SKILL.md packages that extend Claude Code, Cursor, Copilot, and other AI agents.
Tags

terrashark
Diagnose and fix Terraform/OpenTofu failure modes (identity churn, secret exposure, blast radius, CI drift, compliance gaps) and generate risk-controlled remedi

opentelemetry-skill
Expert OpenTelemetry observability skill for designing collectors, pipelines, sampling, cardinality management, security, and production-ready deployment patter

openclaw-master-skills
Pre-execution safety protocol that detects and blocks dangerous shell commands and sensitive file reads, and guides the agent through safe alternatives.

springboot-skills-marketplace
Run focused, evidence-based code reviews for Java 25 and Spring Boot 4 projects — migration risks, architecture boundaries, null-safety (JSpecify), security, an

code-audit
Perform professional code security audits across 9 languages with configurable quick/standard/deep modes and Docker-backed verification.

agent-skills
Infrastructure provisioning agent: designs Terraform/OpenTofu/Pulumi IaC, local dev stacks (Docker Compose), state strategy, and security/cost best practices fo

solanaos
Opinionated end-to-end Solana development playbook for dApp UI, wallet integration, Anchor/Pinocchio programs, testing, and safety-first transaction workflows.

code-mode-skill
Add a sandboxed code mode tool to an MCP server so LLMs run small processing scripts against large API responses and only the script output enters the model con

skills
Securely operate the 1Password CLI for agent workflows: prefer secret references, least-privilege service accounts, and avoid exposing secrets in transcripts.

claude-skill-registry
Expert guidance for writing, testing, and auditing Aiken smart contracts for Cardano, including validator patterns, testing practices, and off-chain MeshJS inte

Anthropic Cybersecurity Skills
Techniques and checks to find and exploit common JWT misconfigurations (alg none, alg confusion, kid/JKU injection, weak secrets).

claude-skills
Provides risk-based security strategy and compliance roadmaps (SOC 2, ISO 27001, HIPAA, GDPR), incident response playbooks, and vendor risk assessments for grow

claude-code-handbook
Guidelines and patterns for building robust REST APIs: correct HTTP status codes, RFC 7807 error responses, validation, sanitization, rate limiting, and central

claude-bughunter
A five-phase bug-hunting workflow and critical-thinking playbook that orients security hunting sessions, maps steps from recon to report, and enforces quality g

safe-solana-builder
Scaffold and produce production‑grade Solana programs (Native Rust or Anchor) with built‑in security checks, test skeletons, and a comprehensive audit checklist

specialist-agent
Performs adversarial stress-testing of code to find edge cases, race conditions, security holes, and logical flaws before deployment.

codex-spellbook
Practical containerization guidance: multi-stage builds, non-root runtime, layer caching, dockerignore hygiene, healthchecks, and secure secret handling.

agentic-commerce-skills-plugins
Guides implementation of Medusa v2 payment module and provider integrations (Stripe, PayPal): sessions, authorization/capture/refund lifecycle, webhooks, and be

skills
Configure and optimize mewt/muton mutation-testing campaigns: scope targets, tune timeouts, and prepare long-running runs for reliable results.

claude-skill-registry
Security review and best-practice guidance for web apps and agentic AI systems covering OWASP Top 10:2025, ASVS 5.0, and agent security patterns.

TerminalSkills Library
Perform structured, prioritized code reviews that find correctness, security, performance, reliability, and testing issues and provide concrete fix suggestions.

gsd-skill-creator
Autonomously triage GitHub issues, submit fixes as PRs, and perform adversarial PR reviews to find security and quality problems.

cc-skills
Rewrite and restructure skill files to fix snyk-agent-scan alerts (W001/W011/W012) without suppressing information; for authors and reviewers in CI or local sca

mcp-security
Expert, tool-aware guidance for proactive threat hunting: formulate SIEM/UDM queries, iterate searches, enrich findings, and produce case or report outputs.

power-platform-skills
Run a server-side security scan of a deployed Power Pages site and produce a plain-language summary of findings and follow-ups.

ai-factory
Set up agent project context: analyze tech stack, install or generate skills, and configure MCP servers with mandatory security scanning for external skills.

solana-vibes-kit
Phase-based adversarial security audit pipeline for Solana/Anchor codebases: scan, analyze, strategize, investigate, and report with parallel auditors and a str

claude-plugins
Provides expert guidance for modern Rust systems programming: cargo workflows, ownership, async/concurrency (Tokio), testing, profiling, and tooling best practi

claude-code-plugins-plus-skills
Practical security best-practices for integrating with the Apollo.io API: safe key storage, PII redaction, minimal permissions, rotation, and automated audit ch

gsd-skill-creator
Security hygiene guidelines for self-modifying agent systems: path sanitization, safe YAML handling, data poisoning checks, and staging/quarantine practices to