Agent skills

Security skills

Read straight from the source repositories, not from submitted listings. Every skill shows what it does, what is inside, where it came from — and whether attention around its source is actually growing.

Toolclaude-code 29,140codex 4,755cursor 3,111copilot 976windsurf 55cline 34
CategoryWorkflow & Productivity 4,979AI & Agents 3,037Data & Analytics 2,345Code Review & Quality 1,376Backend & API 1,244Security 1,194Design & Presentation 1,154Documentation 965Content & Marketing 916Testing & QA 777DevOps & Cloud 576Databases 550Frontend 469Business & Finance 328Media & Video 257Other 9,833
2,762 found
1,2011,248 · page 26 / 58
ara-rigor-reviewerPerforms ARA Seal Level 2 semantic epistemic review on Agent-Native Research Artifacts, scoring six dimensions (evidence…Orchestra-Researchdiscovery.risk_assessmentIdentify potential quality, security, and delivery risks early in discovery to inform mitigation planning.majiayu000running-security-release-gateUse when running security release gate is required during security work, especially when the result must be traceable…casioreview20-glitchsandbox-entitlements-auditorAudit and recommend minimal sandbox entitlements for secure desktop applicationsa5c-aiwritessandboxing-untrusted-executionUse when sandboxing untrusted execution is required during security work, especially when the result must be traceable…casioreview20-glitchsast-analyzerStatic Application Security Testing orchestration and analysis. Execute Semgrep, Bandit, ESLint security plugins, CodeQL, and…a5c-aiwritessc-analyzeComprehensive code analysis, quality assessment, and issue diagnosis. Use when analyzing code quality, security vulnerabilities…majiayu000scanning-dependency-vulnerabilitiesUse when scanning dependency vulnerabilities is required during security work, especially when the result must be traceable…casioreview20-glitchschemaWhen the user wants to add, fix, or optimize schema markup and structured data on their site. Also use when the user mentions…Infrasity-Labsscope-checkUse when determining which repositories or files a task affects. Distinguishes between target repos (where changes happen) and…majiayu000script-kit-mcpModel Context Protocol (MCP) implementation for Script Kit. Use when working with MCP server, JSON-RPC 2.0 protocol, kit tools…majiayu000rfiCrowdsourced forecasting questions and predictions from the RAND Forecasting Initiative (formerly INFER). Policy-relevant…majiayu000secret-detection-scannerDetect secrets, credentials, and sensitive data in code and configurations. Scan git history for secrets, detect API keys…a5c-aiwritessecrets-managementEnterprise secrets management across platforms. Manage secrets with HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, GCP…a5c-aiwritessecrets-managerAWS Secrets Manager for secure secret storage and rotation. Use when storing credentials, configuring automatic rotation…itsmostafasection-reviewFirst-principles, truth-seeking, zero-assumption section review. Decomposes the problem before judging the solution. Questions…majiayu000secure-coding-training-skillDeveloper security training and assessment for secure coding practices and vulnerability preventiona5c-aiwritessecuring-software-supply-chainUse when securing software supply chain is required during security work, especially when the result must be traceable…casioreview20-glitchsecurity-baselineEstablish a security baseline for a website or web app. Use this skill when configuring HTTPS and TLS, setting security headers…rampstackcosecurity-compliance-compliance-checkYou are a compliance expert specializing in regulatory requirements for software systems including GDPR, HIPAA, SOC2, PCI-DSS…sickn33security-hardeningAIDefence security layer with prompt injection blocking, input validation, sandboxed execution, output sanitization, and STRIDE…a5c-aiwritessecurity-requirement-extractionDerive security requirements from threat models and business context. Use when translating threats into actionable requirements…sickn33security-requirement-extractionDerive security requirements from threat models and business context. Use when translating threats into actionable requirements…wshobsonsecurity-reviewSecurity vulnerability assessment identifying OWASP risks, injection vectors, authentication issues, and data exposure with…a5c-aiwritessecurity-reviewUse this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing…mturacsecurity-reviewUse this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing…vibeevalsecurity-sandboxIsolated analysis environment management for malware and exploit testing. Create and manage isolated VMs, configure Cuckoo…a5c-aiwritessecurity-scannerRun security scans including SAST, dependency scanning, and secret detectiona5c-aiwritessecurity-scanningAgentShield security audit with 5 scanning categories, 102 static analysis rules, and optional red-team simulation.a5c-aiwritessecurity-scanning-security-dependenciesYou are a security expert specializing in dependency vulnerability analysis, SBOM generation, and supply chain security. Scan…sickn33selfauditPause and do a first-principles audit of recent workmajiayu000seo-a11y-analyzerAnalyzes HTML/JSX/TSX files for SEO and accessibility issues including WCAG 2.1 AA compliance, color contrast (4.5:1), heading…majiayu000seo-analyzerAnalyzes HTML files for SEO issues using static analysis with cheerio. Checks meta tags, Open Graph, Twitter Cards, heading…majiayu000seo-auditAudit affiliate blog posts and landing pages for SEO issues. Triggers on: "audit my blog post for SEO", "check my SEO", "SEO…Affitorseo-auditRun comprehensive SEO audit. Use when: checking technical health, on-page, content quality, E-E-A-T, or link profile.indranilbanerjeeseo-auditWhen the user wants to audit, review, or diagnose SEO issues on their site. Also use when the user mentions "SEO audit,"…majiayu000seo-audit-orchestrationMaster orchestrator for a full SEO audit suite powered by the Ahrefs MCP. Use this skill when running a comprehensive SEO audit…rampstackcoseo-auditDiagnose and audit SEO issues affecting crawlability, indexation, rankings, and organic performance.majiayu000seo-auditAudit websites for SEO, technical, content, security, JS rendering, and AI readiness using SEOmator CLI. Returns LLM-optimized…majiayu000seo-backlink-auditAudit a backlink profile using Ahrefs MCP data: profile health, anchor text distribution, toxic link identification, lost link…rampstackcoseo-content-auditComprehensive SEO footprint analysis. Catalogs all content, pulls real SEO metrics (via Apify Semrush/Ahrefs scrapers or free web…gooseworks-aiseo-content-engineBuild and run an SEO content engine: audit current state, identify gaps, build keyword architecture, generate content calendar…gooseworks-aiseo-content-gap-auditAudit content gaps and decay using Ahrefs MCP data: missing topics, thin coverage, outdated content, and decaying pages. Use this…rampstackcoseo-imagesImage optimization analysis for SEO and performance. Checks alt text, file sizes, formats, responsive images, lazy loading, and…majiayu000writesseo-keyword-gap-auditFind keywords competitors rank for that the target property does not, and prioritize them by opportunity. Uses Ahrefs MCP for…rampstackcoseo-site-health-auditTriage technical SEO findings from Ahrefs Site Audit (and similar crawlers) by SEO impact, not just severity. Use this skill when…rampstackcoseo-technicalTechnical SEO audit across 9 categories: crawlability, indexability, security, URL structure, mobile, Core Web Vitals, structured…Infrasity-Labsshap-model-explainabilityModel interpretability via SHAP (Shapley values from game theory). Covers explainer choice (Tree, Deep, Linear, Kernel, Gradient…BioTender-max
← Prev26 / 58Next →
How the catalog works
What is an agent skill?

A folder with a SKILL.md inside — instructions, and often scripts and assets, that an AI agent loads when the task matches. Claude Code, Codex, Cursor and Copilot all read the same format, so one skill usually works across them.

Where does this catalog come from?

We read 660 source repositories straight from their file trees rather than from submitted listings — what you see is what is actually published. 98 repositories were rejected because they advertise skills but contain none: link lists, not folders.

Why is there no install counter?

Because install counts live in the registry that serves `npx skills add`, and that is not ours — publishing a number we cannot verify would be worse than showing none. Instead we show where a skill comes from and whether attention around its source is actually growing, measured from our own weekly snapshots.

Do you deduplicate?

Yes, and it matters more than expected. Aggregator repositories republish the same skill in several places — one source carried 6,317 SKILL.md files for 2,001 actual skills. We collapse by folder name and keep the canonical copy, so the catalog counts things, not copies.

Keep going