Agent skills

Security skills

Read straight from the source repositories, not from submitted listings. Every skill shows what it does, what is inside, where it came from — and whether attention around its source is actually growing.

Toolclaude-code 29,140codex 4,755cursor 3,111copilot 976windsurf 55cline 34
CategoryWorkflow & Productivity 4,979AI & Agents 3,037Data & Analytics 2,345Code Review & Quality 1,376Backend & API 1,244Security 1,194Design & Presentation 1,154Documentation 965Content & Marketing 916Testing & QA 777DevOps & Cloud 576Databases 550Frontend 469Business & Finance 328Media & Video 257Other 9,833
2,762 found
2,4492,496 · page 52 / 58
review-pr-liteReview a pull request for code quality and security issues without using subagents. Use when the user wants a lighter-weight PR…dyoshikawareview-rRun the R code review protocol on R scripts. Checks code quality, reproducibility, domain correctness, and professional…brycewang-stanfordwritesreview-workPost-implementation review orchestrator. Launches 5 parallel background sub-agents: Oracle (goal/constraint verification), Oracle…code-yeongyurfc-writerWrite an engineering RFC (Request for Comments) for a technical decision, architectural change, or significant implementation…mohitagw15856risk-managementRisk identification, assessment matrices, mitigation strategies, BCP, and risk reportingcosmicstack-labsrisk-mitigation-planningDevelop comprehensive risk management plans for collections and cultural venues including disaster preparedness, security…a5c-aiwritesrisk_register_vulnerability_analysisIdentifies technical, procedural, and human vulnerabilities enabling specific threats against assets, formatted as a…ECNU-ICALKrobots-txtWhen the user wants to configure, audit, or optimize robots.txt. Also use when the user mentions "robots.txt," "crawler rules,"…kostja94runway-install-authRunway install auth \u2014 AI video generation and creative AI platform.\n\ Use when working with Runway for video generation…jeremylongshorewritesrunway-security-basicsRunway security basics \u2014 AI video generation and creative AI platform.\n\ Use when working with Runway for video generation…jeremylongshorewritesrust-reviewPerforms comprehensive Rust security review for safe/unsafe boundary issues, memory safety in unsafe blocks, concurrency hazards…trailofbitswritessaas-auth-patternsSaaS authentication and authorization patterns including JWT vs session strategies, multi-tenant isolation, RBAC, API key…vibeevalsaas-launch-checklistPre-launch verification across infrastructure, security, legal, payment, email, analytics, and performance. Day-1 monitoring…vibeevalsaas-multi-tenantDesign and implement multi-tenant SaaS architectures with row-level security, tenant-scoped queries, shared-schema isolation, and…sickn33saas-mvp-launcherUse when planning or building a SaaS MVP from scratch. Provides a structured roadmap covering tech stack, architecture, auth…sickn33saas-payment-patternsPayment provider abstraction, webhook security, subscription lifecycle, dunning flows, pricing models, invoicing, tax handling…vibeevalsalesforce-apex-qualityApex code quality guardrails for Salesforce development. Enforces bulk-safety rules (no SOQL/DML in loops), sharing model…githubsalesforce-component-standardsQuality standards for Salesforce Lightning Web Components (LWC), Aura components, and Visualforce pages. Covers SLDS 2…githubsalesforce-install-authInstall and configure Salesforce SDK/CLI authentication with jsforce or Salesforce CLI. Use when setting up a new Salesforce…jeremylongshorewritessalesforce-security-basicsApply Salesforce security best practices for Connected Apps, OAuth, and field-level security. Use when securing API credentials…jeremylongshorewritessalesloft-install-authSet up SalesLoft API authentication with OAuth 2.0 or API key. Use when configuring a new SalesLoft integration, setting up OAuth…jeremylongshorewritessalesloft-security-basicsSecure SalesLoft OAuth tokens, API keys, and webhook signatures. Use when implementing token rotation, securing webhook…jeremylongshorewritesSalsa20/12 Encryption ImplementationImplements the Salsa20/12 stream cipher in Python, supporting 64-bit, 128-bit, and 256-bit keys with specific expansion logic and…ECNU-ICALKsast-configurationStatic Application Security Testing (SAST) tool setup, configuration, and custom rule creation for comprehensive security…sickn33sast-configurationConfigure Static Application Security Testing (SAST) tools for automated vulnerability detection in application code. Use when…wshobsonsast-patternsStatic Application Security Testing patterns, OWASP Top 10 checklist, language-specific vulnerability patterns, Semgrep rule…vibeevalsaying-no-kindlyDecline requests without damaging relationships or your standing — the fast-clear-warm formula, the alternative-attached no, the…mohitagw15856scam_baiting_email_generatorGenerates verbose, formal email responses to engage scammers using the 'Cameron McCaffrey' persona (or custom overrides). Employs…ECNU-ICALKscanning-toolsMaster essential security scanning tools for network discovery, vulnerability assessment, web application testing, wireless…sickn33sci_academic_and_technical_polishingPolishes, rewrites, and generates specific sections (Abstract, Summary, Conclusion) for SCI academic and professional technical…ECNU-ICALKScrape Moonarch.app Token DataExtracts specific token metrics (name, symbol, price, supply, market cap, liquidity, age) and security checks from a Moonarch.app…ECNU-ICALKscreenshot-optimizationWhen the user wants to design, optimize, or evaluate App Store screenshots and preview videos. Also use when the user mentions…Eronredsecond-brain-lintHealth-check the wiki for contradictions, orphan pages, stale claims, and missing cross-references. Use when the user says…NicholasSpisakwritessecret-handlingThe secret-source gate. Routed to when changed code reads, writes, or passes a secret — API key, token, password, connection…arbiterForgesecret-management-patternsHashiCorp Vault, cloud secret managers, rotation strategies, and zero-trust secret accessvibeevalsecret-patterns30+ service-specific secret detection regex patterns, entropy-based detection, PEM/JWT/Base64 identification, and false positive…vibeevalsecret-scannerScan secret scanner operations. Auto-activating skill for Security Fundamentals. Triggers on: secret scanner, secret scanner Part…jeremylongshorewritessecret-scannerPre-push API key and credential scanner - blocks git push if secrets foundvibeevalsecure-codingComprehensive secure coding practices covering input validation, authentication, authorization, cryptography, secrets management…cosmicstack-labsgsd:secure-phaseRetroactively verify threat mitigations for a completed phasedavepoonwritessecurity-and-hardeningHardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external integrations. Use…addyosmanisecurity-and-hardeningHardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external integrations. Use…sickn33security-architectureOptional, opt-in STRIDE threat pass for a sensitive feature — invoked deliberately via /threat-model, never forced on ordinary…arbiterForgesecurity-auditComprehensive security audit methodology covering OWASP Top 10, dependency scanning, threat modeling, and vulnerability…cosmicstack-labssecurity-auditDeep security audit covering OWASP Top 10, authentication, authorization, data protection, dependency vulnerabilities, and…davepoonsecurity-auditComprehensive security auditing workflow covering web application testing, API security, penetration testing, vulnerability…sickn33security-auditorExpert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks.sickn33security-benchmark-runnerManage security benchmark runner operations. Auto-activating skill for Security Advanced. Triggers on: security benchmark runner…jeremylongshorewrites
← Prev52 / 58Next →
How the catalog works
What is an agent skill?

A folder with a SKILL.md inside — instructions, and often scripts and assets, that an AI agent loads when the task matches. Claude Code, Codex, Cursor and Copilot all read the same format, so one skill usually works across them.

Where does this catalog come from?

We read 660 source repositories straight from their file trees rather than from submitted listings — what you see is what is actually published. 98 repositories were rejected because they advertise skills but contain none: link lists, not folders.

Why is there no install counter?

Because install counts live in the registry that serves `npx skills add`, and that is not ours — publishing a number we cannot verify would be worse than showing none. Instead we show where a skill comes from and whether attention around its source is actually growing, measured from our own weekly snapshots.

Do you deduplicate?

Yes, and it matters more than expected. Aggregator repositories republish the same skill in several places — one source carried 6,317 SKILL.md files for 2,001 actual skills. We collapse by folder name and keep the canonical copy, so the catalog counts things, not copies.

Keep going