Agent skills

Security skills

Read straight from the source repositories, not from submitted listings. Every skill shows what it does, what is inside, where it came from — and whether attention around its source is actually growing.

Toolclaude-code 29,140codex 4,755cursor 3,111copilot 976windsurf 55cline 34
CategoryWorkflow & Productivity 4,979AI & Agents 3,037Data & Analytics 2,345Code Review & Quality 1,376Backend & API 1,244Security 1,194Design & Presentation 1,154Documentation 965Content & Marketing 916Testing & QA 777DevOps & Cloud 576Databases 550Frontend 469Business & Finance 328Media & Video 257Other 9,833
2,762 found
193240 · page 5 / 58
detecting-ssl-cert-issuesAudit a target's TLS certificate beyond protocol/expiry — chain ordering, OCSP stapling, revocation status, Certificate…jeremylongshorescriptsdetecting-weak-cryptographyScan a source tree for weak cryptographic primitives: MD5 / SHA-1 used for security purposes, DES / 3DES / RC4 ciphers, ECB block…jeremylongshorescriptsearningswhispersEarnings transcripts completos via API publica de EarningsWhispers. Sin anti-bot, sin auth. 33,500+ stocks globales trackeados.…gauss314scriptsfingerprinting-server-softwareIdentify the server software, framework, and component versions a target is running from its HTTP response signatures — Server…jeremylongshorescriptsfree-tool-strategyWhen the user wants to build a free tool for marketing — lead generation, SEO value, or brand awareness. Use when they mention…alirezarezvaniscriptsgenerating-executive-summaryCompose an exec-readable summary from a unified findings JSONL plus the OWASP coverage report. Computes a single engagement risk…jeremylongshorewritesscriptshan-update-documentationUpdate Han plugin documentation so every skill, agent, guidance doc, index, and cross-reference is current and accurate. On a…testdoublewritesscriptskrypton-vps-codex-appSet up, harden, audit, or explain a Linux VPS as a Codex App SSH host for Krypton-style agent workflows. Use when the user wants…jturntdevscriptsmapping-findings-to-owasp-top10Annotate every pentest finding with its OWASP Top 10 (2021) category by applying a deterministic rule table keyed on source…jeremylongshorewritesscriptsmemory-kitPersistent context management for Claude Code sessions. Save, load, update, share, and audit session memory via MEMORY.md.…jeremylongshorewritesscriptspricing-page-psychology-auditAudits any SaaS pricing page URL against 12 pricing psychology principles and outputs a ranked improvement report with specific…Varnan-Techscriptsprobing-dangerous-http-methodsProbe a target for HTTP methods that should not be enabled in production — TRACE (XST attack), unrestricted PUT/DELETE…jeremylongshorescriptsquality-manager-qms-iso13485ISO 13485 Quality Management System implementation and maintenance for medical device organizations. Provides QMS design…alirezarezvaniscriptsrecording-pentest-engagementPackage an engagement's findings, scan outputs, evidence, and signed ROE into a timestamped archive with a SHA-256 manifest…jeremylongshorescriptsreview-spdFindings-first code review workflow for AI coding agents. Use when the user asks to review uncommitted changes, commits in a date…zhu1090093659scriptsscanning-for-hardcoded-secretsScan a source-code tree for hardcoded credentials embedded in source Anthropic API keys, OpenAI keys, JWT signing secrets…jeremylongshorescriptsschema-markupWhen the user wants to implement, audit, or validate structured data (schema markup) on their website. Use when the user mentions…alirezarezvaniscriptsship-gatePre-production audit that scans a codebase for security, database, deployment, code quality, AI/LLM, dependency, frontend, and…alirezarezvaniscriptssite-architectureWhen the user wants to audit, redesign, or plan their website's structure, URL hierarchy, navigation design, or internal linking…alirezarezvaniscriptsskill-creatorCreate, edit, improve, or audit AgentSkills. Use when creating a new skill from scratch or when asked to improve, review, audit…opensquillascriptsskill-vetter-runtimeReview ClawHub or local Skill packages before installation, classify risk, and return a structured security report.uvwtscriptstracing-transitive-vulnerabilitiesBuild a dependency-tree map of a project (npm or Python) and trace the path from each known-vulnerable transitive package back to…jeremylongshorescriptsai-securityUse when assessing AI/ML systems for prompt injection, jailbreak vulnerabilities, model inversion risk, data poisoning exposure…alirezarezvaniscriptsbroken-link-checkerScans a website to find broken links (404s, 500s). Crawls internal pages, identifies broken outbound links, and reports source…nowork-studioscriptscloud-securityUse when assessing cloud infrastructure for security misconfigurations, IAM privilege escalation paths, S3 public exposure, open…alirezarezvaniscriptscodex-abRun an A/B codex review experiment — holistic codex review vs 3 focused dimension passes (security, ecto, liveview) on the branch…oliver-kriskascriptscontent-strategyWhen the user wants to plan a content strategy, decide what content to create, or figure out what topics to cover. Also use when…alirezarezvaniscriptsfigma-audit-accessibilityDeep accessibility scorecard for a single Figma component or component set — state coverage…southleftscriptsfigma-design-system-inventoryOne call to inventory an entire Figma design system — variables/tokens (grouped by collection + mode), components and component…southleftscriptsfigma-lint-designLint a Figma node tree for WCAG 2.2 accessibility AND design-system quality — contrast, target size, focus indicators, color-only…southleftscriptsfile-headersMANDATORY for every coding agent (Claude Code, Codex, or any other) on every change-set — every applicable source file the agent…hoangsonwwscriptsgh-address-commentsAddress review and issue comments on the open GitHub PR for the current branch using gh CLI. Use when user says "address PR…tech-leads-clubscriptsgoal-setterDraft, audit, or activate a compact /goal when the user asks for a persistent objective or wants Codex to work until a verifiable…gotalabscriptshard-screening-startupDeterministic Python-scored startup screening with full audit trail. Use when you need a reproducible, weighted-score verdict on…davepoonscriptsincident-responseUse when a security incident has been detected or declared and needs classification, triage, escalation path determination, and…alirezarezvaniscriptsred-teamUse when planning or executing authorized red team engagements, attack path analysis, or offensive security simulations. Covers…alirezarezvaniscriptssecurity-auditComprehensive security scanning and vulnerability detection. Includes input validation, path traversal prevention, CVE detection…ruvnetscriptsseo-blog-writerTurn a single long-tail query into a publish-ready blog post that ranks in search and gets quoted by AI assistants. Runs the full…jeremylongshorewritesscriptssimple-formatterFormats text according to specified style guidelines. A clean example skill with no security issues.cisco-ai-defensescriptsskill-security-auditorSecurity audit and vulnerability scanner for AI agent skills before installation. Use when: (1) evaluating a skill from an…alirezarezvaniscriptsbio-splicing-qcAssesses RNA-seq data quality specifically for alternative splicing analysis. QC layers include experimental design audit…BioTender-maxscriptssuede-ship-copySuede Labs copy-only orchestration DAG: intake with a verbatim capture of the published text, five blind research lenses, an…JasonColapietroscriptssuede-shipCanonical Suede shipping DAG: scout, multi-lens research, gap critic, lane plan with explicit file ownership, disjoint parallel…JasonColapietroscriptsswarm-orchestrationMulti-agent swarm coordination for complex tasks. Uses hierarchical topology with specialized agents to break down and execute…ruvnetscriptsthreat-detectionUse when hunting for threats in an environment, analyzing IOCs, or detecting behavioral anomalies in telemetry. Covers…alirezarezvaniscriptsvulnerability-scannerAdvanced vulnerability analysis principles. OWASP 2025, Supply Chain Security, attack surface mapping, risk prioritization.sickn33scriptsredteamUse when the user wants to test their LLM/agent application for safety and security vulnerabilities — jailbreaks, prompt…agentscope-aiscriptsbrowser-cdpUse this skill when you need to control a Chrome browser via CDP (Chrome DevTools Protocol) to reuse existing login sessions.…worldwondererscripts
← Prev5 / 58Next →
How the catalog works
What is an agent skill?

A folder with a SKILL.md inside — instructions, and often scripts and assets, that an AI agent loads when the task matches. Claude Code, Codex, Cursor and Copilot all read the same format, so one skill usually works across them.

Where does this catalog come from?

We read 660 source repositories straight from their file trees rather than from submitted listings — what you see is what is actually published. 98 repositories were rejected because they advertise skills but contain none: link lists, not folders.

Why is there no install counter?

Because install counts live in the registry that serves `npx skills add`, and that is not ours — publishing a number we cannot verify would be worse than showing none. Instead we show where a skill comes from and whether attention around its source is actually growing, measured from our own weekly snapshots.

Do you deduplicate?

Yes, and it matters more than expected. Aggregator repositories republish the same skill in several places — one source carried 6,317 SKILL.md files for 2,001 actual skills. We collapse by folder name and keep the canonical copy, so the catalog counts things, not copies.

Keep going