Agent skills

Security skills

Read straight from the source repositories, not from submitted listings. Every skill shows what it does, what is inside, where it came from — and whether attention around its source is actually growing.

Toolclaude-code 29,140codex 4,755cursor 3,111copilot 976windsurf 55cline 34
CategoryWorkflow & Productivity 4,979AI & Agents 3,037Data & Analytics 2,345Code Review & Quality 1,376Backend & API 1,244Security 1,194Design & Presentation 1,154Documentation 965Content & Marketing 916Testing & QA 777DevOps & Cloud 576Databases 550Frontend 469Business & Finance 328Media & Video 257Other 9,833
2,762 found
1,1051,152 · page 24 / 58
notion-install-authInstall and configure the Notion API SDK with authentication. Use when setting up a new Notion integration, configuring API…jeremylongshorewritesoctocodeSemantic code research across GitHub repositories for finding implementations, patterns, and conducting PR/security reviews.majiayu000Offensive Security SkillOffensive security tools and techniques integrationa5c-aiwritesold-coderEvidence-first development — surround the implementation with an executable spec and a gauntlet of constraints (tests, types…AmazingAngonenote-install-authInstall and configure OneNote SDK/API authentication with delegated auth (MSAL). Use when setting up a new OneNote integration…jeremylongshorewritesonenote-prod-checklistProduction readiness checklist for OneNote Graph API integrations covering auth, rate limits, and failure modes. Use when…jeremylongshorewritesonenote-security-basicsImplement secure authentication, token management, and permission scoping for OneNote Graph API. Use when hardening OneNote…jeremylongshorewritesonenote-upgrade-migrationMigrate OneNote integrations across Graph SDK versions, auth deprecations, and API changes. Use when upgrading Graph SDK…jeremylongshorewritesopenai-knowledgeUse when working with the OpenAI API (Responses API) or OpenAI platform features (tools, streaming, Realtime API, auth, models…majiayu000openai-knowledgeUse when working with the OpenAI API (Responses API) or OpenAI platform features (tools, streaming, Realtime API, auth, models…majiayu000openapi-validatorValidate OpenAPI specifications for correctness, security, and best practicesa5c-aiwritesopenzeppelinExpert usage of OpenZeppelin Contracts library for secure smart contract development. Covers access control, token standards…a5c-aiwritesops-inboxFull inbox management across all channels — WhatsApp (wacli), Email (Gmail MCP), Slack (MCP), Telegram (user-auth MCP), Discord…davepoonwritesoraclecloud-common-errorsDiagnose and fix Oracle Cloud Infrastructure API errors with real error codes and proven fixes. Use when encountering OCI…jeremylongshoreoraclecloud-core-workflow-bBuild OCI networking from scratch \u2014 VCN, subnets, gateways, and\ \ security rules.\nUse when creating a new VCN, debugging…jeremylongshorewritesoraclecloud-enterprise-rbacDesign OCI compartment hierarchies, dynamic groups, and cross-tenancy access patterns. Use when planning enterprise RBAC, setting…jeremylongshorewritesoraclecloud-install-authInstall and configure Oracle Cloud Infrastructure (OCI) SDK and CLI authentication. Use when setting up a new OCI integration…jeremylongshorewritesoraclecloud-prod-checklistPre-production readiness checklist for OCI \u2014 backup policies, security\ \ audit, key rotation, encryption, and Cloud…jeremylongshorewritesoraclecloud-sdk-patternsProduction-grade OCI SDK patterns for client lifecycle, retry logic, and memory leak avoidance. Use when building long-running…jeremylongshorewritesoraclecloud-security-basicsMaster OCI IAM policy syntax, common policy patterns, and API key management. Use when writing IAM policies, granting access to…jeremylongshorewritesoraclecloud-webhooks-eventsWire up event-driven workflows with OCI Events, Notifications, and Functions. Use when building serverless event processing…jeremylongshorewritesowasp-security-scannerAutomated OWASP Top 10 vulnerability detection and assessment. Run OWASP ZAP automated scans, detect injection vulnerabilities…a5c-aiwritesowasp-zap-securityDeep integration with OWASP ZAP for automated security scanning, vulnerability detection, and API security testing. Execute…a5c-aiwritespaper-claim-auditZero-context verification that every number, comparison, and scope claim in the paper matches raw result files. Uses a fresh…majiayu000writespaper-claim-auditZero-context verification that every number, comparison, and scope claim in the paper matches raw result files. Uses a fresh…majiayu000writespaper-review-litePre-submission audit: argument, numerics, refs, writing, figures, replication.brycewang-stanfordieee-pes-paper-reviewerComprehensive IEEE PES paper review for Physics-Guided SSL GNN power grid research. Use when reviewing paper sections, checking…majiayu000pave-auditAudit developer experience — measure onboarding time, build speed, deployment friction, and developer satisfaction. Use when…jeremylongshorewritespaw-review-impactAnalyzes system-wide impact of PR changes including integration effects, breaking changes, performance, and security implications.majiayu000pci-complianceImplement PCI DSS compliance requirements for secure handling of payment card data and payment systems. Use when securing payment…wshobsonperception-systemAI perception skill for sight, hearing, and threat detection systems.a5c-aiwritesphishing-simulation-skillPhishing simulation campaign execution and analysis for security awareness assessmenta5c-aiwritespitch-reconMarketing and messaging reconnaissance — read existing landing pages, copy, positioning docs, and marketing materials to…jeremylongshorewritesplan-implementationDisciplined execution of approved plans with step-by-step verification, phase checkpoints, failure investigation, and mandatory…a5c-aiwritesplanning-incident-responseUse when planning incident response is required during security work, especially when the result must be traceable, independently…casioreview20-glitchPokemon Card AnalystUse when analyzing individual Pokemon cards, comparing card stats, evaluating attacks/abilities, or researching card rarity.…majiayu000polisci-reviewYou are coordinating a rigorous political science pre-submission audit.majiayu000polisci-reviewRun a political science pre-submission audit with journal-aware personas, stage-aware standards, and evidence-grounded issue…majiayu000political-scientist-analystAnalyzes events through political science lens using IR theory (Realism, Liberalism, Constructivism), comparative politics…majiayu000portaljs-check-data-qualityAudit a local or remote tabular file (CSV/TSV) for common data quality issues — schema, nulls, types, duplicates. Read-only. Use…datopianprism-auditFrontend audit — bundle size, dependencies, accessibility, performance, component quality. Use when asked for "frontend review"…jeremylongshorewritesproactive-agentTransform AI agents from task-followers into proactive partners that anticipate needs and continuously improve. Includes memory…majiayu000programmatic-seoWhen the user wants to create SEO-driven pages at scale using templates and data. Also use when the user mentions "programmatic…growthack88programmatic-seoWhen the user wants to create SEO-driven pages at scale using templates and data. Also use when the user mentions "programmatic…Infrasity-Labsproject-skill-auditAudit a project and recommend the highest-value skills to add or update.sickn33prompt-engeneeringUniversal prompt engineering techniques for any LLM. Use when crafting, optimizing, or reviewing prompts for AI models. Triggers…majiayu000prompt-engineeringPrompt engineering knowledge base — technique taxonomy with decision tree, prompt template patterns and formatting conventions…majiayu000prompt-improverAnalyze and improve plugin prompts, skill definitions, and command instructions for clarity, safety, and effectiveness. Use when…jeremylongshorewrites
← Prev24 / 58Next →
How the catalog works
What is an agent skill?

A folder with a SKILL.md inside — instructions, and often scripts and assets, that an AI agent loads when the task matches. Claude Code, Codex, Cursor and Copilot all read the same format, so one skill usually works across them.

Where does this catalog come from?

We read 660 source repositories straight from their file trees rather than from submitted listings — what you see is what is actually published. 98 repositories were rejected because they advertise skills but contain none: link lists, not folders.

Why is there no install counter?

Because install counts live in the registry that serves `npx skills add`, and that is not ours — publishing a number we cannot verify would be worse than showing none. Instead we show where a skill comes from and whether attention around its source is actually growing, measured from our own weekly snapshots.

Do you deduplicate?

Yes, and it matters more than expected. Aggregator repositories republish the same skill in several places — one source carried 6,317 SKILL.md files for 2,001 actual skills. We collapse by folder name and keep the canonical copy, so the catalog counts things, not copies.

Keep going