Agent Skills
Instruction packs that give your AI agent know-how — some work anywhere, some only with the tool they came with.
✦ Standalone skills3,373
Self-contained. Install one into any project and it works on its own — no other software needed.
🧰 Tool add-ons952
Come bundled with a specific tool and only work together with it — they teach your agent how to operate that tool.
✓ Official
48 companiesPublished by the companies themselves — pick one to see everything they ship.
openai5 skills
anthropics10 skills
google-gemini17 skills
microsoft92 skills
github8 skills
facebook4 skills
react1 skill
coinbase6 skills
stripe7 skills
shopify2 skills
cloudflare11 skills
vercel22 skills
vercel-labs63 skills
supabase4 skills
huggingface6 skills
pytorch2 skills
flutter3 skills
DataDog11 skills
getsentry89 skills
brave2 skills
googleworkspace95 skills
google-labs-code3 skills
genkit-ai9 skills
expo2 skills
n8n-io21 skills
sveltejs3 skills
nuxt1 skill
shadcn-ui2 skills
bitwarden2 skills
automattic14 skills
larksuite35 skills
browserbase1 skill
browser-use9 skills
apify2 skills
clickhouse8 skills
neondatabase11 skills
upstash10 skills
posthog165 skills
langfuse2 skills
resend3 skills
sanity-io24 skills
streamlit4 skills
remotion-dev3 skills
tldraw7 skills
apollographql1 skill
mastra-ai28 skills
triggerdotdev1 skill
mcp-use4 skillsAll Tool add-ons
26 tool add-onsn8n:human-like-code-review
★ 195,330by n8n-io
Reviews a GitHub pull request like a thoughtful human reviewer and writes the feedback to a markdown file. Prioritizes context, architecture fit, solution complexity, bugs, security edge cases, and missing tests. Use when given a PR URL to review, or when the user says /human-like-code-review.
🧰 Not standalone — use together with n8n-io/n8n
critique
✓★ 105,779by google-gemini
Expertise in auditing and fixing repository scripts and GitHub Actions workflows to ensure technical robustness and security.
🧰 Not standalone — use together with google-gemini/gemini-cli
signals-scout-csp-violations
★ 35,336by posthog
Signals scout for Content Security Policy violation reports. Watches `$csp_violation` events for blocked-URL clusters, per-directive bursts, post-deploy regressions, and suspicious third-party domains, and files each validated cluster as a report in the inbox.
🧰 Not standalone — use together with posthog/posthog
security-audit
★ 35,336by posthog
Focused security audit of code, calibrated to surface real exploitable bugs and suppress theoretical findings. Use when the user asks to "audit", "security-audit", "find vulnerabilities", "check for IDOR/SSRF/XSS/injection", or wants a security review of a file, directory, branch diff, or PR. Covers access control, injection, auth/secrets, sensitive data, business logic, web boundary, and AI agent/LLM trifecta risks. Produces calibrated findings with data flow, exploit request, fix, and confiden
🧰 Not standalone — use together with posthog/posthog
react-doctor
★ 35,336by posthog
Diagnose and fix React codebase health issues. Use when reviewing React code, fixing performance problems, auditing security, or improving code quality.
🧰 Not standalone — use together with posthog/posthog
persona-it-admin
✓★ 29,425by Google
Administer IT — monitor security and configure Workspace.
🧰 Not standalone — use together with googleworkspace/cli
security-review
★ 25,837by mastra-ai
Security-focused code review checklist for identifying vulnerabilities
🧰 Not standalone — use together with mastra-ai/mastra
mcp-builder
★ 10,252by mcp-use
**MANDATORY for ALL MCP server work** - mcp-use framework best practices and patterns. **READ THIS FIRST** before any MCP server work, including: - Creating new MCP servers - Modifying existing MCP servers (adding/updating tools, resources, prompts, widgets) - Debugging MCP server issues or errors - Reviewing MCP server code for quality, security, or performance - Answering questions about MCP development or mcp-use patterns - Making ANY changes to server.tool(), server.resource(), server.prompt
🧰 Not standalone — use together with mcp-use/mcp-use
chatgpt-app-builder
★ 10,252by mcp-use
**MANDATORY for ALL MCP server work** - mcp-use framework best practices and patterns. **READ THIS FIRST** before any MCP server work, including: - Creating new MCP servers - Modifying existing MCP servers (adding/updating tools, resources, prompts, widgets) - Debugging MCP server issues or errors - Reviewing MCP server code for quality, security, or performance - Answering questions about MCP development or mcp-use patterns - Making ANY changes to server.tool(), server.resource(), server.prompt
🧰 Not standalone — use together with mcp-use/mcp-use
mcp-apps-builder
★ 10,252by mcp-use
**MANDATORY for ALL MCP server work** - mcp-use framework best practices and patterns. **READ THIS FIRST** before any MCP server work, including: - Creating new MCP servers - Modifying existing MCP servers (adding/updating tools, resources, prompts, widgets) - Debugging MCP server issues or errors - Reviewing MCP server code for quality, security, or performance - Answering questions about MCP development or mcp-use patterns - Making ANY changes to server.tool(), server.resource(), server.prompt
🧰 Not standalone — use together with mcp-use/mcp-use
skill-scanner
✓★ 8,701by sentry
Scan agent skills for security issues. Use when asked to "scan a skill",
🧰 Not standalone — use together with getsentry/sentry-javascript
fix-security-vulnerability
✓★ 8,701by sentry
Analyze and propose fixes for Dependabot security alerts
🧰 Not standalone — use together with getsentry/sentry-javascript
streamdown
✓★ 5,367by vercel
Implement, configure, and customize Streamdown — a streaming-optimized React Markdown renderer with syntax highlighting, Mermaid diagrams, math rendering, and CJK support. Use when working with Streamdown setup, configuration, plugins, styling, security, or integration with AI streaming (e.g., Vercel AI SDK). Triggers on: (1) Installing or setting up Streamdown, (2) Configuring plugins (code, mermaid, math, cjk), (3) Styling or theming Streamdown output, (4) Integrating with AI chat/streaming, (
🧰 Not standalone — use together with vercel/streamdown
supply-chain-security
✓★ 3,123by microsoft
Activate when reviewing or modifying dependency resolution, lockfile schema, package downloaders, signature/integrity checks, file integration cleanup, or anything that could expose APM to dependency confusion, typosquatting, malicious packages, or token leakage.
🧰 Not standalone — use together with microsoft/apm
jinja2
✓★ 2,433by microsoft
Best practices for template rendering with Jinja2 including environments, filters, autoescaping, and security.
🧰 Not standalone — use together with microsoft/debugpy
security-review
✓★ 2,194by sentry
Security code review for vulnerabilities. Use when asked to "security review", "find vulnerabilities", "check for security issues", "audit security", "OWASP review", or review code for injection, XSS, authentication, authorization, cryptography issues. Provides systematic review with confidence-based reporting.
🧰 Not standalone — use together with getsentry/sentry-python
find-bugs
✓★ 2,194by sentry
Find bugs, security vulnerabilities, and code quality issues in local branch changes. Use when asked to review changes, find bugs, security review, or audit code on the current branch.
🧰 Not standalone — use together with getsentry/sentry-python
skill-scanner
✓★ 2,194by sentry
Scan agent skills for security issues. Use when asked to "scan a skill",
🧰 Not standalone — use together with getsentry/sentry-python
code-review
✓★ 2,194by sentry
Perform code reviews following Sentry engineering practices. Use when reviewing pull requests, examining code changes, or providing feedback on code quality. Covers security, performance, testing, and design review.
🧰 Not standalone — use together with getsentry/sentry-python
stripe-best-practices
✓★ 1,644by stripe
Guides Stripe integration decisions — API selection (Checkout Sessions vs PaymentIntents), Connect platform setup (Accounts v2, controller properties), billing/subscriptions, Treasury financial accounts, integration surfaces (Checkout, Payment Element), migrating from deprecated Stripe APIs, and security best practices (API key management, restricted keys, webhooks, OAuth). Use when building, modifying, or reviewing any Stripe integration — including accepting payments, building marketplaces, in
🧰 Not standalone — use together with stripe/ai
pup
★ 940by datadog-labs
Datadog API CLI with 49 command groups, 300+ subcommands. Skills and domain agents for monitoring, logs, APM, security, and infrastructure.
🧰 Not standalone — use together with DataDog/pup
mcp-audit
✓★ 753by sentry
Audit MCP servers for protocol compliance, metadata drift, and compatibility regressions. Use when reviewing tool annotations, tool/result schemas, structured output, lifecycle/init handshake, capabilities, prompts/resources support, transports, auth, security, version drift, or Warden/CI MCP compatibility checks. Trigger phrases include "audit MCP", "check MCP spec compliance", "review tool hints", "validate tools/list", "check initialize handshake", "review prompt or resource capabilities", an
🧰 Not standalone — use together with getsentry/sentry-mcp
create-payment-credential
✓★ 602by stripe
Gets secure, one-time-use payment credentials (cards, tokens) from a Link wallet so agents can complete purchases on behalf of users. Use when the user says "get me a card", "buy something", "pay for X", "make a purchase", "I need to pay", "complete checkout", or asks to transact on any merchant site. Use when the user asks to connect or log in to or sign up for their Link account.
🧰 Not standalone — use together with stripe/link-cli
security-review
✓★ 347by getsentry
Finds exploitable application security vulnerabilities in code changes. Use for Warden security scans, appsec review, OWASP-style checks, authentication or authorization bugs, injection, XSS, SSRF, path traversal, secrets, unsafe crypto, webhook verification, open redirects, or sensitive data exposure.
🧰 Not standalone — use together with getsentry/warden
entra-poc-advisor
✓★ 7by microsoft
Guides Microsoft Entra administrators through proof-of-concept deployments of Entra Suite products including Private Access, Internet Access, Global Secure Access, ID Protection, ID Governance, Verified ID, and External Identities. Use when user mentions "Entra POC", "Global Secure Access setup", "private access proof of concept", "Entra Suite trial", "GSA configuration", "zero trust network access POC", "secure web gateway POC", "identity governance POC", "external identities POC", "B2B collabo
🧰 Not standalone — use together with microsoft/entra-pocadvisor
healthcheck
★ 3by firecrawl
Host security hardening and risk-tolerance configuration for OpenClaw deployments. Use when a user asks for security audits, firewall/SSH/update hardening, risk posture, exposure review, OpenClaw cron scheduling for periodic checks, or version status checks on a machine running OpenClaw (laptop, workstation, Pi, VPS).
🧰 Not standalone — use together with firecrawl/openclaw