Agent skills

Security skills

Read straight from the source repositories, not from submitted listings. Every skill shows what it does, what is inside, where it came from — and whether attention around its source is actually growing.

Toolclaude-code 29,140codex 4,755cursor 3,111copilot 976windsurf 55cline 34
CategoryWorkflow & Productivity 4,979AI & Agents 3,037Data & Analytics 2,345Code Review & Quality 1,376Backend & API 1,244Security 1,194Design & Presentation 1,154Documentation 965Content & Marketing 916Testing & QA 777DevOps & Cloud 576Databases 550Frontend 469Business & Finance 328Media & Video 257Other 9,833
2,762 found
817864 · page 18 / 58
audit-aggregatorAggregate and deduplicate findings from multiple audit reportsmajiayu000auditGenerate usage report for MiniMax and token optimization Use when: (1) /audit is invoked, (2) task relates to audit functionality.majiayu000audit-api-consistencyAudit existing API endpoints for consistency when the user asks to check API quality, review API patterns, audit endpoints, or…majiayu000writesaudit-bugsAnalyze historical bug patterns by mining Claude Code project logs for /autoskillit:investigate skill invocations since a…majiayu000audit-bugsAnalyze historical bug patterns by mining Claude Code project logs for /investigate skill invocations since a specified date.…majiayu000audit-coverageAudit MVP component, platform mechanism, and advanced mechanism coverage for analyzed agents, identifying gaps and suggesting…majiayu000audit-frictionScan Claude Code project logs for friction patterns — repeated failures, approach loops, tool errors, misunderstanding cycles…majiayu000audit-frictionScan Claude Code project logs for friction patterns — repeated failures, approach loops, tool errors, misunderstanding cycles…majiayu000audit-reportPhase 3: Generate and present audit report for user reviewmajiayu000auditProject-wide health audit pipeline that fans out to all analysis skills in parallel, evaluates findings, and produces a unified…majiayu000auditProject-wide health audit pipeline that fans out to all analysis skills in parallel, evaluates findings, and produces a unified…majiayu000Audit Trails for AgentsComprehensive guide to implementing audit trails and logging for AI agents including tracing, observability, compliance, and…majiayu000audit-websiteAudit websites for SEO, performance, security, technical, content, and 15 other issue cateories with 230+ rules using the…majiayu000writesaudit-websiteAudit websites for SEO, technical, content, and security issues using squirrelscan CLI. Returns LLM-optimized reports with health…majiayu000audit-website(中文)Audit websites for SEO, performance, security, technical, content, and 15 other issue cateories with 230+ rules using the…majiayu000writesaudit-websiteAudit websites for SEO, performance, security, technical, content, and 15 other issue cateories with 230+ rules using the…majiayu000writesaudit-website使用 squirrelscan CLI(squirrel)对网站进行审计,覆盖 SEO、技术、内容、性能、安全等 140+ 规则。当需要分析网站健康、排查技术 SEO、检查死链、校验 meta…majiayu000auth-implementation-patternsBuild secure, scalable authentication and authorization systems using industry-standard patterns and modern best practices.sickn33auth-implementation-patternsMaster authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable…wshobsonauth-nodejs-cloudbaseComplete guide for CloudBase Auth using the CloudBase Node SDK – caller identity, user lookup, custom login tickets, and…majiayu000auth-web-cloudbaseCloudBase Web Authentication Quick Guide for frontend integration after auth-tool has already been checked. Provides concise and…TencentCloudBaseauth-wechat-miniprogramCloudBase WeChat Mini Program native authentication guide. This skill should be used when users need mini program identity…TencentCloudBaseautoAutonomous task execution with testing and security. Works through all tasks without stopping.majiayu000writesautonomous-agent-harnessSet up autonomous coding agent projects with long-running harnesses using Archon MCP for state management. Creates complete…majiayu000autonomous-agent-readinessAssess a codebase's readiness for autonomous agent development and provide tailored recommendations. Use when asked to evaluate…majiayu000autoresearchALWAYS activate when user types /autoresearch, $autoresearch plan, $autoresearch debug, $autoresearch fix, $autoresearch…majiayu000aws-cost-operationsAWS cost optimization, monitoring, and operational excellence expert. Use when analyzing AWS bills, estimating costs, setting up…majiayu000aws-sdk-java-v2-coreProvides AWS SDK for Java 2.x client configuration, credential resolution, HTTP client tuning, timeout, retry, and testing…majiayu000writesaws-sdk-java-v2-secrets-managerProvides AWS Secrets Manager patterns for AWS SDK for Java 2.x, including secret retrieval, caching, rotation-aware access, and…majiayu000writesaws-security-scannerAWS security configuration scanning and hardening using Prowler, Security Hub, and AWS Configa5c-aiwritesaxiom-auditAudit Axiom logs to identify and prioritize errors and warnings, research probable causes, and flag log smells. Use when user…majiayu000writesazure-api-managementAPI gateway and management with Azure API Management. Configure policies, rate limiting, authentication, and developer portal.…majiayu000azure-api-managementExpert knowledge for Azure API Management development including troubleshooting, best practices, decision making, architecture &…majiayu000azure-language-serviceExpert knowledge for Azure AI Language development including troubleshooting, best practices, decision making, architecture &…majiayu000azure-machine-learningExpert knowledge for Azure Machine Learning development including troubleshooting, best practices, decision making, architecture…majiayu000azure-mapsExpert knowledge for Azure Maps development including troubleshooting, best practices, decision making, architecture & design…majiayu000azure-metrics-advisorExpert knowledge for Azure AI Metrics Advisor development including decision making, security, configuration, and integrations &…majiayu000azure-resource-visualizerAnalyze Azure resource groups and generate detailed Mermaid architecture diagrams showing the relationships between individual…majiayu000azure-resource-visualizerAnalyze Azure resource groups and generate detailed Mermaid architecture diagrams showing the relationships between individual…majiayu000azure-security-keyvault-keys-javaAzure Key Vault Keys Java SDK for cryptographic key management. Use when creating, managing, or using RSA/EC keys, performing…microsoftazure-security-keyvault-secrets-javaAzure Key Vault Secrets Java SDK for secret management. Use when storing, retrieving, or managing passwords, API keys, connection…microsoftazure-security-scannerAzure security configuration scanning and hardening using Azure Security Center, Azure Policy, and ScoutSuitea5c-aiwritesazure-smart-city-iot-solution-builderDesign and plan end-to-end Azure IoT and Smart City solutions: requirements, architecture, security, operations, cost, and a…githubbackend-apiCreate Express.js API endpoints for IntelliFill following established patterns (Prisma, Supabase auth, Joi validation, Bull…majiayu000backend-apiBuild FastAPI REST APIs with CORS, JWT auth, Pydantic validation, async endpoints, and proper error handling. Use when creating…majiayu000backend-api-patternsBackend API implementation patterns for scalability, security, and maintainability. Use when building APIs, services, and backend…majiayu000benchmark-datasetsStandard datasets and benchmarks for evaluating AI security, robustness, and safetymajiayu000bias-and-fairness-auditingAudit pilot data, models, and workflows for bias and inclusivity issues. Use when evaluating fairness across demographic groups…majiayu000
← Prev18 / 58Next →
How the catalog works
What is an agent skill?

A folder with a SKILL.md inside — instructions, and often scripts and assets, that an AI agent loads when the task matches. Claude Code, Codex, Cursor and Copilot all read the same format, so one skill usually works across them.

Where does this catalog come from?

We read 660 source repositories straight from their file trees rather than from submitted listings — what you see is what is actually published. 98 repositories were rejected because they advertise skills but contain none: link lists, not folders.

Why is there no install counter?

Because install counts live in the registry that serves `npx skills add`, and that is not ours — publishing a number we cannot verify would be worse than showing none. Instead we show where a skill comes from and whether attention around its source is actually growing, measured from our own weekly snapshots.

Do you deduplicate?

Yes, and it matters more than expected. Aggregator repositories republish the same skill in several places — one source carried 6,317 SKILL.md files for 2,001 actual skills. We collapse by folder name and keep the canonical copy, so the catalog counts things, not copies.

Keep going