AI Agent Skill Repository

AI Agent Skills Directory

Browse reusable skills for Codex, Claude Code, Cursor, finance, research, web scraping, PPT, football analytics, data, marketing, design, and more.

Browse by scenario

Real skills, grouped by the work your agent needs to finish.

Each directory entry links to real skill pages with GitHub adoption, trust score, install handoff, risk notes, and agent-readable metadata. Use these as starting points when you want a shortlist before asking an agent to install anything.

Design to deployment

Frontend and UI skills

Design direction, Figma implementation, UI review, React performance, browser QA, and safe preview deployments.

  • Backpack539 stars

    Backpack Design System for the Web

    Trust 79Quality 76design-creative
  • Vuls12K stars

    Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Ne…

    Trust 88Quality 100security
  • Faraday6.5K stars

    Open Source Vulnerability Management Platform

    Trust 87Quality 100devops

Codex, Claude Code, Cursor

Coding agent skills

Code review, repo inspection, testing, planning, shipping, and engineering workflows for coding agents.

  • A Claude Code skill bundle for bug hunting and external red-team work — 71 skills, 15 slash commands, 681 dis…

    Trust 84Quality 91development
  • Sast Skills661 stars

    Collection of agent skills that turn your AI coder into a SAST scanner

    Trust 77Quality 73agent-skills
  • Skills16 stars

    AI agent skills for OpenText Fortify — SAST/DAST/SCA scanning, vulnerability triage, remediation, dependency…

    Trust 70Quality 64security

Documents and knowledge

Research and RAG skills

Research, recent-events briefings, PDF parsing, markdown conversion, RAG ingestion, and knowledge workflows.

  • Document scanning app

    Trust 84Quality 96document-processing
  • AirSane355 stars

    Publish SANE scanners to MacOS, Android, and Windows via Apple AirScan.

    Trust 75Quality 74document-processing
  • 🧾✨ AI-Powered Receipt and Invoice Scanner for Laravel, with support for images, documents and text

    Trust 78Quality 70document-processing

Markets and quant

Finance and trading skills

Stock analysis, market research, quant backtesting, financial data, and investment research skills.

  • Vetix57 stars

    Vetix — Automated scanning, identification, and assessment of SKILL security risks.

    Trust 77Quality 68utility
  • Foxguard270 stars

    A blazingly fast security scanner, written in Rust. Batteries included, TUI for triage, secrets, post-quantum…

    Trust 75Quality 73security

Crawlers and extraction

Web scraping skills

Crawling, scraping, extraction, browser automation, structured data capture, and website-to-markdown workflows.

  • Crawlergo3.0K stars

    A powerful browser crawler for web vulnerability scanners

    Trust 78Quality 69web-automation
  • dynamic crawler for web vulnerability scanner

    Trust 70Quality 60browser-automation
  • ScopeSentry1.5K stars

    ScopeSentry-Cyberspace mapping, subdomain enumeration, port scanning, sensitive information discovery, vulner…

    Trust 84Quality 89web-automation

Slides and decks

PPT and presentation skills

Presentation generation, editable PPTX, slide decks, speaker notes, and visual storytelling workflows.

  • Kill Ai Slop786 stars

    A field guide to the visual & copy tics of AI-generated products — and an Agent Skill that scans your project…

    Trust 87Quality 95design-creative

Images, video, UI

Design and creative skills

Image, video, creative production, UI design, multimodal generation, and visual workflow skills.

  • XAttacker1.7K stars

    X Attacker Tool ☣ Website Vulnerability Scanner & Auto Exploiter

    Trust 75Quality 62security
  • Grype13K stars

    A vulnerability scanner for container images and filesystems

    Trust 88Quality 100development
  • Clair11K stars

    Vulnerability Static Analysis for Containers

    Trust 88Quality 100development

Analysis and pipelines

Data and analytics skills

Data analysis, analytics, ETL, notebooks, databases, tables, charts, and reporting workflows.

  • Cloudquery6.4K stars

    Data pipelines for cloud config and security data. Build cloud asset inventory, CSPM, FinOps, and vulnerabili…

    Trust 89Quality 100data-analysis
  • GoSQLX101 stars

    High-performance SQL parser, formatter, linter & security scanner for Go - 1.5M+ ops/sec, multi-dialect, zero…

    Trust 73Quality 68data-analysis
  • Sqlifinder392 stars

    SQL Injection Vulnerability Scanner made with Python

    Trust 70Quality 66data-analysis

Supply tracks

Build the registry by domain, not just by count.

Coding

Coding and developer agents

242

Code review, repo analysis, testing, CI, GitHub, DevOps, and developer workflow skills.

233 quality222 maintained

Research

Research and knowledge work

80

Deep research, source comparison, literature review, RAG, knowledge search, and reports.

79 quality76 maintained

Presentation

Presentation and deck workflows

1

PPTX generation, HTML slides, pitch decks, speaker notes, and presentation workflow skills.

1 quality1 maintained

Finance

Finance and quant workflows

15

Market data, SEC filings, portfolio analysis, quant research, backtesting, and risk workflows.

15 quality15 maintained

Marketing

Marketing and growth automation

13

SEO, content operations, lead generation, CRM, email automation, analytics, and growth workflows.

13 quality12 maintained

Design

Design and creative production

50

Design assets, images, video, audio, multimodal media, presentation, and creative production skills.

50 quality49 maintained

Data

Data, BI, and analytics

36

CSV, SQL, notebooks, dashboards, data pipelines, BI, ETL, and spreadsheet analysis.

35 quality36 maintained

Legal

Legal, policy, and compliance

22

Contract analysis, privacy, policy review, compliance checks, governance, and document risk review.

22 quality18 maintained

Education

Education and tutoring

5

Tutoring, course generation, quizzes, learning analytics, classrooms, and teaching workflows.

5 quality5 maintained

World Cup

Football and World Cup analytics

2

Football data, World Cup dashboards, xG, match prediction, scouting, and sports analytics.

2 quality2 maintained

High-intent entry points

Start from the task, not a keyword list.

These shortcuts use the same trust, supply, and relevance signals as the registry API, so humans and agents land on a useful shortlist faster.

Agent-readable index

Decision filters

Choose by scenario, quality, and trust signals.

Showing 1-16 of 453 ranked candidates matching "vulnerability-scanner"

Best blend of quality, stars, freshness, and agent usage

1

Web Cache Vulnerability Scanner

VERIFIEDSTRONG · 82TRUST · 79SAFE · EXPERIMENTALCODING

Web Cache Vulnerability Scanner is a Go-based CLI tool for testing for web cache poisoning. It is developed by Hackmanit GmbH (http://hackmanit.de/).

$ npx skills add Hackmanit/Web-Cache-Vulnerability-Scanner
1.2K stars56 quality79 trustExperimental6mo since pushNeeds review
QualitySolid option that is likely worth shortlisting for production workflows.
TrustGood trust signals with a few areas worth checking before rollout.Review: Documentation summary is thin
Safety gateSparse or mixed signals. Useful for discovery, but not for autonomous installation.

Scenario Testing and QA

CLI + Codex · 4 targets

gosecurity
by HackmanitDetailsQuick view
2

Osv Scanner

VERIFIEDEXCELLENT · 100TRUST · 90SAFE · REVIEWEDCODING

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

$ npx skills add google/osv-scanner
10.6K stars71 quality90 trustReviewed1mo since pushSafe to try
QualityHigh-confidence pick with strong adoption and healthy maintenance signals.
TrustStrong OpenAgentSkill Trust Score across adoption, recent maintenance, license clarity, documentation, dependency/…Review: Documentation summary is thin
Safety gateGood audit and safety signals with no high-risk permission hints in public metadata.

Scenario GitHub automation

CLI + Codex · 4 targets

gosecurity
by googleDetailsQuick view
3

Terrapin Scanner

NEEDS REVIEW · 50TRUST · 72SAFE · EXPERIMENTALCODING

This repository contains a simple vulnerability scanner for the Terrapin attack present in the paper "Terrapin Attack: Breaking SSH Channel Integrity By Sequence Number…

$ npx skills add RUB-NDS/Terrapin-Scanner
993 stars40 quality72 trustExperimental2y since pushNeeds review
QualityInspect the repository carefully before adding it to an agent workflow.Check: Repository looks stale
TrustGood trust signals with a few areas worth checking before rollout.Review: Repository looks stale
Safety gateSparse or mixed signals. Useful for discovery, but not for autonomous installation.

Scenario GitHub automation

CLI + Codex · 4 targets

gosecurity
by RUB-NDSDetailsQuick view
4

Nettacker

VERIFIEDEXCELLENT · 100TRUST · 88SAFE · REVIEWEDCODING

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

$ npx skills add OWASP/Nettacker
5.3K stars68 quality88 trustReviewed1mo since pushSafe to try
QualityHigh-confidence pick with strong adoption and healthy maintenance signals.
TrustStrong OpenAgentSkill Trust Score across adoption, recent maintenance, license clarity, documentation, dependency/…Review: Documentation summary is thin
Safety gateGood audit and safety signals with no high-risk permission hints in public metadata.

Scenario Testing and QA

CLI + Codex · 4 targets

pythonsecurity
by OWASPDetailsQuick view
5

Crlfuzz

VERIFIEDEXCELLENT · 94TRUST · 85SAFE · REVIEWEDCODING

A fast tool to scan CRLF vulnerability written in Go

$ npx skills add dwisiswant0/crlfuzz
1.5K stars64 quality85 trustReviewed1mo since pushSafe to try
QualityHigh-confidence pick with strong adoption and healthy maintenance signals.
TrustGood trust signals with a few areas worth checking before rollout.Review: Documentation summary is thin
Safety gateGood audit and safety signals with no high-risk permission hints in public metadata.

Scenario GitHub automation

CLI + Codex · 4 targets

gosecurity
by dwisiswant0DetailsQuick view
6

Artemis

VERIFIEDEXCELLENT · 93TRUST · 85SAFE · REVIEWEDCODING

A modular vulnerability scanner with automatic report generation capabilities.

$ npx skills add CERT-Polska/Artemis
1.2K stars63 quality85 trustReviewed2mo since pushSafe to try
QualityHigh-confidence pick with strong adoption and healthy maintenance signals.
TrustGood trust signals with a few areas worth checking before rollout.Review: Documentation summary is thin
Safety gateGood audit and safety signals with no high-risk permission hints in public metadata.

Scenario Testing and QA

CLI + Codex · 4 targets

pythonsecurity
by CERT-PolskaDetailsQuick view
7

Fuxploider

VERIFIEDSTRONG · 70TRUST · 79SAFE · EXPERIMENTALCODING

File upload vulnerability scanner and exploitation tool.

$ npx skills add almandin/fuxploider
3.3K stars51 quality79 trustExperimental1y since pushNeeds review
QualitySolid option that is likely worth shortlisting for production workflows.Check: Repository looks stale
TrustGood trust signals with a few areas worth checking before rollout.Review: Repository looks stale
Safety gateSparse or mixed signals. Useful for discovery, but not for autonomous installation.

Scenario Coding agents

CLI + Codex · 4 targets

pythonsecurity
by almandinDetailsQuick view
8

OSS DocumentScanner

VERIFIEDEXCELLENT · 96TRUST · 84SAFE · REVIEWEDRESEARCH

Document scanning app

$ npx skills add ossappscollective/OSS-DocumentScanner
2.3K stars65 quality84 trustReviewed1mo since pushSafe to try
QualityHigh-confidence pick with strong adoption and healthy maintenance signals.
TrustGood trust signals with a few areas worth checking before rollout.Review: Documentation summary is thin
Safety gateGood audit and safety signals with no high-risk permission hints in public metadata.

Scenario Document processing

CLI + Codex · 4 targets

c++pdf
by ossappscollectiveDetailsQuick view
9

POC T

VERIFIEDPROMISING · 62TRUST · 75SAFE · EXPERIMENTALCODING

渗透测试插件化并发框架 / Open-sourced remote vulnerability PoC/EXP framework

$ npx skills add Xyntax/POC-T
1.9K stars50 quality75 trustExperimental4y since pushNeeds review
QualityUseful candidate, but compare it with alternatives before adopting.Check: Repository looks stale
TrustGood trust signals with a few areas worth checking before rollout.Review: License is unclear
Safety gateSparse or mixed signals. Useful for discovery, but not for autonomous installation.

Scenario Coding agents

CLI + Codex · 4 targets

pythonsecurity
by XyntaxDetailsQuick view
10

BurpBounty

VERIFIEDPROMISING · 67TRUST · 80SAFE · REVIEWEDCODING

Burp Bounty (Scan Check Builder in BApp Store) is a extension of Burp Suite that allows you, in a quick and simple way, to improve the active and passive scanner by mean…

$ npx skills add wagiro/BurpBounty
1.8K stars50 quality80 trustReviewed with permission notes2y since pushNeeds review
QualityUseful candidate, but compare it with alternatives before adopting.Check: Repository looks stale
TrustGood trust signals with a few areas worth checking before rollout.Review: Repository looks stale
Safety gateUsable candidate, but the agent should surface permission and audit notes before installation.

Scenario GitHub automation

CLI + Codex · 4 targets

javasecurity
by wagiroDetailsQuick view
11

BinAbsInspector

VERIFIEDPROMISING · 67TRUST · 77SAFE · EXPERIMENTALCODING

BinAbsInspector: Vulnerability Scanner for Binaries

$ npx skills add KeenSecurityLab/BinAbsInspector
1.7K stars49 quality77 trustExperimental2y since pushNeeds review
QualityUseful candidate, but compare it with alternatives before adopting.Check: Repository looks stale
TrustGood trust signals with a few areas worth checking before rollout.Review: Repository looks stale
Safety gateSparse or mixed signals. Useful for discovery, but not for autonomous installation.

Scenario GitHub automation

CLI + Codex · 4 targets

javasecurity
by KeenSecurityLabDetailsQuick view
12

Corsy

VERIFIEDPROMISING · 66TRUST · 77SAFE · EXPERIMENTALCODING

CORS Misconfiguration Scanner

$ npx skills add s0md3v/Corsy
1.5K stars49 quality77 trustExperimental4y since pushNeeds review
QualityUseful candidate, but compare it with alternatives before adopting.Check: Repository looks stale
TrustGood trust signals with a few areas worth checking before rollout.Review: Repository looks stale
Safety gateSparse or mixed signals. Useful for discovery, but not for autonomous installation.

Scenario GitHub automation

CLI + Codex · 4 targets

pythonsecurity
by s0md3vDetailsQuick view
13

Wscan

STRONG · 72TRUST · 76SAFE · REVIEWEDDATA

Wscan is a web security scanner that focuses on web security, dedicated to making web security accessible to everyone.

$ npx skills add chushuai/wscan
709 stars54 quality76 trustReviewed with permission notes1mo since pushNeeds review
QualitySolid option that is likely worth shortlisting for production workflows.
TrustGood trust signals with a few areas worth checking before rollout.Review: License is unclear
Safety gateUsable candidate, but the agent should surface permission and audit notes before installation.

Scenario Database and SQL

CLI + Codex · 4 targets

gocrawler
by chushuaiDetailsQuick view
14

Vigolium

STRONG · 72TRUST · 77SAFE · REVIEWEDCODING

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

$ npx skills add vigolium/vigolium
682 stars54 quality77 trustReviewed with permission notes2mo since pushNeeds review
QualitySolid option that is likely worth shortlisting for production workflows.
TrustGood trust signals with a few areas worth checking before rollout.Review: License is unclear
Safety gateUsable candidate, but the agent should surface permission and audit notes before installation.

Scenario GitHub automation

CLI + Codex · 4 targets

gosecurity
by vigoliumDetailsQuick view
15

DockSec

STRONG · 75TRUST · 77SAFE · REVIEWEDRESEARCH

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

$ npx skills add OWASP/DockSec
434 stars52 quality77 trustReviewed with permission notes1mo since pushNeeds review
QualitySolid option that is likely worth shortlisting for production workflows.
TrustGood trust signals with a few areas worth checking before rollout.Review: Quality score needs review
Safety gateUsable candidate, but the agent should surface permission and audit notes before installation.

Scenario RAG and knowledge

CLI + Codex · 4 targets

pythonsecurity
by OWASPDetailsQuick view
16

Zen AI Pentest

STRONG · 74TRUST · 78SAFE · REVIEWEDCODING

🛡⚔️AI-Powered Penetration Testing Framework with automated vulnerability scanning, multi-agent system, and compliance reporting🛡⚔️

$ npx skills add SHAdd0WTAka/Zen-Ai-Pentest
403 stars52 quality78 trustReviewed1mo since pushSafe to try
QualitySolid option that is likely worth shortlisting for production workflows.
TrustGood trust signals with a few areas worth checking before rollout.Review: Quality score needs review
Safety gateGood audit and safety signals with no high-risk permission hints in public metadata.

Scenario Testing and QA

CLI + Codex · 4 targets

pythonsecurity
by SHAdd0WTAkaDetailsQuick view

Page 1

Showing the strongest 16 results to keep the registry fast for humans and agents. Refine by use case, platform, stars, or search query for a narrower shortlist.

Try the agent resolve API