Labsco

Agent Skills

Instruction packs that give your AI agent know-how — some work anywhere, some only with the tool they came with.

✓ Official

48 companies

Published by the companies themselves — pick one to see everything they ship.

All Tool add-ons

26 tool add-ons
n8n-io logo

n8n:human-like-code-review

★ 195,330

by n8n-io

Reviews a GitHub pull request like a thoughtful human reviewer and writes the feedback to a markdown file. Prioritizes context, architecture fit, solution complexity, bugs, security edge cases, and missing tests. Use when given a PR URL to review, or when the user says /human-like-code-review.

🧰 Not standalone — use together with n8n-io/n8n

google-gemini logo

critique

✓★ 105,779

by google-gemini

Expertise in auditing and fixing repository scripts and GitHub Actions workflows to ensure technical robustness and security.

🧰 Not standalone — use together with google-gemini/gemini-cli

PostHog logo

signals-scout-csp-violations

★ 35,336

by posthog

Signals scout for Content Security Policy violation reports. Watches `$csp_violation` events for blocked-URL clusters, per-directive bursts, post-deploy regressions, and suspicious third-party domains, and files each validated cluster as a report in the inbox.

🧰 Not standalone — use together with posthog/posthog

PostHog logo

security-audit

★ 35,336

by posthog

Focused security audit of code, calibrated to surface real exploitable bugs and suppress theoretical findings. Use when the user asks to "audit", "security-audit", "find vulnerabilities", "check for IDOR/SSRF/XSS/injection", or wants a security review of a file, directory, branch diff, or PR. Covers access control, injection, auth/secrets, sensitive data, business logic, web boundary, and AI agent/LLM trifecta risks. Produces calibrated findings with data flow, exploit request, fix, and confiden

🧰 Not standalone — use together with posthog/posthog

PostHog logo

react-doctor

★ 35,336

by posthog

Diagnose and fix React codebase health issues. Use when reviewing React code, fixing performance problems, auditing security, or improving code quality.

🧰 Not standalone — use together with posthog/posthog

🔥🔥🔥✓ VerifiedFreeQuick setup
googleworkspace logo

persona-it-admin

✓★ 29,425

by Google

Administer IT — monitor security and configure Workspace.

🧰 Not standalone — use together with googleworkspace/cli

🔥🔥✓ VerifiedFreeAdvanced setup
mastra-ai logo

security-review

★ 25,837

by mastra-ai

Security-focused code review checklist for identifying vulnerabilities

🧰 Not standalone — use together with mastra-ai/mastra

mcp-use logo

mcp-builder

★ 10,252

by mcp-use

**MANDATORY for ALL MCP server work** - mcp-use framework best practices and patterns. **READ THIS FIRST** before any MCP server work, including: - Creating new MCP servers - Modifying existing MCP servers (adding/updating tools, resources, prompts, widgets) - Debugging MCP server issues or errors - Reviewing MCP server code for quality, security, or performance - Answering questions about MCP development or mcp-use patterns - Making ANY changes to server.tool(), server.resource(), server.prompt

🧰 Not standalone — use together with mcp-use/mcp-use

🔥🔥✓ VerifiedFreeAdvanced setup
mcp-use logo

chatgpt-app-builder

★ 10,252

by mcp-use

**MANDATORY for ALL MCP server work** - mcp-use framework best practices and patterns. **READ THIS FIRST** before any MCP server work, including: - Creating new MCP servers - Modifying existing MCP servers (adding/updating tools, resources, prompts, widgets) - Debugging MCP server issues or errors - Reviewing MCP server code for quality, security, or performance - Answering questions about MCP development or mcp-use patterns - Making ANY changes to server.tool(), server.resource(), server.prompt

🧰 Not standalone — use together with mcp-use/mcp-use

🔥🔥✓ VerifiedFreeAdvanced setup
mcp-use logo

mcp-apps-builder

★ 10,252

by mcp-use

**MANDATORY for ALL MCP server work** - mcp-use framework best practices and patterns. **READ THIS FIRST** before any MCP server work, including: - Creating new MCP servers - Modifying existing MCP servers (adding/updating tools, resources, prompts, widgets) - Debugging MCP server issues or errors - Reviewing MCP server code for quality, security, or performance - Answering questions about MCP development or mcp-use patterns - Making ANY changes to server.tool(), server.resource(), server.prompt

🧰 Not standalone — use together with mcp-use/mcp-use

🔥🔥🔥🔥✓ VerifiedFreeAdvanced setup
getsentry logo

skill-scanner

✓★ 8,701

by sentry

Scan agent skills for security issues. Use when asked to "scan a skill",

🧰 Not standalone — use together with getsentry/sentry-javascript

🔥🔥🔥✓ VerifiedFreeQuick setup
getsentry logo

fix-security-vulnerability

✓★ 8,701

by sentry

Analyze and propose fixes for Dependabot security alerts

🧰 Not standalone — use together with getsentry/sentry-javascript

🔥🔥🔥✓ VerifiedFreeQuick setup
vercel logo

streamdown

✓★ 5,367

by vercel

Implement, configure, and customize Streamdown — a streaming-optimized React Markdown renderer with syntax highlighting, Mermaid diagrams, math rendering, and CJK support. Use when working with Streamdown setup, configuration, plugins, styling, security, or integration with AI streaming (e.g., Vercel AI SDK). Triggers on: (1) Installing or setting up Streamdown, (2) Configuring plugins (code, mermaid, math, cjk), (3) Styling or theming Streamdown output, (4) Integrating with AI chat/streaming, (

🧰 Not standalone — use together with vercel/streamdown

🔥🔥🔥🔥✓ VerifiedFreeQuick setup
microsoft logo

supply-chain-security

✓★ 3,123

by microsoft

Activate when reviewing or modifying dependency resolution, lockfile schema, package downloaders, signature/integrity checks, file integration cleanup, or anything that could expose APM to dependency confusion, typosquatting, malicious packages, or token leakage.

🧰 Not standalone — use together with microsoft/apm

🔥🔥FreeQuick setup
microsoft logo

jinja2

✓★ 2,433

by microsoft

Best practices for template rendering with Jinja2 including environments, filters, autoescaping, and security.

🧰 Not standalone — use together with microsoft/debugpy

🔥🔥🔥🔥✓ VerifiedFreeQuick setup
getsentry logo

security-review

✓★ 2,194

by sentry

Security code review for vulnerabilities. Use when asked to "security review", "find vulnerabilities", "check for security issues", "audit security", "OWASP review", or review code for injection, XSS, authentication, authorization, cryptography issues. Provides systematic review with confidence-based reporting.

🧰 Not standalone — use together with getsentry/sentry-python

🔥🔥🔥🔥✓ VerifiedFreeQuick setup
getsentry logo

find-bugs

✓★ 2,194

by sentry

Find bugs, security vulnerabilities, and code quality issues in local branch changes. Use when asked to review changes, find bugs, security review, or audit code on the current branch.

🧰 Not standalone — use together with getsentry/sentry-python

🔥🔥🔥FreeQuick setup
getsentry logo

skill-scanner

✓★ 2,194

by sentry

Scan agent skills for security issues. Use when asked to "scan a skill",

🧰 Not standalone — use together with getsentry/sentry-python

🔥🔥🔥✓ VerifiedFreeQuick setup
getsentry logo

code-review

✓★ 2,194

by sentry

Perform code reviews following Sentry engineering practices. Use when reviewing pull requests, examining code changes, or providing feedback on code quality. Covers security, performance, testing, and design review.

🧰 Not standalone — use together with getsentry/sentry-python

🔥🔥🔥✓ VerifiedFreeQuick setup
stripe logo

stripe-best-practices

✓★ 1,644

by stripe

Guides Stripe integration decisions — API selection (Checkout Sessions vs PaymentIntents), Connect platform setup (Accounts v2, controller properties), billing/subscriptions, Treasury financial accounts, integration surfaces (Checkout, Payment Element), migrating from deprecated Stripe APIs, and security best practices (API key management, restricted keys, webhooks, OAuth). Use when building, modifying, or reviewing any Stripe integration — including accepting payments, building marketplaces, in

🧰 Not standalone — use together with stripe/ai

🔥🔥🔥🔥✓ VerifiedFreeQuick setup
DataDog logo

pup

★ 940

by datadog-labs

Datadog API CLI with 49 command groups, 300+ subcommands. Skills and domain agents for monitoring, logs, APM, security, and infrastructure.

🧰 Not standalone — use together with DataDog/pup

🔥🔥🔥✓ VerifiedFreeQuick setup
getsentry logo

mcp-audit

✓★ 753

by sentry

Audit MCP servers for protocol compliance, metadata drift, and compatibility regressions. Use when reviewing tool annotations, tool/result schemas, structured output, lifecycle/init handshake, capabilities, prompts/resources support, transports, auth, security, version drift, or Warden/CI MCP compatibility checks. Trigger phrases include "audit MCP", "check MCP spec compliance", "review tool hints", "validate tools/list", "check initialize handshake", "review prompt or resource capabilities", an

🧰 Not standalone — use together with getsentry/sentry-mcp

🔥🔥🔥🔥✓ VerifiedFreeQuick setup
stripe logo

create-payment-credential

✓★ 602

by stripe

Gets secure, one-time-use payment credentials (cards, tokens) from a Link wallet so agents can complete purchases on behalf of users. Use when the user says "get me a card", "buy something", "pay for X", "make a purchase", "I need to pay", "complete checkout", or asks to transact on any merchant site. Use when the user asks to connect or log in to or sign up for their Link account.

🧰 Not standalone — use together with stripe/link-cli

🔥🔥🔥✓ VerifiedFreeQuick setup
getsentry logo

security-review

✓★ 347

by getsentry

Finds exploitable application security vulnerabilities in code changes. Use for Warden security scans, appsec review, OWASP-style checks, authentication or authorization bugs, injection, XSS, SSRF, path traversal, secrets, unsafe crypto, webhook verification, open redirects, or sensitive data exposure.

🧰 Not standalone — use together with getsentry/warden

microsoft logo

entra-poc-advisor

✓★ 7

by microsoft

Guides Microsoft Entra administrators through proof-of-concept deployments of Entra Suite products including Private Access, Internet Access, Global Secure Access, ID Protection, ID Governance, Verified ID, and External Identities. Use when user mentions "Entra POC", "Global Secure Access setup", "private access proof of concept", "Entra Suite trial", "GSA configuration", "zero trust network access POC", "secure web gateway POC", "identity governance POC", "external identities POC", "B2B collabo

🧰 Not standalone — use together with microsoft/entra-pocadvisor

🔥🔥🔥✓ VerifiedFreeQuick setup
firecrawl logo

healthcheck

★ 3

by firecrawl

Host security hardening and risk-tolerance configuration for OpenClaw deployments. Use when a user asks for security audits, firewall/SSH/update hardening, risk posture, exposure review, OpenClaw cron scheduling for periodic checks, or version status checks on a machine running OpenClaw (laptop, workstation, Pi, VPS).

🧰 Not standalone — use together with firecrawl/openclaw

🔥🔥🔥✓ VerifiedFreeQuick setup