Agent skills

Security skills

Read straight from the source repositories, not from submitted listings. Every skill shows what it does, what is inside, where it came from — and whether attention around its source is actually growing.

Toolclaude-code 29,140codex 4,755cursor 3,111copilot 976windsurf 55cline 34
CategoryWorkflow & Productivity 4,979AI & Agents 3,037Data & Analytics 2,345Code Review & Quality 1,376Backend & API 1,244Security 1,194Design & Presentation 1,154Documentation 965Content & Marketing 916Testing & QA 777DevOps & Cloud 576Databases 550Frontend 469Business & Finance 328Media & Video 257Other 9,833
2,762 found
385432 · page 9 / 58
doraExpert DORA (Regulation (EU) 2022/2554 — Digital Operational Resilience Act) compliance advisor for EU financial entities. Use…lawve-aientra-agent-idProvision Microsoft Entra Agent Identity Blueprints, BlueprintPrincipals, and per-instance Agent Identities via Microsoft Graph…microsoftfedrampExpert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026). Use this skill…Sushegaadfigma-incident-runbookRespond to Figma API outages, auth failures, and rate limit incidents. Use when Figma integration is down, experiencing errors…jeremylongshorefigma-install-authSet up Figma REST API authentication with personal access tokens or OAuth 2.0. Use when connecting to the Figma API, generating…jeremylongshorewritesfigma-policy-guardrailsEnforce security policies and coding standards for Figma API integrations. Use when setting up linting rules for Figma tokens…jeremylongshorewritesfigma-security-basicsSecure Figma API tokens, configure scopes, and validate webhook signatures. Use when securing API keys, implementing…jeremylongshorewritesfinding-security-misconfigurationsConfigure identify security misconfigurations in infrastructure-as-code, application settings, and system configurations. Use…jeremylongshorewritesfp-checkSystematically verifies suspected security bugs to eliminate false positives. Produces TRUE POSITIVE or FALSE POSITIVE verdicts…waybarriossolution-architect解决方案架构师助手。当用户要设计新系统架构、评审现有架构、做技术选型决策、诊断性能/可扩展性/可用性问题、规划架构演进或重构时使用。覆盖微服务、事件驱动、云原生等架构模式,技术趋势通过实时搜索获取而非依赖内置知识。不用于:具体功能的代码实现、安全漏洞审计(用s…staruhubgenerating-security-audit-reportsGenerate comprehensive security audit reports for applications and systems. Use when you need to assess security posture…jeremylongshorewriteshipaa-complianceExpert HIPAA compliance assistant for healthcare and software contexts. Use this skill whenever the user mentions HIPAA, PHI…lawve-aik8s-manifest-generatorCreate production-ready Kubernetes manifests for Deployments, Services, ConfigMaps, and Secrets following best practices and…wshobsonlangchain-enterprise-rbacEnforce tenant isolation and role-based access across LangChain 1.0\ \ chains and\nLangGraph 1.0 agents \u2014 per-request…jeremylongshorewritesllms-txt-generatorGenerates and maintains a standards-compliant llms.txt file for any website — either by crawling the live site OR by reading the…Varnan-Techloop-libraryCompatibility alias for Loopy. Use only when an existing installation or older instruction explicitly invokes loop-library; use…Forward-FutureloopyDiscover, find, compare, audit, repair, adapt, craft, run, debrief, save, and prepare repeatable AI-agent loops for publication.…Forward-FutureloopyDiscover, find, compare, audit, repair, adapt, craft, run, debrief, and prepare repeatable AI-agent loops for publication. Use…sickn33matlab-connect-opcua-clientDiscover OPC UA servers and create client connections in MATLAB using opcuaserverinfo, opcua, connect, setSecurityModel, and…matlaboma-deepsecDrive Vercel's `deepsec` agent-powered vulnerability scanner end-to-end: installing the `.deepsec/` workspace, bootstrapping…first-flukephx-planPlan features spanning multiple domains: billing (Stripe), auth (RBAC), real-time (Presence), webhooks, jobs (Oban). Use when…oliver-kriskaplanPlan features spanning multiple domains: billing (Stripe), auth (RBAC), real-time (Presence), webhooks, jobs (Oban). Use when…oliver-kriskaproduct-designTurn a vague product ask ("this page feels wrong", "we need a team view") into a grounded, shippable design by establishing…lobehubreviewReview code with parallel agents — tests, security, Ecto, LiveView, Oban. Use after implementation to catch bugs and…oliver-kriskasecurity-reviewerIdentifies security vulnerabilities, generates structured audit reports with severity ratings, and provides actionable…Jeffallanwritessentry-data-handlingConfigure GDPR-compliant data handling, PII scrubbing, and data retention policies in Sentry. Use when implementing beforeSend…jeremylongshorewritessoc2Expert SOC 2 compliance assistant covering all five Trust Services Criteria (Security/CC, Availability/A, Confidentiality/C…lawve-aistripe-best-practicesGuides Stripe integration decisions across API selection (Checkout Sessions vs PaymentIntents), Connect platform setup (Accounts…fcakyonsupabase-data-handlingImplement GDPR/CCPA compliance with Supabase: RLS for data isolation, user deletion via auth.admin.deleteUser(), data export via…jeremylongshorewritessupabase-sdk-patternsUse when implementing Supabase queries, auth, realtime, storage, or RPC calls with @supabase/supabase-js or supabase-py and you…jeremylongshorewritesthe-foolUse when challenging ideas, plans, decisions, or proposals using structured critical reasoning. Invoke to play devil's advocate…Jeffallanzero-tech-debtRebuild a feature as if the correct product architecture existed from day one — remove compatibility cruft, dead abstractions…jeremylongshorewritesaudit-context-buildingEnables ultra-granular, line-by-line code analysis to build deep architectural context before vulnerability or bug finding.trailofbitscapabilities-managerManage capa CLI configuration — `capabilities.yaml` / `capabilities.json`, skills, MCP servers, tools, hooks, sub-agents, rules…infragatecis-controlsExpert CIS Controls v8 (CIS Top 18) advisor — implementation group scoping (IG1/IG2/IG3), control gap assessments…lawve-aicloud-architectDesigns cloud architectures, creates migration plans, generates cost optimization recommendations, and produces disaster recovery…JeffallancloudbaseEssential CloudBase (TCB, Tencent CloudBase, 云开发, 微信云开发) development guidelines. MUST read for CloudBase Web apps, mini programs…TencentCloudBasecloudbaseUse this skill when you develop, design, build, deploy, debug, migrate, or troubleshoot CloudBase (腾讯云开发, 云开发, TCB, 微信云开发)…TencentCloudBasecmmcExpert CMMC 2.0 (Cybersecurity Maturity Model Certification) advisor for US defense contractors and subcontractors in the Defense…lawve-aideep-diveRigorous multi-agent deep-dive analysis for complex investigative tasks — auditing codebases, evaluating strategies or systems…nelsonwerddeployUse when ready to ship — runs pre-push gates (lint, typecheck, build, tests, security sweep), commits, releases, and pushes.…jeremylongshorewritesdocs-auditorAudits any developer documentation site across 33 checks in 7 categories and produces a scored report (out of 100) with Pass /…Infrasity-Labsexternal-resource-contextCaptures and persists access methods for resources outside the repository (design source, design system, API schema, IaC source…shinprgithub-actions-hardeningSecurity hardening reviewer for GitHub Actions workflow files (.github/workflows/*.yml). Reasons about the Actions threat model…githubgood-strategy-bad-strategyFormulate and audit real strategy using Richard Rumelt''s "Good Strategy Bad Strategy": an honest diagnosis, a guiding policy…wondelaiinbound-lead-audit-cx-mapAudit inbound lead handling and map the customer experience from source event to follow-up outcome.zapieriso27001Expert ISO 27001 compliance assistant for security and compliance teams. Use this skill whenever a user asks about ISO 27001 or…lawve-aijava-architectUse when building, configuring, or debugging enterprise Java applications with Spring Boot 3.x, microservices, or reactive…Jeffallan
← Prev9 / 58Next →
How the catalog works
What is an agent skill?

A folder with a SKILL.md inside — instructions, and often scripts and assets, that an AI agent loads when the task matches. Claude Code, Codex, Cursor and Copilot all read the same format, so one skill usually works across them.

Where does this catalog come from?

We read 660 source repositories straight from their file trees rather than from submitted listings — what you see is what is actually published. 98 repositories were rejected because they advertise skills but contain none: link lists, not folders.

Why is there no install counter?

Because install counts live in the registry that serves `npx skills add`, and that is not ours — publishing a number we cannot verify would be worse than showing none. Instead we show where a skill comes from and whether attention around its source is actually growing, measured from our own weekly snapshots.

Do you deduplicate?

Yes, and it matters more than expected. Aggregator repositories republish the same skill in several places — one source carried 6,317 SKILL.md files for 2,001 actual skills. We collapse by folder name and keep the canonical copy, so the catalog counts things, not copies.

Keep going