Agent skills

Security skills

Read straight from the source repositories, not from submitted listings. Every skill shows what it does, what is inside, where it came from — and whether attention around its source is actually growing.

Toolclaude-code 29,140codex 4,755cursor 3,111copilot 976windsurf 55cline 34
CategoryWorkflow & Productivity 4,979AI & Agents 3,037Data & Analytics 2,345Code Review & Quality 1,376Backend & API 1,244Security 1,194Design & Presentation 1,154Documentation 965Content & Marketing 916Testing & QA 777DevOps & Cloud 576Databases 550Frontend 469Business & Finance 328Media & Video 257Other 9,833
2,762 found
1,7771,824 · page 38 / 58
ccs-artifact-evaluationUse when packaging ACM CCS artifacts for the artifact-evaluation committee and the ACM badges — Artifacts Available, Artifacts…brycewang-stanfordccs-author-responseUse when drafting an ACM CCS rebuttal during the HotCRP author-response window, covering threat-model defenses, adaptive-attack…brycewang-stanfordccs-experimentsUse when designing or auditing ACM CCS experiments, attack demonstrations, adaptive-attack defense evaluations, security…brycewang-stanfordccs-related-workUse when positioning an ACM CCS submission against the security big-four and specialist literature, including arXiv preprints…brycewang-stanfordccs-reproducibilityUse when strengthening ACM CCS reproducibility evidence, including the artifact-availability posture, threat-model-to-evidence…brycewang-stanfordccs-supplementaryUse when preparing ACM CCS appendices and supplementary material, including the ethics considerations appendix, protocol…brycewang-stanfordccs-topic-selectionUse when deciding whether a security project fits ACM CCS versus IEEE S&P, USENIX Security, NDSS, PETS, or a crypto/theory venue…brycewang-stanfordccs-workflowUse when planning an ACM CCS project timeline across the two HotCRP review cycles, from venue fit through abstract registration…brycewang-stanfordccs-writing-styleUse when revising an ACM CCS paper for a precise threat model, calibrated attack/defense claims, 12-page ACM sigconf compression…brycewang-stanfordcertificate-lifecycle-managerManage certificate lifecycle manager operations. Auto-activating skill for Security Advanced. Triggers on: certificate lifecycle…jeremylongshorewritescertificate-monitoringUse when the user asks about SSL/TLS certificates, certificate expiration, monitoring domains for cert health, or issuing free…davepoonchannel-hygieneFix a team's chat sprawl — the channel map with one purpose per channel, the naming scheme that makes purpose findable, the…mohitagw15856checkRead-only drift detector. Diffs SPEC.md against current code and reports violations grouped by severity. Writes nothing —…JuliusBrusseecheck-modelFinancial model audit: structural checks, formula validation, integrity testingginlix-aichi-author-responseUse when an ACM CHI paper receives a revise-and-resubmit invitation and the five-week window opens — planning the revision…brycewang-stanfordchn-043-trade-secret-protectionWenn es um Trade Secret Protection in China-Wirtschaftsverkehr geht: prüft Frist, Form, Zuständigkeit, Rechtsweg und…Klotzkettechn-063-supplier-audit-without-window-dressingWenn es um Supplier Audit Without Window Dressing in China-Wirtschaftsverkehr geht: prüft Frist, Form, Zuständigkeit, Rechtsweg…Klotzkettechn-093-security-of-travel-and-devicesWenn es um Security Of Travel And Devices in China-Wirtschaftsverkehr geht: prüft Frist, Form, Zuständigkeit, Rechtsweg und…Klotzkettecitation-checkAudit in-text/reference parity, DOIs, claim support, and citation style.brycewang-stanfordcitation-hygieneKeep citations honest in business documents — every load-bearing claim sourced, links that actually contain the claim, the as-of…mohitagw15856claimsClaims-based authorization for agents and operations. Grant, revoke, and verify permissions for secure multi-agent coordination.…ruvnetclari-common-errorsDiagnose and fix Clari API errors including auth failures, export issues, and data mismatches. Use when Clari API calls fail…jeremylongshoreclari-install-authConfigure Clari API authentication with API key and set up export access. Use when connecting to the Clari API, generating API…jeremylongshorewritesclari-security-basicsSecure Clari API tokens and implement data handling best practices. Use when managing API tokens, restricting data access, or…jeremylongshorewritesclassic-to-default-syncInspect a given commit's web/classic changes and sync all features/fixes to web/default. Use when the user provides a commit ID…charliehzmclaude-authenticityDetect whether an API endpoint is backed by genuine Claude (not a wrapper, proxy, or impersonator) using 9 weighted rule-based…agentscope-aiclaude-md-reviewAudit a CLAUDE.md file for the patterns that actually degrade Claude Code's output — vagueness, unnamed files, stale facts, and…wesammustafaclaude-settings-auditAnalyze a repository to generate recommended Claude Code settings.json permissions. Use when setting up a new project, auditing…sickn33clawkeeperInstall, configure, verify, and debug the Clawkeeper watcher stack in this workspace. Use when a user asks to set up…SafeAI-Lab-Xclay-install-authSet up Clay account access, API keys, webhook URLs, and provider connections. Use when onboarding to Clay, connecting data…jeremylongshorewritesclay-security-basicsApply Clay security best practices for API keys, webhook secrets, and data access control. Use when securing Clay integrations…jeremylongshorewritesclerk-authExpert patterns for Clerk auth implementation, middleware, organizations, webhooks, and user syncsickn33click-path-auditTrace every user-facing button/touchpoint through its full state change sequence to find bugs where functions individually work…mturacclickup-install-authSet up ClickUp API v2 authentication with personal tokens or OAuth 2.0. Use when configuring a new ClickUp integration, setting…jeremylongshorewritesclickup-prod-checklistProduction readiness checklist for ClickUp API v2 integrations covering auth, rate limits, error handling, monitoring, and…jeremylongshoreclickup-security-basicsSecure ClickUp API tokens, implement least-privilege access, and audit usage. Use when securing API keys, rotating tokens…jeremylongshorewritesclinpgx-databaseQuery the ClinPGx (formerly PharmGKB) REST API plus the CPIC PostgREST companion API for pharmacogenomic clinical annotations…BioTender-maxcloud-audit-componentWenn es um Cloud Audit Component in Berufsrecht Wirtschaftsprüfer geht: klärt Rolle, Ziel, Frist, Unterlagen und den passenden…Klotzkettecloud-auditWenn es um Cloud Audit in Berufsrecht Wirtschaftsprüfer geht: zerlegt Ergebnis, Frist, Zuständigkeit, Beweislast und…Klotzkettecloud-audit-tools-und-datenschutz-kammerantwortWenn es um Cloud Audit Tools Und Datenschutz Kammerantwort in Berufsrecht Wirtschaftsprüfer geht: ordnet Akteninhalt, Belege…Klotzkettecloud-audit-tools-und-datenschutz-organisatiWenn es um Cloud Audit Tools Und Datenschutz Organisati in Berufsrecht Wirtschaftsprüfer geht: zerlegt Ergebnis, Frist…Klotzkettecloud-security-postureManage cloud security posture operations. Auto-activating skill for Security Advanced. Triggers on: cloud security posture, cloud…jeremylongshorewritescloudflareComprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK)…shobcodercoach-trainer-program-drittpersonal-securityWenn es um Coach Trainer Seminarleiter in Sozialversicherungsstatus-Prüfer / DRV-Statusfeststellung geht: ordnet Sachverhalt…Klotzkettecode-auditorPerforms comprehensive codebase analysis covering architecture, code quality, security, performance, testing, and…mhattingpetecode-injection-detectorDetect code injection detector operations. Auto-activating skill for Security Fundamentals. Triggers on: code injection detector…jeremylongshorewritescode-review-checklistComprehensive checklist for conducting thorough code reviews covering functionality, security, performance, and maintainabilitysickn33gsd:code-reviewReview source files changed during a phase for bugs, security issues, and code quality problemsdavepoonwrites
← Prev38 / 58Next →
How the catalog works
What is an agent skill?

A folder with a SKILL.md inside — instructions, and often scripts and assets, that an AI agent loads when the task matches. Claude Code, Codex, Cursor and Copilot all read the same format, so one skill usually works across them.

Where does this catalog come from?

We read 660 source repositories straight from their file trees rather than from submitted listings — what you see is what is actually published. 98 repositories were rejected because they advertise skills but contain none: link lists, not folders.

Why is there no install counter?

Because install counts live in the registry that serves `npx skills add`, and that is not ours — publishing a number we cannot verify would be worse than showing none. Instead we show where a skill comes from and whether attention around its source is actually growing, measured from our own weekly snapshots.

Do you deduplicate?

Yes, and it matters more than expected. Aggregator repositories republish the same skill in several places — one source carried 6,317 SKILL.md files for 2,001 actual skills. We collapse by folder name and keep the canonical copy, so the catalog counts things, not copies.

Keep going