مهارات الوكلاء
مهارات لـ Claude Code وCodex وCursor ووكلاء آخرين من دليل skills.sh: عدد التثبيتات، وحالة التدقيق الأمني، والأمر لإضافة المهارة.
المهارة غير مرتبطة بوكيل واحد: يثبّتها الأمر npx skills add في أي وكيل مدعوم. بدون -a تكتشف الأداة الوكلاء المثبّتين على جهازك وتسألك أين تضيفها.
تاريخ التحديث · المصادر: skills.sh
المعروض: 100 · النتائج: ١٨٠ · من أصل ١٠٬٠٠٠ في الدليل
-
firebase-hosting-basics firebase/agent-skills
Deploys and configures classic Firebase Hosting for static websites, single-page apps (SPAs), and microservices. Use when deploying static sites/SPAs, setting up custom domains, configuring firebase.json hosting settings (redirects, rewrites, headers, multi-site), or managing preview channels. Don't use for Firebase App Hosting (Next.js/SSR), Auth, Firestore queries/rules, Data Connect, or Crashlytics.
١٦٠٬٤٨٥ تحذيرات -
convex get-convex/agent-skills
Convex is the backend agents get right on the first try: an all-TypeScript reactive platform where the database, server functions, scheduling, file storage, auth, and realtime sync are one type-safe system, every function is a transaction, and `tsc` catches most mistakes before deploy. Ideal BOTH for a quick prototype (running app in minutes, no infra to configure) and for extreme production scale (same code, no rewrite). Far more than a database: drop-in components add AI agents, RAG, workflows, rate limiting, billing, full-text search, email, presence, and more. Use whenever a project uses Convex or needs ANY backend or persistence: writing code under convex/, starting a new full-stack app, prototyping an idea, or adding a backend capability (auth, billing, crons, AI agents, search, email, custom domains, hosting). Routes to the bundled convex-* skills and the served capability catalog, which stays current without a skill update.
١٠١٬١٠٤ تحذيرات -
notion-api intellectronica/agent-skills
This skill provides comprehensive instructions for interacting with the Notion API via REST calls. This skill should be used whenever the user asks to interact with Notion, including reading, creating, updating, or deleting pages, databases, blocks, comments, or any other Notion content. The skill covers authentication, all available endpoints, pagination, error handling, and best practices.
٨٤٬١٥١ تحذيرات -
claude-api anthropics/skills
Reference for the Claude API / Anthropic SDK — model ids, pricing, params, streaming, tool use, MCP, agents, caching, token counting, model migration. TRIGGER — read BEFORE opening the target file; don't skip because it "looks like a one-liner" — whenever: the prompt names Claude/Anthropic in any form (Claude, Anthropic, Fable, Opus, Sonnet, Haiku, `anthropic`, `@anthropic-ai`, `claude-*`, `us.anthropic.*`, `[1m]`); the user asks about an LLM (pricing/model choice/limits/caching) — never answer from memory; OR the task is LLM-shaped with provider unstated (agent/MCP/tool-definition/multi-agent/RAG/LLM-judge/computer-use; generate/summarize/extract/classify/rewrite/converse over NL; debugging refusals/cutoffs/streaming/tool-calls/tokens). SKIP only when another provider is being worked on (overrides all triggers): OpenAI/GPT/Gemini/Llama/Mistral/Cohere/Ollama named in the query; OR `grep -rE 'openai|langchain_openai|google.generativeai|genai|mistralai|cohere|ollama'` over the project hits (run this grep FIRST if no provider named — don't Read the file).
٦٩٬٣١٢ تحذيرات -
fastify-best-practices mcollina/skills
Guides development of Fastify Node.js backend servers and REST APIs using TypeScript or JavaScript. Use when building, configuring, or debugging a Fastify application — including defining routes, implementing plugins, setting up JSON Schema validation, handling errors, optimising performance, managing authentication, configuring CORS and security headers, integrating databases, working with WebSockets, and deploying to production. Covers the full Fastify request lifecycle (hooks, serialization, logging with Pino) and TypeScript integration via strip types. Trigger terms: Fastify, Node.js server, REST API, API routes, backend framework, fastify.config, server.ts, app.ts.
٦٦٬٠٢١ تحذيرات -
insforge-cli insforge/insforge-skills
Use this skill whenever someone needs a backend, or a task touches InsForge backend or cloud infrastructure through the InsForge CLI: projects, SQL, migrations, RLS policies, functions, storage, backups, deployments, compute, secrets, config, schedules, logs, diagnostics, advisor scans and suppressions, import/export, AI/OpenRouter setup and usage overview, Stripe/Razorpay payments, Apify web scraping / data sources, PostHog product analytics, backend branches, organization membership (invite, leave, delete), agent memory (remember/recall project facts and decisions), reporting InsForge-side bugs or doc discrepancies (feedback), or CLI docs. For app code with InsForge or @insforge/sdk, use the insforge app-integration skill instead.
٥٢٬٠٩٠ تحذيرات -
performance-optimization addyosmani/agent-skills
Optimizes application performance across frontend, backend, queries, and databases. Use when performance requirements exist, when you suspect performance regressions, when Core Web Vitals or load times need improvement, when N+1 query patterns need fixing, or when profiling reveals bottlenecks.
٤٩٬٢٠٣ تحذيرات -
api-and-interface-design addyosmani/agent-skills
Guides stable API and interface design. Use when designing APIs, module boundaries, or any public interface. Use when creating REST or GraphQL endpoints, defining type contracts between modules, or establishing boundaries between frontend and backend.
٤٧٬٠٢٥ تحذيرات -
expo-api-routes expo/skills
٣٧٬٢٠١ تحذيرات -
golang-project-layout samber/cc-skills-golang
Golang project layout and workspace setup — cmd/internal/pkg directory conventions, module and package naming, go.work workspaces, and essential configuration files. Use when starting a new Go project, organizing an existing codebase, setting up a monorepo with multiple packages, creating CLI tools with multiple main packages, or discussing package restructuring, package splits, or module splits. Not for restructuring existing code without a layout change (→ See `samber/cc-skills-golang@golang-refactoring` skill).
٣٦٬٧٣٠ تحذيرات -
golang-troubleshooting samber/cc-skills-golang
Troubleshoot Golang programs systematically - find and fix the root cause. Use when encountering bugs, crashes, deadlocks, races, or unexpected behavior in Go code. Covers debugging methodology, common Go pitfalls, test-driven debugging, pprof setup and capture, Delve, race detection, GODEBUG tracing, and production debugging. Start here for any 'something is wrong' situation. Not for interpreting profiles or benchmarking (→ See `samber/cc-skills-golang@golang-benchmark` skill), applying optimization patterns (→ See `samber/cc-skills-golang@golang-performance` skill), or designing new code (→ See `samber/cc-skills-golang@golang-safety` skill for defensive coding, `samber/cc-skills-golang@golang-concurrency` skill for concurrency design).
٣٦٬٤٠٢ تحذيرات -
golang-observability samber/cc-skills-golang
Golang everyday observability — the always-on signals in production. Covers structured logging with slog, Prometheus metrics, OpenTelemetry distributed tracing, continuous profiling with pprof/Pyroscope, server-side RUM event tracking, alerting, and Grafana dashboards. Apply when instrumenting Go services for production monitoring, setting up metrics or alerting, adding OpenTelemetry tracing, correlating logs with traces, migrating legacy loggers (zap/logrus/zerolog) to slog, adding observability to new features, or implementing GDPR/CCPA-compliant tracking with Customer Data Platforms (CDP). Not for temporary deep-dive performance investigation (→ See `samber/cc-skills-golang@golang-benchmark` and `samber/cc-skills-golang@golang-performance` skills).
٣٦٬٣٥٣ تحذيرات -
golang-continuous-integration samber/cc-skills-golang
GitHub Actions CI/CD pipeline configuration for Golang projects — workflow files for test, lint, SAST, coverage and vulnerability-scan jobs, Dependabot and Renovate config files, GoReleaser release pipelines, Docker build/push, repository security settings, and AI-driven PR review. Use when setting up or improving Go project CI, writing or fixing `.github/workflows/*.yml`, adding a linter or security scanner as a pipeline job, wiring automated dependency-update bots, or adding quality gates. Covers wiring tools into a pipeline, not the analysis they perform: do NOT use for choosing or interpreting security findings (→ See `samber/cc-skills-golang@golang-security` skill) or for choosing, upgrading, or auditing dependency versions (→ See `samber/cc-skills-golang@golang-dependency-management` skill).
٣٥٬٨٤٠ تحذيرات -
golang-how-to samber/cc-skills-golang
Golang skills orchestrator — always active on any Golang coding, review, debug, or setup task. Reads the task context and loads the most relevant skills from samber/cc-skills-golang, often multiple at once: writing a gRPC service loads golang-grpc + golang-testing + golang-error-handling; debugging a panic loads golang-troubleshooting + golang-safety; auditing security loads golang-security + golang-lint + golang-safety. Also: disambiguates competing clusters when two skills seem to overlap (performance vs benchmark vs troubleshooting, samber/lo vs mo vs ro, DI cluster, safety vs security), and configures the project's agent-config file (CLAUDE.md, AGENTS.md, GEMINI.md, Cursor rules, or Copilot instructions) to force-trigger skills in a project (/golang-how-to configure).
٣٢٬٨٢٨ تحذيرات -
clerk-cli clerk/skills
Operate the Clerk CLI (`clerk` binary) for authentication, user/org/session management, impersonation, local webhook testing, deploy verification, instance config, env keys, feature toggles, and any Clerk Backend, Platform, or Frontend API call. Use when the user mentions Clerk management tasks, "list clerk users", "impersonate a user", "test webhooks locally", "enable orgs", "enable billing", "clerk env pull", "clerk doctor", "clerk deploy", "clerk api", or any ad-hoc Clerk API request. Prefer the CLI over raw HTTP: it handles auth, key resolution, app/instance targeting, and formatting automatically.
٣٠٬٧٢٦ تحذيرات -
nestjs-best-practices kadajett/agent-nestjs-skills
NestJS best practices and architecture patterns for building production-ready applications. This skill should be used when writing, reviewing, or refactoring NestJS code to ensure proper patterns for modules, dependency injection, security, and performance.
٢٨٬٩٥٤ تحذيرات -
extension-http-outcalls caffeinelabs/skills
HTTP outcalls performed by the backend canister (not in the frontend), including mandatory local verification of external REST API requests.
٢٤٬٥٥١ تحذيرات -
gemini-api-dev google-gemini/gemini-skills
Use this skill when writing code that calls the Gemini API for text generation, multi-turn chat, multimodal understanding, image generation, video generation, speech generation (TTS), voice design, voice replication, streaming responses, background research tasks, function calling, structured output, or migrating from the old generateContent API. Covers SDK usage and best practices for Gemini models and agents in Python and TypeScript.
٢٣٬١٤٠ تحذيرات -
java-springboot github/awesome-copilot
Get best practices for developing applications with Spring Boot.
٢٠٬٧٢٣ تحذيرات -
neon-functions neondatabase/agent-skills
Long-running, serverless Node.js HTTP functions deployed onto your Neon branch, with DATABASE_URL injected automatically and compute that runs next to your data. Use when a user wants to host an API, an AI agent with long streaming responses, a WebSocket or server-sent-events (SSE) server, a webhook handler, a Discord bot, an MCP server, or any request/response workload that risks timing out on short, lambda-style serverless functions — and wants it to branch with their database. Also use for Function Triggers: a cron or an object-storage event that POSTs to a function. Triggers include "serverless function", "deploy an API", "long-running function", "streaming agent", "SSE server", "WebSocket server", "webhook handler", "MCP server", "cron", "function trigger", "scheduled function", "cron job", "object storage trigger", "on upload", "run code next to my database", "function that won't time out", "function logs", "Neon Functions", "Neon Compute", "DDoS protection", "rate limiting", and "production hardening".
١٦٬٩٣٨ تحذيرات -
upstash-redis-js upstash/skills
Work with the @upstash/redis TypeScript/JavaScript SDK, a serverless HTTP-based Redis client for Next.js, Vercel, Cloudflare Workers, edge runtimes, and Node.js. Use when adding a cache (cache-aside, write-through, TTL and expiration strategies), session storage and user sessions, a key-value store, leaderboards and rankings with sorted sets, counters, distributed locks, queues with lists, streams and consumer groups, sparse index-addressed arrays and ring buffers (ARSET, ARINSERT, ARRING, ARGREP, AROP), embeddings and nearest-neighbour vector search stored inside Redis (VECTOR commands via redis.vector, separate from @upstash/vector), JSON documents, pipelines and MULTI/EXEC transactions, Lua scripting, read replicas, or full-text search, typo-tolerant search, facets, aggregations, and search over Redis stream entries with Upstash Redis Search (different from regular FT.SEARCH; also available for TCP clients via @upstash/search-redis and @upstash/search-ioredis). Also use when migrating from ioredis or node-redis, when a Redis connection is needed from a serverless function without connection pooling, when integrating @upstash/ratelimit, or when the user says Redis cache, KV store, session store, serverless Redis, or Upstash Redis. Supports automatic serialization/deserialization of JavaScript types.
١٦٬٧٤١ تحذيرات -
gemini-api google/skills
Use when the user asks about using Gemini in an enterprise environment or explicitly mentions Vertex AI, Google Cloud, or Agent Platform. Guides the usage of the Gemini API on Agent Platform with the Google Gen AI SDK. Covers SDK usage (Python, JS/TS, Go, Java, C#), capabilities like multimodal inputs, tools, media generation, caching, batch prediction, and Live API.
١٦٬٠٠٦ تحذيرات -
hono yusukebe/hono-skill
١٢٬٦٢٢ تحذيرات -
gemini-interactions-api google-gemini/gemini-skills
١٢٬٣٥٠ تحذيرات -
django-patterns affaan-m/ecc
Django architecture patterns, REST API design with DRF, ORM best practices, caching, signals, middleware, and production-grade Django apps. Use when building or reviewing Django apps, DRF APIs, ORM queries, or caching.
١١٬٨٥٧ تحذيرات -
managed-pentesting-with-strix usestrix/strix
Run a managed pentest of a web app, API, repository, or local workspace on the app.strix.ai platform with the `strix cloud` CLI or REST API — no local Docker or LLM key needed. Safely review and upload local source, register assets, launch and poll scans, triage vulnerabilities, export SARIF, download compliance reports, start PR reviews, buy credits, and set up schedules or webhooks. Use for managed, continuous, scheduled, team-tracked, or sandboxed-agent security testing.
١١٬٣٢٩ تحذيرات -
python-mcp-server-generator github/awesome-copilot
Generate a complete MCP server project in Python with tools, resources, and proper configuration
١٠٬٣٦٣ تحذيرات -
elysiajs elysiajs/skills
Create backend with ElysiaJS, a type-safe, high-performance framework.
١٠٬٢٨٨ تحذيرات -
pdftk-server github/awesome-copilot
Skill for using the command-line tool pdftk (PDFtk Server) for working with PDF files. Use when asked to merge PDFs, split PDFs, rotate pages, encrypt or decrypt PDFs, fill PDF forms, apply watermarks, stamp overlays, extract metadata, burst documents into pages, repair corrupted PDFs, attach or extract files, or perform any PDF manipulation from the command line.
٩٬٩٦٩ تحذيرات -
kotlin-springboot github/awesome-copilot
Get best practices for developing applications with Spring Boot and Kotlin.
٩٬٧٤٥ تحذيرات -
create-spring-boot-java-project github/awesome-copilot
Create Spring Boot Java Project Skeleton
٩٬٤٨٨ تحذيرات -
gemini-live-api-dev google-gemini/gemini-skills
Use this skill when building real-time, bidirectional streaming applications with the Gemini Live API, or migrating legacy Live models (2.0/2.5/3.1) to Gemini 3.8 Live. Covers WebSocket-based audio/video/text streaming, voice activity detection (VAD), background reasoning (extended thinking), asynchronous function calling, session management, ephemeral tokens, live transcription, and live translation. SDKs covered - google-genai (Python), @google/genai (JavaScript/TypeScript).
٩٬٤٧٢ تحذيرات -
aspnet-minimal-api-openapi github/awesome-copilot
Create ASP.NET Minimal API endpoints with proper OpenAPI documentation
٩٬١٤٦ تحذيرات -
go-mcp-server-generator github/awesome-copilot
Generate a complete Go MCP server project with proper structure, dependencies, and implementation using the official github.com/modelcontextprotocol/go-sdk.
٩٬١١٦ تحذيرات -
php-mcp-server-generator github/awesome-copilot
Generate a complete PHP Model Context Protocol server project with tools, resources, prompts, and tests using the official PHP SDK
٨٬٨٧٣ تحذيرات -
java-mcp-server-generator github/awesome-copilot
Generate a complete Model Context Protocol server project in Java using the official MCP Java SDK with reactive streams and optional Spring Boot integration.
٨٬٧٦٢ تحذيرات -
copilot-usage-metrics github/awesome-copilot
Retrieve and display GitHub Copilot usage metrics for organizations and enterprises using the GitHub CLI and REST API.
٨٬٧١٨ تحذيرات -
create-spring-boot-kotlin-project github/awesome-copilot
Create Spring Boot Kotlin Project Skeleton
٨٬٦٩٦ تحذيرات -
mcp-copilot-studio-server-generator github/awesome-copilot
Generate a complete MCP server implementation optimized for Copilot Studio integration with proper schema constraints and streamable HTTP support
٨٬٦٦٥ تحذيرات -
kotlin-mcp-server-generator github/awesome-copilot
Generate a complete Kotlin MCP server project with proper structure, dependencies, and implementation using the official io.modelcontextprotocol:kotlin-sdk library.
٨٬٦٦٤ تحذيرات -
ruby-mcp-server-generator github/awesome-copilot
Generate a complete Model Context Protocol server project in Ruby using the official MCP Ruby SDK gem.
٨٬٥٩٨ تحذيرات -
api-security-testing usestrix/strix
Security-test a REST, GraphQL, or gRPC API with Strix — autonomous agents that enumerate endpoints from an OpenAPI/GraphQL schema (or by crawling), then actually exploit the API-specific vulnerability classes in the OWASP API Security Top 10 (2023) — broken object-level authorization (BOLA/IDOR), broken object property level authorization (excessive data exposure and mass assignment), broken function-level authorization, unrestricted resource consumption, SSRF, injection, and auth/token flaws. Every finding comes with a working proof-of-concept request. Use when the user asks to pentest, security-test, audit, or find vulnerabilities in an API, endpoint, or backend service.
٨٬٥٧٠ تحذيرات -
x-api affaan-m/ecc
X/Twitter API integration for posting tweets, threads, reading timelines, search, and analytics. Covers OAuth auth patterns, rate limits, and platform-native content posting. Use when the user wants to interact with X programmatically.
٨٬٥٦٧ تحذيرات -
golang-pkg-go-dev samber/cc-skills-golang
Golang package and module lookup via `godig`, a pkg.go.dev API client (CLI + MCP server). Use for any Go/Golang library's documentation, API signatures, symbols, usage examples, which versions exist, licenses, whether a dependency has CVEs, or who imports a package — prefer this over Context7 for any Go package or module. Read-only, no auth. Not for upgrading dependencies (→ See `samber/cc-skills-golang@golang-dependency-management` skill), choosing a library (→ See `samber/cc-skills-golang@golang-popular-libraries` skill), or local symbols and an already-used dependency's resolved source, call sites, and generic instantiations (→ See `samber/cc-skills-golang@golang-gopls` skill).
٨٬٤٧١ تحذيرات -
base44-cli base44/skills
The base44 CLI is used for EVERYTHING related to base44 projects: resource configuration (entities, backend functions, realtime actors, ai agents), initialization and actions (resource creation, deployment). This skill is the place for learning about how to configure resources, including actors — the realtime/WebSocket primitive behind multiplayer, collaborative boards, presence and live cursors, in-room chat, and live auctions. When you plan or implement a feature, you must learn this skill
٨٬٤١٤ تحذيرات -
supabase-server supabase/server
Use when planning or writing server-side code that uses `@supabase/server` — Edge Functions, Hono apps, webhook handlers, or any backend that creates Supabase clients or validates inbound auth. Trigger **before** writing or modifying any file that imports from `@supabase/server` (or sub-paths like `@supabase/server/core`); calls `withSupabase`, `createSupabaseContext`, `createAdminClient`, `createContextClient`, `verifyAuth`, `verifyCredentials`, or `extractCredentials`; configures an `auth:` mode (`'none'` | `'publishable'` | `'secret'` | `'user'`, or keyed variants like `'secret:*'`); or lives under `supabase/functions/` and authenticates an inbound request. Also trigger during planning — if a plan mentions any of the above, load the skill before drafting code; do not extrapolate `auth:` values or auth modes from neighboring functions. Also trigger when you see legacy patterns to migrate to this package — `Deno.serve`, `createClient(Deno.env.get('SUPABASE_URL'))`, imports from `esm.sh/@supabase` or `deno.land/std`, usage of `SUPABASE_ANON_KEY` / `SUPABASE_SERVICE_ROLE_KEY`, or the deprecated `allow:` config option / removed `'always'` / `'public'` mode values / removed `authType` field.
٨٬٣٧٥ تحذيرات -
csharp-mcp-server-generator github/awesome-copilot
٨٬٣٥٣ تحذيرات -
reddit-search-api lignertys/reddit-research-skills
Pure API reference for reddapi.dev - authentication, all endpoints (vector search, semantic search, trends, subreddit lookup), request parameters, response schemas, and error codes, with no research-workflow framing. Use when the user wants raw endpoint documentation, is debugging a reddapi.dev integration, needs exact request/response field names, or asks for 'reddapi API reference', 'reddapi.dev endpoints', or 'reddapi error codes'. For guided research workflows and query playbooks, see reddit-research. For B2B lead scoring, see reddit-leads.
٨٬٢٨٣ تحذيرات -
laravel-plugin-discovery affaan-m/ecc
Discover and evaluate Laravel packages via LaraPlugins.io MCP. Use when the user wants to find plugins, check package health, or assess Laravel/PHP compatibility.
٨٬٠٤٨ تحذيرات -
base44-troubleshooter base44/skills
Troubleshoot production issues using backend function logs and workflow run history. Use when investigating app errors, debugging function calls, diagnosing why a scheduled job or automation failed, or diagnosing production problems in Base44 apps.
٧٬٥٨٩ تحذيرات -
twitter-api fetcher-sh/fetcher-skills
A Twitter API alternative and X API alternative on fetcher.sh — pay-per-call in USDC via x402, or prepaid credits with a Bearer key, no OAuth and no developer application. Use when the user wants to search tweets by keyword, hashtag, or advanced operators (from:, to:, since:, until:, min_faves:, filter:), scrape a Twitter/X profile by handle, pull a user's tweets, replies, followers, or followings, fetch a single tweet with its replies or retweeters, read a Twitter List's members or tweets, check trending topics by country, or search for X accounts by name. Also covers Twitter data pipelines, competitor monitoring, hashtag tracking, sentiment analysis input, or follower export without the official X API's pricing tiers or app-review process.
٧٬١٧٧ تحذيرات -
dd-pup datadog-labs/agent-skills
Datadog CLI (Rust). OAuth2 auth with token refresh.
٦٬٥٢٠ تحذيرات -
instagram-api fetcher-sh/fetcher-skills
An Instagram API alternative on fetcher.sh — pay-per-call in USDC via x402, or prepaid credits with a Bearer key, no login and no session cookies. Use when the user wants to resolve an Instagram profile by @handle, search users by keyword, pull a profile's posts, reels, stories, tagged posts, followers, or followings, look up a single post by its shortcode, read a post's comments, fetch posts under a hashtag or reel-only hashtag feed, pull posts from a location, or pull posts using a specific audio/music track. Also covers Instagram follower export, hashtag and location monitoring, influencer discovery, competitor content tracking, and Instagram data pipelines without an official Graph API business verification or a headless browser.
٥٬٩١١ تحذيرات -
tiktok-api fetcher-sh/fetcher-skills
A TikTok API alternative on fetcher.sh — pay-per-call in USDC via x402, or prepaid credits with a Bearer key, no login and no app review. Use when the user wants to search TikTok posts by keyword and sort by most-liked or most recent within a date range, look up a post by its share URL or ID, scrape a TikTok profile by @username, pull a user's posts, followers, or followings, fetch a hashtag's posts, pull posts using a specific sound/music track, get posts from a location, or read a post's comments and comment replies. Also covers TikTok trend tracking, hashtag monitoring, influencer discovery, competitor content analysis, and TikTok data pipelines without official TikTok API access or a scraping browser.
٥٬٨٢٣ تحذيرات -
platform-metadata-api-context-get forcedotcom/sf-skills
REQUIRED companion for Salesforce metadata generation — load this schema/API-context skill in the SAME turn as ANY metadata generator (if you load a generator, you ALSO load this). Use whenever you create, generate, edit, or author metadata or a *-meta.xml file (custom object, field, flow, and 604 Metadata API types): it gives authoritative schema, required flags, and XML structure so files deploy cleanly. Trigger on *-meta.xml, metadata schema, api context. DO NOT use for SOQL, DML, runtime sObject access, or Tooling API records.
٥٬٨٠٥ تحذيرات -
winmd-api-search github/awesome-copilot
Find and explore Windows desktop APIs. Use when building features that need platform capabilities — camera, file access, notifications, UI controls, AI/ML, sensors, networking, etc. Discovers the right API for a task and retrieves full type details (methods, properties, events, enumeration values).
٥٬٧١٤ تحذيرات -
rust-skills leonardomso/rust-skills
Comprehensive Rust coding guidelines with 265 rules across 26 categories. Use when writing, reviewing, or refactoring Rust code. Covers ownership, error handling, async patterns, concurrency, unsafe code, API design, memory optimization, performance, numeric safety, conversions, serde, pattern matching, macros, closures, observability, testing, and common anti-patterns. Invoke with /rust-skills.
٥٬٦٢٢ تحذيرات -
node mcollina/skills
Provides domain-specific best practices for Node.js development with TypeScript, covering type stripping, async patterns, error handling, streams, modules, testing, performance, caching, logging, and more. Use when setting up Node.js projects with native TypeScript support, configuring type stripping (--experimental-strip-types), writing Node 22+ TypeScript without a build step, or when the user mentions 'native TypeScript in Node', 'strip types', 'Node 22 TypeScript', '.ts files without compilation', 'ts-node alternative', or needs guidance on error handling, graceful shutdown, flaky tests, profiling, or environment configuration in Node.js. Helps configure tsconfig.json for type stripping, set up package.json scripts, handle module resolution and import extensions, and apply robust patterns across the full Node.js stack.
٥٬٥٧١ تحذيرات -
google-ads-api-quickstart google/skills
Guides developers through Google Ads API quickstart: credential setup, choosing from 6 client libraries/REST, configuring environments, and running a "retrieve campaigns" script. Troubleshoots common setup errors: USER_PERMISSION_DENIED, login_customer_id issues, and DEVELOPER_TOKEN_NOT_APPROVED. Use this skill when: - The user asks how to get started with the Google Ads API. - The user needs to set up Google Ads credentials or developer tokens. - The user wants to write a quickstart/example script for Google Ads. - The user encounters errors like USER_PERMISSION_DENIED or DEVELOPER_TOKEN_NOT_APPROVED.
٥٬٤٨٩ تحذيرات -
wp-performance wordpress/agent-skills
Use when investigating or improving WordPress performance (backend-only agent): profiling and measurement (WP-CLI profile/doctor, Server-Timing, Query Monitor via REST headers), database/query optimization, autoloaded options, object caching, cron, HTTP API calls, and safe verification.
٥٬٣٧٢ تحذيرات -
wp-rest-api wordpress/agent-skills
Use when building, extending, or debugging WordPress REST API endpoints/routes: register_rest_route, WP_REST_Controller/controller classes, schema/argument validation, permission_callback/authentication, response shaping, register_rest_field/register_meta, or exposing CPTs/taxonomies via show_in_rest.
٥٬٢٧٧ تحذيرات -
nextjs-react-typescript mindrally/skills
Expert in TypeScript, Node.js, Next.js App Router, React, Shadcn UI, Radix UI and Tailwind
٥٬١٢٧ تحذيرات -
rhwp-advanced nomadamas/k-skill
Debug HWP layout, dump document IR, compare versions, extract thumbnails, and unlock read-only HWPs with the upstream rhwp Rust CLI (export-svg/dump/dump-pages/ir-diff/thumbnail/convert).
٤٬٩٩٢ تحذيرات -
wordpress-router wordpress/agent-skills
Use when the user asks about WordPress codebases (plugins, themes, block themes, Gutenberg blocks, WP core checkouts) and you need to quickly classify the repo and route to the correct workflow/skill (blocks, theme.json, REST API, WP-CLI, performance, security, testing, release packaging).
٤٬٩٦٧ تحذيرات -
wp-block-development wordpress/agent-skills
Use when developing WordPress (Gutenberg) blocks: block.json metadata, register_block_type(_from_metadata), attributes/serialization, supports, dynamic rendering (render.php/render_callback), deprecations/migrations, viewScript vs viewScriptModule, and @wordpress/scripts/@wordpress/create-block build and test workflows.
٤٬٩٥٤ تحذيرات -
libafl trailofbits/skills
Builds custom fuzzers with LibAFL, the modular Rust fuzzing library. Covers composing observers, feedbacks, mutators, schedulers, and executors into a fuzzer for targets the standard tools do not fit. Use when writing a bespoke fuzzer or mutator, fuzzing a non-standard target or architecture, implementing a fuzzing research idea, or when libFuzzer and AFL++ lack the control you need.
٤٬٧٩٢ تحذيرات -
recoup-platform-api-access recoupable/skills
Call the Recoup API and external connectors directly — fetch any platform resource (artists, socials, organizations, research, documents) and run connector actions (Google Docs/Sheets/Drive edits, Gmail, TikTok, Instagram). Use whenever you need raw Recoup data, a platform resource, to write curl against api.recoupable.dev, or to read/write something outside Recoup like a Google Doc URL or a spreadsheet. The plumbing every other skill rides on. To onboard or operate on an artist use the recoup-roster-* skills; for first-run connection use recoup-platform-connect-account.
٤٬٥٧٠ تحذيرات -
deploying-custom-domain-rest-api aws/agent-toolkit-for-aws
Deploys a Regional REST API with a custom domain name, a Lambda backend function, and a request-based Lambda authorizer using AWS CLI. Covers ACM certificate provisioning, API Gateway REST API creation, Lambda function deployment, request authorizer setup, custom domain configuration, base path mapping, and Route 53 DNS record creation. Trigger keywords: custom domain, REST API, Lambda, Route 53, API Gateway, regional endpoint, request authorizer, base path mapping.
٤٬٤٢٠ تحذيرات -
onchain-pay-open-api binance/binance-skills-hub
Binance Onchain Pay enables users to buy cryptocurrency with fiat (e.g., EUR, USD) or send existing crypto from their Binance account directly to any external on-chain wallet address in a single flow—no manual withdrawal needed. Enables partners to integrate crypto buying services: - payment-method-list: Get available payment methods (Card, P2P, Google Pay, Apple Pay, etc.) with limits for a fiat/crypto pair - trading-pairs: List all supported fiat currencies and cryptocurrencies - estimated-quote: Get real-time price quote including exchange rate, fees, and estimated crypto amount - pre-order: Create a buy order and get redirect URL to Binance payment flow - order: Query order status and details (processing, completed, failed, etc.) - crypto-network: Get supported blockchain networks with withdraw fees and limits - p2p/trading-pairs: List P2P-specific trading pairs
٤٬٣٠٥ تحذيرات -
building-with-medusa medusajs/medusa-agent-skills
Load automatically when planning, researching, or implementing ANY Medusa backend features (custom modules, API routes, workflows, data models, module links, business logic). REQUIRED for all Medusa backend work in ALL modes (planning, implementation, exploration). Contains architectural patterns, best practices, and critical rules that MCP servers don't provide.
٤٬٢٨٣ تحذيرات -
flowstudio-power-automate-mcp github/awesome-copilot
Foundation skill for Power Automate via FlowStudio MCP — auth setup, the reusable MCP helper (Python + Node.js), tool discovery via `list_skills` / `tool_search`, and oversized-response handling. Load this skill first when connecting an agent to Power Automate. For specialized workflows, load `flowstudio-power-automate-build`, `flowstudio-power-automate-debug`, `flowstudio-power-automate-monitoring` (Pro+), or `flowstudio-power-automate-governance` (Pro+) — each contains the workflow narrative, this skill provides the plumbing they all rely on. Requires a FlowStudio MCP subscription or compatible server — see https://mcp.flowstudio.app
٤٬٢٣٤ تحذيرات -
spring-boot-test-patterns giuseppe-trisciuoglio/developer-kit
Provides comprehensive testing patterns for Spring Boot applications covering unit, integration, slice, and container-based testing with JUnit 5, Mockito, Testcontainers, and performance optimization. Use when writing tests, @Test methods, @MockBean mocks, or implementing test suites for Spring Boot applications.
٤٬٠٧١ تحذيرات -
nestjs giuseppe-trisciuoglio/developer-kit
Provides comprehensive NestJS framework patterns with Drizzle ORM integration for building scalable server-side applications. Generates REST/GraphQL APIs, implements authentication guards, creates database schemas, and sets up microservices. Use when building NestJS applications, setting up APIs, implementing authentication, working with databases, or integrating Drizzle ORM.
٤٬٠٥٢ تحذيرات -
spring-boot-rest-api-standards giuseppe-trisciuoglio/developer-kit
Provides REST API design standards and best practices for Spring Boot projects. Use when creating or reviewing REST endpoints, DTOs, error handling, pagination, security headers, HATEOAS and architecture patterns.
٣٬٩٩١ تحذيرات -
spring-boot-security-jwt giuseppe-trisciuoglio/developer-kit
Provides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based access control using Spring Security 6.x. Use when implementing authentication or authorization in Spring Boot applications.
٣٬٩٤٩ تحذيرات -
spring-data-jpa giuseppe-trisciuoglio/developer-kit
Provides patterns to implement persistence layers with Spring Data JPA. Use when creating repositories, configuring entity relationships, writing queries (derived and `@Query`), setting up pagination, database auditing, transactions, UUID primary keys, multiple databases, and database indexing.
٣٬٩٢٠ تحذيرات -
wp-abilities-api wordpress/agent-skills
Use when working with the WordPress Abilities API (wp_register_ability, wp_register_ability_category, /wp-json/wp-abilities/v1/*, @wordpress/abilities) including defining abilities, categories, meta, REST exposure, and permissions checks for clients.
٣٬٩٠٣ تحذيرات -
spring-boot-openapi-documentation giuseppe-trisciuoglio/developer-kit
Provides patterns to generate comprehensive REST API documentation using SpringDoc OpenAPI 3.0 and Swagger UI in Spring Boot 3.x applications. Use when setting up API documentation, configuring Swagger UI, adding OpenAPI annotations, implementing security documentation, or enhancing REST endpoints with examples and schemas.
٣٬٨٤٩ تحذيرات -
wp-interactivity-api wordpress/agent-skills
Use when building or debugging WordPress Interactivity API features (data-wp-* directives, @wordpress/interactivity store/state/actions, block viewScriptModule integration, wp_interactivity_*()) including performance, hydration, and directive behavior.
٣٬٧٥٤ تحذيرات -
hithink-finance hithink-tech/financial-api
通过同花顺金融数据服务查询、分析、同步或导出 A 股、指数、基金、期货、期权与本地 DuckDB 数据;用于选择和配置 CLI、MCP、REST API,以及执行金融取数任务。
٣٬٦٩٧ تحذيرات -
typescript-security-review giuseppe-trisciuoglio/developer-kit
Provides security review capability for TypeScript/Node.js applications, validates code against XSS, injection, CSRF, JWT/OAuth2 flaws, dependency CVEs, and secrets exposure. Use when performing security audits, before deployment, reviewing authentication/authorization implementations, or ensuring OWASP compliance for Express, NestJS, and Next.js. Triggers on "security review", "check for security issues", "TypeScript security audit".
٣٬٦٩٤ تحذيرات -
spring-boot-crud-patterns giuseppe-trisciuoglio/developer-kit
Provides and generates complete CRUD workflows for Spring Boot 3 services. Creates feature-focused architecture with Spring Data JPA aggregates, repositories, DTOs, controllers, and REST APIs. Validates domain invariants and transaction boundaries. Use when modeling Java backend services, REST API endpoints, database operations, web service patterns, or JPA entities for Spring Boot applications.
٣٬٦٩٢ تحذيرات -
spring-boot-event-driven-patterns giuseppe-trisciuoglio/developer-kit
Provides Event-Driven Architecture (EDA) patterns for Spring Boot — creates domain events, configures ApplicationEvent and @TransactionalEventListener, sets up Kafka producers and consumers, and implements the transactional outbox pattern for reliable distributed messaging. Use when implementing event-driven systems in Spring Boot, setting up async messaging with Kafka, publishing domain events from DDD aggregates, or needing reliable event publishing with the outbox pattern.
٣٬٦٦٥ تحذيرات -
spring-boot-cache giuseppe-trisciuoglio/developer-kit
Provides patterns for implementing Spring Boot caching: configures Redis/Caffeine/EhCache providers with TTL and eviction policies, applies @Cacheable/@CacheEvict/@CachePut annotations, validates cache hit/miss behavior, and exposes metrics via Actuator. Use when adding caching to Spring Boot services, configuring cache expiration, evicting stale data, or diagnosing cache misses.
٣٬٦٥٦ تحذيرات -
spring-boot-resilience4j giuseppe-trisciuoglio/developer-kit
Provides fault tolerance patterns for Spring Boot 3.x using Resilience4j. Use when implementing circuit breakers, handling service failures, adding retry logic with exponential backoff, configuring rate limiters, or protecting services from cascading failures. Generates circuit breaker, retry, rate limiter, bulkhead, time limiter, and fallback implementations. Validates resilience configurations through Actuator endpoints.
٣٬٦٤٧ تحذيرات -
spring-ai-mcp-server-patterns giuseppe-trisciuoglio/developer-kit
Provides Spring Boot MCP server patterns that create Model Context Protocol servers with Spring AI by defining tool handlers, exposing resources, configuring prompt templates, and setting up transports for AI function calling and tool calling. Use when building MCP servers to extend AI capabilities with Spring's official AI framework, implementing AI tools, custom function calling, or MCP client integration.
٣٬٦٣٨ تحذيرات -
spring-boot-actuator giuseppe-trisciuoglio/developer-kit
Provides patterns to configure Spring Boot Actuator for production-grade monitoring, health probes, secured management endpoints, and Micrometer metrics across JVM services. Use when setting up monitoring, health checks, or metrics for Spring Boot applications.
٣٬٦٣٠ تحذيرات -
unit-test-wiremock-rest-api giuseppe-trisciuoglio/developer-kit
Provides patterns for unit testing external REST APIs using WireMock. Stubs API responses, verifies request details, simulates failures (timeouts, 4xx/5xx errors), and validates HTTP client behavior without real network calls. Use when testing service integrations with external APIs or mocking HTTP endpoints.
٣٬٦٢٧ تحذيرات -
spring-boot-dependency-injection giuseppe-trisciuoglio/developer-kit
Provides dependency injection patterns for Spring Boot projects, including constructor-first design, optional collaborator handling, bean selection, and wiring validation. Use when creating services and configurations, replacing field injection, or troubleshooting ambiguous or fragile Spring wiring.
٣٬٦١٧ تحذيرات -
unit-test-security-authorization giuseppe-trisciuoglio/developer-kit
Provides patterns for unit testing Spring Security with `@PreAuthorize`, `@Secured`, `@RolesAllowed`. Validates role-based access control and authorization policies. Use when testing security configurations and access control logic.
٣٬٥٨٩ تحذيرات -
spring-boot-saga-pattern giuseppe-trisciuoglio/developer-kit
Provides distributed transaction patterns using the Saga Pattern for Spring Boot microservices. Use when implementing distributed transactions across services, handling compensating transactions, ensuring eventual consistency, or building choreography or orchestration-based sagas with Kafka, RabbitMQ, or Axon Framework.
٣٬٥٨٨ تحذيرات -
spring-data-neo4j giuseppe-trisciuoglio/developer-kit
Provides Spring Data Neo4j integration patterns for Spring Boot applications. Use when you need to work with a graph database, Neo4j nodes and relationships, Cypher queries, or Spring Data Neo4j. Creates node entities with @Node annotation, defines relationships with @Relationship, writes Cypher queries using @Query, configures imperative and reactive Neo4j repositories, implements graph traversal patterns, and sets up testing with embedded databases.
٣٬٥٨٨ تحذيرات -
unit-test-scheduled-async giuseppe-trisciuoglio/developer-kit
Provides patterns for unit testing Spring `@Scheduled` and `@Async` methods using JUnit 5, CompletableFuture, Awaitility, and Mockito. Covers mocking task execution and timing, verifying execution counts, testing cron expressions, validating retry behavior, and simulating thread pool behavior. Use when testing background tasks, cron jobs, periodic execution, scheduled tasks, or thread pool behavior.
٣٬٥٧٠ تحذيرات -
unit-test-caching giuseppe-trisciuoglio/developer-kit
Provides patterns for unit testing Spring Cache annotations (@Cacheable, @CachePut, @CacheEvict). Generates test code that mocks cache managers, verifies cache hit/miss behavior, tests cache key generation with SpEL expressions, validates eviction strategies, and checks conditional caching scenarios. Triggers: caching tests, test Spring cache, mock cache, Spring Boot caching, cache hit/miss verification, @Cacheable testing.
٣٬٥٥٨ تحذيرات -
unit-test-application-events giuseppe-trisciuoglio/developer-kit
Provides patterns for unit testing Spring application events. Validates event publishing with ApplicationEventPublisher, tests @EventListener annotation behavior, and verifies async event handling. Use when writing tests for event listeners, mocking application events, or verifying events were published in your Spring Boot services.
٣٬٥٥٣ تحذيرات -
langchain4j-mcp-server-patterns giuseppe-trisciuoglio/developer-kit
Provides LangChain4j patterns for implementing MCP (Model Context Protocol) servers, creating Java AI tools, exposing tool calling capabilities, and integrating MCP clients with AI services. Use when building a Java MCP server, implementing tool calling in Java, connecting LangChain4j to external MCP servers, or securing tool exposure for agent workflows.
٣٬٥٤٧ تحذيرات -
ssrf-server-side-request-forgery yaklang/hack-skills
SSRF playbook. Use when the server fetches URLs, resolves hostnames, imports remote content, or can be driven toward internal networks, cloud metadata, or secondary protocols.
٣٬٥٣٧ تحذيرات -
aws-rds-spring-boot-integration giuseppe-trisciuoglio/developer-kit
Provides patterns to configure AWS RDS (Aurora, MySQL, PostgreSQL) with Spring Boot applications. Configures HikariCP connection pools, implements read/write splitting, sets up IAM database authentication, enables SSL connections, and integrates with AWS Secrets Manager. Use when setting up RDS connections in Spring Boot, configuring connection pooling, or managing database credentials securely.
٣٬٥٢٨ تحذيرات -
aws-sdk-java-v2-secrets-manager giuseppe-trisciuoglio/developer-kit
Provides AWS Secrets Manager patterns for AWS SDK for Java 2.x, including secret retrieval, caching, rotation-aware access, and Spring Boot integration. Use when storing or reading secrets in Java services, replacing hardcoded credentials, or wiring secret-backed configuration into applications.
٣٬٥١٣ تحذيرات -
api-recon-and-docs yaklang/hack-skills
API reconnaissance and documentation review playbook. Use when discovering endpoints, schemas, versions, OpenAPI specs, hidden docs, and surface area for API testing.
٣٬٤٧٣ تحذيرات
الأوصاف من كتابة المؤلفين أنفسهم وباللغة الإنجليزية. اقرأ شيفرة المهارة في مستودعها قبل تثبيتها.
ما هي مهارات الوكلاء؟
المهارة مجلد فيه ملف SKILL.md وسكربتات اختيارية، يحمله الوكيل عندما تتطابق المهمة مع وصف المهارة. مهارة لكتابة الاختبارات مثلا تعطي الوكيل تعليمات وأدوات جاهزة بدلا من أن تشرحها له في كل مرة. هذه الصفحة تعرض مهارات من دليل skills.sh لوكلاء مثل Claude Code وCodex وCursor وغيرها.
ماذا تعرض كل بطاقة؟
- اسم المهارة والمؤلف والمستودع.
- عدد التثبيتات وفق skills.sh.
- حالة «التدقيق الأمني»: «ناجح»، أو «تحذيرات»، أو «فاشل»، أو «غير مدقَّق».
- أمر إضافة المهارة مع زر «نسخ الأمر».
ما حجم الدليل هنا؟
نعرض أعلى 10,000 مهارة حسب التثبيتات، مع مزامنة يومية. تبويب «الرائجة» يرتب حسب التثبيتات المكتسبة خلال آخر 7 أيام. ويمكنك التصفية حسب الموضوع أو الوكيل أو البحث بالاسم، مع 100 مهارة كحد أقصى في كل عرض.
هل المهارة الناجحة في التدقيق آمنة؟
التدقيق الناجح ليس ضمانا. حالات التدقيق مأخوذة من التدقيقات التي ينشرها skills.sh، والمهارة قد تحتوي سكربتات يشغلها الوكيل على جهازك. اقرأ شيفرة المهارة في مستودعها على GitHub قبل تثبيتها، خاصة إن كانت تنفذ أوامر أو تتصل بالإنترنت.
كيف أقرأ عدد التثبيتات؟
العدد الكبير يعني أن المهارة مستخدمة على نطاق واسع، لا أنها مناسبة لمشروعك أو خالية من المشكلات. أما «الرائجة» فتكشف المهارات الجديدة التي تكتسب اهتماما بسرعة، وقد تكون مفيدة لكنها لم تختبر طويلا بعد. استخدم التصفية حسب الوكيل الذي تعمل به حتى لا تثبت مهارة لا يدعمها.
لماذا الأوصاف بالإنجليزية؟
الأوصاف كتبها المؤلفون أنفسهم بالإنجليزية، ونعرضها كما هي دون ترجمة حتى لا يتغير معناها. عدد التثبيتات أيضا من حساب skills.sh، لا من حسابنا.
كيف أبدأ؟
ابحث عن مهمة تكررها كثيرا مع وكيلك، وابحث عن مهارة لها، واقرأ الشيفرة، ثم انسخ الأمر ونفذه في مشروعك. وللاطلاع على الوكلاء أنفسهم راجع صفحة وكلاء البرمجة.