Agent skills

Security skills

Read straight from the source repositories, not from submitted listings. Every skill shows what it does, what is inside, where it came from — and whether attention around its source is actually growing.

Toolclaude-code 29,140codex 4,755cursor 3,111copilot 976windsurf 55cline 34
CategoryWorkflow & Productivity 4,979AI & Agents 3,037Data & Analytics 2,345Code Review & Quality 1,376Backend & API 1,244Security 1,194Design & Presentation 1,154Documentation 965Content & Marketing 916Testing & QA 777DevOps & Cloud 576Databases 550Frontend 469Business & Finance 328Media & Video 257Other 9,833
2,762 found
2,6412,688 · page 56 / 58
test-anti-patternsAudits an existing test file or suite in any language for anti-patterns and quality issues — produces a severity-ranked report…dotnettest-taggingAnalyzes test suites in any language and tags each test with standardized traits (positive, negative, critical-path, boundary…dotnetText-based Five Nights at Freddy's SimulatorSimulates a text-based survival horror game based on FNaF 1 mechanics, managing power, security doors, cameras, lights, and…ECNU-ICALKthe-procurement-gauntletSimulate enterprise procurement and security review of your product before your first big deal meets it for real — the…mohitagw15856the-vibe-checkHarden a vibe-coded app before strangers use it — the audit for prototypes built fast with AI: exposed secrets, missing auth…mohitagw15856threat-model-creatorCreate threat model creator operations. Auto-activating skill for Security Advanced. Triggers on: threat model creator, threat…jeremylongshorewritesthreat-modelThreat-model a system or feature to find where it could be attacked, before you build it. Use when asked to threat-model, do a…mohitagw15856threat-modeling-expertExpert in threat modeling methodologies, security architecture review, and risk assessment. Masters STRIDE, PASTA, attack trees…sickn33toc-generatorWhen the user wants to add, optimize, or audit table of contents (TOC) for long-form content. Also use when the user mentions…kostja94together-install-authInstall Together AI SDK and configure API key for inference and fine-tuning. Use when setting up Together AI, configuring the…jeremylongshorewritestogether-security-basicsTogether AI security basics for inference, fine-tuning, and model deployment. Use when working with Together AI''s…jeremylongshorewritestokenisierung-security-token-mica-mifidWenn es um Tokenisierung Rechtsqualifikation in Bank-Rechtsabteilung geht: ordnet Sachverhalt, Norm, Beweislast, Gegenargumente…Klotzkettetool-permission-reviewReview what an agent is actually allowed to do before you turn it loose — the tool-by-tool audit (each capability's blast…mohitagw15856tool-procurement-evalEvaluate a new tool before it joins the stack — the problem-first framing (tools answer needs, not demos), the trial designed…mohitagw15856toolifyWhen you want to integrate an external tool, API, MCP server, or service into a project — the wizard walks you through auth…coreyhaines31tools-page-generatorWhen the user wants to create, optimize, or audit free tools pages. Also use when the user mentions "free tools," "tools page,"…kostja94top-banner-generatorWhen the user wants to add, optimize, or audit a top announcement bar or sticky banner. Also use when the user mentions…kostja94top-web-vulnerabilitiesProvide a comprehensive, structured reference for the 100 most critical web application vulnerabilities organized by category.…sickn33analytics-trackingWhen the user wants to set up, audit, or optimize analytics tracking (GA4, events, conversions). Also use when the user mentions…kostja94trade-conflictWenn es um Trade-Secret-Leak und Geheimnisverrat in Internal Investigations Praxis geht: ordnet Sachverhalt, Norm, Beweislast…Klotzkettetrade-secret-misappropriation-codeWenn es um Trade Secret Misappropriation Code in Softwarerecht Deutschland/EU/International/USA geht: ordnet Sachverhalt, Norm…Klotzkettetransfer-restrictions-upstream-securityWenn es um Transfer Restrictions und Vinkulierung in Didaktisches Gesellschaftsrecht — English Business Terms geht: ordnet…Klotzkettetravel-expense-auditAudit travel / 差旅报销 claims against uploaded policy handbooks and rate tables (lodging caps, transport, per diem). Use for 差旅费审核…vixuestree-ring-memoryUse Tree Ring Memory for local-first AI-agent memory lifecycle work: recall, evidence, audit, forgetting, and consolidation…sickn33trust-badges-generatorWhen the user wants to add or optimize trust badges, "Trusted by" logos, security seals, or social proof elements. Also use when…kostja94twinmind-install-authInstall and configure TwinMind Chrome extension, mobile app, and API access. Use when setting up TwinMind for meeting…jeremylongshorewritesua-campaignWhen the user wants to plan or optimize paid user acquisition campaigns. Also use when the user mentions "Apple Search Ads"…Eronredui-a11yAudit a component or page for accessibility issues and fix themsickn33gsd:ui-reviewRetroactive 6-pillar visual audit of implemented frontend codedavepoonwritesuist-submissionUse when performing the final pre-upload audit of a UIST paper in PCS — the abstract-then-paper deadline pair, 10-page/5-page…brycewang-stanfordumsatzmeldung-audit-und-nachzahlungWenn es um Franchiserecht: Umsatzmeldung, Audit und Nachzahlung in Franchiserecht Praxis geht: ordnet Sachverhalt, Norm…Klotzketteunichem-databaseCross-reference compound IDs across 20+ databases (ChEMBL, DrugBank, PubChem, ChEBI, PDB, SureChEMBL, HMDB, DrugCentral…BioTender-maxunifi-context-mapUse when an agent keeps guessing wrong about a UniFi network, when starting recurring agent work against a gateway, or when asked…t3chnazteaunifi-wifiUse when UniFi Wi-Fi is slow, unstable, or being tuned: "my wifi is slow but speedtest on the router is fast", "great signal…t3chnazteaupdate-depsAudit and update npm/Bun dependencies with supply chain integrity checks — verifies maintainers, publish age, tarball diffs, and…backnotpropupstream-security-financial-assistanceWenn es um Upstream Security und Financial Assistance in Didaktisches Gesellschaftsrecht — English Business Terms geht: ordnet…Klotzketteupwork-profile-optimizerAudit and improve an Upwork freelancer profile. Use when the user pastes their profile (title, overview, portfolio list, skills…abullaisius-trade-secret-dtsaWenn es um US Trade Secret DTSA Software in Softwarerecht Deutschland/EU/International/USA geht: ordnet Sachverhalt, Norm…Klotzketteuse-cases-page-generatorWhen the user wants to create, optimize, or audit use case pages. Also use when the user mentions "use cases," "use case page,"…kostja94usenix-security-symposiumUse when targeting USENIX Security Symposium (USENIX Security) or deciding whether a computer-science manuscript fits this venue.…brycewang-stanfordusenixsec-artifact-evaluationUse when packaging artifacts for USENIX Security Symposium evaluation — the mandatory Phase-1 availability check that acceptance…brycewang-stanfordusenixsec-author-responseUse when reviews arrive from a USENIX Security Symposium cycle and the authors must respond — writing the rebuttal that survives…brycewang-stanfordusenixsec-camera-readyUse when preparing final papers for the USENIX Security Symposium after acceptance — de-anonymizing, keeping the Ethical…brycewang-stanfordusenixsec-experimentsUse when designing or auditing the evaluation of a USENIX Security Symposium paper — building threat-model-faithful experiments…brycewang-stanfordusenixsec-related-workUse when positioning a USENIX Security Symposium paper against prior work — covering the Big-Four security venues plus specialty…brycewang-stanfordusenixsec-reproducibilityUse when strengthening reproducibility for a USENIX Security Symposium paper — writing the mandatory Open Science appendix…brycewang-stanfordusenixsec-review-processUse when reasoning about how a USENIX Security Symposium cycle actually decides — early-reject notifications, multi-round…brycewang-stanfordusenixsec-submissionUse when finalizing a USENIX Security Symposium submission — the per-cycle HotCRP site, the registration deadline a week before…brycewang-stanford
← Prev56 / 58Next →
How the catalog works
What is an agent skill?

A folder with a SKILL.md inside — instructions, and often scripts and assets, that an AI agent loads when the task matches. Claude Code, Codex, Cursor and Copilot all read the same format, so one skill usually works across them.

Where does this catalog come from?

We read 660 source repositories straight from their file trees rather than from submitted listings — what you see is what is actually published. 98 repositories were rejected because they advertise skills but contain none: link lists, not folders.

Why is there no install counter?

Because install counts live in the registry that serves `npx skills add`, and that is not ours — publishing a number we cannot verify would be worse than showing none. Instead we show where a skill comes from and whether attention around its source is actually growing, measured from our own weekly snapshots.

Do you deduplicate?

Yes, and it matters more than expected. Aggregator repositories republish the same skill in several places — one source carried 6,317 SKILL.md files for 2,001 actual skills. We collapse by folder name and keep the canonical copy, so the catalog counts things, not copies.

Keep going