مهارات الوكلاء
مهارات لـ Claude Code وCodex وCursor ووكلاء آخرين من دليل skills.sh: عدد التثبيتات، وحالة التدقيق الأمني، والأمر لإضافة المهارة.
المهارة غير مرتبطة بوكيل واحد: يثبّتها الأمر npx skills add في أي وكيل مدعوم. بدون -a تكتشف الأداة الوكلاء المثبّتين على جهازك وتسألك أين تضيفها.
تاريخ التحديث · المصادر: skills.sh
المعروض: 31 · النتائج: ٣١ · من أصل ١٠٬٠٠٠ في الدليل
-
code-review mattpocock/skills
Review the changes since a fixed point (commit, branch, tag, or merge-base) along two axes: Standards (does the code follow this repo's documented coding standards?) and Spec (does the code match what the originating issue/spec asked for?). Runs both reviews in parallel sub-agents and reports them side by side. Use when the user wants to review a branch, a PR, work-in-progress changes, or asks to "review since X".
٦٦٩٬٣٧٦ فاشل -
security-review getsentry/skills
Security code review for vulnerabilities. Use when asked to "security review", "find vulnerabilities", "check for security issues", "audit security", "OWASP review", or review code for injection, XSS, authentication, authorization, cryptography issues. Provides systematic review with confidence-based reporting.
١٨٬٩٢٤ فاشل -
azure-devops-cli github/awesome-copilot
Manage Azure DevOps resources via CLI including projects, repos, pipelines, builds, pull requests, work items, artifacts, and service endpoints. Use when working with Azure DevOps, az commands, devops automation, CI/CD, or when user mentions Azure DevOps CLI.
١٤٬٠٦٨ فاشل -
marimo-pair marimo-team/marimo-pair
Drive a live marimo notebook as a workspace: run Python in the same kernel the user does, inspect live notebook state, and commit durable notebook changes. Use when the user wants to start a marimo notebook or pair on an active marimo session.
١١٬٤٣٥ فاشل -
github-actions callstackincubator/agent-skills
GitHub Actions workflow patterns for React Native iOS simulator and Android emulator cloud builds with downloadable artifacts. Use when setting up CI build pipelines or downloading GitHub Actions artifacts via gh CLI and GitHub API.
٩٬٦٨٩ فاشل -
copilot-instructions-blueprint-generator github/awesome-copilot
Technology-agnostic blueprint generator for creating comprehensive copilot-instructions.md files that guide GitHub Copilot to produce code consistent with project standards, architecture patterns, and exact technology versions by analyzing existing codebase patterns and avoiding assumptions.
٨٬٩٢٨ فاشل -
suggest-awesome-github-copilot-instructions github/awesome-copilot
Suggest relevant GitHub Copilot instruction files from the awesome-copilot repository based on current repository context and chat history, avoiding duplicates with existing instructions in this repository, and identifying outdated instructions that need updates.
٨٬٧٥٢ فاشل -
ci-cd-security superagent-ai/skills
Scan GitHub Actions workflow files for security vulnerabilities by reading the YAML and reporting findings directly — no external tools, no installation, no shell execution. Use this skill whenever the user shares a `.github/workflows/` file, pastes workflow YAML, asks for a CI/CD security review, mentions `pull_request_target`, `workflow_run`, action pinning, `GITHUB_TOKEN` permissions, pwn requests, template injection, cache poisoning, secret exfiltration, supply chain risk, or any GitHub Actions hardening topic. Also trigger when the user is hardening an OSS repo, doing a CI/CD red team assessment, evaluating a target for supply-chain scanning, or writing publicly about CI/CD security. Bias toward triggering this skill rather than answering from memory — CI/CD security defaults are wrong almost everywhere and the rules are unintuitive.
٧٬٢٧٠ فاشل -
news-aggregator-skill cclank/news-aggregator-skill
Comprehensive news aggregator that fetches, filters, and deeply analyzes real-time content from 44+ sources including Hacker News, Lobsters, Dev.to, GitHub, arXiv, Hugging Face Papers, AIHOT, TLDR AI, Import AI, BBC, The Guardian, Al Jazeera, France 24, Reuters fallback, AI Newsletters, WallStreetCN, Weibo, 少数派, InfoQ 中文, Podcasts, and user-defined OPML feeds. Use when user requests 'daily scans', 'tech news', 'finance updates', 'AI briefings', 'international news', 'deep analysis', or says '如意如意' to open the interactive menu.
٥٬٩٢٤ فاشل -
worktrunk max-sixty/worktrunk
Guidance for Worktrunk (the `wt` CLI) — git worktree management, hooks, and config. Load when working out which worktree a `wt` command will act on, or reaching for the global `-C <path>` to target one; editing .config/wt.toml or ~/.config/worktrunk/config.toml; adding, modifying, or debugging hooks (post-merge, post-start, pre-commit, pre-merge, post-switch, etc.); configuring commit message generation or command aliases; or troubleshooting wt behavior. Also answers general worktrunk/wt questions.
٥٬٠٣١ فاشل -
gha-security-review getsentry/skills
GitHub Actions security review for workflow exploitation vulnerabilities. Use when asked to "review GitHub Actions", "audit workflows", "check CI security", "GHA security", "workflow security review", or review .github/workflows/ for pwn requests, expression injection, credential theft, and supply chain attacks. Exploitation-focused with concrete PoC scenarios.
٤٬٥٤٤ فاشل -
composio starchild-ai-agent/official-skills
Composio gateway: act on 1000+ connected apps like Gmail, Slack, GitHub, Calendar. Use when the user wants to act in a connected SaaS app (e.g. send Gmail, create Notion page, add Calendar event, open a GitHub issue).
٤٬٣١٩ فاشل -
gemini softaworks/agent-toolkit
Use when the user asks to run Gemini CLI for code review, plan review, or big context (>200k) processing. Ideal for comprehensive analysis requiring large context windows. Uses Gemini 3 Pro by default for state-of-the-art reasoning and coding.
٣٬٩٢٨ فاشل -
security-ownership-map openai/skills
Analyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensitive-code ownership, and export CSV/JSON for graph databases and visualization. Trigger only when the user explicitly wants a security-oriented ownership or bus-factor analysis grounded in git history (for example: orphaned sensitive code, security maintainers, CODEOWNERS reality checks for risk, sensitive hotspots, or ownership clusters). Do not trigger for general maintainer lists or non-security ownership questions.
٣٬٥٥٣ فاشل -
git-fork-clone zc277584121/mygitplugin
Fork a GitHub repo and clone it locally with proper remote setup
٣٬٢١١ فاشل -
nuget-trusted-publishing dotnet/skills
Set up NuGet trusted publishing (OIDC) on a GitHub Actions repo — replaces long-lived API keys with short-lived tokens. USE FOR: trusted publishing, NuGet OIDC, keyless NuGet publish, migrate from NuGet API key, NuGet/login, secure NuGet publishing. DO NOT USE FOR: publishing to private feeds or Azure Artifacts (OIDC is nuget.org only). INVOKES: shell (powershell or bash), edit, create, ask_user for guided repo setup.
٢٬٤٨٠ فاشل -
fusion-github-review-resolution equinor/fusion-skills
Resolves unresolved GitHub PR review threads end-to-end: evaluates whether each review comment is correct, applies a targeted fix when valid, replies with rationale when not, commits, and resolves the thread. USE FOR: unresolved review threads, PR review feedback, changes requested PRs, PR review URLs (#pullrequestreview-...), fix the review comments, close the open threads, address PR feedback. DO NOT USE FOR: summarizing feedback without code changes, creating new PRs, or read-only branches.
٢٬٣٦٣ فاشل -
sentry-pr-code-review getsentry/sentry-for-ai
٢٬٢٦٣ فاشل -
difit yoshiko-pg/difit
Ask the user for a code review by opening the changes in difit, a local diff viewer. Explicit opt-in only — use when the user names difit, asks to open or show the diff in the viewer, or has a standing instruction to request reviews through difit after changes. Do not use it for ordinary requests to review code, diffs, commits, branches, or pull requests.
٢٬١٠٩ فاشل -
code-review paulrberg/agent-skills
٢٬٠١٣ فاشل -
issue-fields-migration github/awesome-copilot
Bulk-migrate metadata to GitHub issue fields from two sources: repo labels (e.g. priority labels to a Priority field) and Project V2 fields. Use when users say "migrate my labels to issue fields", "migrate project fields to issue fields", "convert labels to issue fields", "copy project field values to issue fields", or ask about adopting issue fields. Issue fields are org-level typed metadata (single select, text, number, date) that replace label-based workarounds with structured, searchable, cross-repo fields.
١٬٨٨٢ فاشل -
publish-to-pages github/awesome-copilot
Publish presentations and web content to GitHub Pages. Converts PPTX, PDF, HTML, or Google Slides to a live GitHub Pages URL. Handles repo creation, file conversion, Pages enablement, and returns the live URL. Use when the user wants to publish, deploy, or share a presentation or HTML file via GitHub Pages.
١٬٨٣٣ فاشل -
nodejs-core mcollina/skills
Contributes to and debugs Node.js core, including nodejs/node commit and PR tone, contribution workflows, native crashes, V8 performance, node-gyp builds, N-API bindings, and libuv issues. Use when drafting or reviewing a Node.js core commit or pull request, working in nodejs/node, or diagnosing C++ addons, binding.gyp failures, segfaults, native leaks, V8 deoptimizations, and event-loop internals.
١٬٨١٢ فاشل -
gitlab-cli-skills vince-winkintel/gitlab-cli-skills
Comprehensive GitLab CLI (glab) command reference and workflows for all GitLab operations via terminal. Use when user mentions GitLab CLI, glab commands, GitLab automation, MR/issue management via CLI, CI/CD pipeline commands, Artifact Registry token exchange, repo operations, authentication setup, or any GitLab terminal operations. Routes to specialized sub-skills for auth, CI, MRs, issues, releases, repos, and 30+ other glab commands. Triggers on glab, GitLab CLI, GitLab commands, GitLab terminal, GitLab automation.
١٬٧٨٠ فاشل -
gstack-workflow-assistant reason-machines/trending-skills
Team of specialist AI workflows for Claude Code with CEO review, engineering planning, code review, shipping, QA testing, and browser automation
١٬٦٣٩ فاشل -
ctx-upgrade mksglu/context-mode
Update context-mode from GitHub and fix hooks/settings. Pulls latest, builds, installs, updates npm global, configures hooks. Trigger: /context-mode:ctx-upgrade
١٬٤٣٢ فاشل -
speckit-taskstoissues dceoy/speckit-agent-skills
Convert existing tasks into actionable, dependency-ordered GitHub issues for the feature based on available design artifacts.
١٬٤٣١ فاشل -
code-review alinaqi/maggy
Mandatory code reviews via /code-review before commits and deploys
١٬٣٨٦ فاشل -
adversarial-review poteto/noodle
Adversarial code review using cross-model approach. Spawns reviewers on the opposing model (Claude uses Codex, Codex uses Claude) to challenge work from distinct critical lenses. Produces a synthesized verdict with findings and lead judgment. Triggers: "adversarial review".
١٬٣٦٨ فاشل -
github-project-management ruvnet/ruflo
Comprehensive GitHub project management with swarm-coordinated issue tracking, project board automation, and sprint planning
١٬٣٦١ فاشل -
github-release jezweb/claude-skills
Prepare and publish GitHub releases. Sanitizes code for public release (secrets scan, personal artifacts, LICENSE/README validation), creates version tags, and publishes via gh CLI. Trigger with 'release', 'publish', 'open source', 'prepare for release', 'create release', or 'github release'.
١٬٢٨٦ فاشل
الأوصاف من كتابة المؤلفين أنفسهم وباللغة الإنجليزية. اقرأ شيفرة المهارة في مستودعها قبل تثبيتها.
ما هي مهارات الوكلاء؟
المهارة مجلد فيه ملف SKILL.md وسكربتات اختيارية، يحمله الوكيل عندما تتطابق المهمة مع وصف المهارة. مهارة لكتابة الاختبارات مثلا تعطي الوكيل تعليمات وأدوات جاهزة بدلا من أن تشرحها له في كل مرة. هذه الصفحة تعرض مهارات من دليل skills.sh لوكلاء مثل Claude Code وCodex وCursor وغيرها.
ماذا تعرض كل بطاقة؟
- اسم المهارة والمؤلف والمستودع.
- عدد التثبيتات وفق skills.sh.
- حالة «التدقيق الأمني»: «ناجح»، أو «تحذيرات»، أو «فاشل»، أو «غير مدقَّق».
- أمر إضافة المهارة مع زر «نسخ الأمر».
ما حجم الدليل هنا؟
نعرض أعلى 10,000 مهارة حسب التثبيتات، مع مزامنة يومية. تبويب «الرائجة» يرتب حسب التثبيتات المكتسبة خلال آخر 7 أيام. ويمكنك التصفية حسب الموضوع أو الوكيل أو البحث بالاسم، مع 100 مهارة كحد أقصى في كل عرض.
هل المهارة الناجحة في التدقيق آمنة؟
التدقيق الناجح ليس ضمانا. حالات التدقيق مأخوذة من التدقيقات التي ينشرها skills.sh، والمهارة قد تحتوي سكربتات يشغلها الوكيل على جهازك. اقرأ شيفرة المهارة في مستودعها على GitHub قبل تثبيتها، خاصة إن كانت تنفذ أوامر أو تتصل بالإنترنت.
كيف أقرأ عدد التثبيتات؟
العدد الكبير يعني أن المهارة مستخدمة على نطاق واسع، لا أنها مناسبة لمشروعك أو خالية من المشكلات. أما «الرائجة» فتكشف المهارات الجديدة التي تكتسب اهتماما بسرعة، وقد تكون مفيدة لكنها لم تختبر طويلا بعد. استخدم التصفية حسب الوكيل الذي تعمل به حتى لا تثبت مهارة لا يدعمها.
لماذا الأوصاف بالإنجليزية؟
الأوصاف كتبها المؤلفون أنفسهم بالإنجليزية، ونعرضها كما هي دون ترجمة حتى لا يتغير معناها. عدد التثبيتات أيضا من حساب skills.sh، لا من حسابنا.
كيف أبدأ؟
ابحث عن مهمة تكررها كثيرا مع وكيلك، وابحث عن مهارة لها، واقرأ الشيفرة، ثم انسخ الأمر ونفذه في مشروعك. وللاطلاع على الوكلاء أنفسهم راجع صفحة وكلاء البرمجة.