انتقل إلى المحتوى
fedi.software

مهارات الوكلاء

مهارات لـ Claude Code وCodex وCursor ووكلاء آخرين من دليل skills.sh: عدد التثبيتات، وحالة التدقيق الأمني، والأمر لإضافة المهارة.

المهارة غير مرتبطة بوكيل واحد: يثبّتها الأمر npx skills add في أي وكيل مدعوم. بدون ‎-a تكتشف الأداة الوكلاء المثبّتين على جهازك وتسألك أين تضيفها.

تاريخ التحديث · المصادر: skills.sh

المعروض: 100 · النتائج: ١٣٥ · من أصل ١٠٬٠٠٠ في الدليل

  • firebase-firestore firebase/agent-skills

    Sets up, manages, queries, and configures Cloud Firestore databases (Standard/Enterprise edition), including data modeling, security rules, indexes, and SDK integrations (Web, Python, iOS, Android, Flutter). Use when creating/listing Firestore databases, defining data models/indexes, writing SDK queries, or integrating Firestore SDKs. For authoring or modifying Firestore Security Rules (firestore.rules), delegate to the firestore-rules-author subagent if subagent delegation is available, or use firestore-rules-creation otherwise. Don't use for Firebase Hosting, Data Connect, Auth, Storage/GCS, Crashlytics, Functions, or BigQuery.

    ١٢٥٬٨١٣ تحذيرات
  • vercel-cli-with-tokens vercel-labs/agent-skills

    Deploy and manage projects on Vercel using token-based authentication. Use when working with Vercel CLI using access tokens rather than interactive login — e.g. "deploy to vercel", "set up vercel", "add environment variables to vercel".

    ١١٨٬٤٣٣ تحذيرات
  • better-auth-best-practices better-auth/skills

    Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables. Use when users mention Better Auth, betterauth, auth.ts, or need to set up TypeScript authentication with email/password, OAuth, or plugin configuration.

    ١١٨٬٣٠٩ تحذيرات
  • investigate-without-getting-made useosint/skills

    Investigator OPSEC — threat-model who might notice you, control your attribution surface across IP, ASN, browser and TLS fingerprint, timing and logged-in accounts, separate research identity from real identity, build and age a sockpuppet research persona, and choose between VPN, residential proxy and Tor. Use when setting up a research account, avoiding tipping off a subject, worrying about LinkedIn profile-view leakage, needing a burner phone or email, or hardening a research VM or browser profile. Applies to covert due diligence, insider-threat investigation, source protection in journalism, and law-enforcement online work. Reference at useosint.com/skills/investigate-without-getting-made.

    ٥٨٬١٣٦ تحذيرات
  • security-and-hardening addyosmani/agent-skills

    Hardens code against vulnerabilities. Use when auditing an input handler for vulnerabilities, when handling user input, authentication, data storage, or external integrations, or when checking a login flow is safe against the OWASP Top Ten. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services. Use when auditing dependencies for known vulnerabilities, triaging package-manager audit findings, or assessing supply-chain risk in a new package. Use when personal data or privacy compliance (GDPR, CCPA) is involved.

    ٥٣٬٦٠٣ تحذيرات
  • clerk-custom-ui clerk/skills

    Custom authentication flows and component appearance - hooks (useSignIn,

    ٥٠٬٩٨٧ تحذيرات
  • email-and-password-best-practices better-auth/skills

    Configure email verification, implement password reset flows, set password policies, and customise hashing algorithms for Better Auth email/password authentication. Use when users need to set up login, sign-in, sign-up, credential authentication, or password security with Better Auth.

    ٤٠٬١٢٨ تحذيرات
  • golang-continuous-integration samber/cc-skills-golang

    GitHub Actions CI/CD pipeline configuration for Golang projects — workflow files for test, lint, SAST, coverage and vulnerability-scan jobs, Dependabot and Renovate config files, GoReleaser release pipelines, Docker build/push, repository security settings, and AI-driven PR review. Use when setting up or improving Go project CI, writing or fixing `.github/workflows/*.yml`, adding a linter or security scanner as a pipeline job, wiring automated dependency-update bots, or adding quality gates. Covers wiring tools into a pipeline, not the analysis they perform: do NOT use for choosing or interpreting security findings (→ See `samber/cc-skills-golang@golang-security` skill) or for choosing, upgrading, or auditing dependency versions (→ See `samber/cc-skills-golang@golang-dependency-management` skill).

    ٣٦٬٠٧٠ تحذيرات
  • two-factor-authentication-best-practices better-auth/skills

    Configure TOTP authenticator apps, send OTP codes via email/SMS, manage backup codes, handle trusted devices, and implement 2FA sign-in flows using Better Auth's twoFactor plugin. Use when users need MFA, multi-factor authentication, authenticator setup, or login security with Better Auth.

    ٣٢٬٤٠٩ تحذيرات
  • clerk-cli clerk/skills

    Operate the Clerk CLI (`clerk` binary) for authentication, user/org/session management, impersonation, local webhook testing, deploy verification, instance config, env keys, feature toggles, and any Clerk Backend, Platform, or Frontend API call. Use when the user mentions Clerk management tasks, "list clerk users", "impersonate a user", "test webhooks locally", "enable orgs", "enable billing", "clerk env pull", "clerk doctor", "clerk deploy", "clerk api", or any ad-hoc Clerk API request. Prefer the CLI over raw HTTP: it handles auth, key resolution, app/instance targeting, and formatting automatically.

    ٣٠٬٩٠٢ تحذيرات
  • create-auth-skill better-auth/skills

    ٢٩٬٢٦٣ تحذيرات
  • persona-it-admin googleworkspace/cli

    Administer IT — monitor security and configure Workspace.

    ٢٩٬٠٢٨ تحذيرات
  • best-practices addyosmani/web-quality-skills

    Apply modern web development best practices for security, compatibility, and code quality. Use when asked to "apply best practices", "security audit", "modernize code", "code quality review", or "check for vulnerabilities".

    ٢٦٬٦٥١ تحذيرات
  • security-audit cloudflare/security-audit-skill

    Security guidance and vulnerability review for codebases, APIs, services, CLI tools, libraries, and daemons. Use for security questions, focused reviews, vulnerability research, security audits, or pen tests. Run the complete workflow only for explicit codebase audit or pen-test requests, full/comprehensive/end-to-end reviews, or requested report artifacts.

    ٢٥٬٣٢٥ تحذيرات
  • validate-changes-match-specs warpdotdev/common-skills

    Validate that a branch or pull request implementation matches introduced product, technical, security, and related specs. Use when reviewing or finishing a spec-driven change and resolving mismatches between checked-in specs and implementation.

    ٢٤٬١١٨ تحذيرات
  • auth-implementation-patterns wshobson/agents

    Master authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable access control systems. Use when implementing auth systems, securing APIs, or debugging security issues.

    ١٧٬٦٥٣ تحذيرات
  • gmgn-token gmgnai/gmgn-skills

    Research any crypto or meme token by address — real-time price, market cap, liquidity, holder list, trader list, top Smart Money and KOL positions, security audit (honeypot, rug pull risk, dev wallet, renounced status), social links (Twitter/X, website) via GMGN API on Solana, BSC, Base, or Ethereum. Use when user asks about a token's price, safety, holders, traders, smart money exposure, or wants due diligence before buying.

    ١٦٬١٨٧ تحذيرات
  • attack-tree-construction wshobson/agents

    Build comprehensive attack trees to visualize threat paths. Use when mapping attack scenarios, identifying defense gaps, or communicating security risks to stakeholders.

    ١٥٬٦١٧ تحذيرات
  • clerk-swift clerk/skills

    Implement Clerk authentication for native Swift and iOS apps using ClerkKit

    ١٣٬٨٢٤ تحذيرات
  • code-review coderabbitai/skills

    Run CodeRabbit CLI reviews, retrieve saved local or GitHub PR fix prompts, and interpret CodeRabbit authentication and review output. Use for CodeRabbit review commands, committed/uncommitted or directory scopes, and CodeRabbit runbooks. Default code-review skill: also trigger for explicit code/PR/quality/security review requests or when a review is needed.

    ١٣٬٥٦١ تحذيرات
  • sql-code-review github/awesome-copilot

    Universal SQL code review assistant that performs comprehensive security, maintainability, and code quality analysis across all SQL databases (MySQL, PostgreSQL, SQL Server, Oracle). Focuses on SQL injection prevention, access control, code standards, and anti-pattern detection. Complements SQL optimization prompt for complete development coverage.

    ١٣٬٤٣٥ تحذيرات
  • secrets-management wshobson/agents

    Implement secure secrets management for CI/CD pipelines using Vault, AWS Secrets Manager, or native platform solutions. Use when handling sensitive credentials, rotating secrets, or securing CI/CD environments.

    ١٢٬٥٩٢ تحذيرات
  • fix-security-vulnerabilities-with-strix usestrix/strix

    Fix security vulnerabilities found by a Strix pentest (open-source CLI or app.strix.ai cloud) — triage by severity, patch the root cause rather than the symptom, and re-run Strix to prove each fix actually closes the exploit. Handles injection, XSS, SSRF, broken access control, IDOR, and other validated findings. Use after a Strix scan reports findings, or when the user asks to remediate, patch, or fix security issues from a strix_runs report, vulnerabilities.json, findings.sarif, or a cloud scan.

    ١١٬٧٤٧ تحذيرات
  • managed-pentesting-with-strix usestrix/strix

    Run a managed pentest of a web app, API, repository, or local workspace on the app.strix.ai platform with the `strix cloud` CLI or REST API — no local Docker or LLM key needed. Safely review and upload local source, register assets, launch and poll scans, triage vulnerabilities, export SARIF, download compliance reports, start PR reviews, buy credits, and set up schedules or webhooks. Use for managed, continuous, scheduled, team-tracked, or sandboxed-agent security testing.

    ١١٬٥٠٠ تحذيرات
  • ci-security-scanning-with-strix usestrix/strix

    Add security scanning to CI/CD with Strix — GitHub Actions, GitLab CI, or any pipeline — so every pull request gets a diff-scoped AI pentest that blocks vulnerable code before it merges, with results as PR comments and SARIF uploaded to code scanning. Covers both the self-hosted open-source CLI (runs in your runner) and the managed app.strix.ai platform (GitHub/GitLab app or API, no runner infra). Use when the user asks to add security scanning, SAST/DAST, pentesting, vulnerability checks, or automated security review to their CI pipeline, pre-merge gate, or PR workflow.

    ١١٬٤٥٩ تحذيرات
  • k8s-manifest-generator wshobson/agents

    Create production-ready Kubernetes manifests for Deployments, Services, ConfigMaps, and Secrets following best practices and security standards. Use when generating Kubernetes YAML manifests, creating K8s resources, or implementing production-grade Kubernetes configurations.

    ١٠٬٦٨٢ تحذيرات
  • code-review anthropics/knowledge-work-plugins

    Review code changes for security, performance, and correctness. Trigger with a PR URL or diff, "review this before I merge", "is this code safe?", or when checking a change for N+1 queries, injection risks, missing edge cases, or error handling gaps.

    ٩٬٦٦٦ تحذيرات
  • web-app-penetration-testing usestrix/strix

    Pentest a web app or website end to end — black-box testing of a live URL, staging environment, or local dev server that finds and exploits real vulnerabilities (auth bypass, broken access control, IDOR, injection, XSS, SSRF, business logic) and proves each one with a working proof-of-concept instead of a signature match. Runs with Strix, either the self-hosted open-source CLI or the managed app.strix.ai cloud. Use when the user asks to pentest, hack, security-test, or audit their web app, website, web application, or staging site.

    ٨٬٨٠١ تحذيرات
  • kotlin-ktor-patterns affaan-m/ecc

    Ktor server patterns including routing DSL, plugins, authentication, Koin DI, kotlinx.serialization, WebSockets, and testApplication testing. Use when building a Ktor server — routing, plugins, auth, DI, serialization, or tests.

    ٨٬٧٧١ تحذيرات
  • find-security-vulnerabilities-in-code usestrix/strix

    Find security vulnerabilities in a codebase or repository with Strix — a white-box AI security review that reads your source, reasons about the actual data flow and authorization model, then exploits what it finds in a live sandbox so every reported issue has a working proof-of-concept instead of a noisy static-analysis alert. Covers injection, XSS, SSRF, broken access control and IDOR, insecure deserialization, secrets in code, unsafe dependencies, and business-logic flaws. Use when the user asks to security-scan, security-review, or audit their code, repo, or pull request for vulnerabilities.

    ٨٬٧٦١ تحذيرات
  • owasp-top-10-testing usestrix/strix

    Test an application against the OWASP Top 10 with Strix — autonomous AI agents that attempt real exploits for each category of the current OWASP Top 10:2025 (broken access control including SSRF, security misconfiguration, software supply chain failures, cryptographic failures, injection, insecure design, authentication failures, integrity failures, logging and alerting failures, mishandling of exceptional conditions) and report only what they could actually prove, mapped back to the category with a proof-of-concept. Also covers the OWASP API Security Top 10 (2023). Use when the user asks for an OWASP Top 10 assessment, OWASP compliance testing, or a security review mapped to OWASP categories.

    ٨٬٧٥٨ تحذيرات
  • semgrep trailofbits/skills

    Runs a Semgrep security scan over a codebase: detects languages, selects rulesets, presents the plan for explicit approval, then runs every approved ruleset through scripts/run-scans.sh, which batches the semgrep processes and writes scans.json, and merges the output to SARIF. Supports two scan modes, "run all" for full ruleset coverage and "important only" for security findings at medium-to-high confidence and impact. Uses Semgrep Pro for cross-file taint analysis when it is available. Use when asked to scan code for vulnerabilities, run a security audit with Semgrep, find bugs, or perform static analysis. For the same scan without the approval gate, use the /static-analysis:semgrep-scan workflow.

    ٨٬٧٥٧ تحذيرات
  • api-security-testing usestrix/strix

    Security-test a REST, GraphQL, or gRPC API with Strix — autonomous agents that enumerate endpoints from an OpenAPI/GraphQL schema (or by crawling), then actually exploit the API-specific vulnerability classes in the OWASP API Security Top 10 (2023) — broken object-level authorization (BOLA/IDOR), broken object property level authorization (excessive data exposure and mass assignment), broken function-level authorization, unrestricted resource consumption, SSRF, injection, and auth/token flaws. Every finding comes with a working proof-of-concept request. Use when the user asks to pentest, security-test, audit, or find vulnerabilities in an API, endpoint, or backend service.

    ٨٬٧٤٤ تحذيرات
  • emblem-ai emblemcompany/agent-skills

    One-shot user management for apps, multi-chain wallet authentication, an AI-powered assistant, and AI app introspection. Use when the user wants to let website users sign in with wallets, email/password, or social login and give each user a wallet-enabled account, then embed EmblemAI chat surfaces, connect plugins, or add Reflexive observability. Provides React components, TypeScript SDKs, session-based authentication, and pointers to the React and agent-wallet skills for specialized workflows.

    ٨٬٧٣٠ تحذيرات
  • application-security-testing usestrix/strix

    Application security testing (AppSec) across a whole product with Strix — decide which asset needs which test (source code, running web app, API, CI pipeline), run it, and turn the results into a ranked remediation plan. Autonomous agents exploit and prove each issue instead of emitting static-analysis alerts, so the plan is ordered by what is actually reachable. Use when the user asks for an application security review or audit, an appsec assessment, vulnerability scanning across their stack, a security review before a launch or a customer security questionnaire, or does not yet know which kind of security test they need.

    ٨٬٦٢٣ تحذيرات
  • reddit-search-api lignertys/reddit-research-skills

    Pure API reference for reddapi.dev - authentication, all endpoints (vector search, semantic search, trends, subreddit lookup), request parameters, response schemas, and error codes, with no research-workflow framing. Use when the user wants raw endpoint documentation, is debugging a reddapi.dev integration, needs exact request/response field names, or asks for 'reddapi API reference', 'reddapi.dev endpoints', or 'reddapi error codes'. For guided research workflows and query playbooks, see reddit-research. For B2B lead scoring, see reddit-leads.

    ٨٬٤١١ تحذيرات
  • security-bounty-hunter affaan-m/ecc

    Hunt for exploitable, bounty-worthy security issues in repositories. Focuses on remotely reachable vulnerabilities that qualify for real reports instead of noisy local-only findings. Use when hunting reportable, remotely reachable vulnerabilities in a repository.

    ٧٬٨٩٨ تحذيرات
  • email-best-practices resend/email-best-practices

    Use when building email features, emails going to spam, high bounce rates, setting up SPF/DKIM/DMARC authentication, implementing email capture, ensuring compliance (CAN-SPAM, GDPR, CASL), handling webhooks, retry logic, making emails accessible (alt text, headings, contrast, screen readers), or deciding transactional vs marketing.

    ٧٬٨٤٧ تحذيرات
  • llm-trading-agent-security affaan-m/ecc

    Security patterns for autonomous trading agents with wallet or transaction authority. Covers prompt injection, spend limits, pre-send simulation, circuit breakers, MEV protection, and key handling. Use when an autonomous agent holds wallet or transaction authority and its limits, simulation, or key handling need review.

    ٧٬٧٣٩ تحذيرات
  • defi-amm-security affaan-m/ecc

    Security checklist for Solidity AMM contracts, liquidity pools, and swap flows. Covers reentrancy, CEI ordering, donation or inflation attacks, oracle manipulation, slippage, admin controls, and integer math. Use when auditing or writing Solidity AMM, liquidity pool, or swap code.

    ٧٬٥٣٨ تحذيرات
  • skill-security superagent-ai/skills

    Audit an AI agent skill for security risks before installing or trusting it. Runs a deterministic scanner (regex patterns, Python AST analysis, source-to-sink taint tracking, and YARA signatures) and then reasons about intent — catching prompt injection, credential exfiltration, persistence, memory poisoning, malicious code, supply-chain risks, and description-vs-behavior mismatch. Make sure to use this skill whenever the user wants to scan, audit, vet, review, or check the safety of a skill, plugin, SKILL.md, or agent tool — whether it is a local folder, a zip/.skill file, or a cloned repo — and whenever someone asks "is this skill safe to install?".

    ٧٬٣٤٤ تحذيرات
  • wp-plugin-development wordpress/agent-skills

    Use when developing WordPress plugins: architecture and hooks, activation/deactivation/uninstall, admin UI and Settings API, data storage, cron/tasks, security (nonces/capabilities/sanitization/escaping), and release packaging.

    ٧٬١٧٨ تحذيرات
  • security-threat-model openai/skills

    Repository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, and writes a concise Markdown threat model. Trigger only when the user explicitly asks to threat model a codebase or path, enumerate threats/abuse paths, or perform AppSec threat modeling. Do not trigger for general architecture summaries, code review, or non-security design work.

    ٧٬١٤٤ تحذيرات
  • okx-security okx/onchainos-skills

    ٦٬٤٩٩ تحذيرات
  • fp-check trailofbits/skills

    Systematically verifies suspected security bugs to eliminate false positives, producing a TRUE POSITIVE or FALSE POSITIVE verdict with documented evidence for each. Use when asked whether a specific finding is real, exploitable, or a false positive, or to verify or validate a suspected vulnerability — not for hunting or discovering new bugs.

    ٦٬٤٧٩ تحذيرات
  • seo-technical agricidaniel/claude-seo

    Audit technical SEO across crawlability, indexability, security, URLs, mobile, Core Web Vitals, rendering, structured data, and IndexNow. Exclude content strategy and backlinks.

    ٦٬٤٥٣ تحذيرات
  • agentic-actions-auditor trailofbits/skills

    Audits GitHub Actions workflows for security vulnerabilities in AI agent integrations including Claude Code Action, Gemini CLI, OpenAI Codex, and GitHub AI Inference. Detects attack vectors where attacker-controlled input reaches AI agents running in CI/CD pipelines, including env var intermediary patterns, direct expression injection, dangerous sandbox configurations, and wildcard user allowlists. Use when reviewing workflow files that invoke AI coding agents, auditing CI/CD pipeline security for prompt injection risks, or evaluating agentic action configurations.

    ٦٬٢٨٧ تحذيرات
  • sharp-edges trailofbits/skills

    Identifies error-prone APIs, dangerous configurations, and footgun designs that enable security mistakes. Use when reviewing API designs, configuration schemas, cryptographic library ergonomics, or evaluating whether code follows 'secure by default' and 'pit of success' principles. Triggers: footgun, misuse-resistant, secure defaults, API usability, dangerous configuration.

    ٦٬١٩٦ تحذيرات
  • dx-code-analyzer-run forcedotcom/sf-skills

    Run Salesforce Code Analyzer to scan code for security, performance, best practice, and code style violations. Supports all engines (PMD, ESLint, CPD, RetireJS, Flow, SFGE, ApexGuru), targets (files, folders, git diff), categories, and severities. Also handles post-scan exploration: filtering results by engine/severity/category/file, and explaining what rules mean. TRIGGER when: user says 'scan my code', 'check security issues', 'run PMD/ESLint', 'find duplicates', 'analyze Flows', 'check vulnerable libraries', 'AppExchange review', 'lint my LWC', 'static analysis', 'code quality', 'show security violations', 'what is this rule', 'explain ApexCRUDViolation', 'filter results', or mentions engines/file types (.cls, .trigger, .js, .flow-meta.xml). Use this skill for scanning, exploring results, and listing rules. DO NOT TRIGGER when: user asks only about installation/configuration (use dx-code-analyzer-configure), or wants to create a custom rule (use dx-code-analyzer-custom-rule-create).

    ٦٬١٠١ تحذيرات
  • creating-secrets-using-best-practices aws/agent-toolkit-for-aws

    Creates and manages secrets in AWS Secrets Manager following security best practices. Always use this skill when creating secrets — it sets up dedicated KMS encryption keys, automatic rotation, least-privilege IAM policies, CloudTrail auditing, and lifecycle management that are essential for production-grade secret handling.

    ٦٬٠٢٥ تحذيرات
  • agentforce-test forcedotcom/sf-skills

    Write, run, and analyze structured test suites for Agentforce agents — functional AND security. TRIGGER when: user writes or modifies test spec YAML (AiEvaluationDefinition); runs sf agent test create, run, run-eval, or results commands; asks about test coverage strategy, metric selection, or custom evaluations; interprets test results or diagnoses test failures; asks about batch testing, regression suites, or CI/CD test integration; requests security testing, OWASP LLM Top 10, red-teaming, penetration testing, prompt-injection tests, a security grade, or a vulnerability assessment of an agent. DO NOT TRIGGER when: user creates, modifies, previews, or debugs .agent files (use agentforce-generate); deploys or publishes agents; writes Agent Script code; uses sf agent preview for development iteration; analyzes production session traces (use agentforce-observe); performs a static safety review of .agent file content (use agentforce-generate Section 15).

    ٥٬٥٧٣ تحذيرات
  • google-cloud-recipe-foundation-builder google/skills

    Deploys a baseline landing zone foundation for a Google Cloud Organization, establishing security guardrails using Organization Policies, resource hierarchy folders and projects, billing association, and centralized logging and monitoring. Deploys Google Cloud's recommended security controls and architecture. Use when setting up a new Google Cloud Organization or establishing a secure, enterprise-grade landing zone foundation. Don't use for individual project onboarding (use google-cloud-recipe-onboarding or product-specific skills instead).

    ٥٬٥١٦ تحذيرات
  • enabling-lambda-vpc-internet-access aws/agent-toolkit-for-aws

    Enables internet access for AWS Lambda functions deployed in VPC subnets by creating NAT Gateway infrastructure, configuring public/private subnet routing, and updating security groups. Use when a VPC-attached Lambda function cannot reach the internet.

    ٥٬٤٩٤ تحذيرات
  • semgrep-rule-creator trailofbits/skills

    Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns. Use when writing Semgrep rules or building custom static analysis detections.

    ٥٬٣٦٠ تحذيرات
  • wp-rest-api wordpress/agent-skills

    Use when building, extending, or debugging WordPress REST API endpoints/routes: register_rest_route, WP_REST_Controller/controller classes, schema/argument validation, permission_callback/authentication, response shaping, register_rest_field/register_meta, or exposing CPTs/taxonomies via show_in_rest.

    ٥٬٣١٤ تحذيرات
  • firebase-apk-scanner trailofbits/skills

    Scans Android APKs for Firebase security misconfigurations including open databases, storage buckets, authentication issues, and exposed cloud functions. Use when analyzing APK files for Firebase vulnerabilities, performing mobile app security audits, or testing Firebase endpoint security. For authorized security research only.

    ٥٬٠٥٧ تحذيرات
  • constant-time-analysis trailofbits/skills

    Detects timing side-channel vulnerabilities in cryptographic code. Use when implementing or reviewing crypto code, encountering division on secrets, secret-dependent branches, or constant-time programming questions in C, C++, Go, Rust, Swift, Java, Kotlin, C#, PHP, JavaScript, TypeScript, Python, or Ruby.

    ٥٬٠٣٥ تحذيرات
  • cosmos-vulnerability-scanner trailofbits/skills

    Scans Cosmos SDK blockchain modules and CosmWasm contracts for consensus-critical vulnerabilities — chain halts, fund loss, state divergence. 25 core + 16 IBC + 10 EVM + 3 CosmWasm patterns. Use when auditing custom x/ modules, reviewing IBC integrations, or assessing pre-launch chain security. Updated for SDK v0.53.x.

    ٤٬٩٦٦ تحذيرات
  • experience-ui-bundle-features-generate forcedotcom/sf-skills

    MUST activate when the project contains a uiBundles/*/src/ directory (React or Angular) and the user wants to add a pre-built feature — such as authentication (login, logout, protected routes, session management) or search (global search across pages and content) — instead of building it from scratch. Always run list first to see the current feature catalog, since it can include more than authentication and search. Always use this skill for installing pre-built features rather than hand-building them. DO NOT TRIGGER for Agentforce conversational client or file-upload features — use experience-ui-bundle-agentforce-client-generate and experience-ui-bundle-file-upload-generate respectively.

    ٤٬٩٥٥ تحذيرات
  • ton-vulnerability-scanner trailofbits/skills

    Scans TON (The Open Network) smart contracts for 3 critical vulnerabilities including integer-as-boolean misuse, fake Jetton contracts, and forward TON without gas checks. Use when auditing FunC contracts.

    ٤٬٨٦١ تحذيرات
  • cairo-vulnerability-scanner trailofbits/skills

    Scans Cairo/StarkNet smart contracts for 6 critical vulnerabilities including felt252 arithmetic overflow, L1-L2 messaging issues, address conversion problems, and signature replay. Use when auditing StarkNet projects.

    ٤٬٨٥١ تحذيرات
  • clawdirect-dev napoleond/clawdirect

    Build agent-facing web experiences with ATXP-based authentication, following the ClawDirect pattern. Use this skill when building websites that AI agents interact with via MCP tools, implementing cookie-based agent auth, or creating agent skills for web apps. Provides templates using @longrun/turtle, Express, SQLite, and ATXP.

    ٤٬٥٩٢ تحذيرات
  • openclaw-control-center reason-machines/trending-skills

    Local-first, security-first control center for OpenClaw agents — visibility dashboard with readonly defaults, token attribution, collaboration tracing, and safe write operations.

    ٤٬٣٩٣ تحذيرات
  • ghost-scan-secrets ghostsecurity/skills

    Ghost Security - Secrets and credentials scanner. Scans codebase for leaked API keys, tokens, passwords, and sensitive data. Detects hardcoded secrets and generates findings with severity and remediation guidance. Use when the user asks to check for leaked secrets, scan for credentials, find hardcoded API keys or passwords, detect exposed .env values, or audit code for sensitive data exposure.

    ٤٬١٠٠ تحذيرات
  • ghost-scan-deps ghostsecurity/skills

    Ghost Security - Software Composition Analysis (SCA) scanner. Scans dependency lockfiles for known vulnerabilities, identifies CVEs, and generates findings with severity levels and remediation guidance. Use when the user asks about dependency vulnerabilities, vulnerable packages, CVE checks, security audits of dependencies, or wants to scan lockfiles like package-lock.json, yarn.lock, go.mod, or Gemfile.lock.

    ٣٬٩٧٦ تحذيرات
  • rds-oracle aws/agent-toolkit-for-aws

    Diagnoses and resolves Amazon RDS for Oracle connectivity, authentication, networking, and driver troubleshooting. Applicable to any RDS-for-Oracle question including connecting a Python Lambda to RDS Oracle in a VPC with pooling and cold-start optimization, EKS pods to RDS Oracle via the Secrets Manager CSI driver with IRSA and SecretProviderClass, ORA-12170 cross-VPC timeouts from EC2, DPI-1047 cannot-locate-64-bit-Oracle-Client errors, and Oracle Connection Manager (CMAN) on EC2 as a proxy with HA across two AZs. Covers python-oracledb thin vs thick mode, init_oracle_client, RDS Proxy does NOT support RDS Oracle, port 1521, VPC peering, Transit Gateway, Kerberos with AWS Managed Microsoft AD, SSL/TLS/NNE, SSM port forwarding, EC2/ECS Fargate/EKS/Lambda, SQL Developer/DBeaver/Toad/SQLcl, and Secrets Manager.

    ٣٬٩٦٦ تحذيرات
  • spring-boot-security-jwt giuseppe-trisciuoglio/developer-kit

    Provides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based access control using Spring Security 6.x. Use when implementing authentication or authorization in Spring Boot applications.

    ٣٬٩٥٨ تحذيرات
  • android-pentesting-tricks yaklang/hack-skills

    Android pentesting playbook. Use when testing Android applications for SSL pinning bypass, exported component abuse, WebView vulnerabilities, intent redirection, root detection bypass, tapjacking, and backup extraction during authorized mobile security assessments.

    ٣٬٧٣١ تحذيرات
  • typescript-security-review giuseppe-trisciuoglio/developer-kit

    Provides security review capability for TypeScript/Node.js applications, validates code against XSS, injection, CSRF, JWT/OAuth2 flaws, dependency CVEs, and secrets exposure. Use when performing security audits, before deployment, reviewing authentication/authorization implementations, or ensuring OWASP compliance for Express, NestJS, and Next.js. Triggers on "security review", "check for security issues", "TypeScript security audit".

    ٣٬٧٠٣ تحذيرات
  • authentication dpearson2699/swift-ios-skills

    Implement iOS authentication flows with AuthenticationServices and LocalAuthentication. Use when building Sign in with Apple, passkey/WebAuthn registration or sign-in with ASAuthorizationPlatformPublicKeyCredentialProvider, ASAuthorizationController credential state and revocation handling, ASWebAuthenticationSession OAuth or third-party login, Password AutoFill, identity-token server validation, or local biometric re-authentication with LAContext.

    ٣٬٦٨٠ تحذيرات
  • ads-landing agricidaniel/claude-ads

    Audit paid-ad landing pages for message match, mobile experience, performance, accessibility, trust, forms, consent, tracking, security, and conversion friction. Use for landing-page audit, post-click experience, LP audit, conversion-rate optimization, form optimization, ad-to-page message match, redirects, blocked navigation, or requests involving private, loopback, link-local, or metadata IP destinations.

    ٣٬٦٧٥ تحذيرات
  • unit-test-security-authorization giuseppe-trisciuoglio/developer-kit

    Provides patterns for unit testing Spring Security with `@PreAuthorize`, `@Secured`, `@RolesAllowed`. Validates role-based access control and authorization policies. Use when testing security configurations and access control logic.

    ٣٬٥٩٤ تحذيرات
  • nextjs-authentication giuseppe-trisciuoglio/developer-kit

    Provides authentication implementation patterns for Next.js 15+ App Router using Auth.js 5 (NextAuth.js). Use when setting up authentication flows, implementing protected routes, managing sessions in Server Components and Server Actions, configuring OAuth providers, implementing role-based access control, or handling sign-in/sign-out flows in Next.js applications.

    ٣٬٥٩١ تحذيرات
  • ghost-validate ghostsecurity/skills

    This skill should be used when the user asks to "validate a finding", "check if a vulnerability is real", "triage a security finding", "confirm a vulnerability", "determine if a finding is a true positive or false positive", or provides a security finding for review. It validates security vulnerability findings by tracing data flows, verifying exploit conditions, analyzing security controls, and optionally testing attack vectors against a live application.

    ٣٬٥٢٦ تحذيرات
  • ghost-report ghostsecurity/skills

    Ghost Security — combined security report. Aggregates findings from all scan skills (scan-deps, scan-secrets, scan-code) into a single prioritized report focused on the highest risk, highest confidence issues. Use when the user requests a security overview, vulnerability summary, full security audit, or combined scan results.

    ٣٬٥١٨ تحذيرات
  • aws-sdk-java-v2-secrets-manager giuseppe-trisciuoglio/developer-kit

    Provides AWS Secrets Manager patterns for AWS SDK for Java 2.x, including secret retrieval, caching, rotation-aware access, and Spring Boot integration. Use when storing or reading secrets in Java services, replacing hardcoded credentials, or wiring secret-backed configuration into applications.

    ٣٬٥١٨ تحذيرات
  • authbypass-authentication-flaws yaklang/hack-skills

    Authentication bypass testing playbook. Use when assessing login flows, password reset logic, account recovery, MFA bypass, token predictability, brute-force resistance, and session boundary flaws.

    ٣٬٤٩٦ تحذيرات
  • websocket-security yaklang/hack-skills

    WebSocket handshake, CSWSH, tooling (wsrepl, ws-harness, Burp), and common flaws. Use when apps use real-time channels, chat, notifications, or WS-backed APIs.

    ٣٬٤٦١ تحذيرات
  • infra-clickhouse clickhouse/agent-skills

    Sets up and manages ClickHouse using the clickhousectl CLI — installs and runs a local ClickHouse server for development, and creates managed ClickHouse Cloud services for production (authentication, service creation, schema migration, application connection). Use when the user wants to build an application with ClickHouse, set up a local ClickHouse dev environment, create tables and start querying, deploy ClickHouse to production or ClickHouse Cloud, or migrate from a local setup to the cloud.

    ٣٬٤٥٥ تحذيرات
  • inngest-middleware inngest/inngest-skills

    Use when adding cross-cutting concerns to durable functions — structured logging or tracing across all functions, error tracking with Sentry, payload encryption for sensitive data, dependency injection of clients (DB, Stripe, etc.) into function handlers, custom telemetry, or behavior that should apply uniformly across many functions. Covers Inngest middleware lifecycle, creating custom middleware, dependencyInjectionMiddleware, @inngest/middleware-encryption, @inngest/middleware-sentry, and custom middleware patterns.

    ٣٬٤٥٣ تحذيرات
  • auth-sec yaklang/hack-skills

    Entry P1 category router for authentication and authorization. Use when testing login flows, sessions, object authorization, JWT, OAuth, CORS, CSRF, and enterprise SSO weaknesses before any deeper auth topic skill.

    ٣٬٤٣٦ تحذيرات
  • better-auth giuseppe-trisciuoglio/developer-kit

    Provides Better Auth integration patterns for NestJS backend and Next.js frontend with Drizzle ORM and PostgreSQL. Use when setting up Better Auth with NestJS backend, integrating Next.js App Router frontend, configuring Drizzle ORM schema, implementing social login (GitHub, Google), adding plugins (2FA, Organization, SSO, Magic Link, Passkey), implementing email/password authentication with session management, or creating protected routes and middleware.

    ٣٬٤٣١ تحذيرات
  • healthcheck openclaw/openclaw

    Audit/harden OpenClaw hosts: SSH, firewall, updates, exposure, backups, disk encryption, gateway security.

    ٣٬٤٢٥ تحذيرات
  • kubernetes-pentesting yaklang/hack-skills

    Kubernetes penetration testing playbook. Use when targeting Kubernetes clusters via API server, RBAC enumeration, service account abuse, etcd access, Kubelet API, pod escape, cloud-specific metadata, admission webhook bypass, and registry secrets.

    ٣٬٤٢٥ تحذيرات
  • ios-pentesting-tricks yaklang/hack-skills

    iOS pentesting playbook. Use when testing iOS applications for keychain extraction, URL scheme hijacking, Universal Links exploitation, runtime manipulation, binary protection analysis, data storage issues, and transport security bypass during authorized mobile security assessments.

    ٣٬٤٠٤ تحذيرات
  • csp-bypass-advanced yaklang/hack-skills

    Advanced Content Security Policy bypass techniques. Use when XSS or data exfiltration is blocked by CSP and you need to find policy weaknesses, trusted endpoint abuse, nonce leakage, or exfiltration channels that CSP cannot block.

    ٣٬٣٣١ تحذيرات
  • smart-contract-vulnerabilities yaklang/hack-skills

    Smart contract vulnerability playbook. Use when auditing Solidity/EVM contracts for reentrancy, integer overflow, access control, delegatecall, flash loan, signature replay, and MEV-related attack patterns.

    ٣٬٢٥٣ تحذيرات
  • nodejs-express-server aj-geddes/useful-ai-prompts

    Build production-ready Express.js servers with middleware, authentication, routing, and database integration. Use when creating REST APIs, managing requests/responses, implementing middleware chains, and handling server logic.

    ٣٬٢٤٩ تحذيرات
  • pr-review pytorch/pytorch

    Review PyTorch pull requests for code quality, test coverage, security, and backward compatibility. Use when reviewing PRs, when asked to review code changes, or when the user mentions "review PR", "code review", or "check this PR".

    ٣٬٢٣٨ تحذيرات
  • macos-security-bypass yaklang/hack-skills

    macOS security bypass playbook. Use when targeting macOS endpoints and need to bypass TCC, Gatekeeper, SIP, sandbox, code signing, or entitlement-based protections during authorized red team or pentest engagements.

    ٣٬٢٢٠ تحذيرات
  • longbridge-market-data longbridge/skills

    Real-time quotes, K-line charts, order book, trade ticks, intraday capital flow, market sentiment temperature, trading session schedule, security lists, exchange rates, and IPO calendar for HK/US/A-share/SG via Longbridge. Also covers ADR premium and FX carry frameworks. Triggers: "股价", "行情", "K线", "走势", "盘口", "资金流", "市场温度", "汇率", "IPO", "打新", "隔夜股", "ADR溢价", "外汇套息", "K線", "盤口", "資金流", "市場溫度", "匯率", "ADR溢價", "外匯套息", "现在多少钱", "多少钱", "stock price", "quote", "kline", "chart", "depth", "orderbook", "capital flow", "market sentiment", "exchange rate", "IPO calendar", "security list", "ADR premium", "fx carry", "market open", "trading hours", "开市", "溢价", "NVDA.US", "700.HK", "600519.SH", "股價", "走勢", "開盤", "今天開市"

    ٣٬١١٣ تحذيرات
  • squirrelscan squirrelscan/skills

    squirrelscan audits websites for SEO, performance, security, accessibility, content, and structured data issues (260+ rules) and scores site health, via the squirrel CLI. Use when the user wants to check, audit, or improve a website's SEO, ranking, speed, or health, and for anything squirrelscan itself, installing or updating the CLI, login and API keys, running audits, publishing and sharing reports, cloud credits, MCP server setup, configuration, or troubleshooting. Also covers the entity map: the site-wide graph of the entities a site declares in its JSON-LD, and fixing structured data identity problems such as an organization declared separately on every page.

    ٣٬٠٨٠ تحذيرات
  • oss-issue-triage samber/developer-relations-skills

    Designs an issue and pull-request triage system a maintainer team can sustain - response targets sized against real capacity, the label taxonomy, intake cuts through structured forms and off-tracker routing, a separate security-report path, triage duty assignment, and the closing, staleness and volume-gating policy. Use whenever someone says "our issue tracker is out of control", "design an issue triage process", "set up labels for our repo", "we have 900 open issues", "should we run a stale bot", "PR backlog nobody reviews", "triage rotation", or "we are drowning in AI-generated reports" - even if they only say maintenance is overwhelming. Not good-first-issue curation - use samber/developer-relations-skills@oss-contributor-onboarding.

    ٣٬٠١٠ تحذيرات
  • owasp-security hoodini/ai-agents-skills

    Implement secure coding practices following OWASP Top 10. Use when preventing security vulnerabilities, implementing authentication, securing APIs, or conducting security reviews. Triggers on OWASP, security, XSS, SQL injection, CSRF, authentication security, secure coding, vulnerability.

    ٢٬٩٨٤ تحذيرات
  • cryptotokenkit dpearson2699/swift-ios-skills

    Access security tokens and smart cards using CryptoTokenKit. Use when building TKTokenDriver or TKSmartCardTokenDriver extensions, communicating with smart cards via TKSmartCard/TKSmartCardSlotManager, using iOS 26+ NFC smart-card sessions, registering smart cards, querying token-backed keychain items with kSecAttrTokenID, monitoring TKTokenWatcher, or configuring certificate-based smart-card authentication.

    ٢٬٨٨٨ تحذيرات
  • google-cloud-scc-query google/skills

    Queries and retrieves active security findings, external exposures, toxic combinations, vulnerabilities, threats, and sensitive data risks from Google Cloud Security Command Center. Use when retrieving details for a security finding by its name, validating finding scope (e.g., verifying findingClass is TOXIC_COMBINATION, VULNERABILITY, EXTERNAL_EXPOSURE, or THREAT), or fetching finding details for triage. Don't use to draft remediations, apply patches, or execute configurations.

    ٢٬٧٦٥ تحذيرات
  • google-cloud-solution-multi-agent-security google/skills

    Designs, deploys, and secures Google Cloud Agent Gateway solutions. Use when the user needs to configure multi-agent security, ingress (CLIENT_TO_AGENT), or egress (AGENT_TO_ANYWHERE) patterns involving Model Armor, IAP, and Agent Registry. Don't use for general Cloud Load Balancing or basic VPC setup not related to Agent Gateways.

    ٢٬٧١٧ تحذيرات
  • chrome-extension-development mindrally/skills

    Expert guidelines for Chrome extension development with Manifest V3, covering security, performance, and best practices. Use when building browser extensions, creating popup UIs, implementing content scripts, working with Chrome APIs, managing extension permissions, or publishing to Chrome Web Store.

    ٢٬٧١٥ تحذيرات
  • db oracle/skills

    Oracle Database guidance for SQL, PL/SQL, SQLcl, ORDS, Oracle Vector SDK, administration, app development, performance, security, migrations, and agent-safe database workflows. Use when the user asks to write, edit, rewrite, review, format, debug, tune, or explain SQL; create or refactor PL/SQL; use Oracle VecDB through the Python SDK, REST API, or DBMS_VECTOR_DATABASE package; use SQLcl, Liquibase, ORDS, JDBC, node-oracledb, Python, Java, .NET, or database frameworks; troubleshoot vector tables, embeddings, vector search, reranking, queries, sessions, locks, waits, indexes, optimizer plans, AWR, ASH, migrations, schemas, users, roles, privileges, backup, recovery, Data Guard, RAC, multitenant, containers, monitoring, auditing, encryption, VPD, or safe agent database operations.

    ٢٬٥٩٦ تحذيرات
  • django-access-review getsentry/skills

    Django access control and IDOR security review. Use when reviewing Django views, DRF viewsets, ORM queries, or any Python/Django code handling user authorization. Trigger keywords: "IDOR", "access control", "authorization", "Django permissions", "object permissions", "tenant isolation", "broken access".

    ٢٬٤٦٢ تحذيرات

الأوصاف من كتابة المؤلفين أنفسهم وباللغة الإنجليزية. اقرأ شيفرة المهارة في مستودعها قبل تثبيتها.

ما هي مهارات الوكلاء؟

المهارة مجلد فيه ملف SKILL.md وسكربتات اختيارية، يحمله الوكيل عندما تتطابق المهمة مع وصف المهارة. مهارة لكتابة الاختبارات مثلا تعطي الوكيل تعليمات وأدوات جاهزة بدلا من أن تشرحها له في كل مرة. هذه الصفحة تعرض مهارات من دليل skills.sh لوكلاء مثل Claude Code وCodex وCursor وغيرها.

ماذا تعرض كل بطاقة؟

  • اسم المهارة والمؤلف والمستودع.
  • عدد التثبيتات وفق skills.sh.
  • حالة «التدقيق الأمني»: «ناجح»، أو «تحذيرات»، أو «فاشل»، أو «غير مدقَّق».
  • أمر إضافة المهارة مع زر «نسخ الأمر».

ما حجم الدليل هنا؟

نعرض أعلى 10,000 مهارة حسب التثبيتات، مع مزامنة يومية. تبويب «الرائجة» يرتب حسب التثبيتات المكتسبة خلال آخر 7 أيام. ويمكنك التصفية حسب الموضوع أو الوكيل أو البحث بالاسم، مع 100 مهارة كحد أقصى في كل عرض.

هل المهارة الناجحة في التدقيق آمنة؟

التدقيق الناجح ليس ضمانا. حالات التدقيق مأخوذة من التدقيقات التي ينشرها skills.sh، والمهارة قد تحتوي سكربتات يشغلها الوكيل على جهازك. اقرأ شيفرة المهارة في مستودعها على GitHub قبل تثبيتها، خاصة إن كانت تنفذ أوامر أو تتصل بالإنترنت.

كيف أقرأ عدد التثبيتات؟

العدد الكبير يعني أن المهارة مستخدمة على نطاق واسع، لا أنها مناسبة لمشروعك أو خالية من المشكلات. أما «الرائجة» فتكشف المهارات الجديدة التي تكتسب اهتماما بسرعة، وقد تكون مفيدة لكنها لم تختبر طويلا بعد. استخدم التصفية حسب الوكيل الذي تعمل به حتى لا تثبت مهارة لا يدعمها.

لماذا الأوصاف بالإنجليزية؟

الأوصاف كتبها المؤلفون أنفسهم بالإنجليزية، ونعرضها كما هي دون ترجمة حتى لا يتغير معناها. عدد التثبيتات أيضا من حساب skills.sh، لا من حسابنا.

كيف أبدأ؟

ابحث عن مهمة تكررها كثيرا مع وكيلك، وابحث عن مهارة لها، واقرأ الشيفرة، ثم انسخ الأمر ونفذه في مشروعك. وللاطلاع على الوكلاء أنفسهم راجع صفحة وكلاء البرمجة.