Agent skills

Security skills

Read straight from the source repositories, not from submitted listings. Every skill shows what it does, what is inside, where it came from — and whether attention around its source is actually growing.

Toolclaude-code 29,140codex 4,755cursor 3,111copilot 976windsurf 55cline 34
CategoryWorkflow & Productivity 4,979AI & Agents 3,037Data & Analytics 2,345Code Review & Quality 1,376Backend & API 1,244Security 1,194Design & Presentation 1,154Documentation 965Content & Marketing 916Testing & QA 777DevOps & Cloud 576Databases 550Frontend 469Business & Finance 328Media & Video 257Other 9,833
2,762 found
2,1132,160 · page 45 / 58
howto-section-generatorWhen the user wants to create, optimize, or audit a HowTo section block—an in-page block of ordered steps with optional…kostja94hreflang-checkAudit hreflang tags. Use when: checking missing tags, incorrect language codes, or x-default configuration.indranilbanerjeehreflang-internationalInternational / multilingual SEO audit focused on hreflang correctness. Detects and diagnoses the most common (and…nowork-studiohttp-header-security-auditExecute http header security audit operations. Auto-activating skill for Security Fundamentals. Triggers on: http header security…jeremylongshorewriteshttps-certificate-checkerValidate https certificate checker operations. Auto-activating skill for Security Fundamentals. Triggers on: https certificate…jeremylongshorewriteshuman-in-the-loop-designDesign the human approval surface for an agent system — which actions gate, how approvals batch without becoming rubber stamps…mohitagw15856hyperflow-auditHyperflow code review. Use when the user wants the current diff, a commit, branch, or PR reviewed — verbs like audit, review…jeremylongshorehyperflow-deployHyperflow ship phase. Use when the user is ready to release — verbs like ship, push, release, deploy, "cut a release", "ready to…jeremylongshorei18n-readiness-reviewReview a product/codebase for internationalization readiness before you localize. Use when asked if a product is ready to…mohitagw15856iam-policy-reviewerExecute iam policy reviewer operations. Auto-activating skill for Security Advanced. Triggers on: iam policy reviewer, iam policy…jeremylongshorewritesicde-related-workUse when positioning an IEEE ICDE submission against the database canon and neighboring venues, running a reinvention audit…brycewang-stanfordicra-artifact-evaluationUse when packaging the artifacts behind an ICRA paper — ROS packages, controllers, simulation environments, trained policies, CAD…brycewang-stanfordicra-reproducibilityUse when hardening an ICRA paper's reproducibility — specifying robot platform, firmware, ROS and driver versions, control rates…brycewang-stanfordideogram-install-authInstall and configure Ideogram API authentication. Use when setting up a new Ideogram integration, configuring API keys, or…jeremylongshorewritesideogram-security-basicsApply Ideogram security best practices for API key management and access control. Use when securing API keys, implementing key…jeremylongshorewritesieee-symposium-on-security-and-privacyUse when targeting IEEE Symposium on Security and Privacy (IEEE S&P) or deciding whether a computer-science manuscript fits this…brycewang-stanfordieeesp-author-responseUse when drafting the IEEE S&P (Oakland) rebuttal for second-round papers or the response plan for a Revise decision, including…brycewang-stanfordieeesp-related-workUse when positioning an IEEE S&P (Oakland) paper against prior literature, including coverage across the four security flagships…brycewang-stanfordieeesp-topic-selectionUse when deciding whether a security or privacy project belongs at IEEE S&P (Oakland), including the threat-model test, SoK fit…brycewang-stanfordieeesp-writing-styleUse when writing or revising an IEEE S&P (Oakland) paper's prose, including the threat-model-first structure, calibrating…brycewang-stanfordier-robustnessUse when an International Economic Review (IER) result may be sensitive to specification, sample, functional form, calibration…brycewang-stanfordihl-071-audit-rights-supplierWenn es um Audit Rights Supplier in Internationales Handelsrecht und Lex Mercatoria geht: prüft Frist, Form, Zuständigkeit…Klotzketteimage-seo-auditAudit image SEO. Use when: checking alt text, file sizes, WebP/AVIF formats, lazy loading, or responsive images.indranilbanerjeeimage-seoImage SEO audit — make a site's images discoverable in Google Images and stop them from dragging down Core Web Vitals. Audits alt…nowork-studioimc-topic-selectionUse when deciding whether an empirical networking project belongs at ACM IMC or should be routed to SIGCOMM, NSDI, CoNEXT, PAM…brycewang-stanfordimpeccable-design-polishFollow-up design polish skill inspired by Impeccable. Use after a web or HTML artifact exists to audit, critique, polish…nexu-ioimprove-architectureAudit an area of the codebase and propose the smallest structural moves that improve it - untangle boundaries, kill duplication…rohitg00improveAnalyses the current project across code quality, feature gaps, documentation, security, competitive landscape, and monetisation…jeremylongshorewritesin-app-eventsWhen the user wants to create, plan, or optimize App Store In-App Events — the event cards that appear on the Today tab, search…Eronredincident-public-statementWrite a single clear, honest public statement about an incident. Use when asked to draft a public statement, a press statement…mohitagw15856incident-response-plannerConfigure incident response planner operations. Auto-activating skill for Security Advanced. Triggers on: incident response…jeremylongshorewritesinfra-as-code-reviewWrite an infrastructure-as-code review checklist and conduct a structured review of Terraform, CloudFormation, Pulumi, or Ansible…mohitagw15856ink-reconContent marketing reconnaissance — audit current content, SEO health, competitor content gaps, and content distribution. Use when…jeremylongshorewritesink-seoSEO strategy and keyword research — build topic clusters, keyword gap analysis, on-page audit, and prioritized SEO roadmap. Use…jeremylongshorewritesinput-validation-checkerValidate input validation checker operations. Auto-activating skill for Security Fundamentals. Triggers on: input validation…jeremylongshorewritesinsecure-defaultsDetect fail-open configurations, hardcoded secrets, weak authentication defaults, permissive CORS, disabled security features…vibeevalinsecure-deserialization-checkerValidate insecure deserialization checker operations. Auto-activating skill for Security Fundamentals. Triggers on: insecure…jeremylongshorewritesinstantly-debug-bundleCollect Instantly.ai debug evidence for support tickets and troubleshooting. Use when encountering persistent issues, preparing…jeremylongshorewritesinstantly-install-authSet up Instantly.ai API v2 authentication and project configuration. Use when creating a new Instantly integration, generating…jeremylongshorewritesinstantly-security-basicsApply Instantly.ai security best practices for API keys, scopes, and access control. Use when securing API keys, implementing…jeremylongshorewritesintegrate-harnessUse when adding a new agent harness (CLI-based coding agent) adapter to adapters. Covers capability audit, adapter scaffold…a5c-aiintegrations-page-generatorWhen the user wants to create, optimize, or audit integrations, plugins, or extensions pages. Also use when the user mentions…kostja94intercreditor-und-sicherheitenagentWenn es um Intercreditor, Security Agent und Sicherheitenpool in Private Equity Praxis geht: prüft Frist, Form, Zuständigkeit…Klotzketteinternal-linking-optimizerAnalyze site's internal link structure and optimize for hub-and-spoke SEO architecture. Triggers on: "optimize internal links"…Affitorinv-024-audit-committeeWenn es um Internal Investigation: Audit Committee in Internal Investigations Praxis geht: prüft Frist, Form, Zuständigkeit…Klotzketteinv-034-trade-secret-leakWenn es um Internal Investigation: Trade Secret Leak in Internal Investigations Praxis geht: prüft Frist, Form, Zuständigkeit…Klotzketteio-literature-positioningUse when positioning an International Organization (IO) manuscript against the international-relations literature so it reads as…brycewang-stanfordisca-submissionUse when running the final pre-deadline audit of an ISCA submission — the two-step abstract-then-paper gate a week apart, the…brycewang-stanford
← Prev45 / 58Next →
How the catalog works
What is an agent skill?

A folder with a SKILL.md inside — instructions, and often scripts and assets, that an AI agent loads when the task matches. Claude Code, Codex, Cursor and Copilot all read the same format, so one skill usually works across them.

Where does this catalog come from?

We read 660 source repositories straight from their file trees rather than from submitted listings — what you see is what is actually published. 98 repositories were rejected because they advertise skills but contain none: link lists, not folders.

Why is there no install counter?

Because install counts live in the registry that serves `npx skills add`, and that is not ours — publishing a number we cannot verify would be worse than showing none. Instead we show where a skill comes from and whether attention around its source is actually growing, measured from our own weekly snapshots.

Do you deduplicate?

Yes, and it matters more than expected. Aggregator repositories republish the same skill in several places — one source carried 6,317 SKILL.md files for 2,001 actual skills. We collapse by folder name and keep the canonical copy, so the catalog counts things, not copies.

Keep going