Ir para o conteúdo
fedi.software

Skills para agentes

Skills para Claude Code, Codex, Cursor e outros agentes do diretório skills.sh: instalações, status da auditoria de segurança e o comando para adicionar cada skill.

Uma skill não fica presa a um agente: npx skills add a instala em qualquer agente compatível. Sem -a, a CLI encontra os agentes do seu computador e pergunta onde adicioná-la.

Atualizado · Fontes: skills.sh

Exibidas: 100 · encontradas: 321 · de 10.000 no diretório

  • code-review mattpocock/skills

    Review the changes since a fixed point (commit, branch, tag, or merge-base) along two axes: Standards (does the code follow this repo's documented coding standards?) and Spec (does the code match what the originating issue/spec asked for?). Runs both reviews in parallel sub-agents and reports them side by side. Use when the user wants to review a branch, a PR, work-in-progress changes, or asks to "review since X".

    669.376 Reprovada
  • git-guardrails-claude-code mattpocock/skills

    Set up Claude Code hooks to block dangerous git commands (push, reset --hard, clean, branch -D, etc.) before they execute. Use when user wants to prevent destructive git operations, add git safety hooks, or block git push/reset in Claude Code.

    430.155 Alertas
  • setup-pre-commit mattpocock/skills

    Set up Husky pre-commit hooks with lint-staged (Prettier), type checking, and tests in the current repo. Use when user wants to add pre-commit hooks, set up Husky, configure lint-staged, or add commit-time formatting/typechecking/testing.

    420.595 Alertas
  • caveman-commit juliusbrussee/caveman

    Write a Conventional Commits message compressed to intent only. Use for "write a commit", "commit message", /commit or /caveman-commit.

    391.990 Aprovada
  • caveman-review juliusbrussee/caveman

    Compressed code review - one line per finding with location, problem and fix. Use for /caveman-review, "review this PR", or "review the diff".

    387.998 Alertas
  • pr-to-video heygen-com/hyperframes

    Turn a GitHub pull request (a PR URL, owner/repo#N, or 'this PR' in a checked-out repo) into a code-change explainer video — changelog, feature reveal, fix, or refactor walkthrough built from the diff, commits, and files: the input is a code change, not a website. Not a product promo (/product-launch-video) or a no-PR topic explainer (/faceless-explainer). Unclear → /hyperframes.

    310.083 Aprovada
  • requesting-code-review obra/superpowers

    Use when completing tasks, implementing major features, or before merging to verify work meets requirements

    242.681 Aprovada
  • receiving-code-review obra/superpowers

    Use when receiving code review feedback, before implementing suggestions, especially if feedback seems unclear or technically questionable - requires technical rigor and verification, not performative agreement or blind implementation

    206.044 Alertas
  • using-git-worktrees obra/superpowers

    Use when starting feature work that needs isolation from current workspace or before executing implementation plans - ensures an isolated workspace exists via native tools or git worktree fallback

    202.396 Aprovada
  • code-review-and-quality addyosmani/agent-skills

    Conducts multi-axis code review. Use before merging any change. Use when reviewing code written by yourself, another agent, or a human. Use when you need to assess code quality across multiple dimensions before it enters the main branch. Use when asked to review a diff or a pull request, even when the diff is pasted inline.

    55.579 Alertas
  • public-relations coreyhaines31/marketingskills

    When the user wants help with public relations, earned media, press coverage, journalist outreach, or media strategy (not pull requests). Also use when the user mentions 'PR,' 'public relations,' 'press,' 'press release,' 'press coverage,' 'media outreach,' 'pitch a journalist,' 'get featured,' 'media list,' 'media kit,' 'press kit,' 'newsjacking,' 'news hijack,' 'HARO,' 'Qwoted,' 'Featured,' 'Help A Reporter,' 'reporter request,' 'tech press,' 'TechCrunch,' 'earned media,' 'thought leadership placement,' 'op-ed,' 'guest article,' 'press contacts,' 'podcast prep,' 'going on a podcast,' 'podcast guest,' 'prep me for this podcast,' or 'how do I get press.' Use this for earned media work — finding journalists, pitching stories, newsjacking, prepping podcast appearances, and responding to press requests. For startup/SaaS/AI directory submissions, see directory-submissions. For product launches, see launch. For social-media engagement, see social. For cold-email outreach to prospects, see cold-email.

    46.754 Alertas
  • git-commit github/awesome-copilot

    Execute git commit with conventional commit message analysis, intelligent staging, and message generation. Use when user asks to commit changes, create a git commit, or mentions "/commit". Supports: (1) Auto-detecting type and scope from changes, (2) Generating conventional commit messages from diff, (3) Interactive commit with optional type/scope/description overrides, (4) Intelligent file staging for logical grouping

    45.879 Aprovada
  • git-workflow-and-versioning addyosmani/agent-skills

    Structures git workflow practices. Use when making any code change. Use when committing, branching, resolving conflicts, splitting uncommitted work in a messy working tree into clean atomic commits, opening or reviewing a pull request (PR), pushing to a remote, or when you need to organize work across multiple parallel streams. Use when cutting a release, choosing a semantic version bump, tagging, or writing a changelog.

    44.214 Alertas
  • golang-continuous-integration samber/cc-skills-golang

    GitHub Actions CI/CD pipeline configuration for Golang projects — workflow files for test, lint, SAST, coverage and vulnerability-scan jobs, Dependabot and Renovate config files, GoReleaser release pipelines, Docker build/push, repository security settings, and AI-driven PR review. Use when setting up or improving Go project CI, writing or fixing `.github/workflows/*.yml`, adding a linter or security scanner as a pipeline job, wiring automated dependency-update bots, or adding quality gates. Covers wiring tools into a pipeline, not the analysis they perform: do NOT use for choosing or interpreting security findings (→ See `samber/cc-skills-golang@golang-security` skill) or for choosing, upgrading, or auditing dependency versions (→ See `samber/cc-skills-golang@golang-dependency-management` skill).

    35.667 Alertas
  • ponytail-review dietrichgebert/ponytail

    Code review focused exclusively on over-engineering. Finds what to delete: reinvented standard library, unneeded dependencies, speculative abstractions, dead flexibility. One line per finding: location, what to cut, what replaces it. Use when the user says "review for over-engineering", "what can we delete", "is this over-engineered", "simplify review", or invokes /ponytail-review. Complements correctness-focused review, this one only hunts complexity.

    32.309 Aprovada
  • code-review-excellence wshobson/agents

    Master effective code review practices to provide constructive feedback, catch bugs early, and foster knowledge sharing while maintaining team morale. Use when reviewing pull requests, establishing review standards, or mentoring developers.

    29.208 Aprovada
  • review-pr warpdotdev/common-skills

    Review a pull request diff and write structured feedback to review.json for the workflow to publish. Use when reviewing a checked-out PR from local artifacts like pr_diff.txt and pr_description.txt and producing machine-readable review output instead of posting directly to GitHub.

    27.725 Alertas
  • resolve-merge-conflicts warpdotdev/common-skills

    Resolve Git merge conflicts by extracting only unresolved paths, conflict hunks, and compact diffs instead of loading whole files into context. Use when a merge, rebase, cherry-pick, or stash pop stops on conflicts, when `git status` shows unmerged paths, or when files contain conflict markers.

    27.364 Aprovada
  • create-pr warpdotdev/common-skills

    Create a pull request in the warp repository for the current branch. Use when the user mentions opening a PR, creating a pull request, submitting changes for review, or preparing code for merge.

    27.311 Aprovada
  • diagnose-ci-failures warpdotdev/common-skills

    Diagnose CI failures for a PR using the GitHub CLI, extract error logs, and generate a plan to fix them. Use when the user asks to check CI status, pull CI issues, triage test failures, or investigate PR build failures.

    27.258 Alertas
  • pr-walkthrough warpdotdev/common-skills

    Generate a static interactive D3 walkthrough of a pull request. Use when the user wants a zoomable PR map, graph/canvas PR orientation, or alternate visualization of PR system components, data flow, code dependencies, and user actions.

    26.945 Alertas
  • check-impl-against-spec warpdotdev/common-skills

    Compare a pull request's implementation against spec context in spec_context.md and feed any material mismatches into review.json. Use during PR review when approved or repository spec context is available.

    25.806 Aprovada
  • respond-to-pr-comments-in-blocklist warpdotdev/common-skills

    Interactively walk a user through PR review comments one at a time, collect a per-comment decision, then post agent-authored replies on GitHub and resolve the review threads once the user approves a preview. Use only when the user wants to reply to or resolve review threads on GitHub. Skip when the user only wants comments fetched or displayed (use `pr-comments`), or only wants the code changes made without posting anything back to GitHub.

    23.996 Alertas
  • validate-changes-match-specs warpdotdev/common-skills

    Validate that a branch or pull request implementation matches introduced product, technical, security, and related specs. Use when reviewing or finishing a spec-driven change and resolving mismatches between checked-in specs and implementation.

    23.956 Alertas
  • gh-issue-sync mitsuhiko/gh-issue-sync

    Manage GitHub issues locally as Markdown files. Use for triaging, searching, editing, and creating issues without leaving your editor or terminal.

    18.945 Alertas
  • security-review getsentry/skills

    Security code review for vulnerabilities. Use when asked to "security review", "find vulnerabilities", "check for security issues", "audit security", "OWASP review", or review code for injection, XSS, authentication, authorization, cryptography issues. Provides systematic review with confidence-based reporting.

    18.924 Reprovada
  • git-advanced-workflows wshobson/agents

    Master advanced Git workflows including rebasing, cherry-picking, bisect, worktrees, and reflog to maintain clean history and recover from any situation. Use when managing complex Git histories, collaborating on feature branches, or troubleshooting repository issues.

    18.618 Alertas
  • github-issues github/awesome-copilot

    Create, update, and manage GitHub issues using MCP tools. Use this skill when users want to create bug reports, feature requests, or task issues, update existing issues, add labels/assignees/milestones, manage repository labels, set issue fields (dates, priority, custom fields), set issue types, manage issue workflows, link issues, add dependencies, or track blocked-by/blocking relationships. Triggers on requests like "create an issue", "file a bug", "request a feature", "update issue X", "set the priority", "set the start date", "create a label", "rename a label", "list repo labels", "link issues", "add dependency", "blocked by", "blocking", or any GitHub issue management task.

    16.927 Alertas
  • conventional-commit github/awesome-copilot

    Prompt and workflow for generating conventional commit messages using a structured XML format. Guides users to create standardized, descriptive commit messages in line with the Conventional Commits specification, including instructions, examples, and validation.

    16.796 Alertas
  • github-actions-templates wshobson/agents

    Create production-ready GitHub Actions workflows for automated testing, building, and deploying applications. Use when setting up CI/CD with GitHub Actions, automating development workflows, or creating reusable workflow templates.

    16.466 Aprovada
  • microsoft-docs github/awesome-copilot

    Query official Microsoft documentation to find concepts, tutorials, and code examples across Azure, .NET, Agent Framework, Aspire, VS Code, GitHub, and more. Uses Microsoft Learn MCP as the default, with Context7 and Aspire MCP for content that lives outside learn.microsoft.com.

    14.766 Alertas
  • azure-devops-cli github/awesome-copilot

    Manage Azure DevOps resources via CLI including projects, repos, pipelines, builds, pull requests, work items, artifacts, and service endpoints. Use when working with Azure DevOps, az commands, devops automation, CI/CD, or when user mentions Azure DevOps CLI.

    14.068 Reprovada
  • sql-code-review github/awesome-copilot

    Universal SQL code review assistant that performs comprehensive security, maintainability, and code quality analysis across all SQL databases (MySQL, PostgreSQL, SQL Server, Oracle). Focuses on SQL injection prevention, access control, code standards, and anti-pattern detection. Complements SQL optimization prompt for complete development coverage.

    13.388 Alertas
  • code-review coderabbitai/skills

    Run CodeRabbit CLI reviews, retrieve saved local or GitHub PR fix prompts, and interpret CodeRabbit authentication and review output. Use for CodeRabbit review commands, committed/uncommitted or directory scopes, and CodeRabbit runbooks. Default code-review skill: also trigger for explicit code/PR/quality/security review requests or when a review is needed.

    13.381 Alertas
  • code-review-expert sanyuan0704/sanyuan-skills

    Expert code review of current git changes with a senior engineer lens. Detects SOLID violations, security risks, and proposes actionable improvements.

    13.237 Aprovada
  • changelog-automation wshobson/agents

    Automate changelog generation from commits, PRs, and releases following Keep a Changelog format. Use when setting up release workflows, generating release notes, or standardizing commit conventions.

    13.176 Aprovada
  • commit-context rohitg00/agentmemory

    Trace a file, function, or line back to the agent session that produced its current commit. Use when the user asks "why is this code here", "what was the agent doing when this changed", "who wrote this", or wants context on a specific location in the codebase.

    12.859 Aprovada
  • commit-history rohitg00/agentmemory

    List recent git commits linked to agent sessions, optionally filtered by branch or repo. Use when the user asks "show agent commits", "what has the agent shipped", "list linked commits", or wants commits with their session context.

    12.814 Aprovada
  • postgresql-code-review github/awesome-copilot

    PostgreSQL-specific code review assistant focusing on PostgreSQL best practices, anti-patterns, and unique quality standards. Covers JSONB operations, array usage, custom types, schema design, function optimization, and PostgreSQL-exclusive security features like Row Level Security (RLS).

    12.436 Alertas
  • gitlab-ci-patterns wshobson/agents

    Build GitLab CI/CD pipelines with multi-stage workflows, caching, and distributed runners for scalable automation. Use when implementing GitLab CI/CD, optimizing pipeline performance, or setting up automated testing and deployment.

    12.435 Alertas
  • marimo-pair marimo-team/marimo-pair

    Drive a live marimo notebook as a workspace: run Python in the same kernel the user does, inspect live notebook state, and commit durable notebook changes. Use when the user wants to start a marimo notebook or pair on an active marimo session.

    11.435 Reprovada
  • adding-dependencies riekelt/principal-engineer

    Use when about to add, update, vet, or remove a dependency - a package, library, SDK, GitHub action, base image, or vendored code - or when a project's dependency posture needs declaring. Encodes the exhaust-what-you-have ladder, the vetting questions, and pin-and-prove updating. Use even for a tiny utility package: that is exactly how the tree grows.

    11.390 Alertas
  • ci-security-scanning-with-strix usestrix/strix

    Add security scanning to CI/CD with Strix — GitHub Actions, GitLab CI, or any pipeline — so every pull request gets a diff-scoped AI pentest that blocks vulnerable code before it merges, with results as PR comments and SARIF uploaded to code scanning. Covers both the self-hosted open-source CLI (runs in your runner) and the managed app.strix.ai platform (GitHub/GitLab app or API, no runner infra). Use when the user asks to add security scanning, SAST/DAST, pentesting, vulnerability checks, or automated security review to their CI pipeline, pre-merge gate, or PR workflow.

    11.130 Alertas
  • cpp-coding-standards affaan-m/ecc

    C++ coding standards based on the C++ Core Guidelines (isocpp.github.io). Use when writing, reviewing, or refactoring C++ code to enforce modern, safe, and idiomatic practices.

    10.845 Aprovada
  • gh-fix-ci openai/skills

    Use when a user asks to debug or fix failing GitHub PR checks that run in GitHub Actions; use `gh` to inspect checks and logs, summarize failure context, draft a fix plan, and implement only after explicit approval. Treat external providers (for example Buildkite) as out of scope and report only the details URL.

    10.768 Alertas
  • convert-documents-to-markdown firecrawl/anydoc

    Convert Word (.doc, .docx), PowerPoint (.ppt, .pptx), Excel (.xls, .xlsx), OpenDocument (.odt, .ods, .odp), RTF, EPUB, CSV, and PDF files to GitHub-Flavored Markdown. Use when a task needs the contents of an office document, spreadsheet, presentation, ebook, or PDF you cannot read directly.

    10.693 Aprovada
  • create-github-action-workflow-specification github/awesome-copilot

    Create a formal specification for an existing GitHub Actions CI/CD workflow, optimized for AI consumption and workflow maintenance.

    10.611 Alertas
  • workflow-patterns wshobson/agents

    Use this skill when implementing tasks according to Conductor's TDD workflow, handling phase checkpoints, managing git commits for tasks, or understanding the verification protocol.

    10.495 Aprovada
  • companion-clis runpod/runpod-plugins-official

    Companion CLIs for Runpod workflows — HuggingFace, GitHub, Docker, and AWS. Use the ComfyUI model-repair guide in runpod-templates instead when an imported ComfyUI workflow lacks model download metadata.

    10.044 Alertas
  • frontend-code-review langgenius/dify

    Use only when the user explicitly requests a review or audit of frontend code under `web/` or `packages/dify-ui/`. Supports pending-change, file-focused, and pasted-diff reviews. Do not use for implementation-only requests, diagnosis without review intent, or backend-only code.

    9.959 Alertas
  • search-first affaan-m/ecc

    Research-before-coding workflow: search npm/PyPI, MCP servers, skills, and GitHub for existing tools before writing custom code, then adopt, extend, or build. Launches the researcher agent for non-trivial needs. Use when starting a feature, adding a dependency or integration, or about to write a utility that may already exist.

    9.765 Alertas
  • my-pull-requests github/awesome-copilot

    9.711 Alertas
  • github-actions callstackincubator/agent-skills

    GitHub Actions workflow patterns for React Native iOS simulator and Android emulator cloud builds with downloadable artifacts. Use when setting up CI build pipelines or downloading GitHub Actions artifacts via gh CLI and GitHub API.

    9.689 Reprovada
  • git-flow-branch-creator github/awesome-copilot

    Intelligent Git Flow branch creator that analyzes git status/diff and creates appropriate branches following the nvie Git Flow branching model.

    9.678 Alertas
  • code-review anthropics/knowledge-work-plugins

    Review code changes for security, performance, and correctness. Trigger with a PR URL or diff, "review this before I merge", "is this code safe?", or when checking a change for N+1 queries, injection risks, missing edge cases, or error handling gaps.

    9.631 Alertas
  • genshijin-commit interfacex-co-jp/genshijin

    超圧縮コミットメッセージ生成。Conventional Commits形式で件名≤50文字、 「何を」より「なぜ」を重視。日本語・英語両対応。 「コミットメッセージ作って」「/commit」「/genshijin-commit」で起動。 ステージング変更時に自動起動候補。

    9.564 Aprovada
  • baoyu-wechat-summary jimliu/baoyu-skills

    Summarizes WeChat group chat highlights into a structured digest using the local wx-cli binary (https://github.com/jackwener/wx-cli). Generates a normal digest by default; a roast (毒舌) version is opt-in. Maintains per-group history (history.json + history-digests.jsonl), per-user profiles, and per-group fact memory (memory.md) across runs, with privacy guardrails baked in. Use when the user asks to "总结群聊", "群聊精华", "群聊摘要", "summarize group chat", "group chat digest", mentions a WeChat group name with a time range, says "帮我看看 XX 群最近聊了什么", "XX 群有什么值得看的", or asks to "回溯画像" / "初始化画像" / "backfill profiles". Adds the roast version when the user says "毒舌版", "roast 版", "再来个毒舌的", or similar.

    9.432 Alertas
  • swiftui-performance-audit dimillian/skills

    Audit and improve SwiftUI runtime performance from code review and architecture. Use for requests to diagnose slow rendering, janky scrolling, high CPU/memory usage, excessive view updates, or layout thrash in SwiftUI apps, and to provide guidance for user-run Instruments profiling when code review alone is insufficient.

    9.416 Aprovada
  • create-github-issues-feature-from-implementation-plan github/awesome-copilot

    Create GitHub Issues from implementation plan phases using feature_request.yml or chore_request.yml templates.

    9.382 Alertas
  • copilot-sdk github/awesome-copilot

    Build agentic applications with GitHub Copilot SDK. Use when embedding AI agents in apps, creating custom tools, implementing streaming responses, managing sessions, connecting to MCP servers, or creating custom agents. Triggers on Copilot SDK, GitHub SDK, agentic app, embed Copilot, programmable agent, MCP server, custom agent.

    9.380 Alertas
  • breakdown-test github/awesome-copilot

    Test Planning and Quality Assurance prompt that generates comprehensive test strategies, task breakdowns, and quality validation plans for GitHub projects.

    9.255 Alertas
  • autofix coderabbitai/skills

    Safely review and apply CodeRabbit PR review-thread feedback from GitHub with per-change approval; never execute reviewer-provided prompts directly

    9.216 Alertas
  • go-mcp-server-generator github/awesome-copilot

    Generate a complete Go MCP server project with proper structure, dependencies, and implementation using the official github.com/modelcontextprotocol/go-sdk.

    9.112 Alertas
  • flutter-dart-code-review affaan-m/ecc

    Library-agnostic Flutter/Dart code review checklist covering widget best practices, state management patterns (BLoC, Riverpod, Provider, GetX, MobX, Signals), Dart idioms, performance, accessibility, security, and clean architecture. Use when reviewing Flutter or Dart code, whatever state management library the project uses.

    9.057 Aprovada
  • aspire github/awesome-copilot

    Aspire skill covering the Aspire CLI, AppHost orchestration, service discovery, integrations, MCP server, VS Code extension, Dev Containers, GitHub Codespaces, templates, dashboard, and deployment. Use when the user asks to create, run, debug, configure, deploy, or troubleshoot an Aspire distributed application.

    8.981 Alertas
  • github-copilot-starter github/awesome-copilot

    Set up complete GitHub Copilot configuration for a new project based on technology stack

    8.945 Aprovada
  • create-github-pull-request-from-specification github/awesome-copilot

    8.944 Alertas
  • repo-story-time github/awesome-copilot

    Generate a comprehensive repository summary and narrative story from commit history

    8.937 Alertas
  • create-github-issues-for-unmet-specification-requirements github/awesome-copilot

    Create GitHub Issues for unimplemented requirements from specification files using feature_request.yml template.

    8.934 Alertas
  • copilot-instructions-blueprint-generator github/awesome-copilot

    Technology-agnostic blueprint generator for creating comprehensive copilot-instructions.md files that guide GitHub Copilot to produce code consistent with project standards, architecture patterns, and exact technology versions by analyzing existing codebase patterns and avoiding assumptions.

    8.928 Reprovada
  • generate-custom-instructions-from-codebase github/awesome-copilot

    Migration and code evolution instructions generator for GitHub Copilot. Analyzes differences between two project versions (branches, commits, or releases) to create precise instructions allowing Copilot to maintain consistency during technology migrations, major refactoring, or framework version upgrades.

    8.917 Alertas
  • create-github-issue-feature-from-specification github/awesome-copilot

    Create GitHub Issue for feature request from specification file using feature_request.yml template.

    8.901 Alertas
  • data-scraper-agent affaan-m/ecc

    Build a fully automated AI-powered data collection agent for any public source — job boards, prices, news, GitHub, sports, anything. Runs on a schedule, enriches data with a free LLM (Gemini Flash), stores results in Notion/Sheets/Supabase, and learns from user feedback. Runs 100% free on GitHub Actions. Use when the user wants to monitor, collect, or track any public data automatically.

    8.901 Alertas
  • suggest-awesome-github-copilot-skills github/awesome-copilot

    Suggest relevant GitHub Copilot skills from the awesome-copilot repository based on current repository context and chat history, avoiding duplicates with existing skills in this repository, and identifying outdated skills that need updates.

    8.894 Alertas
  • git-workflow affaan-m/ecc

    Git workflow patterns including branching strategies, commit conventions, keeping history clean and readable, tidying local commits before merging, merge vs rebase, conflict resolution, and collaborative development best practices for teams of all sizes. Use when choosing a branching strategy, writing commit conventions, cleaning up history before a pull request, deciding merge versus rebase, or resolving conflicts.

    8.809 Aprovada
  • copilot-cli-quickstart github/awesome-copilot

    Use this skill when someone wants to learn GitHub Copilot CLI from scratch. Offers interactive step-by-step tutorials with separate Developer and Non-Developer tracks, plus on-demand Q&A. Just say "start tutorial" or ask a question! Note: This skill targets GitHub Copilot CLI specifically and uses CLI-specific tools (ask_user, sql, fetch_copilot_cli_documentation).

    8.779 Alertas
  • suggest-awesome-github-copilot-agents github/awesome-copilot

    Suggest relevant GitHub Copilot Custom Agents files from the awesome-copilot repository based on current repository context and chat history, avoiding duplicates with existing custom agents in this repository, and identifying outdated agents that need updates.

    8.772 Alertas
  • tldr-prompt github/awesome-copilot

    Create tldr summaries for GitHub Copilot files (prompts, agents, instructions, collections), MCP servers, or documentation from URLs and queries.

    8.762 Aprovada
  • suggest-awesome-github-copilot-instructions github/awesome-copilot

    Suggest relevant GitHub Copilot instruction files from the awesome-copilot repository based on current repository context and chat history, avoiding duplicates with existing instructions in this repository, and identifying outdated instructions that need updates.

    8.752 Reprovada
  • copilot-usage-metrics github/awesome-copilot

    Retrieve and display GitHub Copilot usage metrics for organizations and enterprises using the GitHub CLI and REST API.

    8.718 Alertas
  • sponsor-finder github/awesome-copilot

    Find which of a GitHub repository's dependencies are sponsorable via GitHub Sponsors. Uses deps.dev API for dependency resolution across npm, PyPI, Cargo, Go, RubyGems, Maven, and NuGet. Checks npm funding metadata, FUNDING.yml files, and web search. Verifies every link. Shows direct and transitive dependencies with OSSF Scorecard health data. Invoke with /sponsor followed by a GitHub owner/repo (e.g. "/sponsor expressjs/express").

    8.672 Alertas
  • az-cost-optimize github/awesome-copilot

    Analyze Azure resources used in the app (IaC files and/or resources in a target rg) and optimize costs - creating GitHub issues for identified optimizations.

    8.660 Alertas
  • benchmark affaan-m/ecc

    Measure performance baselines and detect regressions across browser Core Web Vitals (LCP, INP, CLS, page weight), API endpoint latency percentiles, and build/test feedback times, with before/after comparison stored in git-tracked .ecc/benchmarks JSON. Use when checking page speed, responding to 'it feels slow' reports, verifying launch performance targets, or comparing stack alternatives.

    8.139 Alertas
  • cargo-context getcargohq/cargo-skills

    Read and write the workspace GTM knowledge base — the git-backed repository of markdown describing ICPs, personas, plays, proof points, objections, competitors, and signals — plus its runtime sandbox and typed knowledge graph. Triggers: "document our ICP", "write up this persona", "what is our positioning", "add a battlecard", "capture this objection", "what do we know about <segment>", "update our context", "what is in the context repo", "who do we sell to". Skip when: discovering who actually buys from you by analyzing won/lost data — that is cargo-gtm (this skill writes the conclusion down, it does not derive it); storing structured records rather than prose — use cargo-storage; attaching documents to an agent for RAG — use cargo-content.

    8.099 Aprovada
  • repo-scan affaan-m/ecc

    Bootstrap pointer that installs the external repo-scan skill from a pinned, reviewable commit. Use when repo-scan must be installed before running its cross-stack source-code asset audit; this ECC pointer does not perform the audit itself.

    8.044 Alertas
  • safety-guard affaan-m/ecc

    Guard against destructive operations with three modes: Careful intercepts dangerous commands (rm -rf, git push --force, DROP TABLE) for confirmation, Freeze locks writes to one directory, and Guard combines both via PreToolUse hooks. Use when working on production systems, running agents autonomously, restricting edits to a directory, or during migrations, deploys, and data changes.

    8.041 Aprovada
  • 8.018 Alertas
  • github-ops affaan-m/ecc

    GitHub repository operations, automation, and management. Issue triage, PR management, CI/CD operations, release management, and security monitoring using the gh CLI. Use when the user wants to manage GitHub issues, PRs, CI status, releases, contributors, stale items, or any GitHub operational task beyond simple git commands.

    7.770 Alertas
  • knowledge-ops affaan-m/ecc

    Knowledge base management, ingestion, sync, and retrieval across multiple storage layers (local files, MCP memory, vector stores, Git repos). Use when the user wants to save, organize, sync, deduplicate, or search across their knowledge systems.

    7.732 Alertas
  • project-flow-ops affaan-m/ecc

    Operate execution flow across GitHub and Linear by triaging issues and pull requests, linking active work, and keeping GitHub public-facing while Linear remains the internal execution layer. Use when the user wants backlog control, PR triage, or GitHub-to-Linear coordination.

    7.649 Alertas
  • unified-notifications-ops affaan-m/ecc

    Operate notifications as one ECC-native workflow across GitHub, Linear, desktop alerts, hooks, and connected communication surfaces. Use when the real problem is alert routing, deduplication, escalation, or inbox collapse.

    7.503 Aprovada
  • ci-cd-security superagent-ai/skills

    Scan GitHub Actions workflow files for security vulnerabilities by reading the YAML and reporting findings directly — no external tools, no installation, no shell execution. Use this skill whenever the user shares a `.github/workflows/` file, pastes workflow YAML, asks for a CI/CD security review, mentions `pull_request_target`, `workflow_run`, action pinning, `GITHUB_TOKEN` permissions, pwn requests, template injection, cache poisoning, secret exfiltration, supply chain risk, or any GitHub Actions hardening topic. Also trigger when the user is hardening an OSS repo, doing a CI/CD red team assessment, evaluating a target for supply-chain scanning, or writing publicly about CI/CD security. Bias toward triggering this skill rather than answering from memory — CI/CD security defaults are wrong almost everywhere and the rules are unintuitive.

    7.270 Reprovada
  • changelog-generator composiohq/awesome-claude-skills

    Automatically creates user-facing changelogs from git commits by analyzing commit history, categorizing changes, and transforming technical commits into clear, customer-friendly release notes. Turns hours of manual changelog writing into minutes of automated generation.

    6.969 Aprovada
  • suggest-awesome-github-copilot-prompts github/awesome-copilot

    6.765 Alertas
  • bmad-code-review bmad-code-org/bmad-method

    Review code changes with several independent reviewers in parallel, then triage and present the findings. Use when the user says "run code review" or "review this code"

    6.719 Alertas
  • k-skill-setup nomadamas/k-skill

    Install the k-skill bundle, use the unified CLI, resolve credentials, verify the runtime, and optionally configure update checks and GitHub starring.

    6.702 Alertas
  • bmad-retrospective bmad-code-org/bmad-method

    Review a finished epic folder in the ticket tree against the evidence it left behind — the epic file, each ticket plan, diffs, commits — and produce a retrospective with sourced findings, action items, and an acceptance decision. Use when the user says "run a retrospective" or "lets retro the epic [epic]". Supports -H/--headless

    6.363 Alertas
  • agentic-actions-auditor trailofbits/skills

    Audits GitHub Actions workflows for security vulnerabilities in AI agent integrations including Claude Code Action, Gemini CLI, OpenAI Codex, and GitHub AI Inference. Detects attack vectors where attacker-controlled input reaches AI agents running in CI/CD pipelines, including env var intermediary patterns, direct expression injection, dangerous sandbox configurations, and wildcard user allowlists. Use when reviewing workflow files that invoke AI coding agents, auditing CI/CD pipeline security for prompt injection risks, or evaluating agentic action configurations.

    6.244 Alertas
  • firecrawl-developer-index firecrawl/skills

    Search an index of public repositories, GitHub issues, merged pull requests, repository READMEs, and curated documentation sites. Use when a programming question needs external documentation or upstream evidence.

    6.075 Alertas
  • open-code-review alibaba/open-code-review

    Performs AI-powered code review on Git changes using the `ocr` CLI from alibaba/open-code-review. Use when the user asks to review code, review a pull request, review staged/unstaged changes, review a commit, or compare branches for code quality issues. Produces line-level review comments and can automatically apply fixes when requested. With appropriate review rules, can detect various types of issues including bugs, security vulnerabilities, performance problems, and code quality concerns.

    6.035 Aprovada

As descrições são dos próprios autores, em inglês. Leia o código de uma skill no repositório dela antes de instalá-la.

O que é uma skill

Uma skill é uma pasta com um arquivo SKILL.md e, opcionalmente, scripts, que um agente de IA carrega quando a tarefa combina com ela. Funciona como um manual especializado: em vez de explicar tudo de novo a cada conversa, o agente lê as instruções da skill na hora certa. Este diretório reúne skills do skills.sh para Claude Code, Codex, Cursor e outros agentes.

O que a página mostra

  • nome, autor e repositório de cada skill;
  • número de instalações e status da auditoria de segurança;
  • o comando para adicionar a skill, com o botão “Copiar o comando”.

O diretório traz as 10 000 skills mais instaladas, sincronizadas diariamente. A aba “Em alta” ordena pelas instalações ganhas nos últimos 7 dias. Há filtros por tema e por agente, além da busca; cada visualização mostra no máximo 100 skills.

Como ler a auditoria

Os status vêm das auditorias publicadas pelo skills.sh: “Aprovada”, “Alertas”, “Reprovada” e “Não auditada”. Uma auditoria aprovada não é garantia. Skills podem incluir scripts que rodam na sua máquina, então leia o código no repositório antes de instalar, principalmente se ela pede acesso a arquivos, rede ou credenciais.

Passo a passo para instalar com cuidado

  1. Filtre pelo agente que você usa e pelo tema da tarefa.
  2. Abra o repositório e leia o SKILL.md e os scripts.
  3. Prefira skills com status “Aprovada” e autor identificável.
  4. Copie o comando e instale num projeto de teste antes de usar no trabalho.

Observações

As descrições são dos próprios autores, em inglês, e não são traduzidas. As instalações são contadas pelo skills.sh. Para escolher o agente que vai usar as skills, veja os agentes de programação.