Agent skills

Security skills

Read straight from the source repositories, not from submitted listings. Every skill shows what it does, what is inside, where it came from — and whether attention around its source is actually growing.

Toolclaude-code 29,140codex 4,755cursor 3,111copilot 976windsurf 55cline 34
CategoryWorkflow & Productivity 4,979AI & Agents 3,037Data & Analytics 2,345Code Review & Quality 1,376Backend & API 1,244Security 1,194Design & Presentation 1,154Documentation 965Content & Marketing 916Testing & QA 777DevOps & Cloud 576Databases 550Frontend 469Business & Finance 328Media & Video 257Other 9,833
2,762 found
1,0571,104 · page 23 / 58
langchain-install-authInstall and configure LangChain SDK/CLI authentication. Use when setting up a new LangChain integration, configuring API keys, or…majiayu000writeslangfuse-extractionExtracts traces, observations, and metrics from Langfuse Cloud (EU) API for debugging, telemetry analysis, and regulatory audit…majiayu000writeslangfuse-install-authInstall and configure Langfuse SDK authentication for LLM observability. Use when setting up a new Langfuse integration…majiayu000writeslaunch-readiness-auditorUse when the user asks to "audit our launch plan", "are we ready to launch", or evaluate launch execution/outcomes; runs one…aaron-he-zhulegal-mdl-audit-ignacio-adrian-lererAudits legal AI outputs and workflows for honest compression: unnecessary complexity, false simplicity, excessive caveats, hidden…lawve-ailegal-transition-audit-ignacio-adrian-lererAudits the transition from legal AI output to reliance, recommendation, execution, or real-world commitment. Use it before an…lawve-ailens-auditReview existing analytics — find all dashboards and reports, check who uses them, whether metrics are defined, and whether they…jeremylongshorewriteslindy-install-authSet up Lindy AI account, API access, and webhook authentication. Use when onboarding to Lindy, configuring API keys for webhook…jeremylongshorewriteslinear-multi-env-setupConfigure Linear across development, staging, and production environments. Use when setting up per-environment API keys, secret…jeremylongshorewriteslinux-gpg-signingSign Linux packages with GPG keys for secure distributiona5c-aiwritesln-640-pattern-evolution-auditorAudits architectural patterns against best practices (MCP Ref, Context7, WebSearch). Maintains patterns catalog, calculates 4…majiayu000ln-650-persistence-performance-auditorCoordinates 3 specialized audit workers (query efficiency, transaction correctness, runtime performance). Researches DB/ORM/async…majiayu000writeslog-agentRecord agent run logs into .tmp/logs/. Use this to maintain an audit trail of agent actions and errors.majiayu000lp-onboarding-auditAudit an app's onboarding flow against the "Onboarding Done Right" checklist. Customizes the generic checklist for the app's…majiayu000lp-sell-funnel-auditAudit a live sales funnel with rendered browser evidence, not DOM inference alone. Verifies mobile and fullscreen booking paths…majiayu000lumen-reconAnalytics reconnaissance — scan existing event tracking, metric definitions, dashboards, and analytics configuration to…jeremylongshorewritesm365-agents-dotnetMicrosoft 365 Agents SDK for .NET. Build multichannel agents for Teams/M365/Copilot Studio with ASP.NET Core hosting…majiayu000m365-agents-dotnetMicrosoft 365 Agents SDK for .NET. Build multichannel agents for Teams/M365/Copilot Studio with ASP.NET Core hosting…majiayu000m365-agents-dotnetMicrosoft 365 Agents SDK for .NET. Build multichannel agents for Teams/M365/Copilot Studio with ASP.NET Core hosting…majiayu000m365-agents-pyMicrosoft 365 Agents SDK for Python. Build multichannel agents for Teams/M365/Copilot Studio with aiohttp hosting…majiayu000m365-agents-pyMicrosoft 365 Agents SDK for Python. Build multichannel agents for Teams/M365/Copilot Studio with aiohttp hosting…microsoftm365-agents-pyMicrosoft 365 Agents SDK for Python. Build multichannel agents for Teams/M365/Copilot Studio with aiohttp hosting…majiayu000macos-codesign-workflowExecute macOS code signing with Developer ID and hardened runtime requirementsa5c-aiwritesmacos-entitlements-generatorGenerate entitlements.plist with appropriate sandbox capabilities for macOS applicationsa5c-aiwritesmaintainx-security-basicsConfigure MaintainX API security, credential management, and access control. Use when securing API keys, implementing access…jeremylongshorewritesmanaging-mcpsCreates, analyzes, updates, and evaluates Model Context Protocol (MCP) servers including architecture assessment, security…majiayu000marketInternationalization and accessibility audit - scan for hardcoded text, check i18n coverage, run WCAG 2.1 accessibility audit.…majiayu000writesmarkstream-migrationAudit and migrate an existing Markdown renderer to Markstream while preserving custom renderers, security policy, streaming…sickn33mastra-system-checkComprehensive system check for Mastra AI agent projects. Validates configuration, agents, workflows, memory, tools, prompts, and…majiayu000matlab-secure-credentialsStore, retrieve, and pass credentials securely in MATLAB using the built-in MATLAB Vault (setSecret, getSecret, importSecrets…matlabmatter-allocation-instructionFirm-matter matching, matter instruction drafting, firm onboarding checklist, and instruction audit for in-house legal ops teams.…lawve-aimcp-csp-investigationComprehensive Content Security Policy audit for MCP Apps in sandboxed iframes. Discovers all network origins, traces them to…a5c-aiwritesmeshy-3dProduce 3D assets with Meshy (meshy.ai) through its REST API and web platform — text-to-3D, image-to-3D, multi-image-to-3D, AI…calesthiomoai-change-loggerComprehensive change tracking and audit logging system that monitors file modifications, code changes, and project evolution. Use…majiayu000writesmoai-change-loggerComprehensive change tracking and audit logging system that monitors file modifications, code changes, and project evolution. Use…majiayu000writesmobile-securityMobile application security skill for implementing OWASP MASVS compliance, secure storage, certificate pinning, biometric…a5c-aiwritesmodel-qa-specialistIndependent model QA expert who audits ML and statistical models end-to-end - from documentation review and data reconstruction…majiayu000model-routingModel selection strategy for subagents — haiku for exploration, sonnet for implementation, opus for architecture/securitymajiayu000modeling-security-threatsUse when modeling security threats is required during security work, especially when the result must be traceable, independently…casioreview20-glitchmulti-cloud-security-postureUnified cloud security posture management across AWS, Azure, and GCP with normalized metrics and CIS benchmark comparisona5c-aiwritesnarrative-quality-auditorUse when the user asks to "audit our brand narrative" or "is this message on-canon"; runs separate typed TALE truth, system, or…aaron-he-zhunavan-hello-worldMake your first Navan API call to retrieve trip and user data. Use when verifying a new Navan integration works end-to-end after…jeremylongshorewritesnavan-install-authSet up OAuth 2.0 authentication for the Navan REST API. Use when configuring a new Navan integration or rotating API credentials.…jeremylongshorewritesnavan-prod-checklistUse when validating production readiness for a Navan API integration\ \ \u2014 credential rotation, alerting, rate limits, SSO…jeremylongshorewritesnavan-security-basicsSecure Navan API credentials with OAuth 2.0 best practices, SSO/SAML, and SCIM provisioning. Use when hardening a Navan…jeremylongshorewritesnextauthNextAuth.js (Auth.js) configuration including providers, adapters, session management, callbacks, and JWT handling.a5c-aiwritesnexus-prompt-engineer4-D prompt engineering assistant that transforms vague requirements into high-precision prompts through guided interaction.…majiayu000nixtla-usage-optimizerAnalyze Nixtla usage and optimize cost-effective forecast routing strategies. Use when auditing API usage or reducing costs.…majiayu000
← Prev23 / 58Next →
How the catalog works
What is an agent skill?

A folder with a SKILL.md inside — instructions, and often scripts and assets, that an AI agent loads when the task matches. Claude Code, Codex, Cursor and Copilot all read the same format, so one skill usually works across them.

Where does this catalog come from?

We read 660 source repositories straight from their file trees rather than from submitted listings — what you see is what is actually published. 98 repositories were rejected because they advertise skills but contain none: link lists, not folders.

Why is there no install counter?

Because install counts live in the registry that serves `npx skills add`, and that is not ours — publishing a number we cannot verify would be worse than showing none. Instead we show where a skill comes from and whether attention around its source is actually growing, measured from our own weekly snapshots.

Do you deduplicate?

Yes, and it matters more than expected. Aggregator repositories republish the same skill in several places — one source carried 6,317 SKILL.md files for 2,001 actual skills. We collapse by folder name and keep the canonical copy, so the catalog counts things, not copies.

Keep going