Agent skills

Security skills

Read straight from the source repositories, not from submitted listings. Every skill shows what it does, what is inside, where it came from — and whether attention around its source is actually growing.

Toolclaude-code 29,140codex 4,755cursor 3,111copilot 976windsurf 55cline 34
CategoryWorkflow & Productivity 4,979AI & Agents 3,037Data & Analytics 2,345Code Review & Quality 1,376Backend & API 1,244Security 1,194Design & Presentation 1,154Documentation 965Content & Marketing 916Testing & QA 777DevOps & Cloud 576Databases 550Frontend 469Business & Finance 328Media & Video 257Other 9,833
2,762 found
2,6892,736 · page 57 / 58
usenixsec-supplementaryUse when deciding what goes where in a USENIX Security Symposium paper — the 13-page body, the two mandatory one-page appendices…brycewang-stanfordusenixsec-topic-selectionUse when deciding whether a project belongs at the USENIX Security Symposium or a sibling venue — routing among USENIX Security…brycewang-stanfordusenixsec-workflowUse when planning a USENIX Security Symposium project end to end — choosing between the two annual cycles, mapping the…brycewang-stanfordusenixsec-writing-styleUse when drafting or revising prose for a USENIX Security Symposium paper — threat-model-first structure, calibrated security…brycewang-stanfordux-auditAudit screens for UX issues using Nielsen's heuristics and modern mobile UX best practicessickn33ux-audit-walkthroughMinimalist UX/Interaction Audit Expert that deconstructs complex interactions through cognitive load and operational efficiency…AIPexStudioV3 Security OverhaulComplete security architecture overhaul for claude-flow v3. Addresses critical CVEs (CVE-1, CVE-2, CVE-3) and implements…ruvnetV3 Swarm Coordination15-agent hierarchical mesh coordination for v3 implementation. Orchestrates parallel execution across security, core, and…ruvnetgsd:validate-phaseRetroactively audit and fill Nyquist validation gaps for a completed phasedavepoonwritesvariant-analysisFind similar vulnerabilities and bugs across codebases using pattern-based analysis. Use when hunting bug variants, building…sickn33vastai-data-handlingManage training data and model artifacts securely on Vast.ai GPU instances. Use when transferring data to instances, managing…jeremylongshorewritesvastai-install-authInstall and configure Vast.ai CLI and REST API authentication. Use when setting up a new Vast.ai integration, configuring API…jeremylongshorewritesvastai-security-basicsApply Vast.ai security best practices for API keys and instance access. Use when securing API keys, hardening SSH access to GPU…jeremylongshorewritesveeva-install-authVeeva Vault install auth with REST API and VQL. Use when integrating with Veeva Vault for life sciences document management. 'jeremylongshorewritesveeva-security-basicsVeeva Vault security basics for REST API and clinical operations. Use when working with Veeva Vault document management and CRM. 'jeremylongshorewritesvendor-contract-checklistReview a vendor/SaaS contract against a practical checklist before you sign. Use when asked to review a vendor contract, check a…mohitagw15856vercel-install-authInstall Vercel CLI and configure API token authentication. Use when setting up Vercel for the first time, creating access tokens…jeremylongshorewritesverification-gatesCreates explicit validation checkpoints (verification gates) between project phases to catch errors early and ensure quality…rohitg00verification-loopComprehensive verification system covering build, types, lint, tests, security, and diff review before a PR.vibeevalvibe-code-auditorAudit rapidly generated or AI-produced code for structural flaws, fragility, and production risks.sickn33vibecode-production-qa-validator13-phase production QA for fullstack Next.js apps: build verification, SEO tags, OG images, favicon, route regression, API auth…sickn33vibers-code-reviewHuman review workflow for AI-generated GitHub projects with spec-based feedback, security review, and follow-up PRs from the…sickn33visual-auditPerform adversarial visual audit of Quarto or Beamer slides checking for overflow, font consistency, box fatigue, and layout…brycewang-stanfordwritesvorlage-ma-arbeitsblatt-perspektiven-auditWenn es um /tabellenreview-3d:vorlage-ma-due-diligence in Tabellenreview 3D geht: prüft Frist, Form, Zuständigkeit, Rechtsweg und…KlotzketteVPN Technology Decision Matrix GeneratorGenerates a detailed decision matrix comparing VPN technologies (e.g., OpenSSH, OpenVPN, WireGuard, IPSec) using color-coded…ECNU-ICALKvuln-triageTriage a vulnerability or scanner finding — assess real severity, exploitability, and how urgently to fix. Use when asked to…mohitagw15856Vulnerability and Countermeasure ExtractionAnalyzes provided text to identify security vulnerabilities, providing a short summary and specific countermeasures for each…ECNU-ICALKvulnerability-report-generatorGenerate vulnerability report generator operations. Auto-activating skill for Security Advanced. Triggers on: vulnerability…jeremylongshorewriteswaf-rule-creatorCreate waf rule creator operations. Auto-activating skill for Security Advanced. Triggers on: waf rule creator, waf rule creator…jeremylongshorewriteswardenSecurity engineer — IAM, secrets, threat modeling, hardening, auth, and supply chain security.jeremylongshorewriteswarden-scanAutomated SAST + dependency vulnerability scan. Runs Semgrep (code vulnerabilities) and pip-audit (CVE-matched dependencies) and…jeremylongshorewriteswber-robustnessUse when results for a The World Bank Economic Review (WBER) manuscript may be sensitive to specification, sample, measurement…brycewang-stanfordwcag22-a11y-auditWCAG 2.2 Accessibility Audit skill that systematically evaluates web pages against 8 core Success Criteria (1.1.1, 1.4.3, 1.4.11…AIPexStudiobest-practicesApply modern web development best practices for security, compatibility, and code quality. Use when asked to "apply best…tech-leads-clubweb-design-guidelinesReview UI code for Web Interface Guidelines compliance. Use when asked to "review my UI", "check accessibility", "audit design"…CloudAI-Xweb-design-guidelinesReview UI code for Web Interface Guidelines compliance. Use when asked to "review my UI", "check accessibility", "audit design"…ECNU-ICALKweb-design-guidelinesReview UI code for Web Interface Guidelines compliance. Use when asked to "review my UI", "check accessibility", "audit design"…Infrasity-Labsweb-perfAnalyzes web performance using Chrome DevTools MCP. Measures Core Web Vitals (LCP, INP, CLS) and supplementary metrics (FCP, TBT…cloudflareweb-performance-optimizationAnalyzes web performance using Chrome DevTools MCP. Measures Core Web Vitals (LCP, INP, CLS) and supplementary metrics (FCP, TBT…fcakyonweb-security-testingWeb application security testing workflow for OWASP Top 10 vulnerabilities including injection, XSS, authentication flaws, and…sickn33webflow-enterprise-rbacConfigure Webflow enterprise access control \u2014 OAuth 2.0 app authorization,\n\ scope-based RBAC, per-site token isolation…jeremylongshorewriteswebflow-install-authInstall the Webflow JS SDK (webflow-api) and configure OAuth 2.0 or API token authentication. Use when setting up a new Webflow…jeremylongshorewriteswebflow-multi-env-setupConfigure Webflow across development, staging, and production environments with per-environment API tokens, site IDs, and secret…jeremylongshorewriteswebflow-prod-checklistExecute Webflow production deployment checklist \u2014 token security,\ \ rate limit hardening,\nhealth checks, circuit breakers…jeremylongshorewriteswebflow-security-basicsApply Webflow API security best practices \u2014 token management, scope\ \ least privilege,\nOAuth 2.0 secret rotation, webhook…jeremylongshorewritesWeekly Schedule Audit and Time ProjectionAudits a user's weekly activities by categorizing them into specific groups, sums the hours to verify against the 168-hour weekly…ECNU-ICALKwhizard-auditingUse when working with WizTelemetry Auditing extension for KubeSphere, including installation, configuration, and audit query APIkubespherewiki-lintRun a deterministic, read-only health check on an Obsidian wiki. Use for lint, vault health check, audit wiki health, find…AgriciDaniel
← Prev57 / 58Next →
How the catalog works
What is an agent skill?

A folder with a SKILL.md inside — instructions, and often scripts and assets, that an AI agent loads when the task matches. Claude Code, Codex, Cursor and Copilot all read the same format, so one skill usually works across them.

Where does this catalog come from?

We read 660 source repositories straight from their file trees rather than from submitted listings — what you see is what is actually published. 98 repositories were rejected because they advertise skills but contain none: link lists, not folders.

Why is there no install counter?

Because install counts live in the registry that serves `npx skills add`, and that is not ours — publishing a number we cannot verify would be worse than showing none. Instead we show where a skill comes from and whether attention around its source is actually growing, measured from our own weekly snapshots.

Do you deduplicate?

Yes, and it matters more than expected. Aggregator repositories republish the same skill in several places — one source carried 6,317 SKILL.md files for 2,001 actual skills. We collapse by folder name and keep the canonical copy, so the catalog counts things, not copies.

Keep going