Skill per agenti
Skill per Claude Code, Codex, Cursor e altri agenti dalla directory skills.sh: installazioni, stato dell'audit di sicurezza e il comando per aggiungere una skill.
Una skill non è legata a un solo agente: npx skills add la installa in qualsiasi agente supportato. Senza -a, la CLI trova gli agenti sul tuo computer e chiede dove aggiungerla.
Aggiornato · Fonti: skills.sh
Mostrate: 27 · trovate: 27 · su 10.000 nella directory
-
firebase-data-connect firebase/agent-skills
Builds and deploys Firebase SQL Connect (aka Firebase Data Connect) backends with PostgreSQL securely. Use when designing schemas with tables and relations, writing authorized queries and mutations, configuring real-time data updates, or generating type-safe SDKs. Use when you need a relational database with Firebase, or when the user mentions SQL Connect or Data Connect.
159.088 Non superato -
mysql planetscale/database-skills
Plan and review MySQL/InnoDB schema, indexing, query tuning, transactions, and operations. Use when creating or modifying MySQL tables, indexes, or queries; diagnosing slow/locking behavior; planning migrations; or troubleshooting replication and connection issues. Load when using a MySQL database.
8.135 Non superato -
postgres planetscale/database-skills
PostgreSQL best practices, query optimization, connection troubleshooting, and performance improvement. Load when working with Postgres databases.
7.981 Non superato -
use-railway railwayapp/railway-skills
Operate Railway infrastructure: sign up for or sign in to a Railway account, create projects, provision services, databases, and buckets, deploy code, configure infrastructure as code, environments and variables, manage domains, trace requests with OpenTelemetry, troubleshoot failures, check status and metrics, manage feature flags, database recovery and HA, cloud agents, usage limits, and Railway agent tooling. Use this skill whenever the user mentions Railway, feature flags, flag rollout, targeting rules, signing up, creating an account, registering, logging in, deployments, services, environments, buckets, object storage, tracing, traces, spans, OpenTelemetry, OTLP, build failures, agent setup, MCP, or infrastructure operations, even if they don't say "Railway" explicitly. Also invoke this skill when the user asks to be signed up, registered, or onboarded to Railway: do not refuse — drive them through the unauthed `railway up` flow (deploys + signs up on the fly) or `railway login` (which creates new accounts on the fly).
7.678 Non superato -
postgres-pro jeffallan/claude-skills
Use when optimizing PostgreSQL queries, configuring replication, or implementing advanced database features. Invoke for EXPLAIN analysis, JSONB operations, extension usage, VACUUM tuning, performance monitoring.
7.471 Non superato -
clickhouse-managed-postgres-rca clickhouse/agent-skills
MUST USE when investigating performance issues on a ClickHouse-managed Postgres instance. Provides an evidence-based RCA workflow that scrapes the Prometheus endpoint for system signal, pulls per-digest evidence from the Slow Query Patterns API, and recommends (does not apply) a fix.
6.352 Non superato -
code-reviewer jeffallan/claude-skills
Analyzes code diffs and files to identify bugs, security vulnerabilities (SQL injection, XSS, insecure deserialization), code smells, N+1 queries, naming issues, and architectural concerns, then produces a structured review report with prioritized, actionable feedback. Use when reviewing pull requests, conducting code quality audits, identifying refactoring opportunities, or checking for security issues. Invoke for PR reviews, code quality checks, refactoring suggestions, review code, code quality. Complements specialized skills (security-reviewer, test-master) by providing broad-scope review across correctness, performance, maintainability, and test coverage in a single pass.
6.072 Non superato -
sql-pro jeffallan/claude-skills
Optimizes SQL queries, designs database schemas, and troubleshoots performance issues. Use when a user asks why their query is slow, needs help writing complex joins or aggregations, mentions database performance issues, or wants to design or migrate a schema. Invoke for complex queries, window functions, CTEs, indexing strategies, query plan analysis, covering index creation, recursive queries, EXPLAIN/ANALYZE interpretation, before/after query benchmarking, or migrating queries between database dialects (PostgreSQL, MySQL, SQL Server, Oracle).
6.018 Non superato -
database-optimizer jeffallan/claude-skills
Optimizes database queries and improves performance across PostgreSQL and MySQL systems. Use when investigating slow queries, analyzing execution plans, or optimizing database performance. Invoke for index design, query rewrites, configuration tuning, partitioning strategies, lock contention resolution.
5.524 Non superato -
secure-code-guardian jeffallan/claude-skills
Use when implementing authentication/authorization, securing user input, or preventing OWASP Top 10 vulnerabilities — including custom security implementations such as hashing passwords with bcrypt/argon2, sanitizing SQL queries with parameterized statements, configuring CORS/CSP headers, validating input with Zod, and setting up JWT tokens. Invoke for authentication, authorization, input validation, encryption, OWASP Top 10 prevention, secure session management, and security hardening. For pre-built OAuth/SSO integrations or standalone security audits, consider a more specialized skill.
4.715 Non superato -
security-ownership-map openai/skills
Analyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensitive-code ownership, and export CSV/JSON for graph databases and visualization. Trigger only when the user explicitly wants a security-oriented ownership or bus-factor analysis grounded in git history (for example: orphaned sensitive code, security maintainers, CODEOWNERS reality checks for risk, sensitive hotspots, or ownership clusters). Do not trigger for general maintainer lists or non-security ownership questions.
3.566 Non superato -
qdrant giuseppe-trisciuoglio/developer-kit
Provides Qdrant vector database integration patterns with LangChain4j. Handles embedding storage, similarity search, and vector management for Java applications. Use when implementing vector-based retrieval for RAG systems, semantic search, or recommendation engines.
3.563 Non superato -
redis-development redis/agent-skills
3.148 Non superato -
infra-postgres clickhouse/agent-skills
Sets up and manages Postgres using the clickhousectl CLI — runs a local Docker-backed Postgres for development, and creates and operates managed ClickHouse Cloud Postgres services (connections, TLS, runtime config, read replicas, failover, point-in-time restore). Use when the user wants a Postgres or PostgreSQL database for their application, a local Postgres dev environment, psql access, or a managed/production Postgres in ClickHouse Cloud, or mentions moving a local Postgres to production. Also use when migrating an existing Postgres database (Neon, Supabase, RDS, Aurora, Cloud SQL, self-hosted) into ClickHouse Cloud Postgres.
3.030 Non superato -
tanstack-start jezweb/claude-skills
Build a full-stack TanStack Start app on Cloudflare Workers from scratch — SSR, file-based routing, server functions, D1+Drizzle, better-auth, Tailwind v4+shadcn/ui. Use whenever the user mentions TanStack Start, asks to scaffold a full-stack Cloudflare app with SSR, wants an SSR dashboard, or asks for a React 19 + Cloudflare Workers app with file-based routing and server functions — even if they don't name TanStack Start specifically. No template repo — Claude generates every file fresh per project.
2.491 Non superato -
insta insforge/instacloud-skills
Operate InstaCloud infrastructure with the `insta` CLI: create projects, add postgres/storage/compute services, deploy apps, create disposable branch environments (isolated DB + storage + compute per branch), schedule recurring HTTP calls (cron jobs) against a service or an external URL, bind service credentials into compute env, wire user secrets into `.env`, run multiple agents each in their own branch, handle governance approvals, check metrics/logs/usage, and promote branches to main. Use this skill when working in an InstaCloud-managed project (a `.insta/` dir or the `insta` CLI), when the user mentions InstaCloud or insta, AND when they ask to deploy an app, need a database/backend/object storage, want a scheduled or recurring task, want preview or per-agent sandbox environments, want branchable infrastructure, want to migrate an existing app in from Heroku / Railway / Fly / Render, or mention agent setup or MCP — even if they don't say "InstaCloud" explicitly. Also covers the insta-cloud remote MCP server (insta_* tools) and the self-hosted insta-oss runtime (same CLI, local daemon).
2.433 Non superato -
typescript-e2e-testing bmad-labs/skills
E2E and integration testing for TypeScript/NestJS projects using Jest, supertest, and real infrastructure via Docker (Kafka, PostgreSQL, MongoDB, Redis) with the Given-When-Then pattern. Use whenever the user is working on `.e2e-spec.ts` files or anything under `test/e2e/`, or asks to set up, write, review, run, debug, or optimize E2E or integration tests — including flaky tests, docker-compose for tests, Kafka/Redpanda consumers, test isolation, or GWT compliance.
2.256 Non superato -
claimable-postgres neondatabase/agent-skills
2.185 Non superato -
writing-handlebars celigo/ai
Write Handlebars template expressions for Celigo integrations -- dynamic values in mappings, HTTP bodies, SQL queries, URIs, and filters. Use when building any resource configuration that needs computed, conditional, or formatted field values.
2.117 Non superato -
literature-review k-dense-ai/scientific-agent-skills
Conduct comprehensive, systematic literature reviews using multiple academic databases (PubMed, arXiv, bioRxiv, Semantic Scholar, etc.). This skill should be used when conducting systematic literature reviews, meta-analyses, research synthesis, or comprehensive literature searches across biomedical, scientific, and technical domains. Creates professionally formatted markdown documents and PDFs with verified citations in multiple citation styles (APA, Nature, Vancouver, etc.).
2.066 Non superato -
data-engineering-medallion-pipeline reason-machines/data-skills
End-to-end data engineering pipeline using MinIO, Airbyte, PostgreSQL, DBT, and Airflow with medallion architecture (Bronze/Silver/Gold layers)
2.043 Non superato -
harvard-artifacts-etl-analytics reason-machines/data-skills
Build ETL pipelines and analytics dashboards for Harvard Art Museums API data with Python, SQL, and Streamlit
2.015 Non superato -
retail-etl-pipeline-medallion reason-machines/data-skills
End-to-end retail ETL pipeline using PySpark, SQL Server, and Medallion Architecture (Bronze/Silver/Gold layers) for data warehousing
1.788 Non superato -
postgresql-database-engineering manutej/luxor-claude-marketplace
Comprehensive PostgreSQL database engineering skill covering indexing strategies, query optimization, performance tuning, partitioning, replication, backup and recovery, high availability, and production database management. Master advanced PostgreSQL features including MVCC, VACUUM operations, connection pooling, monitoring, and scalability patterns.
1.760 Non superato -
service railwayapp/railway-skills
Operate Railway infrastructure: sign up for or sign in to a Railway account, create projects, provision services, databases, and buckets, deploy code, configure infrastructure as code, environments and variables, manage domains, trace requests with OpenTelemetry, troubleshoot failures, check status and metrics, manage feature flags, database recovery and HA, cloud agents, usage limits, and Railway agent tooling. Use this skill whenever the user mentions Railway, feature flags, flag rollout, targeting rules, signing up, creating an account, registering, logging in, deployments, services, environments, buckets, object storage, tracing, traces, spans, OpenTelemetry, OTLP, build failures, agent setup, MCP, or infrastructure operations, even if they don't say "Railway" explicitly. Also invoke this skill when the user asks to be signed up, registered, or onboarded to Railway: do not refuse — drive them through the unauthed `railway up` flow (deploys + signs up on the fly) or `railway login` (which creates new accounts on the fly).
1.566 Non superato -
pentest-tools zhaoxuya520/reverse-skill
主动渗透测试工具链。覆盖信息收集、端口扫描、漏洞扫描、Web 渗透、SQL 注入、目录爆破、密码破解等场景。 通过 MCP server(pentestMCP / mcp-security-hub)将 20+ 安全工具暴露给 AI agent。 触发关键词:渗透测试、端口扫描、Nmap、漏洞扫描、Nuclei、SQL 注入、SQLMap、目录爆破、FFUF、密码破解、Hashcat、信息收集、子域名、Web 渗透、ZAP、Burp。
1.327 Non superato -
openviking-context-database reason-machines/trending-skills
Expert skill for using OpenViking, the open-source context database for AI Agents that manages memory, resources, and skills via a filesystem paradigm.
1.316 Non superato
Le descrizioni sono degli autori, in inglese. Leggi il codice di una skill nel suo repository prima di installarla.
Che cos'è una skill
Una skill è una cartella con un file SKILL.md e, se serve, alcuni script: contiene istruzioni che un agente carica quando il compito corrisponde, per esempio come scrivere test in un certo framework o come preparare un rilascio. Questa directory raccoglie le skill di skills.sh per Claude Code, Codex, Cursor e altri agenti. Per ciascuna trovi nome, autore e repository, installazioni, stato dell'audit di sicurezza e il comando per aggiungerla, con il pulsante «Copia il comando».
Cosa mostra la pagina
- 10.000 skill ordinate per installazioni, sincronizzate ogni giorno da skills.sh;
- la vista «Di tendenza», basata sulle installazioni guadagnate negli ultimi 7 giorni;
- i filtri per argomento e per agente e una ricerca, con al massimo 100 skill per vista.
Le descrizioni sono quelle scritte dagli autori, in inglese, e non vengono tradotte.
Come leggere l'audit
Lo stato dell'audit viene dagli audit pubblicati da skills.sh e ha quattro valori: «Superato», «Avvisi», «Non superato» e «Non verificata». Un audit superato è un buon segnale, ma non una garanzia: una skill può eseguire script sul tuo computer, quindi leggi il codice nel repository su GitHub prima di installarla. Diffida delle skill che chiedono accessi non necessari al loro scopo.
Come aggiungere una skill
Trovata la skill che ti serve, controlla con quali agenti è compatibile, apri il repository e leggi il file SKILL.md per capire cosa fa. Poi copia il comando con il pulsante dedicato e lancialo nella cartella del progetto o nella configurazione del tuo agente. Dopo l'installazione, prova la skill su un compito semplice e verifica che l'agente la usi come previsto.
Da dove vengono i numeri
Le installazioni sono contate da skills.sh, non da noi: servono a capire cosa usano gli altri sviluppatori, non a giudicare la qualità. Il codice di ogni skill sta nel suo repository. Per scegliere l'agente a cui aggiungerle, consulta la pagina degli agenti di programmazione.