Agent skills

Security skills

Read straight from the source repositories, not from submitted listings. Every skill shows what it does, what is inside, where it came from — and whether attention around its source is actually growing.

Toolclaude-code 29,140codex 4,755cursor 3,111copilot 976windsurf 55cline 34
CategoryWorkflow & Productivity 4,979AI & Agents 3,037Data & Analytics 2,345Code Review & Quality 1,376Backend & API 1,244Security 1,194Design & Presentation 1,154Documentation 965Content & Marketing 916Testing & QA 777DevOps & Cloud 576Databases 550Frontend 469Business & Finance 328Media & Video 257Other 9,833
2,762 found
2,4972,544 · page 53 / 58
security-bluebook-builderBuild a minimal but real security policy for sensitive apps. The output is a single, coherent Blue Book document using…sickn33security-bounty-hunterHunt for exploitable, bounty-worthy security issues in repositories. Focuses on remotely reachable vulnerabilities that qualify…mturacsecurity-by-design-sprintWenn es um Security-by-Design-Sprint in robotik-recht geht: prüft Frist, Form, Zuständigkeit, Rechtsweg und Sofortmaßnahmen…Klotzkettesecurity-checklistReference document for monopoly security-checklist.sickn33security-deposit-recoveryGet your security deposit back — the move-out documentation that wins disputes before they start, the itemized-deduction…mohitagw15856security-governance-ismsWenn es um Security Governance ISMS in NIS-2, Cybersecurity und IT-Sicherheits-Compliance geht: prüft Frist, Form, Zuständigkeit…Klotzkettesecurity-group-generatorGenerate security group generator operations. Auto-activating skill for AWS Skills. Triggers on: security group generator…jeremylongshorewritessecurity-guardrailsAdversarial defense layer for the mortgage plugin — protects against prompt injection, system prompt extraction, PII leakage…davepoonsecurity-hardeningApplication security covering input validation, auth, headers, secrets management, and dependency auditingrohitg00security-headers-generatorGenerate security headers generator operations. Auto-activating skill for Security Fundamentals. Triggers on: security headers…jeremylongshorewritessecurity-incident-responseRun or document a security incident response — contain, eradicate, recover, and learn. Use when responding to a…mohitagw15856security-incident-shop-datenschutzmeldungWenn es um Security Incident Shop Datenschutzmeldung in E-Commerce-Recht geht: ordnet Akteninhalt, Belege, Lücken und…Klotzkettesecurity-incidentsWenn es um Security Incidents in AGB-Recht-Prüfer geht: ordnet Sachverhalt, Norm, Beweislast, Gegenargumente und nächsten…Klotzkettesecurity-installationWenn es um Security: Dokumentenmatrix, Lückenliste und Nachforderung in Kanzlei-Builder-Hub geht: ordnet Akteninhalt, Belege…Klotzkettesecurity-kpis-board-reportWenn es um Security Kpis Board Report in NIS-2, Cybersecurity und IT-Sicherheits-Compliance geht: prüft Frist, Form…Klotzkettesecurity-of-travel-and-devicesWenn es um Reise- und Gerätesicherheit China: Exit-Ban/Geräteprotokoll in China-Wirtschaftsverkehr geht: prüft Frist, Form…Klotzkettesecurity-package-germanyWenn es um Deutsches Sicherheitenpaket in Private Equity Praxis geht: prüft Frist, Form, Zuständigkeit, Rechtsweg und…KlotzkettesecuritySecurity audit workflow - vulnerability scan → verificationparcadeisecurity-patternsImplements authentication, authorization, encryption, secrets management, and security hardening patterns. Use when designing…CloudAI-Xsecurity-policy-generatorGenerate security policy generator operations. Auto-activating skill for Security Advanced. Triggers on: security policy…jeremylongshorewritessecurity-procurement-training-managementWenn es um Security Procurement Tender in NIS-2, Cybersecurity und IT-Sicherheits-Compliance geht: ordnet Sachverhalt, Norm…Klotzkettesecurity-questionnaire-autofillDraft answers to a vendor security questionnaire (SIG, CAIQ, or a custom sheet) from your real controls — fast, consistent, and…mohitagw15856security-researchTeam Mode security research skill. Orchestrates 3 vulnerability hunters and 2 PoC engineers to audit a codebase in parallel…code-yeongyusecurity-reviewReview a design, PR, or feature for security issues before it ships. Use when asked to do a security review, security-review a…mohitagw15856security-reviewPerform a focused security review of pending git changes to identify high-confidence security vulnerabilities with real…waybarriossecurity-reviewerDedicated security-audit route for OWASP-style risks, secret leaks, auth flaws, injection, unsafe input handling, SSRF/XSS, and…foryourhealth111-pixelsecurity-scan-diffScan for malicious code in git diff between a tag/commit and HEADdyoshikawasecurity-scanScan your OpenAI Codex configuration (.codex/ directory) for security vulnerabilities, misconfigurations, and injection risks…mturacsecurity-scanRun full security scans on the codebase using Ruflo security tools. Use when reviewing PRs for security regressions, auditing…ruvnetsecurity-scanningUse when checking code for vulnerabilities, linting shell scripts, scanning containers or IaC for security issues, or managing…jeremylongshoresecurity-scanning-security-hardeningCoordinate multi-layer security scanning and hardening across application, infrastructure, and compliance controls.sickn33security-scanning-security-sastStatic Application Security Testing (SAST) for code vulnerability analysis across multiple languages and frameworks 'sickn33security-threat-modelWrite a STRIDE-based threat model for a service or feature. Use when asked to produce a threat model, document security risks…mohitagw15856security-training-managementWenn es um Security Training Management in NIS-2, Cybersecurity und IT-Sicherheits-Compliance geht: prüft Frist, Form…Klotzkettesecurity-triageTriage GitHub security advisories for OpenClaw with high-confidence close/keep decisions, exact tag and commit verification…SafeAI-Lab-XsecuritySecurity audit workflow - OWASP Top 10, input validation, auth, secret detection, vulnerability scanvibeevalsemgrep-rule-creatorCreates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns. Use when writing Semgrep…sickn33writesSEMrush AutomationAutomate SEO analysis with SEMrush -- research keywords, analyze domain organic rankings, audit backlinks, assess keyword…ComposioHQsensys-submissionUse when running the final pre-upload audit of a SenSys submission — confirming the right per-edition HotCRP site and which of…brycewang-stanfordseo-aeo-content-quality-auditorAudits content for SEO and AEO performance with scored reports, severity-ranked fix lists, and projected scores after fixes.…sickn33seo-audit-fullFull website SEO audit with parallel subagent delegation. Crawls up to 500 pages, detects business type, delegates to up to 15…Infrasity-Labsseo-auditWhen the user wants to run an SEO audit, technical SEO audit, or site health check. Also use when the user mentions "SEO audit,"…kostja94seo-backlinksBacklink profile analysis: referring domains, anchor text distribution, toxic link detection, competitor gap analysis. Works with…Infrasity-Labsseo-contentContent quality and E-E-A-T analysis with AI citation readiness assessment. Use when user says "content quality", "E-E-A-T"…Infrasity-Labsseo-contentContent quality and E-E-A-T analysis with AI citation readiness assessment. Use when user says "content quality", "E-E-A-T"…sickn33writesseo-hreflangHreflang and international SEO audit, validation, and generation. Detects common mistakes, validates language/region codes, and…sickn33writesseo-imagesImage optimization analysis for SEO and performance. Checks alt text, file sizes, formats, responsive images, lazy loading, CLS…Infrasity-Labsseo-strategyWhen the user wants to plan SEO strategy, prioritize SEO work, or understand the SEO workflow. Also use when the user mentions…kostja94
← Prev53 / 58Next →
How the catalog works
What is an agent skill?

A folder with a SKILL.md inside — instructions, and often scripts and assets, that an AI agent loads when the task matches. Claude Code, Codex, Cursor and Copilot all read the same format, so one skill usually works across them.

Where does this catalog come from?

We read 660 source repositories straight from their file trees rather than from submitted listings — what you see is what is actually published. 98 repositories were rejected because they advertise skills but contain none: link lists, not folders.

Why is there no install counter?

Because install counts live in the registry that serves `npx skills add`, and that is not ours — publishing a number we cannot verify would be worse than showing none. Instead we show where a skill comes from and whether attention around its source is actually growing, measured from our own weekly snapshots.

Do you deduplicate?

Yes, and it matters more than expected. Aggregator repositories republish the same skill in several places — one source carried 6,317 SKILL.md files for 2,001 actual skills. We collapse by folder name and keep the canonical copy, so the catalog counts things, not copies.

Keep going