Agent skills

Security skills

Read straight from the source repositories, not from submitted listings. Every skill shows what it does, what is inside, where it came from — and whether attention around its source is actually growing.

Toolclaude-code 29,140codex 4,755cursor 3,111copilot 976windsurf 55cline 34
CategoryWorkflow & Productivity 4,979AI & Agents 3,037Data & Analytics 2,345Code Review & Quality 1,376Backend & API 1,244Security 1,194Design & Presentation 1,154Documentation 965Content & Marketing 916Testing & QA 777DevOps & Cloud 576Databases 550Frontend 469Business & Finance 328Media & Video 257Other 9,833
2,762 found
2,7372,762 · page 58 / 58
wiki-lintAudit and maintain the health of the Obsidian wiki. Use this skill when the user wants to check their wiki for issues, find…Ar9avwindsurf-install-authInstall Windsurf IDE and configure Codeium authentication. Use when setting up Windsurf for the first time, logging in to…jeremylongshorewriteswindsurf-security-basicsApply Windsurf security best practices for workspace isolation, data privacy, and secret protection. Use when securing sensitive…jeremylongshorewriteswireshark-analysisExecute comprehensive network traffic analysis using Wireshark to capture, filter, and examine network packets for security…sickn33wispr-install-authWispr Flow install auth for voice-to-text API integration. Use when integrating Wispr Flow dictation, WebSocket streaming, or…jeremylongshorewriteswispr-security-basicsWispr Flow security basics for voice-to-text API integration. Use when integrating Wispr Flow dictation, WebSocket streaming, or…jeremylongshorewriteswjs-auditing-projectUse when the user asks to audit what's wrong with a project, "make it right", "看看项目出了什么问题", "为什么用户的需求还没上线", "为什么没提交App Store"…jianshuowordpress-plugin-developmentWordPress plugin development workflow covering plugin architecture, hooks, admin interfaces, REST API, security best practices…sickn33wordpressComplete WordPress development workflow covering theme development, plugin creation, WooCommerce integration, performance…sickn33workflowUse when a task is too large for turn-by-turn orchestration and should run through the big-task workflow lane: system-wide…jeremylongshoreworkflow-schema-tuningUse when modifying `resources/workflow-schema.json` in cc-wf-studio to influence how AI agents generate workflows via the…breaking-brakeworkflow-security-by-design-sprintWenn es um Security-by-Design-Sprint in robotik-recht geht: ordnet Sachverhalt, Norm, Beweislast, Gegenargumente und nächsten…Klotzketteworkhuman-install-authWorkhuman install auth for employee recognition and rewards API. Use when integrating Workhuman Social Recognition, or building…jeremylongshorewritesworkhuman-security-basicsWorkhuman security basics for employee recognition and rewards API. Use when integrating Workhuman Social Recognition, or…jeremylongshorewritesworkspace-surface-auditAudit the active repo, MCP servers, plugins, connectors, env surfaces, and harness setup, then recommend the highest-value…mturacworlddev-robustnessUse when results may be sensitive — to specification, sample, measurement, or inference for quantitative work, or to…brycewang-stanfordWrite Subconscious Command Dialogue ScenesGenerates dialogue scenes for a character named Elena who embeds subconscious commands into casual speech. The output must…ECNU-ICALKwriting-guidelinesReview docs/prose for Writing Guidelines compliance. Use when asked to "review my docs", "check writing style", "audit prose"…millioncox-apiX/Twitter API integration for posting tweets, threads, reading timelines, search, and analytics. Covers OAuth auth patterns, rate…mturacxss-vulnerability-scannerScan xss vulnerability scanner operations. Auto-activating skill for Security Fundamentals. Triggers on: xss vulnerability…jeremylongshorewritesxurlxurl CLI for authenticated X posts, replies, reads/search, DMs, media upload, followers, auth status, or raw v2 API calls.Health-Yangyear-in-reviewRun an honest personal year-in-review and set next year's direction — wins, misses, an energy audit, and one theme, not a…mohitagw15856ylj-footnotes-and-cite-checkUse when running the final footnote-apparatus audit of a The Yale Law Journal (YLJ) piece — verifying every cite exists, is…brycewang-stanfordyoutube-seo-optimizerGenerate complete YouTube & podcast SEO packages with live-researched keywords — titles, descriptions, tags, hashtags, chapters…sickn33zero-trust-config-helperConfigure with zero trust config helper operations. Auto-activating skill for Security Advanced. Triggers on: zero trust config…jeremylongshorewriteszeroize-auditDetects missing zeroization of sensitive data in source code and identifies zeroization removed by compiler optimizations, with…sickn33writes
← Prev58 / 58
How the catalog works
What is an agent skill?

A folder with a SKILL.md inside — instructions, and often scripts and assets, that an AI agent loads when the task matches. Claude Code, Codex, Cursor and Copilot all read the same format, so one skill usually works across them.

Where does this catalog come from?

We read 660 source repositories straight from their file trees rather than from submitted listings — what you see is what is actually published. 98 repositories were rejected because they advertise skills but contain none: link lists, not folders.

Why is there no install counter?

Because install counts live in the registry that serves `npx skills add`, and that is not ours — publishing a number we cannot verify would be worse than showing none. Instead we show where a skill comes from and whether attention around its source is actually growing, measured from our own weekly snapshots.

Do you deduplicate?

Yes, and it matters more than expected. Aggregator repositories republish the same skill in several places — one source carried 6,317 SKILL.md files for 2,001 actual skills. We collapse by folder name and keep the canonical copy, so the catalog counts things, not copies.

Keep going