Agent skills

Security skills

Read straight from the source repositories, not from submitted listings. Every skill shows what it does, what is inside, where it came from — and whether attention around its source is actually growing.

Toolclaude-code 29,140codex 4,755cursor 3,111copilot 976windsurf 55cline 34
CategoryWorkflow & Productivity 4,979AI & Agents 3,037Data & Analytics 2,345Code Review & Quality 1,376Backend & API 1,244Security 1,194Design & Presentation 1,154Documentation 965Content & Marketing 916Testing & QA 777DevOps & Cloud 576Databases 550Frontend 469Business & Finance 328Media & Video 257Other 9,833
2,762 found
1,2971,344 · page 28 / 58
Technical Debt PatternsExpert guide to detecting, categorizing, and prioritizing technical debt in Rails applications. Use when: (1) Auditing codebase…majiayu000technical-writerAI DevKit · Review and improve documentation for novice users. Use when users ask to review docs, improve documentation, audit…codeaholicguytenant-credit-analystExpert in tenant creditworthiness assessment and financial statement analysis. Use when evaluating tenant credit quality…majiayu000terraform-analyzerSpecialized skill for analyzing Terraform configurations. Supports parsing, security scanning (tfsec, checkov), cost estimation…a5c-aiwritestest-smell-detectionDeep-dive audit using the full testsmells.org 19-smell academic catalog for tests in any language. Every finding maps to a named…dotnettesting-agent-tool-abuseUse when testing agent tool abuse is required during security work, especially when the result must be traceable, independently…casioreview20-glitchtesting-authentication-authorizationUse when testing authentication authorization is required during security work, especially when the result must be traceable…casioreview20-glitchtesting-cost-abuseUse when testing cost abuse is required during security work, especially when the result must be traceable, independently…casioreview20-glitchtesting-input-validationUse when testing input validation is required during security work, especially when the result must be traceable, independently…casioreview20-glitchtesting-prompt-injectionUse when testing prompt injection is required during security work, especially when the result must be traceable, independently…casioreview20-glitchtesting-rate-limitsUse when testing rate limits is required during security work, especially when the result must be traceable, independently…casioreview20-glitchtesting-tenant-isolationUse when testing tenant isolation is required during security work, especially when the result must be traceable, independently…casioreview20-glitchthreat-mitigation-mappingMap identified threats to appropriate security controls and mitigations. Use when prioritizing security investments, creating…sickn33threat-mitigation-mappingMap identified threats to appropriate security controls and mitigations. Use when prioritizing security investments, creating…wshobsonthreat-modelerGenerate threat models using STRIDE, PASTA, or VAST methodologiesa5c-aiwritestls-securityExpert skill for TLS/SSL implementation and certificate management. Generate and validate TLS configurations, create and manage…a5c-aiwritestm7-threat-modelCreates valid Microsoft Threat Modeling Tool (.tm7) files compatible with the Microsoft Threat Modeling Tool v7.3+. Use this…githubtool-process-auditDiagnose a named or described business/engineering process for bottlenecks, risks, and optimization opportunities. Use when a…majiayu000touch-auditMobile audit — app size, startup time, crash reporting, store compliance, accessibility, offline behavior. Use when asked for…jeremylongshorewritestwinmind-security-basicsSecurity best practices for TwinMind: on-device audio processing, encrypted cloud backups, microphone permissions, and data…jeremylongshorewritesultrathink-detective⚡ PRIMARY TOOL for: 'comprehensive audit', 'deep analysis', 'full codebase review', 'multi-perspective investigation', 'complex…majiayu000writesutil-research-librarySystematic library evaluation with emphasis on readability, actionable insights, and informed decision-making. Use when asked…majiayu000validate-marketRun an honest market-fit and viability audit of any project or idea and produce a decision doc, not code. Use when someone asks…tamdogoodwritesvault-cleanup-auditorAudit your Obsidian vault in Claude Code — finds stale drafts, empty folders, duplicate filenames, and incomplete files. Saves a…majiayu000vendor-risk-monitorContinuous vendor security monitoring for security ratings, breach notifications, and risk change detectiona5c-aiwritesvendor-security-questionnaireAutomated vendor security assessment through questionnaire generation, response parsing, and risk scoringa5c-aiwritesverify-darkVerify dark earthquake claims against fault databases. Use when checking if a candidate earthquake is truly "dark" (unmapped…majiayu000vigil-checkVerify observability posture — audit monitoring coverage, find blind spots, prioritize gaps. Use when asked "is monitoring…jeremylongshorewritesvision-auditAudit project alignment with VISION.md, identify SDLC gaps, and generate feature proposals. Use when reviewing strategic…majiayu000writesvolt-powerPower management audit — analyze sleep modes, wake sources, power state machines, radio duty cycles, and battery life estimates.…jeremylongshorewritesvuln-reportDraft a single-vulnerability report in GitHub advisory style from an audit finding, bug note, patch diff, PoC, or code review…waybarriosvulnerability-scannerSecurity vulnerability scanning for dependencies and code, with CVE database checking and risk assessmenta5c-aiwritesvulnerability-triage-brocardsThis skill should be used when the user asks to "triage a vulnerability report", "assess a CVE", "evaluate a bug bounty…trailofbitswarden-auditFull security audit — secrets, dependencies, IAM, auth, injection, XSS, HTTPS, rate limiting, public storage. Use when asked for…jeremylongshorewriteswarden-hardenProduce a hardening spec and implement it — auth patterns, security headers, rate limiting, input validation, secrets management…jeremylongshorewriteswarden-reconSecurity reconnaissance — full inventory of secrets management, IAM, dependencies, auth, encryption, audit logging, and…jeremylongshorewriteswarden-threatProduce a threat model — assets, ranked threats, mitigations, accepted risks. Use when asked to "threat model this", "what could…jeremylongshorewriteswavecap-transcriptsCheck and analyze WaveCap transcriptions. Use when the user wants to inspect transcript quality, find problematic transcriptions…majiayu000wcag-audit-patternsComprehensive guide to auditing web content against WCAG 2.2 guidelines with actionable remediation strategies.sickn33wcag-audit-patternsConduct WCAG 2.2 accessibility audits with automated testing, manual verification, and remediation guidance. Use when auditing…wshobsonaccessibilityAudit and improve web accessibility following WCAG 2.1 guidelines. Use when asked to "improve accessibility", "a11y audit", "WCAG…tech-leads-clubweb-design-guidelinesReview UI code for Web Interface Guidelines compliance. Use when asked to "review my UI", "check accessibility", "audit design"…antfuweb-design-guidelinesReview UI code for Web Interface Guidelines compliance. Use when asked to "review my UI", "check accessibility", "audit design"…fcakyonweb-design-guidelinesReview UI code for Web Interface Guidelines compliance. Use when asked to "review my UI", "check accessibility", "audit design"…tech-leads-clubweb-researchUse when the user wants web research: gathering cited, multi-angle evidence on a specific question. Triggers on: \"research X for…majiayu000web-securityOWASP Top 10, security headers, CSP, XSS prevention, and vulnerability prevention.a5c-aiwriteswhen-mapping-dependencies-use-dependency-mapperComprehensive dependency mapping, analysis, and visualization tool for software projectsmajiayu000windows-authenticode-signerSign Windows executables with Authenticode using signtool, supporting EV and standard certificatesa5c-aiwrites
← Prev28 / 58Next →
How the catalog works
What is an agent skill?

A folder with a SKILL.md inside — instructions, and often scripts and assets, that an AI agent loads when the task matches. Claude Code, Codex, Cursor and Copilot all read the same format, so one skill usually works across them.

Where does this catalog come from?

We read 660 source repositories straight from their file trees rather than from submitted listings — what you see is what is actually published. 98 repositories were rejected because they advertise skills but contain none: link lists, not folders.

Why is there no install counter?

Because install counts live in the registry that serves `npx skills add`, and that is not ours — publishing a number we cannot verify would be worse than showing none. Instead we show where a skill comes from and whether attention around its source is actually growing, measured from our own weekly snapshots.

Do you deduplicate?

Yes, and it matters more than expected. Aggregator repositories republish the same skill in several places — one source carried 6,317 SKILL.md files for 2,001 actual skills. We collapse by folder name and keep the canonical copy, so the catalog counts things, not copies.

Keep going