Agent skills

Security skills

Read straight from the source repositories, not from submitted listings. Every skill shows what it does, what is inside, where it came from — and whether attention around its source is actually growing.

Toolclaude-code 29,140codex 4,755cursor 3,111copilot 976windsurf 55cline 34
CategoryWorkflow & Productivity 4,979AI & Agents 3,037Data & Analytics 2,345Code Review & Quality 1,376Backend & API 1,244Security 1,194Design & Presentation 1,154Documentation 965Content & Marketing 916Testing & QA 777DevOps & Cloud 576Databases 550Frontend 469Business & Finance 328Media & Video 257Other 9,833
2,762 found
1,4411,488 · page 31 / 58
anima-security-basicsSecure Anima and Figma tokens for design-to-code pipelines. Use when protecting API credentials, restricting Figma access scope…jeremylongshorewritesannual-computer-security-applications-conferenceUse when targeting Annual Computer Security Applications Conference (ACSAC) or deciding whether a computer-science manuscript…brycewang-stanfordAnsible Dynamic SSH Password Resolution with FallbackUse this skill when creating Ansible tasks that delegate commands to multiple hosts and require dynamically resolving SSH…ECNU-ICALKanth-deploy-integrationDeploy Claude API integrations to production cloud environments. Use when deploying Claude-powered services to Docker, Cloud Run…jeremylongshorewritesanth-install-authInstall and configure Anthropic Claude SDK authentication for Python and TypeScript. Use when setting up a new Claude API…jeremylongshorewritesanth-security-basicsApply Anthropic Claude API security best practices for key management, input validation, and prompt injection defense. Use when…jeremylongshorewritesaos-data-analysisUse when analyzing the material of an Accounting, Organizations and Society (AOS) manuscript — coding and interpreting…brycewang-stanfordapi-analyzerValidates whether an API request is correct based on provided inputs (method, URL, headers, body, auth, query params). Use this…sickn33api-for-yourselfPublish 'how to work with me' as a literal API spec — endpoints (what to ask me for and what you'll get back), rate limits…mohitagw15856api-key-auth-setupConfigure api key auth setup operations. Auto-activating skill for API Development. Triggers on: api key auth setup, api key auth…jeremylongshorewritesapi-key-managerManage api key manager operations. Auto-activating skill for Security Fundamentals. Triggers on: api key manager, api key manager…jeremylongshorewritesapi-page-generatorWhen the user wants to create, optimize, or audit the API introduction/overview page. Also use when the user mentions "API page,"…kostja94API SAAS eCommerce App Feature SpecificationDefine the architecture and feature set for a fully automated API-based eCommerce SaaS application, including specific security…ECNU-ICALKapi-security-arbeitnehmerueberwachung-itWenn es um API Security in NIS-2, Cybersecurity und IT-Sicherheits-Compliance geht: prüft Frist, Form, Zuständigkeit, Rechtsweg…Klotzketteapi-security-best-practicesImplement secure API design patterns including authentication, authorization, input validation, rate limiting, and protection…sickn33api-security-testingAPI security testing workflow for REST and GraphQL APIs covering authentication, authorization, rate limiting, input validation…sickn33api-test-planPlan tests for an API endpoint or service — functional, negative, and contract. Use when asked to test an API, write API test…mohitagw15856apify-collectCollect fresh job-posting URLs into ~/.dear-hiring-manager/urls.txt by running an Apify job scraper — the discovery source for…extrasmall0apollo-install-authInstall and configure Apollo.io API authentication. Use when setting up a new Apollo integration, configuring API keys, or…jeremylongshorewritesapp-clipsWhen the user wants to implement, optimize, or use App Clips for app discovery and conversion. Use when the user mentions "App…Eronredapp-launchWhen the user wants to plan a launch strategy for a new app or major update. Also use when the user mentions "app launch"…Eronredapp-store-featuredWhen the user wants to get featured on the App Store or understand the editorial process. Also use when the user mentions "get…Eronredappfolio-install-authConfigure AppFolio Stack API authentication with OAuth 2.0. Use when setting up property management API access, registering as an…jeremylongshorewritesappfolio-security-basicsSecure AppFolio API credentials and tenant data. 'jeremylongshorewritesapple-notes-install-authSet up macOS automation access for Apple Notes via AppleScript, JXA, and Shortcuts. Use when configuring accessibility…jeremylongshorewritesapple-notes-security-basicsApply security best practices for Apple Notes automation scripts. 'jeremylongshorewritesarbeitsgericht-klage-arbeitsschutz-auditWenn es um Arbeitsgericht Klage in Hinweisgeberschutz, Meldestellen und NDA-Konflikte geht: erstellt den passenden Entwurf aus…Klotzkettearbeitsunfall-dguv-audit-trailWenn es um Arbeitsunfallanzeige DGUV in Berichtspflichten-Erlediger geht: ordnet Akteninhalt, Belege, Lücken und Nachforderungen…Klotzkettearpsych-revisionUse when responding to the Annual Review of Psychology (ARPsych) Editor's or Committee's peer-review letter on a delivered…brycewang-stanfordarsoc-writing-styleUse when revising an Annual Review of Sociology (ARSoc) review for the ARSoc voice — authoritative, accessible to sociologists…brycewang-stanfordasc-apple-adsUse when managing Apple Ads with asc, including auth, org lookup, campaigns, ad groups, ads, keywords, reports, raw API calls…rorkaiasc-cli-usageGuidance for using asc cli in this repo (flags, output formats, pagination, auth, and discovery). Use when asked to run or design…rorkaiasc-workflowDefine, validate, run, resume, and audit repo-local multi-step automations with current `asc workflow` and `.asc/workflow.json`…rorkaiaso-auditWhen the user wants a full ASO health audit, review their App Store listing quality, or diagnose why their app isn't ranking.…Eronredasplos-submissionUse when running the final pre-upload audit of an ASPLOS submission — the 11-page limit covering figures/tables/footnotes with…brycewang-stanfordassemblyai-install-authInstall and configure AssemblyAI SDK authentication. Use when setting up a new AssemblyAI integration, configuring API keys, or…jeremylongshorewritesassemblyai-security-basicsApply AssemblyAI security best practices for API keys, PII, and access control. Use when securing API keys, implementing PII…jeremylongshorewritesassertion-qualityAnalyzes the variety and depth of assertions across test suites in any language. Use when the user asks to evaluate assertion…dotnetasset-freeze-atlas-ausfuhranmeldung-auditWenn es um Asset Freeze: Sofortmassnahmen beim Einfrieren sanktionierten Vermögens in Außenwirtschaft, Sanktionen, Zoll und CBAM…Klotzketteassigns-auditInspect LiveView socket assigns for memory bloat — missing temporary_assigns, unused assigns, unbounded lists needing streams…oliver-kriskawritesassignsCompatibility alias for the Elixir/Phoenix plugin's LiveView assigns audit. Invoke explicitly with /lv:assigns.oliver-kriskaatlas-ledgerCompanion to atlas-contract. Auto-invoked by its Final Audit on caught drift; also use after Post Reviews or user requests to…sickn33attack-surface-analyzerAnalyze attack surface analyzer operations. Auto-activating skill for Security Advanced. Triggers on: attack surface analyzer…jeremylongshorewritesattio-install-authSet up Attio REST API authentication with access tokens or OAuth 2.0. Use when configuring API keys, setting token scopes…jeremylongshorewritesattio-prod-checklistProduction readiness checklist for Attio API integrations -- auth, error handling, rate limits, health checks, monitoring, and…jeremylongshoreattio-security-basicsSecure Attio API integrations -- token scoping, secret management, scope auditing, webhook signature verification, and rotation…jeremylongshorewritesaudit-barrierefreiheits-bfsgWenn es um Audit: Schriftsatz-, Brief- und Memo-Bausteine in Barrierefreiheit Web Checker geht: erstellt den passenden Entwurf…Klotzketteaudit-context-buildingEnables ultra-granular, line-by-line code analysis to build deep architectural context before vulnerability or bug finding.sickn33
← Prev31 / 58Next →
How the catalog works
What is an agent skill?

A folder with a SKILL.md inside — instructions, and often scripts and assets, that an AI agent loads when the task matches. Claude Code, Codex, Cursor and Copilot all read the same format, so one skill usually works across them.

Where does this catalog come from?

We read 660 source repositories straight from their file trees rather than from submitted listings — what you see is what is actually published. 98 repositories were rejected because they advertise skills but contain none: link lists, not folders.

Why is there no install counter?

Because install counts live in the registry that serves `npx skills add`, and that is not ours — publishing a number we cannot verify would be worse than showing none. Instead we show where a skill comes from and whether attention around its source is actually growing, measured from our own weekly snapshots.

Do you deduplicate?

Yes, and it matters more than expected. Aggregator repositories republish the same skill in several places — one source carried 6,317 SKILL.md files for 2,001 actual skills. We collapse by folder name and keep the canonical copy, so the catalog counts things, not copies.

Keep going