Agent skills

Security skills

Read straight from the source repositories, not from submitted listings. Every skill shows what it does, what is inside, where it came from — and whether attention around its source is actually growing.

Toolclaude-code 29,140codex 4,755cursor 3,111copilot 976windsurf 55cline 34
CategoryWorkflow & Productivity 4,979AI & Agents 3,037Data & Analytics 2,345Code Review & Quality 1,376Backend & API 1,244Security 1,194Design & Presentation 1,154Documentation 965Content & Marketing 916Testing & QA 777DevOps & Cloud 576Databases 550Frontend 469Business & Finance 328Media & Video 257Other 9,833
2,762 found
1,1531,200 · page 25 / 58
proof-auditAudit test suite health — find flaky tests, slow tests, coverage gaps, and testing anti-patterns. Use when asked to "audit…jeremylongshorewritesproof-checkerRigorous mathematical proof verification and fixing workflow. Reads a LaTeX proof, identifies gaps via cross-model review…majiayu000writesproof-checkerRigorous mathematical proof verification and fixing workflow. Reads a LaTeX proof, identifies gaps via cross-model review (Codex…majiayu000writesproof-designDesign QA audit — red flags, severity classification, visual quality scorecard. Use when asked to "QA the design", "check visual…jeremylongshorewritesprotecting-secretsUse when protecting secrets is required during security work, especially when the result must be traceable, independently…casioreview20-glitchprotocol-fuzzerExpert skill for protocol fuzzing, vulnerability discovery, and security testinga5c-aiwritesprotocol-reverse-engineeringComprehensive techniques for capturing, analyzing, and documenting network protocols for security research, interoperability, and…sickn33prove-your-worthRuthlessly audit project features for justification. Challenge every feature to prove its value with evidence or face removal.…majiayu000provenance-auditAI generation provenance and audit trail tracking. Records decision factors, data lineage, reasoning chains, confidence scoring…majiayu000Python Backend Architecture ReviewComprehensive design architecture review for Python backend applications. Use this skill when users ask you to review, analyze…majiayu000pytorch-to-tritonTranslate PyTorch implementations to Triton GPU kernels incrementally. Use when converting PyTorch code to Triton, optimizing GPU…majiayu000qa-testingRun QA testing on a page, feature, or full site at one of three depth tiers (smoke, standard, full). Use this skill whenever the…rampstackcoqt-widget-accessibility-auditAudit Qt Widget applications for accessibility compliance using QAccessible interface and platform accessibility APIsa5c-aiwritesquality-assessmentEvaluate ENCODE experiment quality using standard metrics and audit flags. Use when the user asks about data quality, wants to…majiayu000questionably-ultrathink-skillUse this skill when facing complex problems requiring rigorous reasoning, systematic decomposition, or factual verification.…majiayu000writesquestionably-ultrathinkAdvanced reasoning skill integrating Atom of Thoughts (AoT) and Chain of Verification (CoVe) frameworks. Use when facing complex…majiayu000writesralph-loopStart a Ralph Wiggum autonomous task loop that keeps Claude working until a task is complete. Uses the Stop hook pattern to…majiayu000ralph-prompt-researchGenerate Ralph-compatible prompts for research, analysis, and planning tasks. Creates prompts with systematic research phases…majiayu000ralph-wiggum-loopMulti-step autonomous plan execution with bounded iteration (max 10), state persistence, dependency checking, error retry with…majiayu000readiness-reportEvaluate how well a codebase supports autonomous AI development. Analyzes repositories across eight technical pillars (Style &…majiayu000receipts-auditAudit any document against its own sources — every factual claim extracted and graded as evidenced, partially evidenced…mohitagw15856regulator-eyesRead your marketing claims, landing page, or ad copy the way a consumer-protection investigator would (FTC/ASA framing) and draft…mohitagw15856relay-auditAudit an existing CI/CD pipeline for slowness, security issues, and reliability gaps. Use when asked to "audit pipeline", "why is…jeremylongshorewritesrelay-dockerBuild production-ready Dockerfiles with multi-stage builds, security hardening, and docker-compose for local dev. Use when asked…jeremylongshorewritesrepomixPackage entire code repositories into single AI-friendly files using Repomix. Capabilities include pack codebases with…majiayu000repomixGuide for using Repomix - a powerful tool that packs entire repositories into single, AI-friendly files. Use when packaging…majiayu000repomixPackage code repositories into AI-friendly files. Use this skill when packaging codebases for AI analysis, creating repository…majiayu000repomixPackage entire code repositories into single AI-friendly files using Repomix. Capabilities include pack codebases with…majiayu000repomixRepository packaging for AI/LLM analysis. Capabilities: pack repos into single files, generate AI-friendly context, codebase…majiayu000repomixPackage entire code repositories into single AI-friendly files using Repomix. Capabilities include pack codebases with…majiayu000repomixPackage external repositories into AI-friendly files for deep analysis. ALWAYS use when the user shares a github.com URL…majiayu000research-architect-auditUse when reviewing, revising, or deciding whether to complete a Research Architect draft, especially when its reference…mmTheBestresearch-blockchainSenior Blockchain Architect research agent using Zai MCP for comprehensive analysis of EVM chains, perpetual DEX architectures…majiayu000research-git-patternsGit-aware skill for finding implementation patterns and retrieving story context from git history. Use when searching for similar…majiayu000researchTrace execution paths and document how code actually behaves. Use when you need to understand how features work, walk through…majiayu000researchResearch technical solutions, analyze architectures, gather requirements thoroughly. Use for technology evaluation, best…majiayu000researchResearch technical solutions, analyze architectures, gather requirements thoroughly. Use for technology evaluation, best…majiayu000researchResearch technical solutions, analyze architectures, gather requirements thoroughly. Use for technology evaluation, best…majiayu000ck:researchResearch technical solutions, analyze architectures, gather requirements thoroughly. Use for technology evaluation, best…majiayu000ck:researchResearch technical solutions, analyze architectures, gather requirements thoroughly. Use for technology evaluation, best…majiayu000researchTechnical research methodology with YAGNI/KISS/DRY principles. Phases: scope definition, information gathering, analysis…majiayu000researchResearch technical solutions, analyze architectures, gather requirements thoroughly. Use for technology evaluation, best…majiayu000researchSystematic research before planning - gather documentation, security concerns, tech stack analysis, and community insights. Use…majiayu000writesresearchingUse when requirements are fuzzy, multiple technical approaches exist, or change affects architecture, API, data, or securitymajiayu000retellai-security-basicsRetell AI security basics \u2014 AI voice agent and phone call automation.\n\ Use when working with Retell AI for voice agents…jeremylongshorewritesreview-swarmParallel read-only multi-agent review of a current git diff or explicit file scope to find behavioral regressions, security or…sickn33reviewing-data-privacyUse when reviewing data privacy is required during security work, especially when the result must be traceable, independently…casioreview20-glitchreviewing-secure-designUse when reviewing secure design is required during security work, especially when the result must be traceable, independently…casioreview20-glitch
← Prev25 / 58Next →
How the catalog works
What is an agent skill?

A folder with a SKILL.md inside — instructions, and often scripts and assets, that an AI agent loads when the task matches. Claude Code, Codex, Cursor and Copilot all read the same format, so one skill usually works across them.

Where does this catalog come from?

We read 660 source repositories straight from their file trees rather than from submitted listings — what you see is what is actually published. 98 repositories were rejected because they advertise skills but contain none: link lists, not folders.

Why is there no install counter?

Because install counts live in the registry that serves `npx skills add`, and that is not ours — publishing a number we cannot verify would be worse than showing none. Instead we show where a skill comes from and whether attention around its source is actually growing, measured from our own weekly snapshots.

Do you deduplicate?

Yes, and it matters more than expected. Aggregator repositories republish the same skill in several places — one source carried 6,317 SKILL.md files for 2,001 actual skills. We collapse by folder name and keep the canonical copy, so the catalog counts things, not copies.

Keep going