Agent skills

Security skills

Read straight from the source repositories, not from submitted listings. Every skill shows what it does, what is inside, where it came from — and whether attention around its source is actually growing.

Toolclaude-code 29,140codex 4,755cursor 3,111copilot 976windsurf 55cline 34
CategoryWorkflow & Productivity 4,979AI & Agents 3,037Data & Analytics 2,345Code Review & Quality 1,376Backend & API 1,244Security 1,194Design & Presentation 1,154Documentation 965Content & Marketing 916Testing & QA 777DevOps & Cloud 576Databases 550Frontend 469Business & Finance 328Media & Video 257Other 9,833
2,762 found
2,0652,112 · page 44 / 58
github-opsGitHub repository operations, automation, and management. Issue triage, PR management, CI/CD operations, release management, and…mturacgithubGitHub operations via `gh` CLI: issues, PRs, CI runs, code review, API queries. Use when: (1) checking PR status or CI, (2)…SafeAI-Lab-Xgithub-workflow-automationAdvanced GitHub Actions workflow automation with AI swarm coordination, intelligent CI/CD pipelines, and comprehensive repository…ruvnetglean-install-authInstall and configure Glean API authentication with indexing and client tokens. Use when setting up custom datasource indexing…jeremylongshorewritesglean-security-basicsToken security: Indexing tokens have write access -- never expose in frontend. 'jeremylongshorewritesglossary-page-generatorWhen the user wants to create, optimize, or audit glossary page content and structure. Also use when the user mentions…kostja94goZero-config goal-to-tasks engine. Takes any goal (software, pentest, business, learning), runs adaptive discovery, generates a…anombyte93writesgrade-testsGrades a specified set of test methods individually and produces a concise table mapping each test (fully-qualified name) to a…dotnetgrammarly-install-authInstall and configure Grammarly SDK/CLI authentication. Use when setting up a new Grammarly integration, configuring API keys, or…jeremylongshorewritesgrammarly-security-basicsSecurity fundamentals for Grammarly API credential management. Use when setting up secure authentication and token handling for…jeremylongshorewritesgranola-install-authInstall and configure Granola AI meeting notes with calendar and audio permissions. Use when setting up Granola for the first…jeremylongshorewritesgraphql-architectMaster modern GraphQL with federation, performance optimization, and enterprise security. Build scalable schemas, implement…sickn33greenwashing-self-auditAudit your own marketing and report claims for greenwashing risk before a regulator, journalist, or competitor does. Use when…mohitagw15856gridWhen the user wants to design, optimize, or audit grid layouts for content display. Also use when the user mentions "grid…kostja94grocery-budget-auditFind where the food money actually goes — a no-shame ledger built from real receipts/statements, the four leak categories (waste…mohitagw15856gtopdb-databaseQuery IUPHAR/BPS Guide to Pharmacology (GtoPdb) for receptor-ligand interactions, target/ligand metadata, families, and approved…BioTender-maxGuide to cracking a wifi password without a deauthentication attackA step-by-step workflow for auditing Wi-Fi security by capturing a WPA/WPA2 handshake using Wireshark and cracking it with…ECNU-ICALKgws-admin-reportsGoogle Workspace Admin SDK: Audit logs and usage reports.googleworkspacegws-setupSet up the Google Workspace CLI (gws) from scratch. Guides through GCP project creation, OAuth credentials, authentication, and…jezwebhandoff-templatesAgent arasi iletisim sablonlari. Standard handoff, QA verdict (PASS/FAIL), escalation, bug report, security finding ve status…vibeevalhardcoded-credential-finderManage hardcoded credential finder operations. Auto-activating skill for Security Fundamentals. Triggers on: hardcoded credential…jeremylongshorewritesharness-drift-from-historyOne-command drift detection. Composes audit-list + oia-audit + audit-trend into a single primitive — finds the most recent audit…ruvnetwritesharness-gepaInspect and audit GEPA genomes via the `@metaharness/darwin/gepa` library entry (darwin 0.8.0) — load/validate a genome (default…ruvnetwritesharness-mcp-scanStatic security scan of a harness's declared MCP surface via `harness mcp-scan <path>`. Reads `.mcp/servers.json` +…ruvnetwritesharness-oia-auditComposite Phase-2 audit worker (ADR-150). Bundles harness oia-manifest + threat-model + mcp-scan into one timestamped audit…ruvnetwritesharness-security-benchRun `@metaharness/darwin security bench` (upstream "Darwin Shield" / ADR-155) — evolves a champion security-detection harness…ruvnetwritesharness-threat-modelEnterprise-review-grade threat model from `harness threat-model <path>`. Categorizes MCP-surface threats; emits `worst…ruvnetwriteshealth-inspection-prepRun a self-audit of a food establishment before the health inspector arrives, focused on the violations that actually close…mohitagw15856healthcare-phi-complianceProtected Health Information (PHI) and Personally Identifiable Information (PII) compliance patterns for healthcare applications.…mturachealthcheckAudit/harden OpenClaw hosts: SSH, firewall, updates, exposure, backups, disk encryption, gateway security.Health-YanghealthcheckHost security hardening and risk-tolerance configuration for OpenClaw deployments. Use when a user asks for security audits…SafeAI-Lab-Xhero-generatorWhen the user wants to design, optimize, or audit hero sections (above-the-fold main visual area). Also use when the user…kostja94hex-install-authInstall and configure Hex SDK/CLI authentication. Use when setting up a new Hex integration, configuring API keys, or…jeremylongshorewriteshex-security-basicsApply Hex security best practices for secrets and access control. Use when securing API keys, implementing least privilege…jeremylongshorewritesHigh-Security Corporate Meeting PlanningDevelops comprehensive security plans for high-risk corporate meetings or board events, focusing on venue hardening, access…ECNU-ICALKhipaa-audit-helperAssist with hipaa audit helper operations. Auto-activating skill for Security Advanced. Triggers on: hipaa audit helper, hipaa…jeremylongshorewriteshipaa-complianceEnsure HIPAA compliance when handling PHI (Protected Health Information). Use when writing code that accesses user health data…FreedomIntelligencewriteshipaa-complianceHIPAA-specific entrypoint for healthcare privacy and security work. Use when a task is explicitly framed around HIPAA, PHI…mturachipaa-compliance-validatorHIPAA compliance validation skill for genomic data handling and audita5c-aiwritesHIPAA Incident Response Plan GeneratorGenerates a comprehensive, HIPAA-compliant Incident Response Plan for medical companies, including team structures, tiered…ECNU-ICALKhomepage-generatorWhen the user wants to create, optimize, or audit the main site homepage (primary entry page). Also use when the user mentions…kostja94hongkong-risikoszenario-national-security-law-und-rechtsstaatWenn es um Hongkong-Risikoszenario: National Security Law und Rechtsstaat in China-Wirtschaftsverkehr geht: prüft Frist, Form…Klotzkettehonorarabhaengigkeit-non-audit-services-kammerantwortWenn es um Honorarabhaengigkeit Non Audit Services Kammerantwort in Berufsrecht Wirtschaftsprüfer geht: ordnet Akteninhalt…Klotzkettehonorarabhaengigkeit-non-audit-services-rechtsprechungscheckWenn es um Honorarabhaengigkeit Non Audit Services Rechtsprechungscheck in Berufsrecht Wirtschaftsprüfer geht: zerlegt Ergebnis…Klotzkettehonorarabhaengigkeit-und-non-audit-servicesWenn es um Honorarabhaengigkeit Und Non Audit Services in Berufsrecht Wirtschaftsprüfer geht: klärt Rolle, Ziel, Frist…Klotzkettehook-failure-auditAudit hook delivery health from Agent Monitor data — balance PreToolUse vs PostToolUse (a gap means tools that started but never…hoangsonwwhootsuite-install-authInstall and configure Hootsuite SDK/CLI authentication. Use when setting up a new Hootsuite integration, configuring API keys, or…jeremylongshorewriteshootsuite-security-basicsApply Hootsuite security best practices for secrets and access control. Use when securing API keys, implementing least privilege…jeremylongshorewrites
← Prev44 / 58Next →
How the catalog works
What is an agent skill?

A folder with a SKILL.md inside — instructions, and often scripts and assets, that an AI agent loads when the task matches. Claude Code, Codex, Cursor and Copilot all read the same format, so one skill usually works across them.

Where does this catalog come from?

We read 660 source repositories straight from their file trees rather than from submitted listings — what you see is what is actually published. 98 repositories were rejected because they advertise skills but contain none: link lists, not folders.

Why is there no install counter?

Because install counts live in the registry that serves `npx skills add`, and that is not ours — publishing a number we cannot verify would be worse than showing none. Instead we show where a skill comes from and whether attention around its source is actually growing, measured from our own weekly snapshots.

Do you deduplicate?

Yes, and it matters more than expected. Aggregator repositories republish the same skill in several places — one source carried 6,317 SKILL.md files for 2,001 actual skills. We collapse by folder name and keep the canonical copy, so the catalog counts things, not copies.

Keep going