Agent skills

Security skills

Read straight from the source repositories, not from submitted listings. Every skill shows what it does, what is inside, where it came from — and whether attention around its source is actually growing.

Toolclaude-code 29,140codex 4,755cursor 3,111copilot 976windsurf 55cline 34
CategoryWorkflow & Productivity 4,979AI & Agents 3,037Data & Analytics 2,345Code Review & Quality 1,376Backend & API 1,244Security 1,194Design & Presentation 1,154Documentation 965Content & Marketing 916Testing & QA 777DevOps & Cloud 576Databases 550Frontend 469Business & Finance 328Media & Video 257Other 9,833
2,762 found
337384 · page 8 / 58
detecting-sql-injection-vulnerabilitiesDetect and analyze SQL injection vulnerabilities in application code and database queries. Use when you need to scan code for SQL…jeremylongshorewritesfedrampExpert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026). Use this skill…lawve-aifp-checkSystematically verifies suspected security bugs to eliminate false positives, producing a TRUE POSITIVE or FALSE POSITIVE verdict…trailofbitswritesfrontend-code-reviewUse only when the user explicitly requests a review or audit of frontend code under `web/` or `packages/dify-ui/`. Supports…langgeniusfullstack-devFull-stack backend architecture and frontend-backend integration guide. TRIGGER when: building a full-stack app, creating REST…vibeevalgithub-release-guideAssess and guide safer github.com repository releases. Use when an existing private GitHub repository becomes public for the…kyungseopostgresql-development-cloudbaseUse when building, debugging, or evaluating CloudBase PostgreSQL / CloudBase PG / PG mode apps, including Postgres schema setup…TencentCloudBasecoreCore agent-browser usage guide. Read this before running any agent-browser commands. Covers the snapshot-and-ref workflow…friday-platformsupabase-architecture-variantsUse when choosing how to integrate Supabase into a specific stack — setting up Next.js SSR auth flows, wiring an SPA or React…jeremylongshorewritesswiftui-performance-auditAudit SwiftUI performance issues from code review and profiling evidence.sickn33tlc-generative-engine-optimizationGenerative Engine Optimization (GEO) specialist — the technical, on-page publishing work that makes a given page or site…tech-leads-clubambiguity-stress-testAdversarially stress-tests a legal text — a contract, statute, regulation, or judicial opinion — for interpretive ambiguity: it…lawve-aiaudit-integrityShared audit integrity framework for all AppSec agents — enforces output quality, intellectual honesty, and continuous…githubauditUse when the user wants a code review on recent changes — quality, spec, security, or performance feedback. Triggers a…jeremylongshorewritesaz-eu-website-privacy-auditAudits a website for compliance with Azerbaijan's Law on Personal Data No. 998-IIIQ and, where applicable, EU GDPR plus…lawve-aichecking-session-securityAnalyze session management implementations to identify security vulnerabilities in web applications. Use when you need to audit…jeremylongshorewritescodebase-auditPerform a full codebase review, categorize findings by severity, file GitHub issues, then fix each issue in an isolated git…TencentCloudBasecursor-compliance-auditCompliance and security auditing for Cursor IDE usage: SOC 2, GDPR, HIPAA assessment, evidence collection, and remediation.…jeremylongshorewritescursor-privacy-settingsConfigure Cursor privacy mode, data handling, telemetry, and sensitive file exclusion. Triggers on "cursor privacy", "cursor…jeremylongshorewritesdoca-aes-gcmUse this skill when the user is doing hands-on DOCA AES-GCM work on a BlueField DPU or ConnectX NIC — configuring…NVIDIAdoca-argusUse this skill when the user is deploying or operating the DOCA Argus Service — the packaged BlueField-side runtime-security…NVIDIAdoca-flow-grpc-server`grpc::InsecureServerCredentials()` with NO TLS / mTLS / token-auth knob on the binary — transport security must come from…NVIDIAdoca-urom-svcOperate the DOCA UROM Service container on BlueField Arm for remote memory operations (puts, gets, atomics, collectives) enqueued…NVIDIAfrontend-designCreate distinctive, production-grade frontend interfaces with high design quality. Use this skill when the user asks to build web…tech-leads-clubmermaid-to-proverifTranslates Mermaid sequenceDiagrams describing cryptographic protocols into ProVerif formal verification models (.pv files). Use…trailofbitsopenrouter-audit-loggingImplement audit logging for OpenRouter API calls. Use when building compliance trails, debugging production issues, or tracking…jeremylongshorewritespaid-media-strategyA discipline for running paid media that does not light money on fire. Hypothesis writing for paid spend, channel selection…rampstackcoruntime-admissibility-reviewDetermines whether a specific AI-agent action, output, recommendation, or proposed commitment remains admissible for execution or…lawve-aisecurityEnforce Elixir/Phoenix security — auth, OAuth, sessions, CSRF, XSS, SQL injection, input validation, secrets. Use when editing…oliver-kriskaskill-authoringDesign, improve, and evaluate reusable agent skills with high-quality SKILL.md files, precise trigger descriptions, progressive…TencentCloudBaseskill-auto-improverImprove an external, legacy, or drifted SKILL.md to the skill-creator standard — hard validation gates plus an advisory…luongnv89writessupabase-enterprise-rbacImplement custom role-based access control via JWT claims in Supabase: app_metadata.role, RLS policies with auth.jwt() role…jeremylongshorewritessupabase-jsThis skill should be used when user asks to "use supabase-js", "query Supabase database", "supabase auth", "supabase storage"…fcakyonthe-foolUse when challenging ideas, plans, decisions, or proposals. Invoke to play devil's advocate, run a pre-mortem, red team, stress…tech-leads-clubux-heuristicsEvaluate and improve interface usability using heuristic analysis. Use when the user mentions "usability audit", "users are…wondelaiagent-authority-charter-builder-arkadiy-miteikoCreates an Agent Authority Charter for enterprise or regulated AI agents before deployment. Use this Skill when a user needs to…lawve-aiaudit-rgpd-site-internetAudit de conformité RGPD complet d'un site internet. Réalise une observation systématique du site selon une checklist de 10…lawve-aiauth-flowGenerates authentication infrastructure with Sign in with Apple, biometrics, and Keychain storage. Use when user wants to add…rshankraswritesaws-lambda-microvmsBuild, run, debug, and operate applications on AWS Lambda MicroVMs — Firecracker-isolated, snapshot-resumable serverless compute…awslabsazure-databricksExpert knowledge for Azure Databricks development including troubleshooting, best practices, decision making, architecture &…MicrosoftDocsclaude-securityThe Claude Security menu — pick a job: scan the codebase (the whole repository or a scoped part of it), scan changes (this…anthropicswritescode-review-expertExpert code review of current git changes with a senior engineer lens. Detects SOLID violations, security risks, and proposes…dtsolacode-reviewerAnalyzes code diffs and files to identify bugs, security vulnerabilities (SQL injection, XSS, insecure deserialization), code…JeffallancodeqlComprehensive guide for setting up and configuring CodeQL code scanning via GitHub Actions workflows and the CodeQL CLI. This…githubcro-methodologyAudit websites and landing pages for conversion issues and design evidence-based A/B tests. Use when the user mentions "landing…wondelaicursor-sso-integrationConfigure SAML 2.0 and OIDC SSO for Cursor with Okta, Microsoft Entra ID, and Google Workspace. Triggers on "cursor sso", "cursor…jeremylongshorewritesdifferential-reviewPerforms security-focused differential review of code changes (PRs, commits, diffs). Adapts analysis depth to codebase size, uses…trailofbitswritesdigital-health-clinical-asr-evalStage 3 of Clinical ASR Flywheel. Score a NeMo manifest, produce the five-section KER leaderboard (by-ipa_source diagnostic). Not…NVIDIA
← Prev8 / 58Next →
How the catalog works
What is an agent skill?

A folder with a SKILL.md inside — instructions, and often scripts and assets, that an AI agent loads when the task matches. Claude Code, Codex, Cursor and Copilot all read the same format, so one skill usually works across them.

Where does this catalog come from?

We read 660 source repositories straight from their file trees rather than from submitted listings — what you see is what is actually published. 98 repositories were rejected because they advertise skills but contain none: link lists, not folders.

Why is there no install counter?

Because install counts live in the registry that serves `npx skills add`, and that is not ours — publishing a number we cannot verify would be worse than showing none. Instead we show where a skill comes from and whether attention around its source is actually growing, measured from our own weekly snapshots.

Do you deduplicate?

Yes, and it matters more than expected. Aggregator repositories republish the same skill in several places — one source carried 6,317 SKILL.md files for 2,001 actual skills. We collapse by folder name and keep the canonical copy, so the catalog counts things, not copies.

Keep going