Agent skills

Security skills

Read straight from the source repositories, not from submitted listings. Every skill shows what it does, what is inside, where it came from — and whether attention around its source is actually growing.

Toolclaude-code 29,140codex 4,755cursor 3,111copilot 976windsurf 55cline 34
CategoryWorkflow & Productivity 4,979AI & Agents 3,037Data & Analytics 2,345Code Review & Quality 1,376Backend & API 1,244Security 1,194Design & Presentation 1,154Documentation 965Content & Marketing 916Testing & QA 777DevOps & Cloud 576Databases 550Frontend 469Business & Finance 328Media & Video 257Other 9,833
2,762 found
289336 · page 7 / 58
design-motion-principlesMotion and interaction design skill using interpretive lenses informed by publicly available work from Emil Kowalski, Jakub…TheGoat395code-quality-analyzerTriggered when the user submits code or requests a comprehensive code quality analysis. Automatically performs static analysis…alibabalaunchworthyProduction readiness audit that turns a demo into a real product. Built for apps shipped fast with AI coding tools (Lovable…Wunderlandmediavariant-analysisFind similar vulnerabilities and bugs across codebases using pattern-based analysis. Use when hunting bug variants, building…trailofbitsgdpr-breach-sentinel-oliver-schmidt-prietzElite incident response and legal compliance guidance for data breaches under GDPR Articles 33 & 34. Use when: (1) User reports a…lawve-aigolang-securitySecurity best practices and vulnerability prevention for Golang. Covers injection (SQL, command, XSS), cryptography, filesystem…samberwritesseoComprehensive SEO analysis for any website or business type. Full site audits, single-page analysis, technical SEO (crawlability…Infrasity-Labsagentic-actions-auditorAudits GitHub Actions workflows for security vulnerabilities in AI agent integrations including Claude Code Action, Gemini CLI…waybarriossecurity-review-openaiPerform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user…lawve-aifable-methodA step-by-step problem-solving loop (classify the ask, define done, gather evidence, decide, act surgically, verify by…Sahir619growthGrowth skills for indie Apple developers — user acquisition, analytics interpretation, press/media outreach, community building…rshankrasprior-auth-review-skillAutomate payer review of prior authorization (PA) requests. This skill should be used when users say "Review this PA request"…FreedomIntelligencesailApply the SAIL (Secure AI Lifecycle) V2 framework by Pillar Security to secure AI applications and agents. Use this skill…pillar-labssecurity-best-practicesPerform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user…foryourhealth111-pixelvariant-analysisFind similar vulnerabilities and bugs across codebases using pattern-based analysis. Use when hunting bug variants, building…waybarrioswaves-codexWAVES - Workers, Aggregate, Verify, Extend - wave-based orchestration for Codex. Decompose a big goal into independent slices…RayFernando1337constant-time-analysisDetects timing side-channel vulnerabilities in cryptographic code. Use when implementing or reviewing crypto code, encountering…trailofbitswriteseu-ai-act-report-oliver-schmidt-prietzGenerates a formal, structured AI Act compliance assessment report suitable for legal files, audit trails, and regulatory…lawve-aikubernetes-specialistUse when deploying or managing Kubernetes workloads. Invoke to create deployment manifests, configure pod security policies, set…Jeffallancloudbase-agent-pythonBuild production-ready AI agent backends using the CloudBase Agent Python SDK — create agents with LangGraph/CrewAI/LlamaIndex…TencentCloudBasesecurity-best-practicesPerform language and framework specific security best-practice reviews and suggest improvements. Use when the user explicitly…tech-leads-clubvertical-site-conventionsCompose pages and sites that read as their vertical: ecommerce-catalog storefronts that look like storefronts, hospitality-food…rampstackcoazure-kubernetesPlan, create, and configure production-ready Azure Kubernetes Service (AKS) clusters. Covers Day-0 checklist, SKU selection…microsoftcloudbase-code-reviewCode review and validation for CloudBase projects. After writing code for Web / miniprogram / CloudRun / cloud-function projects…TencentCloudBasecosmos-vulnerability-scannerScans Cosmos SDK blockchain modules and CosmWasm contracts for consensus-critical vulnerabilities — chain halts, fund loss, state…trailofbitscs-skills10 computer science skills. Trigger: algorithms, systems research, software engineering, security papers. Design: theory…brycewang-stanfordcursor-known-pitfallsAvoid common Cursor IDE pitfalls: AI feature mistakes, security gotchas, configuration errors, and team workflow issues. Triggers…jeremylongshorewriteseditorial-qaPre-publish QA framework for content. Brief adherence, voice consistency, fact accuracy, structure and clarity, AI-content audit…rampstackcoeu-data-act-complianceAssess compliance obligations under the EU Data Act (Regulation (EU) 2023/2854) for connected products, IoT devices, data…lawve-aifullstack-guardianBuilds security-focused full-stack web applications by implementing integrated frontend and backend components with layered…Jeffallannear-smart-contractsNEAR Protocol smart contract development in Rust. Use when writing, reviewing, or deploying NEAR smart contracts. Covers contract…internet-courtplugin-auditorAudit automatically audits AI assistant code plugins for security vulnerabilities, best practices, AI assistant.md compliance…jeremylongshoretest-masterGenerates test files, creates mocking strategies, analyzes code coverage, designs test architectures, and produces test plans and…Jeffallancloud-design-patternsCloud design patterns for distributed systems architecture covering 42 industry-standard patterns across reliability…githubcloudflare-security-auditAudit authorized codebases for exploitable vulnerabilities using scoped reconnaissance, adversarial review, validation, and…sickn33content-refresh-systemSystematic content refresh discipline. Quarterly audits, refresh prioritization (which pieces, when, how deep)…rampstackcodecomposing-multi-domain-workUse when one request spans independent product, engineering, design, security, data, legal, or operational subsystems that cannot…casioreview20-glitchentry-point-analyzerAnalyzes smart contract codebases to identify state-changing entry points for security auditing. Detects externally callable…trailofbitswritesexpiring-stale-skillsUse when provider sources, tool APIs, model behavior, security assumptions, evaluators, or compatibility windows may have become…casioreview20-glitchjab-hookGary Vaynerchuk's jab-jab-jab-right-hook framework applied to a personal portfolio rotation on X and LinkedIn. Jabs =…coreyhaines31nubaseUse when the user mentions Nubase broadly, wants a backend for an AI-generated app, or needs to deploy/publish generated code…OtterMindpr-reviewReview a GitHub pull request using multiple expert personas. Takes a PR URL as input, analyzes the changes, and generates…agentic-communityproduct-analytics-setupHow to actually instrument product analytics correctly. Event taxonomy, property design, naming conventions, schema versioning…rampstackcotesting-handbook-generatorMeta-skill that analyzes the Trail of Bits Testing Handbook (appsec.guide) and generates Claude Code skills for security testing…trailofbitscode-review-assistantTriggered when the user submits code or requests a code review. Automatically analyzes code quality, identifies potential bugs…alibabaclean-code-guardReview generated or changed production code before it ships, using Clean Code, SOLID, DRY, KISS, YAGNI, and LLM-specific…amElnagdycommissaire-aux-comptesCommissaire aux comptes IA pour l'audit des comptes annuels d'entreprises françaises. Applique la démarche NEP en 7 phases…romainsimoncontent-brief-authoringHow to author a content brief that actually guides a writer (human or AI) to produce a piece that ranks, converts, or both.…rampstackco
← Prev7 / 58Next →
How the catalog works
What is an agent skill?

A folder with a SKILL.md inside — instructions, and often scripts and assets, that an AI agent loads when the task matches. Claude Code, Codex, Cursor and Copilot all read the same format, so one skill usually works across them.

Where does this catalog come from?

We read 660 source repositories straight from their file trees rather than from submitted listings — what you see is what is actually published. 98 repositories were rejected because they advertise skills but contain none: link lists, not folders.

Why is there no install counter?

Because install counts live in the registry that serves `npx skills add`, and that is not ours — publishing a number we cannot verify would be worse than showing none. Instead we show where a skill comes from and whether attention around its source is actually growing, measured from our own weekly snapshots.

Do you deduplicate?

Yes, and it matters more than expected. Aggregator repositories republish the same skill in several places — one source carried 6,317 SKILL.md files for 2,001 actual skills. We collapse by folder name and keep the canonical copy, so the catalog counts things, not copies.

Keep going