Skip to content
fedi.software

Agent skills

Skills for Claude Code, Codex, Cursor and other agents from the skills.sh directory: installs, security audit status and the command to add a skill.

A skill is not tied to one agent: npx skills add installs it into any supported one. Without -a the CLI finds the agents on your computer and asks where to add it.

Updated · Sources: skills.sh

Shown: 27 · found: 27 · of 10,000 in the directory

  • firebase-data-connect firebase/agent-skills

    Builds and deploys Firebase SQL Connect (aka Firebase Data Connect) backends with PostgreSQL securely. Use when designing schemas with tables and relations, writing authorized queries and mutations, configuring real-time data updates, or generating type-safe SDKs. Use when you need a relational database with Firebase, or when the user mentions SQL Connect or Data Connect.

    158,551 Failed
  • mysql planetscale/database-skills

    Plan and review MySQL/InnoDB schema, indexing, query tuning, transactions, and operations. Use when creating or modifying MySQL tables, indexes, or queries; diagnosing slow/locking behavior; planning migrations; or troubleshooting replication and connection issues. Load when using a MySQL database.

    8,113 Failed
  • postgres planetscale/database-skills

    PostgreSQL best practices, query optimization, connection troubleshooting, and performance improvement. Load when working with Postgres databases.

    7,963 Failed
  • use-railway railwayapp/railway-skills

    Operate Railway infrastructure: sign up for or sign in to a Railway account, create projects, provision services, databases, and buckets, deploy code, configure infrastructure as code, environments and variables, manage domains, trace requests with OpenTelemetry, troubleshoot failures, check status and metrics, manage feature flags, database recovery and HA, cloud agents, usage limits, and Railway agent tooling. Use this skill whenever the user mentions Railway, feature flags, flag rollout, targeting rules, signing up, creating an account, registering, logging in, deployments, services, environments, buckets, object storage, tracing, traces, spans, OpenTelemetry, OTLP, build failures, agent setup, MCP, or infrastructure operations, even if they don't say "Railway" explicitly. Also invoke this skill when the user asks to be signed up, registered, or onboarded to Railway: do not refuse — drive them through the unauthed `railway up` flow (deploys + signs up on the fly) or `railway login` (which creates new accounts on the fly).

    7,643 Failed
  • postgres-pro jeffallan/claude-skills

    Use when optimizing PostgreSQL queries, configuring replication, or implementing advanced database features. Invoke for EXPLAIN analysis, JSONB operations, extension usage, VACUUM tuning, performance monitoring.

    7,448 Failed
  • clickhouse-managed-postgres-rca clickhouse/agent-skills

    MUST USE when investigating performance issues on a ClickHouse-managed Postgres instance. Provides an evidence-based RCA workflow that scrapes the Prometheus endpoint for system signal, pulls per-digest evidence from the Slow Query Patterns API, and recommends (does not apply) a fix.

    6,345 Failed
  • code-reviewer jeffallan/claude-skills

    Analyzes code diffs and files to identify bugs, security vulnerabilities (SQL injection, XSS, insecure deserialization), code smells, N+1 queries, naming issues, and architectural concerns, then produces a structured review report with prioritized, actionable feedback. Use when reviewing pull requests, conducting code quality audits, identifying refactoring opportunities, or checking for security issues. Invoke for PR reviews, code quality checks, refactoring suggestions, review code, code quality. Complements specialized skills (security-reviewer, test-master) by providing broad-scope review across correctness, performance, maintainability, and test coverage in a single pass.

    6,049 Failed
  • sql-pro jeffallan/claude-skills

    Optimizes SQL queries, designs database schemas, and troubleshoots performance issues. Use when a user asks why their query is slow, needs help writing complex joins or aggregations, mentions database performance issues, or wants to design or migrate a schema. Invoke for complex queries, window functions, CTEs, indexing strategies, query plan analysis, covering index creation, recursive queries, EXPLAIN/ANALYZE interpretation, before/after query benchmarking, or migrating queries between database dialects (PostgreSQL, MySQL, SQL Server, Oracle).

    5,996 Failed
  • database-optimizer jeffallan/claude-skills

    Optimizes database queries and improves performance across PostgreSQL and MySQL systems. Use when investigating slow queries, analyzing execution plans, or optimizing database performance. Invoke for index design, query rewrites, configuration tuning, partitioning strategies, lock contention resolution.

    5,496 Failed
  • secure-code-guardian jeffallan/claude-skills

    Use when implementing authentication/authorization, securing user input, or preventing OWASP Top 10 vulnerabilities — including custom security implementations such as hashing passwords with bcrypt/argon2, sanitizing SQL queries with parameterized statements, configuring CORS/CSP headers, validating input with Zod, and setting up JWT tokens. Invoke for authentication, authorization, input validation, encryption, OWASP Top 10 prevention, secure session management, and security hardening. For pre-built OAuth/SSO integrations or standalone security audits, consider a more specialized skill.

    4,695 Failed
  • security-ownership-map openai/skills

    Analyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensitive-code ownership, and export CSV/JSON for graph databases and visualization. Trigger only when the user explicitly wants a security-oriented ownership or bus-factor analysis grounded in git history (for example: orphaned sensitive code, security maintainers, CODEOWNERS reality checks for risk, sensitive hotspots, or ownership clusters). Do not trigger for general maintainer lists or non-security ownership questions.

    3,553 Failed
  • qdrant giuseppe-trisciuoglio/developer-kit

    Provides Qdrant vector database integration patterns with LangChain4j. Handles embedding storage, similarity search, and vector management for Java applications. Use when implementing vector-based retrieval for RAG systems, semantic search, or recommendation engines.

    3,553 Failed
  • redis-development redis/agent-skills

    3,148 Failed
  • infra-postgres clickhouse/agent-skills

    Sets up and manages Postgres using the clickhousectl CLI — runs a local Docker-backed Postgres for development, and creates and operates managed ClickHouse Cloud Postgres services (connections, TLS, runtime config, read replicas, failover, point-in-time restore). Use when the user wants a Postgres or PostgreSQL database for their application, a local Postgres dev environment, psql access, or a managed/production Postgres in ClickHouse Cloud, or mentions moving a local Postgres to production. Also use when migrating an existing Postgres database (Neon, Supabase, RDS, Aurora, Cloud SQL, self-hosted) into ClickHouse Cloud Postgres.

    3,024 Failed
  • tanstack-start jezweb/claude-skills

    Build a full-stack TanStack Start app on Cloudflare Workers from scratch — SSR, file-based routing, server functions, D1+Drizzle, better-auth, Tailwind v4+shadcn/ui. Use whenever the user mentions TanStack Start, asks to scaffold a full-stack Cloudflare app with SSR, wants an SSR dashboard, or asks for a React 19 + Cloudflare Workers app with file-based routing and server functions — even if they don't name TanStack Start specifically. No template repo — Claude generates every file fresh per project.

    2,490 Failed
  • insta insforge/instacloud-skills

    Operate InstaCloud infrastructure with the `insta` CLI: create projects, add postgres/storage/compute services, deploy apps, create disposable branch environments (isolated DB + storage + compute per branch), schedule recurring HTTP calls (cron jobs) against a service or an external URL, bind service credentials into compute env, wire user secrets into `.env`, run multiple agents each in their own branch, handle governance approvals, check metrics/logs/usage, and promote branches to main. Use this skill when working in an InstaCloud-managed project (a `.insta/` dir or the `insta` CLI), when the user mentions InstaCloud or insta, AND when they ask to deploy an app, need a database/backend/object storage, want a scheduled or recurring task, want preview or per-agent sandbox environments, want branchable infrastructure, want to migrate an existing app in from Heroku / Railway / Fly / Render, or mention agent setup or MCP — even if they don't say "InstaCloud" explicitly. Also covers the insta-cloud remote MCP server (insta_* tools) and the self-hosted insta-oss runtime (same CLI, local daemon).

    2,385 Failed
  • typescript-e2e-testing bmad-labs/skills

    E2E and integration testing for TypeScript/NestJS projects using Jest, supertest, and real infrastructure via Docker (Kafka, PostgreSQL, MongoDB, Redis) with the Given-When-Then pattern. Use whenever the user is working on `.e2e-spec.ts` files or anything under `test/e2e/`, or asks to set up, write, review, run, debug, or optimize E2E or integration tests — including flaky tests, docker-compose for tests, Kafka/Redpanda consumers, test isolation, or GWT compliance.

    2,255 Failed
  • claimable-postgres neondatabase/agent-skills

    2,185 Failed
  • writing-handlebars celigo/ai

    Write Handlebars template expressions for Celigo integrations -- dynamic values in mappings, HTTP bodies, SQL queries, URIs, and filters. Use when building any resource configuration that needs computed, conditional, or formatted field values.

    2,093 Failed
  • literature-review k-dense-ai/scientific-agent-skills

    Conduct comprehensive, systematic literature reviews using multiple academic databases (PubMed, arXiv, bioRxiv, Semantic Scholar, etc.). This skill should be used when conducting systematic literature reviews, meta-analyses, research synthesis, or comprehensive literature searches across biomedical, scientific, and technical domains. Creates professionally formatted markdown documents and PDFs with verified citations in multiple citation styles (APA, Nature, Vancouver, etc.).

    2,054 Failed
  • data-engineering-medallion-pipeline reason-machines/data-skills

    End-to-end data engineering pipeline using MinIO, Airbyte, PostgreSQL, DBT, and Airflow with medallion architecture (Bronze/Silver/Gold layers)

    2,043 Failed
  • harvard-artifacts-etl-analytics reason-machines/data-skills

    Build ETL pipelines and analytics dashboards for Harvard Art Museums API data with Python, SQL, and Streamlit

    2,015 Failed
  • retail-etl-pipeline-medallion reason-machines/data-skills

    End-to-end retail ETL pipeline using PySpark, SQL Server, and Medallion Architecture (Bronze/Silver/Gold layers) for data warehousing

    1,788 Failed
  • postgresql-database-engineering manutej/luxor-claude-marketplace

    Comprehensive PostgreSQL database engineering skill covering indexing strategies, query optimization, performance tuning, partitioning, replication, backup and recovery, high availability, and production database management. Master advanced PostgreSQL features including MVCC, VACUUM operations, connection pooling, monitoring, and scalability patterns.

    1,757 Failed
  • service railwayapp/railway-skills

    Operate Railway infrastructure: sign up for or sign in to a Railway account, create projects, provision services, databases, and buckets, deploy code, configure infrastructure as code, environments and variables, manage domains, trace requests with OpenTelemetry, troubleshoot failures, check status and metrics, manage feature flags, database recovery and HA, cloud agents, usage limits, and Railway agent tooling. Use this skill whenever the user mentions Railway, feature flags, flag rollout, targeting rules, signing up, creating an account, registering, logging in, deployments, services, environments, buckets, object storage, tracing, traces, spans, OpenTelemetry, OTLP, build failures, agent setup, MCP, or infrastructure operations, even if they don't say "Railway" explicitly. Also invoke this skill when the user asks to be signed up, registered, or onboarded to Railway: do not refuse — drive them through the unauthed `railway up` flow (deploys + signs up on the fly) or `railway login` (which creates new accounts on the fly).

    1,566 Failed
  • openviking-context-database reason-machines/trending-skills

    Expert skill for using OpenViking, the open-source context database for AI Agents that manages memory, resources, and skills via a filesystem paradigm.

    1,316 Failed
  • pentest-tools zhaoxuya520/reverse-skill

    主动渗透测试工具链。覆盖信息收集、端口扫描、漏洞扫描、Web 渗透、SQL 注入、目录爆破、密码破解等场景。 通过 MCP server(pentestMCP / mcp-security-hub)将 20+ 安全工具暴露给 AI agent。 触发关键词:渗透测试、端口扫描、Nmap、漏洞扫描、Nuclei、SQL 注入、SQLMap、目录爆破、FFUF、密码破解、Hashcat、信息收集、子域名、Web 渗透、ZAP、Burp。

    1,306 Failed

Descriptions are the authors' own, in English. Read a skill's code in its repository before you install it.

What agent skills are

A skill is a folder with a SKILL.md file — instructions written for an AI agent — and sometimes scripts or templates. When a task matches the skill's description, an agent such as Claude Code, Codex or Cursor loads it and follows it: how to fill in a form, how to review code in a particular style, how to work with a certain file format. This page is a directory of such skills, based on skills.sh.

What the directory shows

  • the top 10,000 skills by number of installs, synced daily;
  • for each skill: name, author and repository, installs, the status of its security audit and the command that adds it, with a copy button;
  • "Trending": the skills that gained the most installs over the last 7 days;
  • filters by topic and by agent, and a search; each view shows up to 100 skills.

Reading the audit status

skills.sh publishes security audits of skills. We show the result as Passed, Warnings, Failed or Not audited. A passed audit lowers the risk but is not a guarantee: a skill can contain scripts that your agent will run on your machine. Read the code in the repository before you install a skill, especially one with few installs or no audit.

Installing a skill

  1. Find a skill through the topics, the agent filter or the search.
  2. Open its repository and look at SKILL.md and any scripts.
  3. Copy the command from the row and run it in your project.
  4. Ask your agent to perform a task that matches the skill.

About the descriptions

The short descriptions are the authors' own, in English, as written in each SKILL.md. We do not translate or rewrite them, and install counts are those reported by skills.sh.