Agent skills

Security skills

Read straight from the source repositories, not from submitted listings. Every skill shows what it does, what is inside, where it came from — and whether attention around its source is actually growing.

Toolclaude-code 29,140codex 4,755cursor 3,111copilot 976windsurf 55cline 34
CategoryWorkflow & Productivity 4,979AI & Agents 3,037Data & Analytics 2,345Code Review & Quality 1,376Backend & API 1,244Security 1,194Design & Presentation 1,154Documentation 965Content & Marketing 916Testing & QA 777DevOps & Cloud 576Databases 550Frontend 469Business & Finance 328Media & Video 257Other 9,833
2,762 found
9611,008 · page 21 / 58
data-flow-auditDetect split data source anti-patterns and scattered business rule duplication where the same logic is reimplemented across…majiayu000writesdecision-ownership-audit-ignacio-adrian-lererAudits AI-assisted legal, compliance, governance, and institutional decisions before reliance to determine whether the…lawve-aidecision-quality-auditThis skill supports three modes: Create, Update, and Find.majiayu000deck-safety-alert红琥珀警示色 + hazard 条纹 + L1/L2/L3 tier 卡片 + 删除线标题nexu-iodeep-analysisAnalytical thinking patterns for comprehensive evaluation, code audits, security analysis, and performance reviews. Provides…majiayu000writesdeepgram-security-basicsApply Deepgram security best practices for API key management and data protection. Use when securing Deepgram integrations…jeremylongshorewritesdeliverability-health-checkAudit your email deliverability by analyzing bounce rates, open rate anomalies, and sending patterns across reps and sequences to…majiayu000deliverability-qaUse when the user asks to "run a deliverability pre-flight before I send", "check my SPF/DKIM/DMARC/BIMI", "why am I landing in…aaron-he-zhudependency-management-deps-auditYou are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security.…sickn33dependency-managementManage third-party libraries, runtimes, and SaaS dependencies. Use this skill when setting an update cadence, responding to…rampstackcodesign-review-gateParallel design review by 6 specialist agents (PM, Architect, Designer, Security Design, UX, CTO) with mandatory unanimous…a5c-aiwritesdesigning-enterprise-auditUse when designing enterprise audit is required during enterprise product work, especially when the result must be traceable…casioreview20-glitchdevbooks-convergence-auditdevbooks-convergence-audit:以证据优先、声明存疑的原则评估 DevBooks 工作流收敛性,检测"西西弗斯反模式"和"假完成"。主动验证而非信任文档声明。用户说"评估收敛性/检查升级健康度/西西弗斯检测/工作流审计"等时使用。majiayu000writesdeveloper-detective⚡ PRIMARY TOOL for: 'how does X work', 'find implementation of', 'trace data flow', 'where is X defined', 'audit integrations'…majiayu000writesDevice InspectionExecute comprehensive L1-L4 network device inspection. Use when user asks to "inspect all devices", "run comprehensive health…majiayu000dk-agent-native-auditRun comprehensive agent-native architecture review with scored principles. Audits a codebase against 8 agent-native architecture…majiayu000writesdk-loop-auditAudit whether an AI agent can autonomously close the loop on problems in a given area — from discovering a symptom to verifying a…majiayu000writesdocs-seekerFetch up-to-date documentation for any library, framework, API, or service into context. Use when the user wants to look up API…majiayu000documenso-install-authInstall and configure Documenso SDK/API authentication. Use when setting up a new Documenso integration, configuring API keys, or…jeremylongshorewritesdocumenso-security-basicsImplement security best practices for Documenso document signing integrations. Use when securing API keys, configuring webhooks…jeremylongshorewritesdocumentation-strategyDesign and run a documentation system for a team or product. Use this skill when planning what to document, choosing a…rampstackcodomain-authority-auditorThis skill should be used when the user asks to "audit domain authority", "domain trust score", "CITE audit", "how authoritative…majiayu000draft-reviewUsability review — evaluate an existing flow or UI against usability heuristics, flag friction points, and recommend fixes. Use…jeremylongshorewritesechidna-fuzzerProperty-based testing and fuzzing using Echidna for smart contracts. Includes invariant definition, corpus management, coverage…a5c-aiwritesecon-auditAudit economic analysis outputs (fiscal briefings, macro briefings, market research, longlists, and other quantitative economic…brycewang-stanfordwriteselectron-ipc-security-auditAnalyze Electron IPC implementations for security vulnerabilities including contextIsolation, nodeIntegration, preload scripts…a5c-aiwriteselectron-main-preload-generatorGenerate secure main process and preload script boilerplate with proper context isolation, IPC patterns, and security best…a5c-aiwriteselevenlabs-agentsBuild conversational AI voice agents with ElevenLabs Platform. Configure agents, tools, RAG knowledge bases, agent versioning…majiayu000elevenlabs-agentsElevenLabs Agents Platform for AI voice agents (React/JS/Native/Swift). Use for voice AI, RAG, tools, or encountering package…majiayu000email-deliverabilityMake sure email actually reaches inboxes. Use this skill when setting up email authentication (SPF, DKIM, DMARC), diagnosing…rampstackcoemail-quality-auditorUse when the user asks to "audit an email program" or "is this campaign safe to send"; runs a typed 20-item SEND profile with…aaron-he-zhuenterprise-agent-opsOperate long-lived agent workloads with observability, security boundaries, and lifecycle management.majiayu000Enterprise AI PatternsProduction-grade AI architecture patterns for enterprise - security, governance, scalability, and operational excellencemajiayu000enterprise-code-analyzerThree-tier enterprise code analysis system. Tier 1 analyzes individual repositories (structure, patterns, dependencies, memory).…majiayu000epistemic-fault-line-audit-ignacio-adrian-lererAudits legal AI outputs, prompts, skills, workflows and MCP/tool instructions for fluent but unsupported reasoning, missing…lawve-aiesper:auditComprehensive project audit — health, architecture, phase retrospective, and codebase quality. Produces a scannable report with…majiayu000ev-certificate-validatorValidate EV code signing certificate chain and timestamp for Windows SmartScreena5c-aiwriteseval-auditAudit an existing evaluation workflow and produce severity-ranked findings with concrete next actions. Use when inheriting an…majiayu000evernote-install-authInstall and configure Evernote SDK and OAuth authentication. Use when setting up a new Evernote integration, configuring API…jeremylongshorewritesevernote-security-basicsImplement security best practices for Evernote integrations. Use when securing API credentials, implementing OAuth securely, or…jeremylongshorewritesevidence-loggingUse this skill as foundation for all evidence-based review workflows. Use when conducting any review that needs evidence trails…majiayu000evidence-standardsEvidence citation and domain scope standards for Neo4j subagents. Prevents hallucination and ensures audit trail.majiayu000evm-analysisDeep EVM bytecode analysis and decompilation capabilities for smart contract security, gas optimization, and reverse engineering.…a5c-aiwritesevo-os-review-promptReview LLM workflow step prompts for known failure modes (silent ignoring, negation fragility, scope creep, etc). Use when user…majiayu000examples-auditAnalyze mock data and examples for cultural assumptions, understanding what they communicate about who the product is for. Use…majiayu000excel-auditorAnalyze unknown or inherited Excel files to understand what they do, document their purpose, audit formulas for errors, and…majiayu000exhaustive-systems-analysisPerform comprehensive, deep analysis of a system and its subsystems to identify bugs, race conditions, stale documentation, dead…majiayu000expressExpress.js middleware patterns, routing, error handling, security, and production best practices.a5c-aiwrites
← Prev21 / 58Next →
How the catalog works
What is an agent skill?

A folder with a SKILL.md inside — instructions, and often scripts and assets, that an AI agent loads when the task matches. Claude Code, Codex, Cursor and Copilot all read the same format, so one skill usually works across them.

Where does this catalog come from?

We read 660 source repositories straight from their file trees rather than from submitted listings — what you see is what is actually published. 98 repositories were rejected because they advertise skills but contain none: link lists, not folders.

Why is there no install counter?

Because install counts live in the registry that serves `npx skills add`, and that is not ours — publishing a number we cannot verify would be worse than showing none. Instead we show where a skill comes from and whether attention around its source is actually growing, measured from our own weekly snapshots.

Do you deduplicate?

Yes, and it matters more than expected. Aggregator repositories republish the same skill in several places — one source carried 6,317 SKILL.md files for 2,001 actual skills. We collapse by folder name and keep the canonical copy, so the catalog counts things, not copies.

Keep going