Agent skills that run powershell
A skill is a Markdown file that tells a coding agent how to do one job. We parse every one we can find — the frontmatter, the outline, the languages in its code blocks — so you can look for the one that fits instead of reading through a repository to find out.
69,865 skills from 9,574 repositories, last read 11 September 2026.
Skills declare what they need inconsistently: 58.8% name the languages they run, 11.2% list the tools they ask for, and 4.6% give themselves a category. Filtering narrows to the ones that said so, never to the ones that are.
- generating-python-installeraffaan-m/ECC
Commercial-grade Python installer expert for Windows: Nuitka extreme compilation, dist slimming, DLL footprint analysis, and Inno Setup packaging to ship the smallest, fastest inst
pluginbashbatchisspowershell - healthcheckopenclaw/openclaw
Audit/harden OpenClaw hosts: SSH, firewall, updates, exposure, backups, disk encryption, gateway security.
otherbashpowershell - huawei-cloud-find-skillshuaweicloud/huaweicloud-devkit
Invoke this skill to search, discover, browse, find and install any Huawei Cloud (华为云) agent skill.Triggers include: "华为云","华为云有什么skill","华为云相关skill","华为云agent skill 市场","华为云skill类
otherbashpowershell+1 files - ui-ux-pro-maxavelikiy/great_cto
UI/UX design intelligence for web and mobile. Includes 50+ styles, 161 color palettes, 57 font pairings, 161 product types, 99 UX guidelines, and 25 chart types across 10 stacks (R
pluginbashpowershell - windows-mcp-tool-testerCursorTouch/Windows-MCP
Automated testing skill for Windows-MCP tools. Use this skill whenever the user wants to test, validate, benchmark, or evaluate any Windows-MCP tool (App, PowerShell, Screenshot, S
claude-codemarkdownpowershell - stockbit-authINo-xious/stockbit-mcp
Log in to Stockbit and capture the session for this server — opens the browser login flow and verifies the token was stored. Use when the user asks to log in or re-authenticate to
pluginbashpowershell - playwright-clicoleam00/Archon
Automate browser interactions, test web pages and work with Playwright tests.
claude-codebashbatchpowershellBash(playwright-cli:*) Bash(npx:*) Bash(npm:*)+9 files - nacos-skill-registryalibaba/nacos
Discover, install, update, merge, and publish AI skills with Nacos for personal or team skill registries.
otherbashjsonpowershell - planning-with-filesOthmanAdi/planning-with-files
Persistent file-based planning for multi-step AI-agent work. Keeps task_plan.md, findings.md, and progress.md on disk; lifecycle hooks inject selected project planning context. Aut
pluginbashmarkdownpowershellRead Write Edit Bash Glob Grep+5 files - detecting-ntlm-relay-with-event-correlationmukul975/Anthropic-Cybersecurity-Skills
Detect NTLM relay attacks (T1557.001) by correlating Windows Event 4624 LogonType 3 for IP-to-hostname mismatches, identifying Responder/LLMNR poisoning artifacts, auditing SMB/LDA
pluginkqlpowershellsplyaml - conducting-cloud-incident-responsemukul975/Anthropic-Cybersecurity-Skills
Respond to security incidents in AWS, Azure, and GCP via identity-based containment, cloud-native log analysis (CloudTrail, Azure Activity Logs, GCP Audit Logs), resource isolation
pluginbashpowershell - investigating-phishing-email-incidentmukul975/Anthropic-Cybersecurity-Skills
Investigates phishing email incidents from initial user report through header analysis, URL/attachment detonation, impacted user identification, and containment actions using SOC t
pluginpowershellpythonspl - auditing-entra-id-with-aadinternalsmukul975/Anthropic-Cybersecurity-Skills
Drive the AADInternals PowerShell toolkit to perform Microsoft Entra ID tenant reconnaissance, access-token acquisition across Microsoft APIs, and federation/AD FS backdoor testing
pluginpowershell - implementing-delinea-secret-server-for-pammukul975/Anthropic-Cybersecurity-Skills
Implements Delinea Secret Server for privileged access management, covering secret vault configuration, role-based access policies, automated password rotation, session recording,
pluginpowershell - securing-azure-with-microsoft-defendermukul975/Anthropic-Cybersecurity-Skills
Deploys and configures Microsoft Defender for Cloud as a CNAPP for Azure, multi-cloud, and hybrid environments: enabling Defender plans for servers, containers, storage, and databa
pluginpowershell - implementing-honeypot-for-ransomware-detectionmukul975/Anthropic-Cybersecurity-Skills
Deploys canary files, honeypot shares, and decoy systems to detect ransomware activity at the earliest possible stage. Configures canary tokens embedded in strategic file locations
pluginbashpowershellpython - building-soc-playbook-for-ransomwaremukul975/Anthropic-Cybersecurity-Skills
Builds a structured SOC incident response playbook for ransomware attacks covering detection, containment, eradication, and recovery phases with specific SIEM queries, isolation pr
pluginbasheqlpowershellspl - performing-endpoint-forensics-investigationmukul975/Anthropic-Cybersecurity-Skills
Performs digital forensics investigation on compromised endpoints including memory acquisition, disk imaging, artifact analysis, and timeline reconstruction. Use when investigating
pluginbashpowershell - hardening-windows-endpoint-with-cis-benchmarkmukul975/Anthropic-Cybersecurity-Skills
Hardens Windows endpoints using CIS (Center for Internet Security) Benchmark recommendations to reduce attack surface, enforce security baselines, and meet compliance requirements.
pluginpowershell - hunting-for-defense-evasion-via-timestompingmukul975/Anthropic-Cybersecurity-Skills
Detect NTFS timestamp manipulation (MITRE T1070.006) by comparing $STANDARD_INFORMATION vs $FILE_NAME timestamps in the MFT. Uses analyzeMFT and Python to identify files with anoma
pluginbashpowershellpython - analyzing-mft-for-deleted-file-recoverymukul975/Anthropic-Cybersecurity-Skills
Analyze the NTFS Master File Table ($MFT) with MFTECmd, analyzeMFT, and X-Ways Forensics to recover metadata and content of deleted files by examining MFT record entries, $LogFile,
pluginpowershellpython - implementing-usb-device-control-policymukul975/Anthropic-Cybersecurity-Skills
Implements USB device control policies to restrict unauthorized removable media access on endpoints, preventing data exfiltration and malware introduction via USB devices. Use when
pluginpowershellxml - detecting-oauth-token-theftmukul975/Anthropic-Cybersecurity-Skills
Detect and respond to OAuth token theft and replay in Microsoft Entra ID (Azure AD), covering access token theft, refresh token replay, Primary Refresh Token (PRT) abuse, pass-the-
pluginkustopowershell - performing-authenticated-vulnerability-scanmukul975/Anthropic-Cybersecurity-Skills
Plan and run authenticated (credentialed) vulnerability scans with scanners such as Nessus, Qualys, OpenVAS, or Rapid7 InsightVM, using SSH, SMB, WinRM, or SNMPv3 credentials to in
pluginbashjsonpowershell - performing-active-directory-bloodhound-analysismukul975/Anthropic-Cybersecurity-Skills
Use BloodHound and SharpHound (or AzureHound) to enumerate Active Directory relationships and graph attack paths from a compromised user to Domain Admin. Use when performing AD red
pluginbashcypherpowershell - hunting-for-persistence-via-wmi-subscriptionsmukul975/Anthropic-Cybersecurity-Skills
Hunts for adversary persistence via WMI event subscriptions (MITRE T1546.003) by monitoring the creation of WMI event filters, consumers, and filter-to-consumer bindings that trigg
pluginkqlpowershellsplyaml - exploiting-active-directory-certificate-services-esc1mukul975/Anthropic-Cybersecurity-Skills
Exploit misconfigured Active Directory Certificate Services (AD CS) ESC1 vulnerability to request certificates as high-privileged users and escalate domain privileges during author
pluginbashpowershell - performing-cloud-storage-forensic-acquisitionmukul975/Anthropic-Cybersecurity-Skills
Perform forensic acquisition of cloud storage services including Google Drive, OneDrive, Dropbox, and Box by pulling API-based remote data such as revision history and audit logs,
pluginpowershellpython - implementing-device-posture-assessment-in-zero-trustmukul975/Anthropic-Cybersecurity-Skills
Implements device posture assessment as a zero trust access control by integrating endpoint health signals from CrowdStrike ZTA, Microsoft Intune, and Jamf into conditional access
pluginbashpowershellpython - building-cloud-siem-with-sentinelmukul975/Anthropic-Cybersecurity-Skills
Deploy Microsoft Sentinel as a cloud-native SIEM/SOAR by configuring multi-cloud data connectors (AWS, Azure, GCP), writing KQL detection and hunting queries, and building automate
pluginjsonkqlpowershell - parsing-artifacts-with-eric-zimmerman-toolsmukul975/Anthropic-Cybersecurity-Skills
Parse Windows forensic artifacts—$MFT/$J (MFTECmd), Prefetch (PECmd), registry hives (RECmd), shellbags, and Amcache—into normalized CSV/JSON with Eric Zimmerman's EZ Tools, then l
plugincmdpowershell - implementing-application-whitelisting-with-applockermukul975/Anthropic-Cybersecurity-Skills
Implements application whitelisting using Windows AppLocker to restrict unauthorized software execution on endpoints, reducing attack surface from malware, unauthorized tools, and
pluginpowershellxml - detecting-secure-boot-bypassmukul975/Anthropic-Cybersecurity-Skills
Detect UEFI Secure Boot bypasses and bootkits such as BlackLotus and Bootkitty by verifying Secure Boot state, checking dbx revocation currency, and hashing EFI boot binaries again
pluginbashpowershell - performing-credential-access-with-lazagnemukul975/Anthropic-Cybersecurity-Skills
Extract stored credentials from compromised endpoints using the LaZagne post-exploitation tool to recover passwords from browsers, databases, system vaults, and applications during
pluginbashpowershellpython - performing-endpoint-vulnerability-remediationmukul975/Anthropic-Cybersecurity-Skills
Performs vulnerability remediation on endpoints by prioritizing CVEs based on risk scoring, deploying patches, applying configuration changes, and validating fixes. Use when remedi
pluginpowershell - recovering-from-ransomware-attackmukul975/Anthropic-Cybersecurity-Skills
Executes structured ransomware incident recovery following NIST/CISA frameworks: environment isolation, forensic evidence preservation, clean infrastructure rebuild, prioritized re
pluginbashpowershell - mapping-attack-paths-with-bloodhound-cemukul975/Anthropic-Cybersecurity-Skills
Collect Active Directory data with SharpHound and Entra ID data with AzureHound, ingest into BloodHound Community Edition, and analyze on-prem, cloud, and hybrid attack paths using
pluginbashcypherpowershell - implementing-passwordless-auth-with-microsoft-entramukul975/Anthropic-Cybersecurity-Skills
Implements passwordless authentication using Microsoft Entra ID with FIDO2 security keys, Windows Hello for Business, Microsoft Authenticator passkeys, and certificate-based authen
pluginpowershell - performing-purple-team-atomic-testingmukul975/Anthropic-Cybersecurity-Skills
Executes Atomic Red Team tests mapped to MITRE ATT&CK via Invoke-AtomicRedTeam PowerShell, generates ATT&CK Navigator coverage heatmaps, correlates results against Sigma rules, and
pluginpowershellpython - performing-thick-client-application-penetration-testmukul975/Anthropic-Cybersecurity-Skills
Conduct a thick client application penetration test to identify insecure local storage, hardcoded credentials, DLL hijacking, memory manipulation, and insecure API communication in
pluginbashpowershell - conducting-full-scope-red-team-engagementmukul975/Anthropic-Cybersecurity-Skills
Plan and execute a comprehensive, MITRE ATT&CK-aligned red team engagement spanning threat modeling, reconnaissance, initial access, and post-exploitation to evaluate an organizati
pluginbashpowershell - performing-service-account-credential-rotationmukul975/Anthropic-Cybersecurity-Skills
Automates credential rotation for service accounts across Active Directory, cloud platforms, and application databases to eliminate stale secrets and reduce compromise risk. Use wh
pluginpowershellpython - performing-active-directory-vulnerability-assessmentmukul975/Anthropic-Cybersecurity-Skills
Assess Active Directory security posture using PingCastle, BloodHound, and Purple Knight to identify misconfigurations, privilege escalation paths, and attack vectors.
pluginbashcypherpowershell - implementing-rapid7-insightvm-for-scanningmukul975/Anthropic-Cybersecurity-Skills
Deploy and configure Rapid7 InsightVM Security Console and Scan Engines, including scan templates, credentialed scanning, and Insight Agent integration, for authenticated and unaut
pluginbashpowershellpython - auditing-azure-active-directory-configurationmukul975/Anthropic-Cybersecurity-Skills
Auditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies, overly permissive role assignments, stale accounts, conditional access
pluginbashpowershell - implementing-zero-trust-network-accessmukul975/Anthropic-Cybersecurity-Skills
Configures Zero Trust Network Access (ZTNA) in AWS, Azure, and GCP using identity-aware proxies, micro-segmentation, and continuous verification with conditional access policies, r
pluginbashpowershell - implementing-anti-ransomware-group-policymukul975/Anthropic-Cybersecurity-Skills
Configures Windows Group Policy Objects to block ransomware execution and lateral spread, covering AppLocker rules, Software Restriction Policies, Controlled Folder Access, attack
pluginpowershell - performing-cloud-incident-containment-proceduresmukul975/Anthropic-Cybersecurity-Skills
Execute cloud-native incident containment across AWS, Azure, and GCP using platform CLIs to revoke or disable compromised IAM credentials, isolate resources with security groups an
pluginbashpowershell - exploiting-constrained-delegation-abusemukul975/Anthropic-Cybersecurity-Skills
Exploits Kerberos Constrained Delegation misconfigurations in Active Directory using Impacket's findDelegation.py and getST.py (or Rubeus/Kekeo on Windows) to abuse S4U2Self and S4
pluginbashcypherpowershell - conducting-internal-reconnaissance-with-bloodhound-cemukul975/Anthropic-Cybersecurity-Skills
Conduct internal Active Directory reconnaissance using BloodHound Community Edition's graph database with the SharpHound (AD) and AzureHound (Entra ID) collectors, mapping ACLs, se
pluginbashcypherpowershell - implementing-ransomware-backup-strategymukul975/Anthropic-Cybersecurity-Skills
Designs a ransomware-resilient backup strategy using the 3-2-1-1-0 methodology (3 copies, 2 media types, 1 offsite, 1 immutable/air-gapped, 0 restore errors), configuring RPO/RTO-a
pluginbashpowershell - exploiting-kerberoasting-with-impacketmukul975/Anthropic-Cybersecurity-Skills
Performs Kerberoasting (MITRE ATT&CK T1558.003) using Impacket's GetUserSPNs.py to request Kerberos TGS tickets for SPN-registered service accounts, then cracks the extracted RC4/A
pluginbashpowershellyaml - analyzing-lnk-file-and-jump-list-artifactsmukul975/Anthropic-Cybersecurity-Skills
Analyze Windows LNK shortcut files and Jump List artifacts with LECmd, JLECmd, and manual Shell Link Binary Format parsing to establish evidence of file access, program execution,
pluginpowershellpython - implementing-memory-protection-with-dep-aslrmukul975/Anthropic-Cybersecurity-Skills
Implements memory protection mechanisms including DEP (Data Execution Prevention), ASLR (Address Space Layout Randomization), CFG (Control Flow Guard), and other exploit mitigation
pluginpowershell - performing-purple-team-exercisemukul975/Anthropic-Cybersecurity-Skills
Performs purple team exercises by coordinating red team adversary emulation with blue team detection validation using MITRE ATT&CK-mapped attack scenarios, real-time detection test
pluginpowershellpythonsplyaml - implementing-zero-trust-dns-with-nextdnsmukul975/Anthropic-Cybersecurity-Skills
Configure NextDNS as an encrypted (DoH/DoT) zero trust DNS resolver that blocks malicious, phishing, and cryptojacking domains via real-time threat intelligence, detects DNS rebind
pluginbashpowershell - detecting-fileless-attacks-on-endpointsmukul975/Anthropic-Cybersecurity-Skills
Detects fileless malware and in-memory attacks that execute entirely in RAM without writing persistent files to disk, evading traditional antivirus. Use when building detections fo
pluginpowershell - implementing-data-loss-prevention-with-microsoft-purviewmukul975/Anthropic-Cybersecurity-Skills
Implements DLP policies using Microsoft Purview PowerShell cmdlets and the Graph API to protect data across Exchange Online, SharePoint, OneDrive, Teams, endpoints, and Power BI, i
pluginpowershellpython - attacking-oauth-with-device-code-phishingmukul975/Anthropic-Cybersecurity-Skills
Run OAuth 2.0 device-code and illicit-consent phishing attacks against Microsoft Entra ID, using TokenTactics-style tooling to steal access and refresh tokens, bypass MFA, and pivo
pluginbashjsonpowershell - detecting-living-off-the-land-attacksmukul975/Anthropic-Cybersecurity-Skills
Detect abuse of legitimate Windows binaries (LOLBins) used for living off the land attacks. Monitors process creation, command-line arguments, and parent-child relationships to ide
pluginpowershellpythonxmlyaml
Browse all 69,865 skills →200 at a time, grouped by owner. The list above is the skills with the highest standing; this is every one of them.
The whole corpus is one call away through the search API, or ask a question of it on the index itself.