Agent skills in plugin format
A skill is a Markdown file that tells a coding agent how to do one job. We parse every one we can find — the frontmatter, the outline, the languages in its code blocks — so you can look for the one that fits instead of reading through a repository to find out.
69,865 skills from 9,574 repositories, last read 11 September 2026.
Skills declare what they need inconsistently: 58.8% name the languages they run, 11.2% list the tools they ask for, and 4.6% give themselves a category. Filtering narrows to the ones that said so, never to the ones that are.
- analyzing-memory-dumps-with-volatilitymukul975/Anthropic-Cybersecurity-Skills
- configuring-zscaler-private-access-for-ztnamukul975/Anthropic-Cybersecurity-Skills
- coercing-authentication-with-coercer-petitpotammukul975/Anthropic-Cybersecurity-Skills
- implementing-ransomware-backup-strategymukul975/Anthropic-Cybersecurity-Skills
- performing-privilege-escalation-on-linuxmukul975/Anthropic-Cybersecurity-Skills
- testing-for-xss-vulnerabilities-with-burpsuitemukul975/Anthropic-Cybersecurity-Skills
- performing-oil-gas-cybersecurity-assessmentmukul975/Anthropic-Cybersecurity-Skills
- implementing-canary-tokens-for-network-intrusionmukul975/Anthropic-Cybersecurity-Skills
- detecting-pass-the-hash-attacksmukul975/Anthropic-Cybersecurity-Skills
- performing-web-application-scanning-with-niktomukul975/Anthropic-Cybersecurity-Skills
- testing-for-json-web-token-vulnerabilitiesmukul975/Anthropic-Cybersecurity-Skills
- detecting-container-escape-with-falco-rulesmukul975/Anthropic-Cybersecurity-Skills
- investigating-insider-threat-indicatorsmukul975/Anthropic-Cybersecurity-Skills
- performing-docker-bench-security-assessmentmukul975/Anthropic-Cybersecurity-Skills
- detecting-credential-dumping-techniquesmukul975/Anthropic-Cybersecurity-Skills
- implementing-aws-macie-for-data-classificationmukul975/Anthropic-Cybersecurity-Skills
- conducting-malware-incident-responsemukul975/Anthropic-Cybersecurity-Skills
- building-vulnerability-exception-tracking-systemmukul975/Anthropic-Cybersecurity-Skills
- detecting-stuxnet-style-attacksmukul975/Anthropic-Cybersecurity-Skills
- performing-jwt-none-algorithm-attackmukul975/Anthropic-Cybersecurity-Skills
- implementing-soar-playbook-for-phishingmukul975/Anthropic-Cybersecurity-Skills
- collecting-threat-intelligence-with-mispmukul975/Anthropic-Cybersecurity-Skills
- implementing-hipaa-security-rule-safeguardsmukul975/Anthropic-Cybersecurity-Skills
- detecting-attacks-on-historian-serversmukul975/Anthropic-Cybersecurity-Skills
- hunting-for-persistence-via-wmi-subscriptionsmukul975/Anthropic-Cybersecurity-Skills
- building-devsecops-pipeline-with-gitlab-cimukul975/Anthropic-Cybersecurity-Skills
- scanning-container-images-with-grypemukul975/Anthropic-Cybersecurity-Skills
- detecting-golden-ticket-attacks-in-kerberos-logsmukul975/Anthropic-Cybersecurity-Skills
- analyzing-malware-behavior-with-cuckoo-sandboxmukul975/Anthropic-Cybersecurity-Skills
- deploying-cloud-deception-with-decoy-resourcesmukul975/Anthropic-Cybersecurity-Skills
- securing-aws-iam-permissionsmukul975/Anthropic-Cybersecurity-Skills
- analyzing-lnk-file-and-jump-list-artifactsmukul975/Anthropic-Cybersecurity-Skills
- performing-timeline-reconstruction-with-plasomukul975/Anthropic-Cybersecurity-Skills
- detecting-rootkit-activitymukul975/Anthropic-Cybersecurity-Skills
- implementing-diamond-model-analysismukul975/Anthropic-Cybersecurity-Skills
- securing-remote-access-to-ot-environmentmukul975/Anthropic-Cybersecurity-Skills
- performing-threat-intelligence-sharing-with-mispmukul975/Anthropic-Cybersecurity-Skills
- implementing-anti-phishing-training-programmukul975/Anthropic-Cybersecurity-Skills
- conducting-mobile-app-penetration-testmukul975/Anthropic-Cybersecurity-Skills
- configuring-certificate-authority-with-opensslmukul975/Anthropic-Cybersecurity-Skills
- analyzing-network-covert-channels-in-malwaremukul975/Anthropic-Cybersecurity-Skills
- detecting-anomalous-authentication-patternsmukul975/Anthropic-Cybersecurity-Skills
- implementing-privileged-access-management-with-cyberarkmukul975/Anthropic-Cybersecurity-Skills
- building-incident-response-dashboardmukul975/Anthropic-Cybersecurity-Skills
- implementing-memory-protection-with-dep-aslrmukul975/Anthropic-Cybersecurity-Skills
- performing-active-directory-forest-trust-attackmukul975/Anthropic-Cybersecurity-Skills
- implementing-api-security-testing-with-42crunchmukul975/Anthropic-Cybersecurity-Skills
- auditing-tls-certificate-transparency-logsmukul975/Anthropic-Cybersecurity-Skills
- analyzing-powershell-empire-artifactsmukul975/Anthropic-Cybersecurity-Skills
- executing-phishing-simulation-campaignmukul975/Anthropic-Cybersecurity-Skills
- detecting-dependency-confusionmukul975/Anthropic-Cybersecurity-Skills
- implementing-network-traffic-analysis-with-arkimemukul975/Anthropic-Cybersecurity-Skills
- conducting-social-engineering-penetration-testmukul975/Anthropic-Cybersecurity-Skills
- exploiting-insecure-data-storage-in-mobilemukul975/Anthropic-Cybersecurity-Skills
- hunting-for-persistence-mechanisms-in-windowsmukul975/Anthropic-Cybersecurity-Skills
- scanning-containers-with-trivy-in-cicdmukul975/Anthropic-Cybersecurity-Skills
- configuring-network-segmentation-with-vlansmukul975/Anthropic-Cybersecurity-Skills
- performing-web-cache-poisoning-attackmukul975/Anthropic-Cybersecurity-Skills
- implementing-passwordless-authentication-with-fido2mukul975/Anthropic-Cybersecurity-Skills
- performing-ransomware-tabletop-exercisemukul975/Anthropic-Cybersecurity-Skills
- conducting-api-security-testingmukul975/Anthropic-Cybersecurity-Skills
- detecting-lateral-movement-in-networkmukul975/Anthropic-Cybersecurity-Skills
- analyzing-ethereum-smart-contract-vulnerabilitiesmukul975/Anthropic-Cybersecurity-Skills
- reverse-engineering-ios-app-with-fridamukul975/Anthropic-Cybersecurity-Skills
- executing-active-directory-attack-simulationmukul975/Anthropic-Cybersecurity-Skills
- performing-privilege-escalation-assessmentmukul975/Anthropic-Cybersecurity-Skills
- detecting-anomalies-in-industrial-control-systemsmukul975/Anthropic-Cybersecurity-Skills
- hunting-for-scheduled-task-persistencemukul975/Anthropic-Cybersecurity-Skills
- detecting-suspicious-powershell-executionmukul975/Anthropic-Cybersecurity-Skills
- performing-purple-team-exercisemukul975/Anthropic-Cybersecurity-Skills
- building-vulnerability-aging-and-sla-trackingmukul975/Anthropic-Cybersecurity-Skills
- building-threat-intelligence-feed-integrationmukul975/Anthropic-Cybersecurity-Skills
- implementing-github-advanced-security-for-code-scanningmukul975/Anthropic-Cybersecurity-Skills
- implementing-log-integrity-with-blockchainmukul975/Anthropic-Cybersecurity-Skills
- performing-cloud-storage-forensic-acquisitionmukul975/Anthropic-Cybersecurity-Skills
- performing-physical-intrusion-assessmentmukul975/Anthropic-Cybersecurity-Skills
- building-ioc-enrichment-pipeline-with-openctimukul975/Anthropic-Cybersecurity-Skills
- testing-for-sensitive-data-exposuremukul975/Anthropic-Cybersecurity-Skills
- implementing-gcp-vpc-firewall-rulesmukul975/Anthropic-Cybersecurity-Skills
- performing-kerberoasting-attackmukul975/Anthropic-Cybersecurity-Skills
- performing-oauth-scope-minimization-reviewmukul975/Anthropic-Cybersecurity-Skills
- reverse-engineering-rust-malwaremukul975/Anthropic-Cybersecurity-Skills
- implementing-sigstore-for-software-signingmukul975/Anthropic-Cybersecurity-Skills
- detecting-container-runtime-threats-with-falcomukul975/Anthropic-Cybersecurity-Skills
- detecting-network-anomalies-with-zeekmukul975/Anthropic-Cybersecurity-Skills
- performing-adversary-in-the-middle-phishing-detectionmukul975/Anthropic-Cybersecurity-Skills
- detecting-suspicious-oauth-application-consentmukul975/Anthropic-Cybersecurity-Skills
- detecting-aws-guardduty-findings-automationmukul975/Anthropic-Cybersecurity-Skills
- detecting-living-off-the-land-with-lolbasmukul975/Anthropic-Cybersecurity-Skills
- detecting-fileless-attacks-on-endpointsmukul975/Anthropic-Cybersecurity-Skills
- detecting-entra-offensive-tools-in-graph-logsmukul975/Anthropic-Cybersecurity-Skills
- analyzing-network-traffic-of-malwaremukul975/Anthropic-Cybersecurity-Skills
- performing-graphql-depth-limit-attackmukul975/Anthropic-Cybersecurity-Skills
- implementing-secrets-scanning-in-ci-cdmukul975/Anthropic-Cybersecurity-Skills
- implementing-aws-security-hubmukul975/Anthropic-Cybersecurity-Skills
- implementing-attack-surface-managementmukul975/Anthropic-Cybersecurity-Skills
- hunting-for-startup-folder-persistencemukul975/Anthropic-Cybersecurity-Skills
- orchestrating-llm-attacks-with-pyritmukul975/Anthropic-Cybersecurity-Skills
- exploiting-nosql-injection-vulnerabilitiesmukul975/Anthropic-Cybersecurity-Skills
- hunting-for-dcsync-attacksmukul975/Anthropic-Cybersecurity-Skills
- analyzing-campaign-attribution-evidencemukul975/Anthropic-Cybersecurity-Skills
- detecting-wmi-persistencemukul975/Anthropic-Cybersecurity-Skills
- building-super-timelines-with-plasomukul975/Anthropic-Cybersecurity-Skills
- performing-threat-hunting-with-yara-rulesmukul975/Anthropic-Cybersecurity-Skills
- implementing-data-loss-prevention-with-microsoft-purviewmukul975/Anthropic-Cybersecurity-Skills
- performing-steganography-detectionmukul975/Anthropic-Cybersecurity-Skills
- implementing-aws-nitro-enclave-securitymukul975/Anthropic-Cybersecurity-Skills
- attacking-oauth-with-device-code-phishingmukul975/Anthropic-Cybersecurity-Skills
- detecting-data-and-model-poisoningmukul975/Anthropic-Cybersecurity-Skills
- implementing-container-image-minimal-base-with-distrolessmukul975/Anthropic-Cybersecurity-Skills
- performing-cloud-penetration-testing-with-pacumukul975/Anthropic-Cybersecurity-Skills
- analyzing-malware-persistence-with-autorunsmukul975/Anthropic-Cybersecurity-Skills
- triaging-vulnerabilities-with-ssvc-frameworkmukul975/Anthropic-Cybersecurity-Skills
- implementing-aes-encryption-for-data-at-restmukul975/Anthropic-Cybersecurity-Skills
- detecting-misconfigured-azure-storagemukul975/Anthropic-Cybersecurity-Skills
- analyzing-powershell-script-block-loggingmukul975/Anthropic-Cybersecurity-Skills
- analyzing-windows-registry-for-artifactsmukul975/Anthropic-Cybersecurity-Skills
- building-incident-timeline-with-timesketchmukul975/Anthropic-Cybersecurity-Skills
- performing-malware-persistence-investigationmukul975/Anthropic-Cybersecurity-Skills
- implementing-container-network-policies-with-calicomukul975/Anthropic-Cybersecurity-Skills
- implementing-soar-automation-with-phantommukul975/Anthropic-Cybersecurity-Skills
- performing-aws-privilege-escalation-assessmentmukul975/Anthropic-Cybersecurity-Skills
- performing-ai-driven-osint-correlationmukul975/Anthropic-Cybersecurity-Skills
- analyzing-api-gateway-access-logsmukul975/Anthropic-Cybersecurity-Skills
- performing-privileged-account-discoverymukul975/Anthropic-Cybersecurity-Skills
- implementing-cloud-workload-protectionmukul975/Anthropic-Cybersecurity-Skills
- implementing-ics-firewall-with-tofinomukul975/Anthropic-Cybersecurity-Skills
- exploiting-server-side-request-forgerymukul975/Anthropic-Cybersecurity-Skills
- detecting-email-forwarding-rules-attackmukul975/Anthropic-Cybersecurity-Skills
- conducting-wireless-network-penetration-testmukul975/Anthropic-Cybersecurity-Skills
- detecting-ai-model-prompt-injection-attacksmukul975/Anthropic-Cybersecurity-Skills
- conducting-cloud-incident-responsemukul975/Anthropic-Cybersecurity-Skills
- performing-bluetooth-security-assessmentmukul975/Anthropic-Cybersecurity-Skills
- hardening-linux-endpoint-with-cis-benchmarkmukul975/Anthropic-Cybersecurity-Skills
- implementing-scim-provisioning-with-oktamukul975/Anthropic-Cybersecurity-Skills
- implementing-iso-27001-information-security-managementmukul975/Anthropic-Cybersecurity-Skills
- securing-agentic-ai-tool-invocationmukul975/Anthropic-Cybersecurity-Skills
- hunting-for-spearphishing-indicatorsmukul975/Anthropic-Cybersecurity-Skills
- deploying-active-directory-honeytokensmukul975/Anthropic-Cybersecurity-Skills
- detecting-azure-service-principal-abusemukul975/Anthropic-Cybersecurity-Skills
- implementing-cloud-security-posture-managementmukul975/Anthropic-Cybersecurity-Skills
- analyzing-malicious-pdf-with-peepdfmukul975/Anthropic-Cybersecurity-Skills
- performing-serverless-function-security-reviewmukul975/Anthropic-Cybersecurity-Skills
- detecting-command-and-control-over-dnsmukul975/Anthropic-Cybersecurity-Skills
- detecting-shadow-api-endpointsmukul975/Anthropic-Cybersecurity-Skills
- deploying-honeytokens-and-canarytokensmukul975/Anthropic-Cybersecurity-Skills
- detecting-azure-storage-account-misconfigurationsmukul975/Anthropic-Cybersecurity-Skills
- performing-gcp-penetration-testing-with-gcpbucketbrutemukul975/Anthropic-Cybersecurity-Skills
- defending-llms-with-guardrailsmukul975/Anthropic-Cybersecurity-Skills
- testing-ransomware-recovery-proceduresmukul975/Anthropic-Cybersecurity-Skills
- implementing-policy-as-code-with-open-policy-agentmukul975/Anthropic-Cybersecurity-Skills
- detecting-serverless-function-injectionmukul975/Anthropic-Cybersecurity-Skills
- generating-forensic-timelines-with-hayabusamukul975/Anthropic-Cybersecurity-Skills
- performing-firmware-extraction-with-binwalkmukul975/Anthropic-Cybersecurity-Skills
- scanning-network-with-nmap-advancedmukul975/Anthropic-Cybersecurity-Skills
- triaging-security-incident-with-ir-playbookmukul975/Anthropic-Cybersecurity-Skills
- analyzing-ios-app-security-with-objectionmukul975/Anthropic-Cybersecurity-Skills
- deploying-edr-agent-with-crowdstrikemukul975/Anthropic-Cybersecurity-Skills
- auditing-aws-s3-bucket-permissionsmukul975/Anthropic-Cybersecurity-Skills
- implementing-network-access-control-with-cisco-isemukul975/Anthropic-Cybersecurity-Skills
- analyzing-security-logs-with-splunkmukul975/Anthropic-Cybersecurity-Skills
- performing-mobile-app-certificate-pinning-bypassmukul975/Anthropic-Cybersecurity-Skills
- implementing-siem-use-case-tuningmukul975/Anthropic-Cybersecurity-Skills
- configuring-pfsense-firewall-rulesmukul975/Anthropic-Cybersecurity-Skills
- performing-sqlite-database-forensicsmukul975/Anthropic-Cybersecurity-Skills
- analyzing-network-packets-with-scapymukul975/Anthropic-Cybersecurity-Skills
- testing-websocket-api-securitymukul975/Anthropic-Cybersecurity-Skills
- performing-indicator-lifecycle-managementmukul975/Anthropic-Cybersecurity-Skills
- implementing-zero-trust-with-beyondcorpmukul975/Anthropic-Cybersecurity-Skills
- analyzing-cyber-kill-chainmukul975/Anthropic-Cybersecurity-Skills
- hardening-docker-containers-for-productionmukul975/Anthropic-Cybersecurity-Skills
- implementing-browser-isolation-for-zero-trustmukul975/Anthropic-Cybersecurity-Skills
- configuring-snort-ids-for-intrusion-detectionmukul975/Anthropic-Cybersecurity-Skills
- implementing-alert-fatigue-reductionmukul975/Anthropic-Cybersecurity-Skills
- analyzing-ransomware-encryption-mechanismsmukul975/Anthropic-Cybersecurity-Skills
- analyzing-network-traffic-for-incidentsmukul975/Anthropic-Cybersecurity-Skills
- detecting-sql-injection-via-waf-logsmukul975/Anthropic-Cybersecurity-Skills
- testing-mobile-api-authenticationmukul975/Anthropic-Cybersecurity-Skills
- securing-kubernetes-on-cloudmukul975/Anthropic-Cybersecurity-Skills
- emulating-cloud-attacks-with-stratus-red-teammukul975/Anthropic-Cybersecurity-Skills
- performing-red-team-phishing-with-gophishmukul975/Anthropic-Cybersecurity-Skills
- analyzing-tls-certificate-transparency-logsmukul975/Anthropic-Cybersecurity-Skills
- performing-external-network-penetration-testmukul975/Anthropic-Cybersecurity-Skills
- implementing-api-gateway-security-controlsmukul975/Anthropic-Cybersecurity-Skills
- building-threat-feed-aggregation-with-mispmukul975/Anthropic-Cybersecurity-Skills
- integrating-sast-into-github-actions-pipelinemukul975/Anthropic-Cybersecurity-Skills
- deobfuscating-powershell-obfuscated-malwaremukul975/Anthropic-Cybersecurity-Skills
- analyzing-disk-image-with-autopsymukul975/Anthropic-Cybersecurity-Skills
- securing-container-registry-imagesmukul975/Anthropic-Cybersecurity-Skills
- performing-cloud-native-threat-hunting-with-aws-detectivemukul975/Anthropic-Cybersecurity-Skills
- performing-ssl-tls-inspection-configurationmukul975/Anthropic-Cybersecurity-Skills
- performing-cloud-native-forensics-with-falcomukul975/Anthropic-Cybersecurity-Skills
- detecting-business-email-compromise-with-aimukul975/Anthropic-Cybersecurity-Skills
- exploiting-jwt-algorithm-confusion-attackmukul975/Anthropic-Cybersecurity-Skills
- implementing-api-abuse-detection-with-rate-limitingmukul975/Anthropic-Cybersecurity-Skills
- detecting-container-drift-at-runtimemukul975/Anthropic-Cybersecurity-Skills
- attacking-entra-id-with-roadtoolsmukul975/Anthropic-Cybersecurity-Skills
- remediating-s3-bucket-misconfigurationmukul975/Anthropic-Cybersecurity-Skills
- implementing-rbac-hardening-for-kubernetesmukul975/Anthropic-Cybersecurity-Skills
- detecting-malicious-npm-packagesmukul975/Anthropic-Cybersecurity-Skills
The whole corpus is one call away through the search API, or ask a question of it on the index itself.