Agent skills

Security skills

Read straight from the source repositories, not from submitted listings. Every skill shows what it does, what is inside, where it came from — and whether attention around its source is actually growing.

Toolclaude-code 29,139codex 4,760cursor 3,079copilot 978windsurf 55cline 34
CategoryWorkflow & Productivity 4,987AI & Agents 3,033Data & Analytics 2,347Code Review & Quality 1,377Backend & API 1,243Security 1,197Design & Presentation 1,129Documentation 967Content & Marketing 917Testing & QA 777DevOps & Cloud 576Databases 550Frontend 469Business & Finance 328Media & Video 258Other 9,845
2,781 found
145192 · page 4 / 58
validating-authentication-implementationsValidate authentication mechanisms for security weaknesses and compliance. Use when reviewing login systems or auth flows.…jeremylongshorewritesscriptsvalidator-expertValidate production readiness of Vertex AI Agent Engine deployments across security, monitoring, performance, compliance, and…jeremylongshorescriptsaudit-tenant-settingsAutomatically invoke this skill whenever the user asks about Fabric tenant settings or Power BI tenant settings or auditing…data-goblinscriptsbullshit-detectorFact-check and hype-audit content. Extracts the discrete claims from a video, article, tweet, or PDF, verifies each against…SerhiiKorniienkoscriptsciso-advisorSecurity leadership for growth-stage companies. Risk quantification in dollars, compliance roadmap (SOC 2/ISO 27001/HIPAA/GDPR)…alirezarezvaniscriptsfuzzing-apisConfigure perform API fuzzing to discover edge cases, crashes, and security vulnerabilities. Use when performing specialized…jeremylongshorewritesscriptsgraph-evolutionCompares Trailmark code graphs at two source code snapshots (git commits, tags, or directories) to surface security-relevant…trailofbitsscriptsinformation-security-manager-iso27001ISO 27001 ISMS implementation and cybersecurity governance for HealthTech and MedTech companies. Use when designing an ISMS…alirezarezvaniscriptsisms-audit-expertInformation Security Management System (ISMS) audit expert for ISO 27001 compliance verification, security control assessment…alirezarezvaniscriptsqinyan-nature-figures面向 Nature Portfolio 与高影响力期刊的证据驱动科研绘图技能。用于从原始或汇总数据设计单图与多面板 figure、选择合适图形语法、编写 Python/R 绘图代码、重绘现有图件、生成机制示意图草案、撰写图注并导出可编辑 SVG/PDF…LeonChaoXscriptssaas-scaffolderGenerates complete, production-ready SaaS project boilerplate including authentication, database schemas, billing integration…alirezarezvaniscriptsscanning-container-securityExecute use when you need to work with security and compliance. This skill provides security scanning and vulnerability detection…jeremylongshorewritesscriptssemgrepRun Semgrep static analysis scan on a codebase using parallel subagents. Supports two scan modes — \"run all\" (full ruleset…waybarriosscriptssenior-securityUse when the user asks for STRIDE threat modeling, DREAD risk scoring, data-flow-diagram threat analysis, or a quick secret scan…alirezarezvaniscriptsskill-security-auditorSecurity auditing for code, configs, and infrastructure. Use when the user wants to audit or improve security: scan for…eigent-aiscriptsstata-replicationRun replication, robustness, and specification-sensitivity workflows for Stata projects. Use when a researcher wants to reproduce…brycewang-stanfordscriptsvalidating-cors-policiesValidate CORS policies for security issues and misconfigurations. Use when reviewing cross-origin resource sharing. Trigger with…jeremylongshorescriptsanalytics-trackingSet up, audit, and debug analytics tracking implementation — GA4, Google Tag Manager, event taxonomy, conversion tracking, and…alirezarezvaniscriptsanalyzing-tls-configAnalyze a target's TLS configuration — negotiated protocol version, cipher suite, certificate chain, expiry, and downgrade…jeremylongshorescriptsatlassian-adminAtlassian Administrator for managing and organizing Atlassian products (Jira, Confluence, Bitbucket, Trello), users, permissions…alirezarezvaniscriptsauditing-access-controlAudit access control implementations for security vulnerabilities and misconfigurations. Use when reviewing authentication and…jeremylongshorewritesscriptschecking-owasp-complianceCheck compliance with OWASP Top 10 security risks and best practices. Use when performing comprehensive security audits. Trigger…jeremylongshorewritesscriptscode-tourUse this skill to create CodeTour .tour files — persona-targeted, step-by-step walkthroughs that link to real files and line…githubscriptsencrypting-and-decrypting-dataValidate encryption implementations and cryptographic practices. Use when reviewing data security measures. Trigger with 'check…jeremylongshorewritesscriptsfeishu-safety-guideOne-click deployment Skill for Feishu security governance and message anti-data-leakage guide, responsible for Feishu message…SafeAI-Lab-Xscriptsgenerating-compliance-reportsGenerate comprehensive compliance reports for security standards. Use when creating compliance documentation. Trigger with…jeremylongshorewritesscriptsmorningstarMorningstar Screener via API JSON publica: descarga masiva de 53 universes (102K+ listings, 39 paises, NYSE/Nasdaq/BCBA/etc) con…gauss314scriptsqms-audit-expertISO 13485 internal audit expertise for medical device QMS. Covers audit planning, execution, nonconformity classification, and…alirezarezvaniscriptsscanning-for-vulnerabilitiesExecute this skill enables comprehensive vulnerability scanning using the vulnerability-scanner plugin. it identifies security…jeremylongshorewritesscriptsvalidating-csrf-protectionValidate CSRF protection implementations for security gaps. Use when reviewing form security or state-changing operations.…jeremylongshorewritesscriptsvalidating-pci-dss-complianceValidate PCI-DSS compliance for payment card data security. Use when auditing payment systems. Trigger with 'validate PCI-DSS'…jeremylongshorewritesscriptscode-reviewingReview code for quality, security, and best practices. Use when the user asks for code review, wants feedback on their code…huangjia2019scriptsauditing-cors-policyAudit a target's CORS posture — Access-Control-Allow-Origin handling, reflected-origin bypass, credentials+wildcard mismatch…jeremylongshorescriptsauditing-npm-dependenciesAudit a Node.js project's installed npm dependency tree for known CVEs by wrapping the npm audit JSON output and emitting…jeremylongshorescriptsauditing-python-dependenciesAudit a Python project's installed dependencies for known CVEs by wrapping pip-audit (PyPA's official vulnerability auditor) and…jeremylongshorescriptsautomated-test-planningProduce a standalone test plan by analyzing code for test coverage gaps and edge cases. Use when you need to create, generate, or…testdoublescriptsburpsuite-project-parserSearches and explores Burp Suite project files (.burp) from the command line. Use when searching response headers or bodies with…trailofbitswritesscriptscheck-deckInvestment deck QC: number consistency, data-narrative alignment, IB language, formatting auditginlix-aiscriptschecking-http-security-headersAudit a target's HTTP security headers — CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy…jeremylongshorescriptschecking-license-complianceAudit a project's dependency licenses against an explicit policy (allow-list / deny-list / review-required) and flag…jeremylongshorescriptscode-reviewUse when asked to review a PR, MR, branch, or diff, audit changed files, or check code quality.evancascriptscomposing-vulnerability-reportRead findings JSONL files from cluster 1-4 skills, deduplicate by fingerprint, group by severity, and compose a deliverable-…jeremylongshorewritesscriptsconfirming-pentest-authorizationVerify that a penetration test has explicit, written, signed authorization before any scanning begins. Reads a Rules-of-…jeremylongshorescriptsdefining-pentest-scopeParse the ROE scope definition, enumerate every in-scope target (hostnames, IPs, CIDRs, URLs, cloud accounts, SaaS tenants)…jeremylongshorescriptsdetecting-command-injection-patternsScan a source tree for command-injection vulnerable patterns: shell=True calls in Python subprocess, os.system / os.popen with…jeremylongshorescriptsdetecting-debug-endpointsProbe a target for accidentally-public admin / debug / introspection endpoints — Spring Boot Actuator, Apache server-status…jeremylongshorescriptsdetecting-directory-listingProbe a target for directories that return auto-generated index listings instead of denying or serving a specific file — exposes…jeremylongshorescriptsdetecting-eval-exec-usageScan a source tree for dynamic-code-execution APIs that an attacker can hijack: Python eval / exec / compile, JavaScript eval /…jeremylongshorescripts
← Prev4 / 58Next →
How the catalog works
What is an agent skill?

A folder with a SKILL.md inside — instructions, and often scripts and assets, that an AI agent loads when the task matches. Claude Code, Codex, Cursor and Copilot all read the same format, so one skill usually works across them.

Where does this catalog come from?

We read 660 source repositories straight from their file trees rather than from submitted listings — what you see is what is actually published. 98 repositories were rejected because they advertise skills but contain none: link lists, not folders.

Why is there no install counter?

Because install counts live in the registry that serves `npx skills add`, and that is not ours — publishing a number we cannot verify would be worse than showing none. Instead we show where a skill comes from and whether attention around its source is actually growing, measured from our own weekly snapshots.

Do you deduplicate?

Yes, and it matters more than expected. Aggregator repositories republish the same skill in several places — one source carried 6,317 SKILL.md files for 2,001 actual skills. We collapse by folder name and keep the canonical copy, so the catalog counts things, not copies.

Keep going