Agent skills

Security skills

Read straight from the source repositories, not from submitted listings. Every skill shows what it does, what is inside, where it came from — and whether attention around its source is actually growing.

Toolclaude-code 29,139codex 4,760cursor 3,079copilot 978windsurf 55cline 34
CategoryWorkflow & Productivity 4,987AI & Agents 3,033Data & Analytics 2,347Code Review & Quality 1,377Backend & API 1,243Security 1,197Design & Presentation 1,129Documentation 967Content & Marketing 917Testing & QA 777DevOps & Cloud 576Databases 550Frontend 469Business & Finance 328Media & Video 258Other 9,845
2,780 found
97144 · page 3 / 58
ms365-tenant-managerComprehensive Microsoft 365 tenant administration skill for setup, configuration, user management, security policies, and…alirezarezvaniscriptsoss-tool-trust-auditUse when an open-source developer tool, package, CLI, agent, or MCP server must be evaluated for legitimacy, supply-chain risk…asimons81scriptspre-build-feature-auditUse when a proposed open-source feature must be checked across source, history, branches, issues, pull requests, roadmaps, and…asimons81scriptsshapExplain and audit machine-learning predictions with SHAP. Use for selecting SHAP explainers and maskers, computing and validating…K-Dense-AIwritesscriptsvertex-engine-inspectorInspect and validate Vertex AI Agent Engine deployments including Code Execution Sandbox, Memory Bank, A2A protocol compliance…jeremylongshorescriptsanalyzing-security-headersAnalyze HTTP security headers of web domains to identify vulnerabilities and misconfigurations. Use when you need to audit…jeremylongshorescriptsassisting-with-soc2-audit-preparationExecute automate SOC 2 audit preparation including evidence gathering, control assessment, and compliance gap identification. Use…jeremylongshorewritesscriptsaws-advisorExpert AWS Cloud Advisor for architecture design, security review, and implementation guidance. Leverages AWS MCP tools for…tech-leads-clubscriptsazure-cosmos-db-pyBuild Azure Cosmos DB NoSQL services with Python/FastAPI following production-grade patterns. Use when implementing database…microsoftscriptscode-reviewerDefault code-quality route for broad code review, PR review, maintainability, correctness, and regression-risk checks. Do not use…foryourhealth111-pixelscriptshelp-me-get-startedFriendly, jargon-free onboarding for people new to coding agents and Power BI agentic development. Invoke for setup…data-goblinscriptsms365-tenant-managerMicrosoft 365 tenant administration for Global Administrators. Automate M365 tenant setup, Office 365 admin tasks, Azure AD user…alirezarezvaniscriptsperforming-penetration-testingOrchestrate a penetration test by routing user intent to one or more of the 25 narrow skills in this pack. Confirms authorization…jeremylongshorewritesscriptspm-skillsUse when coordinating project-delivery work across the 8 project-management sub-skills — sprint/velocity analytics, portfolio…alirezarezvaniscriptssecurity-ownership-mapAnalyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensitive-code…Haohao-endscriptsanalyzing-dependenciesAnalyze dependencies for known security vulnerabilities and outdated versions. Use when auditing third-party libraries. Trigger…jeremylongshorewritesscriptschecking-infrastructure-complianceExecute use when you need to work with compliance checking. This skill provides compliance monitoring and validation with…jeremylongshorewritesscriptssecurity-audit全面的代码安全检查和服务器安全审计skill。适用于:(1) 代码漏洞扫描 - 检测SQL注入、XSS、SSRF等OWASP Top 10漏洞,(2) 依赖安全检查 - 识别过时或有漏洞的第三方库,结合实时搜索确认最新CVE,(3) 服务器配置审计 -…staruhubscriptsgh-address-commentsHelp address review/issue comments on the open GitHub PR for the current branch using gh CLI; verify gh auth first and prompt the…Haohao-endscriptsimplementing-database-audit-loggingProcess use when you need to track database changes for compliance and security monitoring. This skill implements audit logging…jeremylongshorewritesscriptsiso42001-specialistISO/IEC 42001:2023 AI Management System (AIMS) specialist for compliance teams running internal audits. Three decisions: (1)…alirezarezvaniscriptsjetson-memory-auditMeasure Jetson DRAM/NvMap usage and verify before/after memory reclamation with live audit data.NVIDIAscriptsperforming-security-auditsAnalyze code, infrastructure, and configurations by conducting comprehensive security audits. It leverages tools within the…jeremylongshorewritesscriptsperforming-security-code-reviewExecute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin. it analyzes…jeremylongshorewritesscriptsprocurement-optimizerUse when running an annual SaaS audit, doing category-level spend review, or rationalizing the supplier base — when the user…alirezarezvaniscriptsresponding-to-security-incidentsAnalyze and guide security incident response, investigation, and remediation processes. Use when you need to handle security…jeremylongshorewritesscriptsrfp-responderUse when an RFP, RFI, RFQ, security questionnaire, vendor questionnaire, or proposal request arrives and the team needs a…alirezarezvaniscriptssemgrepRun Semgrep static analysis scan on a codebase using parallel subagents. Supports two scan modes — "run all" (full ruleset…trailofbitswritesscriptssoc2-complianceUse when the user asks to prepare for SOC 2 audits, map Trust Service Criteria, build control matrices, collect audit evidence…alirezarezvaniscriptsxcode-build-orchestratorOrchestrate Xcode build optimization by benchmarking first, running the specialist analysis skills, prioritizing findings…AvdLeescriptsauditorAudit a generated Data2Story blog for build correctness across ALL modalities by ACTUALLY RENDERING it in a real headless browser…QinghongLinwritesscriptsclinical-variant-reporterClassify germline variants from VCF/BCF files according to the ACMG/AMP 2015 28-criteria evidence framework and generate…BioTender-maxscriptscode-review-excellenceThis skill should be used when the user asks to review a diff or pull request, write review comments, audit code quality…brycewang-stanfordscriptsdocxRead, edit, or create Microsoft Word `.docx` files. Trigger this skill whenever the user mentions a Word document, .docx file…opensquillascriptsgh-actions-validatorValidate use when validating GitHub Actions workflows for Google Cloud and Vertex AI deployments. Trigger with phrases like…jeremylongshorewritesscriptsimprove-my-agent-setupAudit and improve an entire agentic-development setup, including skills, context, memory, tools, models, permissions, hooks…data-goblinscriptslight-project-structureAudit, plan, scaffold, and safely migrate research project structures across greenfield, existing Git/non-Git repositories, and…Light0305scriptslocal-seo-managerManage local SEO for service-area businesses — appliance repair, HVAC, plumbing, cleaning, and any business that serves customers…alirezarezvaniscriptsperforming-security-testingTest automate security vulnerability testing covering OWASP Top 10, SQL injection, XSS, CSRF, and authentication issues. Use when…jeremylongshorewritesscriptspptx-html-fidelity-auditAudit a python-pptx export against its source HTML deck, identify layout/content drift (footer overflow, cropped content, missing…nexu-ioscriptssecrets-vault-managerUse when the user asks to set up secret management infrastructure, integrate HashiCorp Vault, configure cloud secret stores (AWS…alirezarezvaniscriptssecurity-ownership-mapAnalyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensitive-code…tech-leads-clubscriptssecurity-pen-testingUse when the user asks to perform security audits, penetration testing, vulnerability scanning, OWASP Top 10 checks, or offensive…alirezarezvaniscriptssenior-secopsSenior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development…alirezarezvaniscriptsseo-auditWhen the user wants to audit, review, or diagnose SEO issues on their site. Also use when the user mentions "SEO audit,"…alirezarezvaniscriptsskill-creatorCreate, edit, audit, tidy, validate, or restructure AgentSkills and SKILL.md files.Health-Yangscriptsskill-creatorCreate, edit, improve, or audit AgentSkills. Use when creating a new skill from scratch or when asked to improve, review, audit…SafeAI-Lab-Xscriptssocial-media-analyzerSocial media campaign analysis and performance tracking. Calculates engagement rates, ROI, and benchmarks across platforms. Use…alirezarezvaniscripts
← Prev3 / 58Next →
How the catalog works
What is an agent skill?

A folder with a SKILL.md inside — instructions, and often scripts and assets, that an AI agent loads when the task matches. Claude Code, Codex, Cursor and Copilot all read the same format, so one skill usually works across them.

Where does this catalog come from?

We read 660 source repositories straight from their file trees rather than from submitted listings — what you see is what is actually published. 98 repositories were rejected because they advertise skills but contain none: link lists, not folders.

Why is there no install counter?

Because install counts live in the registry that serves `npx skills add`, and that is not ours — publishing a number we cannot verify would be worse than showing none. Instead we show where a skill comes from and whether attention around its source is actually growing, measured from our own weekly snapshots.

Do you deduplicate?

Yes, and it matters more than expected. Aggregator repositories republish the same skill in several places — one source carried 6,317 SKILL.md files for 2,001 actual skills. We collapse by folder name and keep the canonical copy, so the catalog counts things, not copies.

Keep going