Agent skills

Security skills

Read straight from the source repositories, not from submitted listings. Every skill shows what it does, what is inside, where it came from — and whether attention around its source is actually growing.

Toolclaude-code 29,140codex 4,755cursor 3,111copilot 976windsurf 55cline 34
CategoryWorkflow & Productivity 4,979AI & Agents 3,037Data & Analytics 2,345Code Review & Quality 1,376Backend & API 1,244Security 1,194Design & Presentation 1,154Documentation 965Content & Marketing 916Testing & QA 777DevOps & Cloud 576Databases 550Frontend 469Business & Finance 328Media & Video 257Other 9,833
2,762 found
1,7291,776 · page 37 / 58
blog-geoAI citation readiness audit as part of SEO, covering classic Google search and AI search surfaces together. Use whenever the user…AgriciDanielblog-geoAI citation readiness audit ONLY (does not touch Google rankings, use blog-rewrite for combined Google+AI work). Use whenever the…Infrasity-Labsblog-page-generatorWhen the user wants to create, optimize, or audit blog index or listing page structure (not a single post). Also use when the…kostja94blog-locale-auditAudit a directory of multilingual blog content for completeness, consistency, hreflang correctness, meta-tag parity, and…AgriciDanielblog-locale-auditAudit a directory of multilingual blog content for completeness, consistency, hreflang correctness, meta-tag parity, and…Infrasity-Labsblog-rewriteRewrite and optimize existing blog posts for Google SEO (May 2026 Core Update, E-E-A-T) and AI citation visibility as one SEO…AgriciDanielblog-rewriteRewrite and optimize existing blog posts for Google rankings (December 2025 Core Update, E-E-A-T) and AI citations (GEO/AEO).…Infrasity-Labsblog-seo-checkPost-writing SEO validation with pass/fail checklist covering title tag length and keyword placement, meta description quality…AgriciDanielblog-seo-checkPost-writing SEO validation with pass/fail checklist covering title tag length and keyword placement, meta description quality…Infrasity-Labsbrand-impersonation-responseRespond to a brand or executive impersonation incident — deepfaked executives, cloned support lines, fake apps, spoofed domains…mohitagw15856brand-visual-generatorWhen the user wants to define, audit, or apply visual identity (typography, colors, spacing, design tokens, frontend aesthetics).…kostja94brandingWhen the user wants to define, audit, or apply brand strategy—purpose, values, positioning, storytelling, voice, narrative (not…kostja94brandkitPremium brand-kit image generation skill for creating high-end brand-guidelines boards, logo systems, identity decks, and…Leonxlnxbreadcrumb-generatorWhen the user wants to add, optimize, or audit breadcrumb navigation. Also use when the user mentions "breadcrumbs," "breadcrumb…kostja94brightdata-install-authInstall and configure Bright Data SDK/CLI authentication. Use when setting up a new Bright Data integration, configuring API…jeremylongshorewritesbrightdata-security-basicsApply Bright Data security best practices for secrets and access control. Use when securing API keys, implementing least…jeremylongshorewritesbroken-authenticationIdentify and exploit authentication and session management vulnerabilities in web applications. Broken authentication…sickn33brooks-harnessMaintenance orchestrator for the brooks-lint plugin itself. Runs a sequential subagent pipeline — author → eval → QA →…hyhmrrightbrooks-harnessMaintenance orchestrator for the brooks-lint plugin itself. Runs a sequential subagent pipeline — author → eval → QA →…sickn33browser-agent-preflightRun the pre-flight checklist before an agent drives a browser — the untrusted-web-content threat (every page is…mohitagw15856browser-auth-flowProbe a site's authentication flow for redirect leaks, missing CSRF, weak session cookies, and OAuth misconfiguration; produces…ruvnetwritesbtm-rezeptur-audit-apothekenverbundWenn es um BtM Rezeptur AMTS Schnellcheck in Apothekenrecht geht: prüft Frist, Form, Zuständigkeit, Rechtsweg und…Klotzkettebuergerversammlung-protokoll-auditWenn es um Bürgerversammlung — Protokoll-Audit in Normenkontrolle Bauleitplanung — Paragraf 47 VwGO geht: zerlegt Ergebnis…KlotzketteBuffer Overflow Exploit Payload GeneratorGenerates a Python script to construct a buffer overflow payload consisting of padding, a return address, a NOP sled, and…ECNU-ICALKBuffer Overflow Payload GeneratorGenerates a buffer overflow attack payload with a specific stack layout (padding, return address, NOP sled, shellcode) and saves…ECNU-ICALKbugs-are-annoyingAdversarial code auditor that hunts down bugs, logic errors, and security flaws. Use for deep correctness passes, not style…sickn33build-appUse when building a new Butterbase app from scratch, creating a full-stack application, or when the user asks to set up a…butterbase-aiburp-suite-testingExecute comprehensive web application security testing using Burp Suite's integrated toolset, including HTTP traffic interception…sickn33burpsuite-project-parserSearches and explores Burp Suite project files (.burp) from the command line. Use when searching response headers or bodies with…sickn33writesbuzz-reconPR and community reconnaissance — audit current press coverage, social presence, community health, and competitor PR. Use when…jeremylongshorewritesca-auditAssemble the governance record for a range — commits, overrides, ADRs, sprint auto-decisions, open questions, checkpoint findings…arbiterForgeca-context-checkOptional manual drift audit — report stale provenance-tracked docs, then per stale doc offer re-scout, re-baseline, or defer. Not…arbiterForgeca-overrideSanctioned, logged bypass of a gate or hard rule — one audit line, then proceed.arbiterForgeca-previewZero-onboarding, read-only dry-run of the reviewer fleet against the current uncommitted diff. Predicts reviewers, runs the…arbiterForgeca-threat-modelOpt-in lightweight STRIDE pass for a sensitive feature before implementation. Not a routine gate — invoke it when a change…arbiterForgeca-tribunalDeep, rarely-convened whole-codebase audit — eleven specialist lenses, a resumable on-disk audit log, findings filed as GitHub…arbiterForgecampaign-architectUse when the user asks to "plan my paid account structure", "pick Search vs PMax", "lay out ad groups / asset groups", or "audit…aaron-he-zhucampaign-auditAudit a brand's existing live campaigns across every active channel — paid, organic, email, social, content, SEO. Produce a…indranilbanerjeewritescanva-install-authSet up Canva Connect API OAuth 2.0 PKCE authentication and project scaffolding. Use when creating a new Canva integration…jeremylongshorewritescanva-security-basicsApply Canva Connect API security best practices for OAuth tokens and access control. Use when securing OAuth credentials…jeremylongshorewritescardWhen the user wants to design, optimize, or audit card layouts for content display. Also use when the user mentions "card…kostja94careers-page-generatorWhen the user wants to create, optimize, or audit a careers or jobs page. Also use when the user mentions "careers," "jobs,"…kostja94carouselWhen the user wants to design, optimize, or audit carousel/slider layouts for content display. Also use when the user mentions…kostja94castai-install-authInstall and configure CAST AI agent on a Kubernetes cluster with API key authentication. Use when onboarding a cluster to CAST…jeremylongshorewritescastai-security-basicsSecure CAST AI API keys, RBAC configuration, and Kvisor security agent. Use when hardening CAST AI cluster access, configuring…jeremylongshorewritescastai-webhooks-eventsConfigure CAST AI webhook notifications for cluster events and audit logs. Use when setting up alerts for node scaling, cost…jeremylongshorewritescategory-page-generatorWhen the user wants to create, optimize, or audit e-commerce category pages or listing pages. Also use when the user mentions…kostja94cc-skill-security-reviewThis skill ensures all code follows security best practices and identifies potential vulnerabilities. Use when implementing…sickn33
← Prev37 / 58Next →
How the catalog works
What is an agent skill?

A folder with a SKILL.md inside — instructions, and often scripts and assets, that an AI agent loads when the task matches. Claude Code, Codex, Cursor and Copilot all read the same format, so one skill usually works across them.

Where does this catalog come from?

We read 660 source repositories straight from their file trees rather than from submitted listings — what you see is what is actually published. 98 repositories were rejected because they advertise skills but contain none: link lists, not folders.

Why is there no install counter?

Because install counts live in the registry that serves `npx skills add`, and that is not ours — publishing a number we cannot verify would be worse than showing none. Instead we show where a skill comes from and whether attention around its source is actually growing, measured from our own weekly snapshots.

Do you deduplicate?

Yes, and it matters more than expected. Aggregator repositories republish the same skill in several places — one source carried 6,317 SKILL.md files for 2,001 actual skills. We collapse by folder name and keep the canonical copy, so the catalog counts things, not copies.

Keep going