SkillsAdd

Install skills for AI.
Extend your AI agent.

A local directory of open agent skills — ranked, searchable, and one command away.

Catalog324,895
Summaries320,711
With docs109,090
Ranked9,730

Topics

All topics
#
Skill
Source
8W Activity
Installs
4451
subdomain-takeover >- Subdomain takeover detection and exploitation playbook. Use when targets have dangling CNAME/NS/MX records pointin…
yaklang/hack-skills
2.9K
4452
csv-formula-injection >- CSV/spreadsheet formula injection (DDE, Excel/LibreOffice, Google Sheets IMPORT*). Use when exports, imports, or u…
yaklang/hack-skills
2.9K
4453
jndi-injection >- JNDI injection playbook. Use when Java applications perform JNDI lookups with attacker-controlled names, especiall…
yaklang/hack-skills
2.9K
4455
creative-director AI creative director with recursive self-assessment: 20+ methodologies (SIT, TRIZ, Bisociation, SCAMPER, Synectics), …
nexu-io/open-design
2.9K
4456
clickjacking >- Clickjacking playbook. Use when testing whether target pages can be framed, whether X-Frame-Options or CSP frame-a…
yaklang/hack-skills
2.9K
4457
active-directory-acl-abuse >- Active Directory ACL abuse playbook. Use when exploiting misconfigured AD permissions including GenericAll, WriteD…
yaklang/hack-skills
2.9K
4460
ads-test Design and evaluate paid-ad experiments with hypotheses, randomization units, sample-size and duration assumptions, g…
agricidaniel/claude-ads
2.9K
4462
saml-sso-assertion-attacks >- SAML SSO assertion attack playbook. Use when testing signature validation, assertion wrapping, audience restrictio…
yaklang/hack-skills
2.9K
4463
active-directory-kerberos-attacks >- Kerberos attack playbook for Active Directory. Use when targeting AD authentication via AS-REP roasting, Kerberoas…
yaklang/hack-skills
2.9K
4464
lesson-learned Analyze recent code changes via git history and extract software engineering lessons.
softaworks/agent-toolkit
2.9K
4465
skill-scanner Official Scan agent skills for security issues. Use when asked to "scan a skill", "audit a skill", "review skill security", "c…
getsentry/skills
2.9K
4466
hash-attack-techniques >- Hash attack playbook. Use when exploiting length extension, MD5/SHA1 collisions, HMAC timing leaks, birthday attac…
yaklang/hack-skills
2.9K
4467
active-directory-certificate-services >- AD Certificate Services attack playbook. Use when targeting misconfigured AD CS for privilege escalation via ESC1-…
yaklang/hack-skills
2.9K
4468
ce-ideate Generate and evaluate grounded ideas. Use when the user wants ideas, improvements, or surprising directions before ch…
everyinc/compound-engineering-plugin
2.9K
4469
google-drive Google Drive integration. Manage Drives, Users, Permissions. Use when the user wants to interact with Google Drive da…
membranedev/application-skills
2.9K
4470
http2-specific-attacks >- HTTP/2 protocol-specific attack playbook. Use when the target supports HTTP/2 and you need to exploit binary frami…
yaklang/hack-skills
2.9K
4471
arbitrary-write-to-rce >- Arbitrary write to RCE playbook. Use when you have an arbitrary write primitive (from heap exploitation, format st…
yaklang/hack-skills
2.9K
4472
competitive-report-structure >- Use after benchmark-methodology has produced scored competitor profile cards. Assembles findings into a decision-g…
affaan-m/ecc
2.9K
4475
dbs-install-skill 将单个 Skill 或 Skill 集合安?
dontbesilent2025/dbskill
2.9K
4477
linux-privilege-escalation >- Linux privilege escalation playbook. Use when you have low-privilege shell access and need to escalate to root via…
yaklang/hack-skills
2.9K
4478
ai-ml-security >- AI/ML security playbook. Use when assessing model supply chain attacks (pickle RCE, poisoned weights), adversarial…
yaklang/hack-skills
2.9K
4479
prototype-pollution >- Prototype pollution testing for JavaScript stacks. Use when user input is merged into objects (query parsers, JSON…
yaklang/hack-skills
2.9K
4480
defi-attack-patterns >- DeFi attack pattern playbook. Use when analyzing flash loan attacks, price oracle manipulation, MEV sandwich attac…
yaklang/hack-skills
2.9K
4481
ce-commit Create a git commit with a clear, value-communicating message. Use when the user asks to commit/save staged or unstag…
everyinc/compound-engineering-plugin
2.9K
4482
windows-av-evasion >- AV/EDR evasion playbook for Windows. Use when bypassing AMSI, ETW, .NET assembly detection, shellcode execution, p…
yaklang/hack-skills
2.9K
4483
dangling-markup-injection >- Dangling markup injection playbook. Use when HTML injection is possible but JavaScript execution is blocked (CSP, …
yaklang/hack-skills
2.9K
4484
network-protocol-attacks >- Network protocol attack playbook. Use when exploiting layer 2/3 protocols including ARP spoofing, LLMNR/NBT-NS/mDN…
yaklang/hack-skills
2.9K
4486
dns-rebinding-attacks >- DNS rebinding attack playbook. Use when testing applications that trust DNS resolution for origin checks, interact…
yaklang/hack-skills
2.9K
4489
longbridge-fundamentals Financial statements, business segments, dividends, valuation multiples (PE/PB/PS), industry comparison, operating da…
longbridge/skills
2.9K
4490
ce-commit-push-pr Commit, push, and open a PR. Use when asked to ship/open a PR, or for PR-description-only flows like writing, rewriti…
everyinc/compound-engineering-plugin
2.9K
4491
xslt-injection >- XSLT injection testing: processor fingerprinting, XXE and document() SSRF, EXSLT write primitives, PHP/Java/.NET e…
yaklang/hack-skills
2.9K
4492
ce-compound-refresh Refresh the repo's captured learnings against the current codebase. Use when auditing stale, overlapping, superseded,…
everyinc/compound-engineering-plugin
2.9K
4493
threejs Three.js skills for creating 3D elements and interactive experiences in the browser — scenes, materials, controls, an…
nexu-io/open-design
2.9K
4494
linux-lateral-movement >- Linux lateral movement playbook. Use after gaining initial access to pivot across Linux hosts via SSH hijacking, c…
yaklang/hack-skills
2.9K
4495
danawa-price-search 다나와 공개 검색/가격비교 표면으로 상품 후보를 찾고, 쇼핑몰별 최저가·배송비 포함 실구매가·카드 할인가·무이자 할부 정…
nomadamas/k-skill
2.9K
4497
type-juggling >- PHP type juggling and weak comparison (`==`) bypass. Use when authentication, HMAC/signature checks, or token vali…
yaklang/hack-skills
2.9K
4498
smux Control tmux panes and communicate between AI agents.
shawnpana/smux
2.9K
4500
loopy Discover, find, compare, audit, repair, adapt, craft, run, debrief, save, and prepare repeatable AI-agent loops for p…
forward-future/loopy
2.9K
4501
container-escape-techniques >- Container escape playbook. Use when operating inside a Docker container, LXC, or Kubernetes pod and need to escape…
yaklang/hack-skills
2.9K
4503
email-header-injection >- Email header injection and spoofing playbook. Use when testing contact forms, email APIs, password reset flows, or…
yaklang/hack-skills
2.9K
4505
longbridge-value-investing Value investing analysis using Graham (NCAV/net-net/defensive-investor) and Buffett (economic moat/ROE/FCF) methodolo…
longbridge/skills
2.9K
4506
windows-privilege-escalation >- Windows local privilege escalation playbook. Use when you have low-privilege shell access on Windows and need to e…
yaklang/hack-skills
2.9K
4507
memory-forensics-volatility >- Memory forensics playbook using Volatility 2/3. Use when analyzing memory dumps for malware analysis, credential e…
yaklang/hack-skills
2.9K
4508
m07-concurrency CRITICAL: Use for concurrency/async. Triggers: E0277 Send Sync, cannot be sent between threads, thread, spawn, channe…
actionbook/rust-skills
2.9K
4509
classical-cipher-analysis >- Classical cipher analysis playbook. Use when encountering substitution ciphers, Vigenere, transposition, XOR, or e…
yaklang/hack-skills
2.9K
4510
cc-use 把较长的编码、排查、测试或交互式 CLI 工作交给 tmux 中的? 由当前外层 Agent 负责拆解任务、读取稳定屏幕快? 任务结束后销…
zc277584121/cc-use
2.9K
4512
ui-ux-designer Create interface designs, wireframes, and design systems. Masters user research, accessibility standards, and modern …
sickn33/agentic-awesome-skills
2.9K
4513
tunneling-and-pivoting >- Tunneling and pivoting playbook. Use when establishing network tunnels through compromised hosts including SSH tun…
yaklang/hack-skills
2.9K
4515
nx-run-tasks Helps with running tasks in an Nx workspace. USE WHEN the user wants to execute build, test, lint, serve, or run any …
nrwl/nx-ai-agents-config
2.9K
4518
linux-security-bypass >- Linux security mechanism bypass playbook. Use when facing restricted bash/rbash, read-only or noexec filesystems, …
yaklang/hack-skills
2.9K
Page 60 · 6,026 ranked Previous Next