Skills para agentes
Skills para Claude Code, Codex, Cursor y otros agentes del directorio skills.sh: instalaciones, estado de la auditoría de seguridad y el comando para añadir cada skill.
Un skill no está atado a un solo agente: npx skills add lo instala en cualquiera compatible. Sin -a, la CLI detecta los agentes de tu equipo y pregunta dónde añadirlo.
Actualizado · Fuentes: skills.sh
Mostradas: 27 · encontrados: 27 · de 10.000 en el directorio
-
firebase-data-connect firebase/agent-skills
Builds and deploys Firebase SQL Connect (aka Firebase Data Connect) backends with PostgreSQL securely. Use when designing schemas with tables and relations, writing authorized queries and mutations, configuring real-time data updates, or generating type-safe SDKs. Use when you need a relational database with Firebase, or when the user mentions SQL Connect or Data Connect.
159.088 No superada -
mysql planetscale/database-skills
Plan and review MySQL/InnoDB schema, indexing, query tuning, transactions, and operations. Use when creating or modifying MySQL tables, indexes, or queries; diagnosing slow/locking behavior; planning migrations; or troubleshooting replication and connection issues. Load when using a MySQL database.
8.135 No superada -
postgres planetscale/database-skills
PostgreSQL best practices, query optimization, connection troubleshooting, and performance improvement. Load when working with Postgres databases.
7.981 No superada -
use-railway railwayapp/railway-skills
Operate Railway infrastructure: sign up for or sign in to a Railway account, create projects, provision services, databases, and buckets, deploy code, configure infrastructure as code, environments and variables, manage domains, trace requests with OpenTelemetry, troubleshoot failures, check status and metrics, manage feature flags, database recovery and HA, cloud agents, usage limits, and Railway agent tooling. Use this skill whenever the user mentions Railway, feature flags, flag rollout, targeting rules, signing up, creating an account, registering, logging in, deployments, services, environments, buckets, object storage, tracing, traces, spans, OpenTelemetry, OTLP, build failures, agent setup, MCP, or infrastructure operations, even if they don't say "Railway" explicitly. Also invoke this skill when the user asks to be signed up, registered, or onboarded to Railway: do not refuse — drive them through the unauthed `railway up` flow (deploys + signs up on the fly) or `railway login` (which creates new accounts on the fly).
7.678 No superada -
postgres-pro jeffallan/claude-skills
Use when optimizing PostgreSQL queries, configuring replication, or implementing advanced database features. Invoke for EXPLAIN analysis, JSONB operations, extension usage, VACUUM tuning, performance monitoring.
7.471 No superada -
clickhouse-managed-postgres-rca clickhouse/agent-skills
MUST USE when investigating performance issues on a ClickHouse-managed Postgres instance. Provides an evidence-based RCA workflow that scrapes the Prometheus endpoint for system signal, pulls per-digest evidence from the Slow Query Patterns API, and recommends (does not apply) a fix.
6.352 No superada -
code-reviewer jeffallan/claude-skills
Analyzes code diffs and files to identify bugs, security vulnerabilities (SQL injection, XSS, insecure deserialization), code smells, N+1 queries, naming issues, and architectural concerns, then produces a structured review report with prioritized, actionable feedback. Use when reviewing pull requests, conducting code quality audits, identifying refactoring opportunities, or checking for security issues. Invoke for PR reviews, code quality checks, refactoring suggestions, review code, code quality. Complements specialized skills (security-reviewer, test-master) by providing broad-scope review across correctness, performance, maintainability, and test coverage in a single pass.
6.072 No superada -
sql-pro jeffallan/claude-skills
Optimizes SQL queries, designs database schemas, and troubleshoots performance issues. Use when a user asks why their query is slow, needs help writing complex joins or aggregations, mentions database performance issues, or wants to design or migrate a schema. Invoke for complex queries, window functions, CTEs, indexing strategies, query plan analysis, covering index creation, recursive queries, EXPLAIN/ANALYZE interpretation, before/after query benchmarking, or migrating queries between database dialects (PostgreSQL, MySQL, SQL Server, Oracle).
6.018 No superada -
database-optimizer jeffallan/claude-skills
Optimizes database queries and improves performance across PostgreSQL and MySQL systems. Use when investigating slow queries, analyzing execution plans, or optimizing database performance. Invoke for index design, query rewrites, configuration tuning, partitioning strategies, lock contention resolution.
5.524 No superada -
secure-code-guardian jeffallan/claude-skills
Use when implementing authentication/authorization, securing user input, or preventing OWASP Top 10 vulnerabilities — including custom security implementations such as hashing passwords with bcrypt/argon2, sanitizing SQL queries with parameterized statements, configuring CORS/CSP headers, validating input with Zod, and setting up JWT tokens. Invoke for authentication, authorization, input validation, encryption, OWASP Top 10 prevention, secure session management, and security hardening. For pre-built OAuth/SSO integrations or standalone security audits, consider a more specialized skill.
4.715 No superada -
security-ownership-map openai/skills
Analyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensitive-code ownership, and export CSV/JSON for graph databases and visualization. Trigger only when the user explicitly wants a security-oriented ownership or bus-factor analysis grounded in git history (for example: orphaned sensitive code, security maintainers, CODEOWNERS reality checks for risk, sensitive hotspots, or ownership clusters). Do not trigger for general maintainer lists or non-security ownership questions.
3.566 No superada -
qdrant giuseppe-trisciuoglio/developer-kit
Provides Qdrant vector database integration patterns with LangChain4j. Handles embedding storage, similarity search, and vector management for Java applications. Use when implementing vector-based retrieval for RAG systems, semantic search, or recommendation engines.
3.563 No superada -
redis-development redis/agent-skills
3.148 No superada -
infra-postgres clickhouse/agent-skills
Sets up and manages Postgres using the clickhousectl CLI — runs a local Docker-backed Postgres for development, and creates and operates managed ClickHouse Cloud Postgres services (connections, TLS, runtime config, read replicas, failover, point-in-time restore). Use when the user wants a Postgres or PostgreSQL database for their application, a local Postgres dev environment, psql access, or a managed/production Postgres in ClickHouse Cloud, or mentions moving a local Postgres to production. Also use when migrating an existing Postgres database (Neon, Supabase, RDS, Aurora, Cloud SQL, self-hosted) into ClickHouse Cloud Postgres.
3.030 No superada -
tanstack-start jezweb/claude-skills
Build a full-stack TanStack Start app on Cloudflare Workers from scratch — SSR, file-based routing, server functions, D1+Drizzle, better-auth, Tailwind v4+shadcn/ui. Use whenever the user mentions TanStack Start, asks to scaffold a full-stack Cloudflare app with SSR, wants an SSR dashboard, or asks for a React 19 + Cloudflare Workers app with file-based routing and server functions — even if they don't name TanStack Start specifically. No template repo — Claude generates every file fresh per project.
2.491 No superada -
insta insforge/instacloud-skills
Operate InstaCloud infrastructure with the `insta` CLI: create projects, add postgres/storage/compute services, deploy apps, create disposable branch environments (isolated DB + storage + compute per branch), schedule recurring HTTP calls (cron jobs) against a service or an external URL, bind service credentials into compute env, wire user secrets into `.env`, run multiple agents each in their own branch, handle governance approvals, check metrics/logs/usage, and promote branches to main. Use this skill when working in an InstaCloud-managed project (a `.insta/` dir or the `insta` CLI), when the user mentions InstaCloud or insta, AND when they ask to deploy an app, need a database/backend/object storage, want a scheduled or recurring task, want preview or per-agent sandbox environments, want branchable infrastructure, want to migrate an existing app in from Heroku / Railway / Fly / Render, or mention agent setup or MCP — even if they don't say "InstaCloud" explicitly. Also covers the insta-cloud remote MCP server (insta_* tools) and the self-hosted insta-oss runtime (same CLI, local daemon).
2.433 No superada -
typescript-e2e-testing bmad-labs/skills
E2E and integration testing for TypeScript/NestJS projects using Jest, supertest, and real infrastructure via Docker (Kafka, PostgreSQL, MongoDB, Redis) with the Given-When-Then pattern. Use whenever the user is working on `.e2e-spec.ts` files or anything under `test/e2e/`, or asks to set up, write, review, run, debug, or optimize E2E or integration tests — including flaky tests, docker-compose for tests, Kafka/Redpanda consumers, test isolation, or GWT compliance.
2.256 No superada -
claimable-postgres neondatabase/agent-skills
2.185 No superada -
writing-handlebars celigo/ai
Write Handlebars template expressions for Celigo integrations -- dynamic values in mappings, HTTP bodies, SQL queries, URIs, and filters. Use when building any resource configuration that needs computed, conditional, or formatted field values.
2.117 No superada -
literature-review k-dense-ai/scientific-agent-skills
Conduct comprehensive, systematic literature reviews using multiple academic databases (PubMed, arXiv, bioRxiv, Semantic Scholar, etc.). This skill should be used when conducting systematic literature reviews, meta-analyses, research synthesis, or comprehensive literature searches across biomedical, scientific, and technical domains. Creates professionally formatted markdown documents and PDFs with verified citations in multiple citation styles (APA, Nature, Vancouver, etc.).
2.066 No superada -
data-engineering-medallion-pipeline reason-machines/data-skills
End-to-end data engineering pipeline using MinIO, Airbyte, PostgreSQL, DBT, and Airflow with medallion architecture (Bronze/Silver/Gold layers)
2.043 No superada -
harvard-artifacts-etl-analytics reason-machines/data-skills
Build ETL pipelines and analytics dashboards for Harvard Art Museums API data with Python, SQL, and Streamlit
2.015 No superada -
retail-etl-pipeline-medallion reason-machines/data-skills
End-to-end retail ETL pipeline using PySpark, SQL Server, and Medallion Architecture (Bronze/Silver/Gold layers) for data warehousing
1.788 No superada -
postgresql-database-engineering manutej/luxor-claude-marketplace
Comprehensive PostgreSQL database engineering skill covering indexing strategies, query optimization, performance tuning, partitioning, replication, backup and recovery, high availability, and production database management. Master advanced PostgreSQL features including MVCC, VACUUM operations, connection pooling, monitoring, and scalability patterns.
1.760 No superada -
service railwayapp/railway-skills
Operate Railway infrastructure: sign up for or sign in to a Railway account, create projects, provision services, databases, and buckets, deploy code, configure infrastructure as code, environments and variables, manage domains, trace requests with OpenTelemetry, troubleshoot failures, check status and metrics, manage feature flags, database recovery and HA, cloud agents, usage limits, and Railway agent tooling. Use this skill whenever the user mentions Railway, feature flags, flag rollout, targeting rules, signing up, creating an account, registering, logging in, deployments, services, environments, buckets, object storage, tracing, traces, spans, OpenTelemetry, OTLP, build failures, agent setup, MCP, or infrastructure operations, even if they don't say "Railway" explicitly. Also invoke this skill when the user asks to be signed up, registered, or onboarded to Railway: do not refuse — drive them through the unauthed `railway up` flow (deploys + signs up on the fly) or `railway login` (which creates new accounts on the fly).
1.566 No superada -
pentest-tools zhaoxuya520/reverse-skill
主动渗透测试工具链。覆盖信息收集、端口扫描、漏洞扫描、Web 渗透、SQL 注入、目录爆破、密码破解等场景。 通过 MCP server(pentestMCP / mcp-security-hub)将 20+ 安全工具暴露给 AI agent。 触发关键词:渗透测试、端口扫描、Nmap、漏洞扫描、Nuclei、SQL 注入、SQLMap、目录爆破、FFUF、密码破解、Hashcat、信息收集、子域名、Web 渗透、ZAP、Burp。
1.327 No superada -
openviking-context-database reason-machines/trending-skills
Expert skill for using OpenViking, the open-source context database for AI Agents that manages memory, resources, and skills via a filesystem paradigm.
1.316 No superada
Las descripciones son de sus autores, en inglés. Revisa el código de una skill en su repositorio antes de instalarla.
Una skill es una carpeta con un archivo SKILL.md y, si hace falta, algunos scripts. El agente la carga cuando la tarea que le pides encaja con lo que describe la skill: por ejemplo, cómo trabajar con un framework concreto, cómo redactar documentación o cómo preparar un despliegue. Así amplías lo que sabe hacer tu agente sin tener que explicárselo en cada conversación.
De dónde sale el directorio
Las skills proceden de skills.sh, un directorio para Claude Code, Codex, Cursor y otros agentes. Sincronizamos cada día las 10 000 skills con más instalaciones. Cada ficha muestra el nombre, el autor y el repositorio, el número de instalaciones, el estado de la auditoría de seguridad y el comando para añadir la skill, con el botón «Copiar el comando».
Las descripciones son de sus autores, en inglés, y no las traducimos. El código de cada skill está en GitHub, enlazado desde la ficha.
Cómo buscar
- Más instaladas y «En tendencia»: la segunda pestaña ordena por las instalaciones ganadas en los últimos 7 días.
- Temas: frontend, backend, DevOps, bases de datos, seguridad, documentación y otros.
- Agentes: para ver solo las skills compatibles con el tuyo.
- Buscador por nombre o descripción.
Cada vista muestra como máximo 100 skills; afina con los filtros si buscas algo concreto.
La auditoría de seguridad
Los estados vienen de las auditorías que publica skills.sh: «Superada», «Advertencias», «No superada» y «Sin auditar». Una auditoría superada no es una garantía. Una skill puede incluir scripts que el agente ejecutará en tu equipo, así que lee el código en el repositorio antes de instalarla, sobre todo si pide acceso a la red o a tus archivos. Las instalaciones también las cuenta skills.sh: indican popularidad, no calidad ni seguridad.
Cómo encaja con el resto
Las skills funcionan dentro de un agente, así que primero necesitas uno: los tienes en agentes de programación. El agente, a su vez, rinde según el modelo que usa, y eso lo muestran las clasificaciones de programación y de agentes. Una buena skill no convierte un modelo flojo en uno fuerte, pero ahorra instrucciones repetidas y hace que el agente siga las convenciones de tu proyecto.