Agent skills

Security skills

Read straight from the source repositories, not from submitted listings. Every skill shows what it does, what is inside, where it came from — and whether attention around its source is actually growing.

Toolclaude-code 29,140codex 4,755cursor 3,111copilot 976windsurf 55cline 34
CategoryWorkflow & Productivity 4,979AI & Agents 3,037Data & Analytics 2,345Code Review & Quality 1,376Backend & API 1,244Security 1,194Design & Presentation 1,154Documentation 965Content & Marketing 916Testing & QA 777DevOps & Cloud 576Databases 550Frontend 469Business & Finance 328Media & Video 257Other 9,833
2,762 found
1,0091,056 · page 22 / 58
fabricIntelligent pattern selection for Fabric CLI. Automatically selects the right pattern from 242+ specialized prompts based on your…majiayu000fabricNative Fabric pattern execution for Claude Code. USE WHEN processing content with Fabric patterns (extract_wisdom, summarize…majiayu000FabricIntelligent prompt pattern system with 240+ specialized patterns for content analysis, extraction, and transformation. USE WHEN…majiayu000FabricIntelligent prompt pattern system with 240+ specialized patterns for content analysis, extraction, and transformation. USE WHEN…majiayu000fact-checkingUse when reviewing code changes, auditing documentation accuracy, validating technical claims before merge, or user says "verify…majiayu000fair-checkAudit manuscript and replication package against FAIR open-science principles.majiayu000farm-auditAudit all Farmwork systems and update FARMHOUSE.md metrics. Use when user says "open the farm", "audit systems", "check farm…majiayu000writesfastmcp-creatorBuild Model Context Protocol (MCP) servers - comprehensive coverage of generic MCP protocol AND FastMCP framework specialization.…majiayu000feed-dietAudit your information diet across HN and RSS feeds — beautiful reports with category breakdowns, ASCII charts, and personalized…majiayu000flywheel-discordSecurity rules and behavioral guidelines for operating as Clawdstein in The Agent Flywheel Hub Discord server. This is a PUBLIC…majiayu000forge-auditAudit existing infrastructure for security issues, waste, and misconfigurations. Use when asked to "audit my infra", "check cloud…jeremylongshorewritesforge-costAudit cloud infrastructure costs and produce a concrete optimization plan with specific changes and estimated savings. Use when…jeremylongshorewritesform-auditUse when asked to audit UI for visual quality, check design consistency, review brand alignment, evaluate design system…jeremylongshorewritesform-examTheory-backed design audit — names the principle violated, cites the source, shows the fix. Use when asked to "evaluate design…jeremylongshorewritesfree-toolsWhen the user wants to plan, evaluate, or build a free tool for marketing purposes — lead generation, SEO value, or brand…Infrasity-Labsgap-analysis-frameworkComprehensive gap analysis framework for identifying missing capabilities, coverage, and requirements. Use for requirements vs…majiayu000writesgap-analysisPerforms a gap analysis between two artifacts (a current state and a desired state) and produces a plain-language…testdoublewritesgcp-security-scannerGCP security configuration scanning and hardening using Security Command Center, Forseti, and ScoutSuitea5c-aiwritesgemini-authSetup and manage Gemini CLI authentication methods including OAuth, API keys, and Vertex AI. Use when configuring Gemini access…majiayu000gemini-cliGoogle Gemini CLI for second opinions, architectural advice, code reviews, security audits. Leverage 1M+ context for…majiayu000gemini-peer-reviewGet a second opinion from Gemini on code, architecture, debugging, or security. Uses gemini-coach CLI with AI-to-AI prompting for…majiayu000gemini-peer-reviewGet a second opinion from Gemini on code, architecture, debugging, or security. Uses direct Gemini API calls — no CLI…majiayu000golang-pkg-go-devGolang package and module documentation and exploration via `godig`, a pkg.go.dev API client (CLI + MCP server) — package docs…samberwritesgoogle-search-ads-builderEnd-to-end Google Search Ads campaign builder. Performs deep keyword research (competitor SEO, review language mining, Reddit/HN…gooseworks-aigranola-security-basicsSecurity and privacy configuration for Granola meeting data. Use when reviewing data handling practices, configuring encryption…jeremylongshorewritesgwas-databaseNHGRI-EBI GWAS Catalog REST API for SNP-trait associations from published GWAS. Query studies, associations, variants, traits…BioTender-maxhardware-securityHardware and embedded security research capabilities. Interface with JTAG debuggers, analyze SPI/I2C communications, dump and…a5c-aiwriteshidden-folder-auditAudit and consolidate hidden folders in a repository. Identifies duplicates, dead directories, and consolidation opportunities…majiayu000hipaa-compliance-automatorHIPAA security and privacy compliance automation for ePHI protection, safeguards assessment, and audit preparationa5c-aiwriteshome-contractor-quote-decoderDecode a home renovation or repair quote — allowances that aren't prices, exclusions that become change orders, payment schedules…mohitagw15856hook-authoringGuide creating Claude Code hooks with security-first design. Use for validation, logging, and policy enforcement.majiayu000hook-developmentUse when creating, modifying, or debugging Claude Code hooks — PreToolUse, PostToolUse, Stop, SubagentStop, SessionStart…majiayu000html-ppt-obsidian-claude-gradientOpen Design's enterprise AI-adoption brief: local-first agents at work, the risk controls, the ROI, and the rollout plan. Built…nexu-ioi18n-content-audit审计和优化**已有国际化内容**的 SEO/GEO 合规性。两种模式:(1) 仅报告(默认,无 --fix 标志):生成审计报告但不修改文件,适合想先审查建议的场景;(2) 报告 + 修复(--fix…majiayu000iac-security-scannerInfrastructure as Code security scanning and policy enforcement for Terraform, CloudFormation, Kubernetes, and Pulumia5c-aiwritesicp-website-auditEnd-to-end website audit through ICP eyes. Builds synthetic personas (if they don't already exist), runs a structured scorecard…gooseworks-aiimpediment-prioritizationRanks any list of impediments and their countermeasures using a value-stream scoring model (ROI, Cost to Implement, Ease of…githubinbox-placement-monitorUse when the user asks to "track where my emails are actually landing after I send", "read my seed-list inbox vs spam vs…aaron-he-zhuincident-responseManage active production incidents through detection, triage, mitigation, communication, and resolution with structured roles and…rampstackcoinfra-setupNon-user-invocable provider/setup reference for evo backend switching, prerequisite checks, and auth/install guidance.evo-hqinsecure-defaultsDetects fail-open insecure defaults (hardcoded secrets, weak auth, permissive security) that allow apps to run insecurely in…waybarriosalpaca-broker-integrationEntry point for integrating with the Alpaca Broker API (plus Market Data and Trading APIs) in any programming language. Use when…alpacahqjourney-mappingBuild customer journey maps and service blueprints that visualize the end-to-end user experience including touchpoints, emotions…rampstackcojwtJWT implementation, token management, refresh patterns, and security.a5c-aiwritesk8s-validatorValidate Kubernetes manifests for security, best practices, and resource limitsa5c-aiwriteskeychain-credential-managerManage credentials in OS keychains across Windows, macOS, and Linuxa5c-aiwriteslanding-optimizerUse when the user asks to "optimize our landing page for influencer traffic", "fix our promo-code landing page", or "improve…aaron-he-zhulanding-page-auditorAudits any landing or service page across 48 checks in 10 categories for LLM/AI discoverability, GEO readiness, content clarity…Infrasity-Labs
← Prev22 / 58Next →
How the catalog works
What is an agent skill?

A folder with a SKILL.md inside — instructions, and often scripts and assets, that an AI agent loads when the task matches. Claude Code, Codex, Cursor and Copilot all read the same format, so one skill usually works across them.

Where does this catalog come from?

We read 660 source repositories straight from their file trees rather than from submitted listings — what you see is what is actually published. 98 repositories were rejected because they advertise skills but contain none: link lists, not folders.

Why is there no install counter?

Because install counts live in the registry that serves `npx skills add`, and that is not ours — publishing a number we cannot verify would be worse than showing none. Instead we show where a skill comes from and whether attention around its source is actually growing, measured from our own weekly snapshots.

Do you deduplicate?

Yes, and it matters more than expected. Aggregator repositories republish the same skill in several places — one source carried 6,317 SKILL.md files for 2,001 actual skills. We collapse by folder name and keep the canonical copy, so the catalog counts things, not copies.

Keep going