Agent skills

Security skills

Read straight from the source repositories, not from submitted listings. Every skill shows what it does, what is inside, where it came from — and whether attention around its source is actually growing.

Toolclaude-code 29,140codex 4,755cursor 3,111copilot 976windsurf 55cline 34
CategoryWorkflow & Productivity 4,979AI & Agents 3,037Data & Analytics 2,345Code Review & Quality 1,376Backend & API 1,244Security 1,194Design & Presentation 1,154Documentation 965Content & Marketing 916Testing & QA 777DevOps & Cloud 576Databases 550Frontend 469Business & Finance 328Media & Video 257Other 9,833
2,762 found
769816 · page 17 / 58
ai-engineering-toolkit6 production-ready AI engineering workflows: prompt evaluation (8-dimension scoring), context budget planning, RAG pipeline…majiayu000ai-ethicsImplement ethical AI practices and responsible AI governance. Use for: identifying and mitigating bias in datasets and models…majiayu000ai-ethics-reviewConduct an ethical review of an AI or ML feature, model, or product. Use when asked to run an AI ethics review, assess AI risks…majiayu000ai-mlopsProduction MLOps and ML/LLM/agent security skill for deploying and operating ML systems in production (registry + CI/CD, serving…majiayu000ai-sdk-coreBuild backend AI with Vercel AI SDK v6 stable. Covers Output API (replaces generateObject/streamObject), speech synthesis…majiayu000ai-securityThis skill should be used when the user asks to "scan AI systems for security threats", "check for prompt injection…majiayu000aiml-securityAI/ML model security testing and adversarial research capabilities. Generate adversarial examples, test model robustness, perform…a5c-aiwritesanalytics-strategyDesign measurement frameworks including event taxonomy, KPI hierarchy, dashboard architecture, attribution models, and analytics…rampstackcoanalyzeRun code analyzers (unused packages, code quality, security). Use when user wants to analyze the codebase or runs /analyze.majiayu000writesanalyze-dependenciesAudit project dependencies for risk when the user asks to check dependencies, audit packages, review dependency health, check for…majiayu000writesanalyzeInvoke IMMEDIATELY via python script when user requests codebase analysis, architecture review, security assessment, or quality…majiayu000analyze-specAnalyze an existing spec for inconsistencies, missing information, ambiguities, and structure issues. Use when user says "analyze…majiayu000analyze-specAnalyze an existing spec for inconsistencies, missing information, ambiguities, and structure issues. Use when user says "analyze…majiayu000animeCLI for AI agents to search and lookup anime info for their humans. Uses Jikan (unofficial MyAnimeList API). No auth required.majiayu000annotator-input-parity-checkBefore designing, training, or auditing ANY model that replicates human-annotated labels, audit the annotation protocol's INPUT —…kennethkhoocyAnnualReportsAnnual security report aggregation and analysis. USE WHEN annual reports, security reports, threat reports, industry reports…majiayu000anti-reversing-techniquesAUTHORIZED USE ONLY: This skill contains dual-use security techniques. Before proceeding with any bypass or analysis: > 1.sickn33computer-use-agentsBuild AI agents that interact with computers like humans do - viewing screens, moving cursors, clicking buttons, and typing text.…majiayu000antigravity-workflowsOrchestrate multiple Antigravity skills through guided workflows for SaaS MVP delivery, security audits, AI agent builds, and…sickn33koan-api-buildingEntityController<T>, custom routes, payload transformers, auth policiesmajiayu000api-designDesign and review REST/GraphQL APIs for correctness, consistency, and security. Generates OpenAPI specs, validates endpoint…majiayu000writesapi-design-expertExpert-level API design principles, REST, GraphQL, versioning, and API best practicesmajiayu000writesapi-documentationUse when API code changes (routes, endpoints, schemas). Enforces Swagger/OpenAPI sync. Pauses work if documentation has drifted…majiayu000api-endpoint-builderBuilds production-ready REST API endpoints with validation, error handling, authentication, and documentation. Follows best…sickn33api-fetch-with-authCreate authenticated API fetch function in Next.js. Use for frontend API calls.majiayu000api-filtering-sortingBuilds flexible API filtering and sorting systems with query parameter parsing, validation, and security. Use when implementing…majiayu000api-filtering-sortingBuilds flexible API filtering and sorting systems with query parameter parsing, validation, and security. Use when implementing…majiayu000api-handlerUse withApiHandler for all API routes. It eliminates boilerplate and ensures consistent auth, validation, and error handling.majiayu000api-key-auth-setupConfigure api key auth setup operations. Auto-activating skill for API Development. Triggers on: api key auth setup, api key auth…majiayu000writesapi-reviewUse this skill to review public API changes, design new surfaces, audit consistency, and validate documentation completeness. Run…majiayu000api-reviewZero-assumption API design review. Uses the API as a consumer first, then audits contracts, error shapes, auth model, pagination…majiayu000api-sdkUse when working with the TypeScript SDK for making API calls to Bknd, handling authentication, and managing data operations from…majiayu000clix-api-triggered-campaignsHelps developers configure API-triggered campaigns in the Clix console and trigger them from backend services with safe auth…majiayu000apollo-enterprise-rbacEnterprise role-based access control for Apollo.io. Use when implementing team permissions, restricting data access, or setting…jeremylongshorewritesapollo-security-basicsApply Apollo.io API security best practices. Use when securing Apollo integrations, managing API keys, or implementing secure…jeremylongshoreapp-deep-reviewDeep analysis of an AinexSuite app with 6 parallel review agents. Use when you want comprehensive modernization recommendations…majiayu000writesarch-apiAPI architecture: REST design, versioning, HATEOAS, auth patterns, OpenAPI docs, gateway patternsmajiayu000architect-detective⚡ PRIMARY TOOL for: 'what's the architecture', 'system design', 'how are layers organized', 'find design patterns', 'audit…majiayu000writesArchitecture AuditComprehensive **project** consistency review across code, documentation, diagrams, and configurationmajiayu000architecture-auditPerform comprehensive software architecture audits to identify improvements for robustness, changeability, and testability. Use…majiayu000architecture-reviewBefore committing to an implementation plan, run this skill to stress-test the proposed architecture. Catches over-engineering…majiayu000asc-aso-auditRun an offline ASO audit on canonical App Store metadata under `./metadata` and surface keyword gaps using Astro MCP. Use after…rorkaiasc-cli-usageGuidance for using the App Store Connect CLI in this repo (flags, output formats, pagination, auth, and discovery). Use when…majiayu000assemblyai-transcriptionUse this skill when an agent needs AssemblyAI for speech-to-text or speech-understanding work in media production, including…calesthioassumption-auditUse as the mandatory evidence gate before signing off on any strategy, PRD, or business case—audits every key claim against…majiayu000assumption-validatorSystematically surface, classify, and stress-test assumptions in decisions, strategies, and plans. Transforms hidden assumptions…majiayu000attack-tree-constructionBuild comprehensive attack trees to visualize threat paths. Use when mapping attack scenarios, identifying defense gaps, or…sickn33attack-tree-constructionBuild comprehensive attack trees to visualize threat paths. Use when mapping attack scenarios, identifying defense gaps, or…wshobson
← Prev17 / 58Next →
How the catalog works
What is an agent skill?

A folder with a SKILL.md inside — instructions, and often scripts and assets, that an AI agent loads when the task matches. Claude Code, Codex, Cursor and Copilot all read the same format, so one skill usually works across them.

Where does this catalog come from?

We read 660 source repositories straight from their file trees rather than from submitted listings — what you see is what is actually published. 98 repositories were rejected because they advertise skills but contain none: link lists, not folders.

Why is there no install counter?

Because install counts live in the registry that serves `npx skills add`, and that is not ours — publishing a number we cannot verify would be worse than showing none. Instead we show where a skill comes from and whether attention around its source is actually growing, measured from our own weekly snapshots.

Do you deduplicate?

Yes, and it matters more than expected. Aggregator repositories republish the same skill in several places — one source carried 6,317 SKILL.md files for 2,001 actual skills. We collapse by folder name and keep the canonical copy, so the catalog counts things, not copies.

Keep going