Agent skills

Security skills

Read straight from the source repositories, not from submitted listings. Every skill shows what it does, what is inside, where it came from — and whether attention around its source is actually growing.

Toolclaude-code 29,140codex 4,755cursor 3,111copilot 976windsurf 55cline 34
CategoryWorkflow & Productivity 4,979AI & Agents 3,037Data & Analytics 2,345Code Review & Quality 1,376Backend & API 1,244Security 1,194Design & Presentation 1,154Documentation 965Content & Marketing 916Testing & QA 777DevOps & Cloud 576Databases 550Frontend 469Business & Finance 328Media & Video 257Other 9,833
2,762 found
2,1612,208 · page 46 / 58
iso13485-audit-prep/cs:iso13485-audit-prep <scope> — ISO 13485 QMS audit 6-question forcing interrogation. Design controls + CAPA + post-market…alirezarezvaniiso27001-audit-prep/cs:iso27001-audit-prep <scope> — ISO 27001 ISMS audit readiness 6-question forcing interrogation. Use before annual Clause 9.2…alirezarezvaniiso27001-gap-analyzerAnalyze iso27001 gap analyzer operations. Auto-activating skill for Security Advanced. Triggers on: iso27001 gap analyzer…jeremylongshorewritesissta-writing-styleUse when revising an ISSTA paper for a clear testing/analysis contribution, covering the threat-model-then-technique structure…brycewang-stanfordIT Asset Risk AssessmentEvaluate the risk profile of IT or organizational assets by determining threat values, vulnerability levels, likelihood of…ECNU-ICALKIT Policy and Threat Analysis GeneratorGenerates IT policy introductions covering specific compliance topics and analyzes security threats using a strict 4-part…ECNU-ICALKit_risk_register_and_impact_generationGenerates structured IT risk register entries (Asset, Risk, Category, Impact, CIA, Severity, Recommendations, Implementation) and…ECNU-ICALKIT Security Risk Explanation from Organizational PerspectiveSummarize IT security vulnerabilities or technical issues from an organization's point of view in a single sentence.ECNU-ICALKjanitor-valueShow whether each skill is earning its context-window cost — combined tokens-used view sorted by waste. Use when the user asks…jeremylongshorejar-literature-positioningUse when positioning a Journal of Accounting Research (JAR) manuscript within the accounting literature — stating the…brycewang-stanfordjava-helidonGet best practices for developing applications with Helidon 4 (SE and MP). Use when working with Helidon SE or Helidon MP…githubjebo-robustnessUse when a Journal of Economic Behavior & Organization (JEBO) result may be fragile to demand effects, multiple comparisons…brycewang-stanfordjegeo-robustnessUse when results for a Journal of Economic Geography (JEG) manuscript may be sensitive to spatial scale, the weight matrix…brycewang-stanfordjfqa-topic-selectionUse when judging whether a research question fits the Journal of Financial and Quantitative Analysis (JFQA) — empirical and…brycewang-stanfordjhe-robustnessUse when a Journal of Health Economics (JHE) result must be shown stable to specification, sample, inference, and mechanism…brycewang-stanfordjleo-robustnessUse when organizing robustness and sensitivity checks for a Journal of Law, Economics, and Organization (JLEO) manuscript —…brycewang-stanfordjmcb-robustnessUse when a Journal of Money, Credit and Banking (JMCB) result may be specification-, sample-, or inference-sensitive and you need…brycewang-stanfordjournalist-fit-checkGate a pitch against one journalist at a time. Runs the pair through proven media-relations checks (last-10-bylines audit, 90-day…elvisunjourney-authUse as the auth build stage of the Butterbase journey, after journey-schema (and rls if separate). Implements the Auth section of…butterbase-aijourney-deployUse as the deploy-verification stage of the Butterbase journey, after journey-frontend (or after any build stage if there is no…butterbase-aijourney-planUse as stage 2 of the Butterbase journey, after journey-idea has written 01-idea.md. Translates the idea + capability map into a…butterbase-aijpe-referee-strategyUse when running a pre-submission pre-mortem on a Journal of Political Economy (JPE) manuscript to anticipate the price-theory…brycewang-stanfordjru-robustnessUse when a Journal of Risk and Uncertainty (JRU) result may be sensitive to specification, incentive frame, sample, or inference.…brycewang-stanfordjuicebox-install-authInstall and configure Juicebox PeopleGPT API authentication. Use when setting up people search or initializing Juicebox. 'jeremylongshorewritesjwt-token-validatorValidate jwt token validator operations. Auto-activating skill for Security Fundamentals. Triggers on: jwt token validator, jwt…jeremylongshorewriteskb-auditAudit a knowledge base / help center for coverage, accuracy, and findability. Use when asked to audit a help center, review KB…mohitagw15856keep-reconCustomer success reconnaissance — audit current onboarding completion, health signals, NRR, churn patterns, and CS motion. Use…jeremylongshorewriteskey-rotation-managerManage key rotation manager operations. Auto-activating skill for Security Advanced. Triggers on: key rotation manager, key…jeremylongshorewriteskeyword-researchWhen the user wants to discover, evaluate, or prioritize App Store keywords. Also use when the user mentions "keyword research"…Eronredklausel-mindestlizenzen-meldungen-auditWenn es um Klausel Mindestlizenzen, Meldungen, Audit in Lizenzvertragsersteller geht: ordnet Sachverhalt, Norm, Beweislast…Klotzkettekpi-lieferbindung-eigenmarkenWenn es um Franchise: KPI-Audit und Kündigungsreife in Franchiserecht Praxis geht: ordnet Akteninhalt, Belege, Lücken und…Klotzkettekubernetes-rbac-analyzerAnalyze kubernetes rbac analyzer operations. Auto-activating skill for Security Advanced. Triggers on: kubernetes rbac analyzer…jeremylongshorewriteskvkk-complianceKVKK and GDPR compliance patterns - consent management, right to erasure, breach notification, audit logging, cookie consent, and…vibeevallanding-page-auditAudit landing pages. Use when: scoring above-fold clarity, trust signals, form friction, message match, or mobile UX.indranilbanerjeelanding-page-generatorWhen the user wants to create, optimize, or audit campaign landing pages for paid ads, email, or other traffic. Also use when the…kostja94langfuse-install-authInstall and configure Langfuse SDK authentication for LLM observability. Use when setting up a new Langfuse integration…jeremylongshorewriteslangfuse-security-basicsImplement Langfuse security best practices for API keys and data privacy. Use when securing Langfuse integration, protecting API…jeremylongshorewriteslanguage-auditAudit multilingual content consistency. Use when: checking language parity, regional compliance, or translation quality.indranilbanerjeelaravel-expertSenior Laravel Engineer role for production-grade, maintainable, and idiomatic Laravel solutions. Focuses on clean architecture…sickn33laravel-security-auditSecurity auditor for Laravel applications. Analyzes code for vulnerabilities, misconfigurations, and insecure practices using…sickn33laravel-securityLaravel security best practices for authn/authz, validation, CSRF, mass assignment, file uploads, secrets, rate limiting, and…mturaclaravel-verificationVerification loop for Laravel projects: env checks, linting, static analysis, tests with coverage, security scans, and deployment…mturaclat-md-knowledge-graphDesign or audit a repo-local markdown knowledge graph with wiki links, source-code backlinks, drift checks, and searchable…stevesolunLFSR Encryption and Decryption ImplementationImplements a Linear Feedback Shift Register (LFSR) algorithm in Python to encrypt and decrypt messages. It handles user inputs…ECNU-ICALKLFSR Encryption and Decryption ScriptGenerates a Python script to encrypt and decrypt messages using a Linear Feedback Shift Register (LFSR) with user-defined…ECNU-ICALKlicense-compliance-scannerScan license compliance scanner operations. Auto-activating skill for Security Fundamentals. Triggers on: license compliance…jeremylongshorewriteslieferkette-supplier-logdaten-beschaeftigteWenn es um Lieferkette Supplier Security in NIS-2, Cybersecurity und IT-Sicherheits-Compliance geht: prüft Frist, Form…Klotzkettelinear-install-authInstall and configure Linear SDK/CLI authentication. Use when setting up a new Linear integration, configuring API keys, OAuth2…jeremylongshorewrites
← Prev46 / 58Next →
How the catalog works
What is an agent skill?

A folder with a SKILL.md inside — instructions, and often scripts and assets, that an AI agent loads when the task matches. Claude Code, Codex, Cursor and Copilot all read the same format, so one skill usually works across them.

Where does this catalog come from?

We read 660 source repositories straight from their file trees rather than from submitted listings — what you see is what is actually published. 98 repositories were rejected because they advertise skills but contain none: link lists, not folders.

Why is there no install counter?

Because install counts live in the registry that serves `npx skills add`, and that is not ours — publishing a number we cannot verify would be worse than showing none. Instead we show where a skill comes from and whether attention around its source is actually growing, measured from our own weekly snapshots.

Do you deduplicate?

Yes, and it matters more than expected. Aggregator repositories republish the same skill in several places — one source carried 6,317 SKILL.md files for 2,001 actual skills. We collapse by folder name and keep the canonical copy, so the catalog counts things, not copies.

Keep going