Lindy AI workspaces. Use when setting up team permissions, managing workspace…jeremylongshorewrites
← Prev14 / 58Next →
How the catalog works
What is an agent skill?

A folder with a SKILL.md inside — instructions, and often scripts and assets, that an AI agent loads when the task matches. Claude Code, Codex, Cursor and Copilot all read the same format, so one skill usually works across them.

Where does this catalog come from?

We read 660 source repositories straight from their file trees rather than from submitted listings — what you see is what is actually published. 98 repositories were rejected because they advertise skills but contain none: link lists, not folders.

Why is there no install counter?

Because install counts live in the registry that serves `npx skills add`, and that is not ours — publishing a number we cannot verify would be worse than showing none. Instead we show where a skill comes from and whether attention around its source is actually growing, measured from our own weekly snapshots.

Do you deduplicate?

Yes, and it matters more than expected. Aggregator repositories republish the same skill in several places — one source carried 6,317 SKILL.md files for 2,001 actual skills. We collapse by folder name and keep the canonical copy, so the catalog counts things, not copies.

Keep going