Agent skills

Security skills

Read straight from the source repositories, not from submitted listings. Every skill shows what it does, what is inside, where it came from — and whether attention around its source is actually growing.

Toolclaude-code 29,140codex 4,755cursor 3,111copilot 976windsurf 55cline 34
CategoryWorkflow & Productivity 4,979AI & Agents 3,037Data & Analytics 2,345Code Review & Quality 1,376Backend & API 1,244Security 1,194Design & Presentation 1,154Documentation 965Content & Marketing 916Testing & QA 777DevOps & Cloud 576Databases 550Frontend 469Business & Finance 328Media & Video 257Other 9,833
2,762 found
2,2572,304 · page 48 / 58
meta-security-review-bundleCompose three independent security gates over a candidate operation — policy/governance review, secret/credential scan, and…opensquillametadata-optimizationWhen the user wants to optimize App Store metadata — title, subtitle, keyword field, or description. Also use when the user…Eronredmetasploit-framework⚠️ AUTHORIZED USE ONLY > This skill is for educational purposes or authorized security assessments only. > You must have…sickn33methodenwahl-ergebnisoffenheit-auditWenn es um Methodenwahl-Audit: Ergebnisoffenheit prüfen in Methodenlehre bürgerliches Recht geht: prüft Frist, Form…Klotzkettemetric-gaslighting-detectorFind out how a dashboard, KPI report, or metrics slide is lying to you — before you repeat its story in a bigger room. Use when…mohitagw15856microsoft-foundry-classicExpert knowledge for Microsoft Foundry Classic (aka Azure AI Foundry classic) development including troubleshooting, best…MicrosoftDocsmicrosoft-foundryExpert knowledge for Microsoft Foundry (aka Azure AI Foundry) development including troubleshooting, best practices, decision…MicrosoftDocsmicrosoft-foundry-toolsExpert knowledge for Microsoft Foundry Tools (aka Azure AI services, Azure Cognitive Services) development including…MicrosoftDocsmigration-page-generatorWhen the user wants to create, optimize, or audit migration guides for users switching from competitors. Also use when the user…kostja94mindtickle-install-authInstall and configure MindTickle SDK/API authentication. Use when setting up a new MindTickle integration. 'jeremylongshorewritesminimal-web-baas-demoFast path for a minimal CloudBase Web + database demo (最小前后端 / 最小可用 fullstack / Lovable-like BaaS). Defaults to @cloudbase/js-sdk…TencentCloudBaseminutes-lintHealth-check your meeting knowledge for contradictions, stale commitments, and decision conflicts. Use when the user asks "any…silversteinmiro-enterprise-rbacConfigure Miro Enterprise features: organization management, SCIM provisioning, board-level access control, audit logs, and SSO…jeremylongshorewritesmiro-install-authInstall and configure Miro REST API v2 authentication with OAuth 2.0. Use when setting up a new Miro app, configuring OAuth…jeremylongshorewritesmiro-multi-env-setupConfigure Miro REST API v2 across development, staging, and production with separate OAuth apps, isolated test boards, and secret…jeremylongshorewritesmiro-security-basicsApply Miro REST API v2 security best practices \u2014 OAuth scope minimization,\n\ token storage, webhook signature validation…jeremylongshorewritesmistral-install-authInstall and configure the Mistral AI SDK with authentication. Use when setting up a new Mistral integration, configuring API…jeremylongshorewritesmistral-security-basicsApply Mistral AI security best practices for secrets, prompt injection, and access control. Use when securing API keys, defending…jeremylongshorewritesmobicom-submissionUse when running the final pre-upload audit of a MobiCom submission — confirming the right per-edition HotCRP site and round, the…brycewang-stanfordmobicom-topic-selectionUse when deciding whether a project belongs at MobiCom or a sibling venue — testing whether the core contribution is a…brycewang-stanfordmobile-security-coderExpert in secure mobile coding practices specializing in input validation, WebView security, and mobile-specific security…sickn33mock-hunterAudit a live web page in five phases (catalog, click, trace, classify, report) to identify mock data, hardcoded values…sickn33naacl-submissionUse when a paper aimed at NAACL is about to be uploaded to an ACL Rolling Review cycle — verifying that the chosen cycle can…brycewang-stanfordnarco-checkMemory integrity audit. Detects hallucinations, circular confirmations, and state poisoning. Runs automatically after 2…open-gitagentnarrative-drift-monitorUse when the user asks to "check if our surfaces have drifted from the canon", "watch for competitor repositioning", or "define…aaron-he-zhunavigation-menu-generatorWhen the user wants to design, optimize, or audit site navigation menus. Also use when the user mentions "navigation," "nav…kostja94nbr-qualitative-caseUse for qualitative theory-building submitted to 《南开管理评论》 (Nankai Business Review) — multi-case comparison (replication logic…brycewang-stanfordnda-und-audit-rightsWenn es um NDA Und Audit Rights in NDA-Generator und Verschwiegenheitsvereinbarungs-Checker geht: ordnet Sachverhalt, Norm…Klotzkettendss-related-workUse when positioning an NDSS submission against prior literature — sweeping the security big four plus the specialist venues…brycewang-stanfordndss-submissionUse when performing the final pre-upload audit of an NDSS submission — HotCRP fields, the AoE deadline, NDSS template and 13-page…brycewang-stanfordndss-topic-selectionUse when deciding whether a security project belongs at NDSS — the Network and Distributed System Security Symposium — or should…brycewang-stanfordndss-workflowUse when planning an NDSS submission calendar — choosing between the summer and fall cycles, backward-planning from the AoE…brycewang-stanfordneon-postgresGuides and best practices for working with Neon Serverless Postgres. Covers setup, connection methods, branching, autoscaling…sickn33network-101Configure and test common network services (HTTP, HTTPS, SNMP, SMB) for penetration testing lab environments. Enable hands-on…sickn33network-and-distributed-system-security-symposiumUse when targeting Network and Distributed System Security Symposium (NDSS) or deciding whether a computer-science manuscript…brycewang-stanfordnetwork-config-validationPre-deployment checks for router and switch configuration, including dangerous commands, duplicate addresses, subnet overlaps…mturacnetwork-engineerExpert network engineer specializing in modern cloud networking, security architectures, and performance optimization.sickn33Network Intrusion Detection Pipeline with K-Means, EPO, and Bi-LSTMExecute a specific machine learning workflow for network intrusion detection that involves preprocessing, K-Means based outlier…ECNU-ICALKnetwork-security-scannerScan network security scanner operations. Auto-activating skill for Security Advanced. Triggers on: network security scanner…jeremylongshorewritesnewsletter-signup-generatorWhen the user wants to design, optimize, or audit newsletter signup forms. Also use when the user mentions "newsletter," "email…kostja94next-taskRun one unattended IMPLEMENTATION iteration of the autonomous value-creation loop — steward any in-flight PR, fix interrupts (red…breaking-brakenextjs-supabase-authExpert integration of Supabase Auth with Next.js App Routersickn33nikaRuns repeatable AI work as checked, budgeted workflow files.sickn33node-connectDiagnose OpenClaw Android, iOS, or macOS node pairing, QR/setup code, route, auth, and connection failures.Health-Yangnodejs-best-practicesNode.js development principles and decision-making. Framework selection, async patterns, security, and architecture. Teaches…sickn33notes-humanizerStrips AI writing patterns from text and rewrites it to sound genuinely human — removing the statistical defaults, then adding…mohitagw15856nsdi-submissionUse when running the final pre-upload audit of an NSDI submission — the abstract-then-paper week on the per-deadline HotCRP site…brycewang-stanfordnsf-award-api-guideSearch NSF awards and grants with free public API, no auth requiredbrycewang-stanford
← Prev48 / 58Next →
How the catalog works
What is an agent skill?

A folder with a SKILL.md inside — instructions, and often scripts and assets, that an AI agent loads when the task matches. Claude Code, Codex, Cursor and Copilot all read the same format, so one skill usually works across them.

Where does this catalog come from?

We read 660 source repositories straight from their file trees rather than from submitted listings — what you see is what is actually published. 98 repositories were rejected because they advertise skills but contain none: link lists, not folders.

Why is there no install counter?

Because install counts live in the registry that serves `npx skills add`, and that is not ours — publishing a number we cannot verify would be worse than showing none. Instead we show where a skill comes from and whether attention around its source is actually growing, measured from our own weekly snapshots.

Do you deduplicate?

Yes, and it matters more than expected. Aggregator repositories republish the same skill in several places — one source carried 6,317 SKILL.md files for 2,001 actual skills. We collapse by folder name and keep the canonical copy, so the catalog counts things, not copies.

Keep going