BigHugger

Agent skills that run powershell

A skill is a Markdown file that tells a coding agent how to do one job. We parse every one we can find — the frontmatter, the outline, the languages in its code blocks — so you can look for the one that fits instead of reading through a repository to find out.

69,865 skills from 9,574 repositories, last read 11 September 2026.

Skills declare what they need inconsistently: 58.8% name the languages they run, 11.2% list the tools they ask for, and 4.6% give themselves a category. Filtering narrows to the ones that said so, never to the ones that are.

  1. generating-python-installeraffaan-m/ECC

    Commercial-grade Python installer expert for Windows: Nuitka extreme compilation, dist slimming, DLL footprint analysis, and Inno Setup packaging to ship the smallest, fastest inst

    pluginbashbatchisspowershell
  2. healthcheckopenclaw/openclaw

    Audit/harden OpenClaw hosts: SSH, firewall, updates, exposure, backups, disk encryption, gateway security.

    otherbashpowershell
  3. huawei-cloud-find-skillshuaweicloud/huaweicloud-devkit

    Invoke this skill to search, discover, browse, find and install any Huawei Cloud (华为云) agent skill.Triggers include: "华为云","华为云有什么skill","华为云相关skill","华为云agent skill 市场","华为云skill类

    otherbashpowershell+1 files
  4. ui-ux-pro-maxavelikiy/great_cto

    UI/UX design intelligence for web and mobile. Includes 50+ styles, 161 color palettes, 57 font pairings, 161 product types, 99 UX guidelines, and 25 chart types across 10 stacks (R

    pluginbashpowershell
  5. windows-mcp-tool-testerCursorTouch/Windows-MCP

    Automated testing skill for Windows-MCP tools. Use this skill whenever the user wants to test, validate, benchmark, or evaluate any Windows-MCP tool (App, PowerShell, Screenshot, S

    claude-codemarkdownpowershell
  6. stockbit-authINo-xious/stockbit-mcp

    Log in to Stockbit and capture the session for this server — opens the browser login flow and verifies the token was stored. Use when the user asks to log in or re-authenticate to

    pluginbashpowershell
  7. playwright-clicoleam00/Archon

    Automate browser interactions, test web pages and work with Playwright tests.

    claude-codebashbatchpowershellBash(playwright-cli:*) Bash(npx:*) Bash(npm:*)+9 files
  8. nacos-skill-registryalibaba/nacos

    Discover, install, update, merge, and publish AI skills with Nacos for personal or team skill registries.

    otherbashjsonpowershell
  9. planning-with-filesOthmanAdi/planning-with-files

    Persistent file-based planning for multi-step AI-agent work. Keeps task_plan.md, findings.md, and progress.md on disk; lifecycle hooks inject selected project planning context. Aut

    pluginbashmarkdownpowershellRead Write Edit Bash Glob Grep+5 files
  10. detecting-ntlm-relay-with-event-correlationmukul975/Anthropic-Cybersecurity-Skills

    Detect NTLM relay attacks (T1557.001) by correlating Windows Event 4624 LogonType 3 for IP-to-hostname mismatches, identifying Responder/LLMNR poisoning artifacts, auditing SMB/LDA

    pluginkqlpowershellsplyaml
  11. conducting-cloud-incident-responsemukul975/Anthropic-Cybersecurity-Skills

    Respond to security incidents in AWS, Azure, and GCP via identity-based containment, cloud-native log analysis (CloudTrail, Azure Activity Logs, GCP Audit Logs), resource isolation

    pluginbashpowershell
  12. investigating-phishing-email-incidentmukul975/Anthropic-Cybersecurity-Skills

    Investigates phishing email incidents from initial user report through header analysis, URL/attachment detonation, impacted user identification, and containment actions using SOC t

    pluginpowershellpythonspl
  13. auditing-entra-id-with-aadinternalsmukul975/Anthropic-Cybersecurity-Skills

    Drive the AADInternals PowerShell toolkit to perform Microsoft Entra ID tenant reconnaissance, access-token acquisition across Microsoft APIs, and federation/AD FS backdoor testing

    pluginpowershell
  14. implementing-delinea-secret-server-for-pammukul975/Anthropic-Cybersecurity-Skills

    Implements Delinea Secret Server for privileged access management, covering secret vault configuration, role-based access policies, automated password rotation, session recording,

    pluginpowershell
  15. securing-azure-with-microsoft-defendermukul975/Anthropic-Cybersecurity-Skills

    Deploys and configures Microsoft Defender for Cloud as a CNAPP for Azure, multi-cloud, and hybrid environments: enabling Defender plans for servers, containers, storage, and databa

    pluginpowershell
  16. implementing-honeypot-for-ransomware-detectionmukul975/Anthropic-Cybersecurity-Skills

    Deploys canary files, honeypot shares, and decoy systems to detect ransomware activity at the earliest possible stage. Configures canary tokens embedded in strategic file locations

    pluginbashpowershellpython
  17. building-soc-playbook-for-ransomwaremukul975/Anthropic-Cybersecurity-Skills

    Builds a structured SOC incident response playbook for ransomware attacks covering detection, containment, eradication, and recovery phases with specific SIEM queries, isolation pr

    pluginbasheqlpowershellspl
  18. performing-endpoint-forensics-investigationmukul975/Anthropic-Cybersecurity-Skills

    Performs digital forensics investigation on compromised endpoints including memory acquisition, disk imaging, artifact analysis, and timeline reconstruction. Use when investigating

    pluginbashpowershell
  19. hardening-windows-endpoint-with-cis-benchmarkmukul975/Anthropic-Cybersecurity-Skills

    Hardens Windows endpoints using CIS (Center for Internet Security) Benchmark recommendations to reduce attack surface, enforce security baselines, and meet compliance requirements.

    pluginpowershell
  20. hunting-for-defense-evasion-via-timestompingmukul975/Anthropic-Cybersecurity-Skills

    Detect NTFS timestamp manipulation (MITRE T1070.006) by comparing $STANDARD_INFORMATION vs $FILE_NAME timestamps in the MFT. Uses analyzeMFT and Python to identify files with anoma

    pluginbashpowershellpython
  21. analyzing-mft-for-deleted-file-recoverymukul975/Anthropic-Cybersecurity-Skills

    Analyze the NTFS Master File Table ($MFT) with MFTECmd, analyzeMFT, and X-Ways Forensics to recover metadata and content of deleted files by examining MFT record entries, $LogFile,

    pluginpowershellpython
  22. implementing-usb-device-control-policymukul975/Anthropic-Cybersecurity-Skills

    Implements USB device control policies to restrict unauthorized removable media access on endpoints, preventing data exfiltration and malware introduction via USB devices. Use when

    pluginpowershellxml
  23. detecting-oauth-token-theftmukul975/Anthropic-Cybersecurity-Skills

    Detect and respond to OAuth token theft and replay in Microsoft Entra ID (Azure AD), covering access token theft, refresh token replay, Primary Refresh Token (PRT) abuse, pass-the-

    pluginkustopowershell
  24. performing-authenticated-vulnerability-scanmukul975/Anthropic-Cybersecurity-Skills

    Plan and run authenticated (credentialed) vulnerability scans with scanners such as Nessus, Qualys, OpenVAS, or Rapid7 InsightVM, using SSH, SMB, WinRM, or SNMPv3 credentials to in

    pluginbashjsonpowershell
  25. performing-active-directory-bloodhound-analysismukul975/Anthropic-Cybersecurity-Skills

    Use BloodHound and SharpHound (or AzureHound) to enumerate Active Directory relationships and graph attack paths from a compromised user to Domain Admin. Use when performing AD red

    pluginbashcypherpowershell
  26. hunting-for-persistence-via-wmi-subscriptionsmukul975/Anthropic-Cybersecurity-Skills

    Hunts for adversary persistence via WMI event subscriptions (MITRE T1546.003) by monitoring the creation of WMI event filters, consumers, and filter-to-consumer bindings that trigg

    pluginkqlpowershellsplyaml
  27. exploiting-active-directory-certificate-services-esc1mukul975/Anthropic-Cybersecurity-Skills

    Exploit misconfigured Active Directory Certificate Services (AD CS) ESC1 vulnerability to request certificates as high-privileged users and escalate domain privileges during author

    pluginbashpowershell
  28. performing-cloud-storage-forensic-acquisitionmukul975/Anthropic-Cybersecurity-Skills

    Perform forensic acquisition of cloud storage services including Google Drive, OneDrive, Dropbox, and Box by pulling API-based remote data such as revision history and audit logs,

    pluginpowershellpython
  29. implementing-device-posture-assessment-in-zero-trustmukul975/Anthropic-Cybersecurity-Skills

    Implements device posture assessment as a zero trust access control by integrating endpoint health signals from CrowdStrike ZTA, Microsoft Intune, and Jamf into conditional access

    pluginbashpowershellpython
  30. building-cloud-siem-with-sentinelmukul975/Anthropic-Cybersecurity-Skills

    Deploy Microsoft Sentinel as a cloud-native SIEM/SOAR by configuring multi-cloud data connectors (AWS, Azure, GCP), writing KQL detection and hunting queries, and building automate

    pluginjsonkqlpowershell
  31. parsing-artifacts-with-eric-zimmerman-toolsmukul975/Anthropic-Cybersecurity-Skills

    Parse Windows forensic artifacts—$MFT/$J (MFTECmd), Prefetch (PECmd), registry hives (RECmd), shellbags, and Amcache—into normalized CSV/JSON with Eric Zimmerman's EZ Tools, then l

    plugincmdpowershell
  32. implementing-application-whitelisting-with-applockermukul975/Anthropic-Cybersecurity-Skills

    Implements application whitelisting using Windows AppLocker to restrict unauthorized software execution on endpoints, reducing attack surface from malware, unauthorized tools, and

    pluginpowershellxml
  33. detecting-secure-boot-bypassmukul975/Anthropic-Cybersecurity-Skills

    Detect UEFI Secure Boot bypasses and bootkits such as BlackLotus and Bootkitty by verifying Secure Boot state, checking dbx revocation currency, and hashing EFI boot binaries again

    pluginbashpowershell
  34. performing-credential-access-with-lazagnemukul975/Anthropic-Cybersecurity-Skills

    Extract stored credentials from compromised endpoints using the LaZagne post-exploitation tool to recover passwords from browsers, databases, system vaults, and applications during

    pluginbashpowershellpython
  35. performing-endpoint-vulnerability-remediationmukul975/Anthropic-Cybersecurity-Skills

    Performs vulnerability remediation on endpoints by prioritizing CVEs based on risk scoring, deploying patches, applying configuration changes, and validating fixes. Use when remedi

    pluginpowershell
  36. recovering-from-ransomware-attackmukul975/Anthropic-Cybersecurity-Skills

    Executes structured ransomware incident recovery following NIST/CISA frameworks: environment isolation, forensic evidence preservation, clean infrastructure rebuild, prioritized re

    pluginbashpowershell
  37. mapping-attack-paths-with-bloodhound-cemukul975/Anthropic-Cybersecurity-Skills

    Collect Active Directory data with SharpHound and Entra ID data with AzureHound, ingest into BloodHound Community Edition, and analyze on-prem, cloud, and hybrid attack paths using

    pluginbashcypherpowershell
  38. implementing-passwordless-auth-with-microsoft-entramukul975/Anthropic-Cybersecurity-Skills

    Implements passwordless authentication using Microsoft Entra ID with FIDO2 security keys, Windows Hello for Business, Microsoft Authenticator passkeys, and certificate-based authen

    pluginpowershell
  39. performing-purple-team-atomic-testingmukul975/Anthropic-Cybersecurity-Skills

    Executes Atomic Red Team tests mapped to MITRE ATT&CK via Invoke-AtomicRedTeam PowerShell, generates ATT&CK Navigator coverage heatmaps, correlates results against Sigma rules, and

    pluginpowershellpython
  40. performing-thick-client-application-penetration-testmukul975/Anthropic-Cybersecurity-Skills

    Conduct a thick client application penetration test to identify insecure local storage, hardcoded credentials, DLL hijacking, memory manipulation, and insecure API communication in

    pluginbashpowershell
  41. conducting-full-scope-red-team-engagementmukul975/Anthropic-Cybersecurity-Skills

    Plan and execute a comprehensive, MITRE ATT&CK-aligned red team engagement spanning threat modeling, reconnaissance, initial access, and post-exploitation to evaluate an organizati

    pluginbashpowershell
  42. performing-service-account-credential-rotationmukul975/Anthropic-Cybersecurity-Skills

    Automates credential rotation for service accounts across Active Directory, cloud platforms, and application databases to eliminate stale secrets and reduce compromise risk. Use wh

    pluginpowershellpython
  43. performing-active-directory-vulnerability-assessmentmukul975/Anthropic-Cybersecurity-Skills

    Assess Active Directory security posture using PingCastle, BloodHound, and Purple Knight to identify misconfigurations, privilege escalation paths, and attack vectors.

    pluginbashcypherpowershell
  44. implementing-rapid7-insightvm-for-scanningmukul975/Anthropic-Cybersecurity-Skills

    Deploy and configure Rapid7 InsightVM Security Console and Scan Engines, including scan templates, credentialed scanning, and Insight Agent integration, for authenticated and unaut

    pluginbashpowershellpython
  45. auditing-azure-active-directory-configurationmukul975/Anthropic-Cybersecurity-Skills

    Auditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies, overly permissive role assignments, stale accounts, conditional access

    pluginbashpowershell
  46. implementing-zero-trust-network-accessmukul975/Anthropic-Cybersecurity-Skills

    Configures Zero Trust Network Access (ZTNA) in AWS, Azure, and GCP using identity-aware proxies, micro-segmentation, and continuous verification with conditional access policies, r

    pluginbashpowershell
  47. implementing-anti-ransomware-group-policymukul975/Anthropic-Cybersecurity-Skills

    Configures Windows Group Policy Objects to block ransomware execution and lateral spread, covering AppLocker rules, Software Restriction Policies, Controlled Folder Access, attack

    pluginpowershell
  48. performing-cloud-incident-containment-proceduresmukul975/Anthropic-Cybersecurity-Skills

    Execute cloud-native incident containment across AWS, Azure, and GCP using platform CLIs to revoke or disable compromised IAM credentials, isolate resources with security groups an

    pluginbashpowershell
  49. exploiting-constrained-delegation-abusemukul975/Anthropic-Cybersecurity-Skills

    Exploits Kerberos Constrained Delegation misconfigurations in Active Directory using Impacket's findDelegation.py and getST.py (or Rubeus/Kekeo on Windows) to abuse S4U2Self and S4

    pluginbashcypherpowershell
  50. conducting-internal-reconnaissance-with-bloodhound-cemukul975/Anthropic-Cybersecurity-Skills

    Conduct internal Active Directory reconnaissance using BloodHound Community Edition's graph database with the SharpHound (AD) and AzureHound (Entra ID) collectors, mapping ACLs, se

    pluginbashcypherpowershell
  51. implementing-ransomware-backup-strategymukul975/Anthropic-Cybersecurity-Skills

    Designs a ransomware-resilient backup strategy using the 3-2-1-1-0 methodology (3 copies, 2 media types, 1 offsite, 1 immutable/air-gapped, 0 restore errors), configuring RPO/RTO-a

    pluginbashpowershell
  52. exploiting-kerberoasting-with-impacketmukul975/Anthropic-Cybersecurity-Skills

    Performs Kerberoasting (MITRE ATT&CK T1558.003) using Impacket's GetUserSPNs.py to request Kerberos TGS tickets for SPN-registered service accounts, then cracks the extracted RC4/A

    pluginbashpowershellyaml
  53. analyzing-lnk-file-and-jump-list-artifactsmukul975/Anthropic-Cybersecurity-Skills

    Analyze Windows LNK shortcut files and Jump List artifacts with LECmd, JLECmd, and manual Shell Link Binary Format parsing to establish evidence of file access, program execution,

    pluginpowershellpython
  54. implementing-memory-protection-with-dep-aslrmukul975/Anthropic-Cybersecurity-Skills

    Implements memory protection mechanisms including DEP (Data Execution Prevention), ASLR (Address Space Layout Randomization), CFG (Control Flow Guard), and other exploit mitigation

    pluginpowershell
  55. performing-purple-team-exercisemukul975/Anthropic-Cybersecurity-Skills

    Performs purple team exercises by coordinating red team adversary emulation with blue team detection validation using MITRE ATT&CK-mapped attack scenarios, real-time detection test

    pluginpowershellpythonsplyaml
  56. implementing-zero-trust-dns-with-nextdnsmukul975/Anthropic-Cybersecurity-Skills

    Configure NextDNS as an encrypted (DoH/DoT) zero trust DNS resolver that blocks malicious, phishing, and cryptojacking domains via real-time threat intelligence, detects DNS rebind

    pluginbashpowershell
  57. detecting-fileless-attacks-on-endpointsmukul975/Anthropic-Cybersecurity-Skills

    Detects fileless malware and in-memory attacks that execute entirely in RAM without writing persistent files to disk, evading traditional antivirus. Use when building detections fo

    pluginpowershell
  58. implementing-data-loss-prevention-with-microsoft-purviewmukul975/Anthropic-Cybersecurity-Skills

    Implements DLP policies using Microsoft Purview PowerShell cmdlets and the Graph API to protect data across Exchange Online, SharePoint, OneDrive, Teams, endpoints, and Power BI, i

    pluginpowershellpython
  59. attacking-oauth-with-device-code-phishingmukul975/Anthropic-Cybersecurity-Skills

    Run OAuth 2.0 device-code and illicit-consent phishing attacks against Microsoft Entra ID, using TokenTactics-style tooling to steal access and refresh tokens, bypass MFA, and pivo

    pluginbashjsonpowershell
  60. detecting-living-off-the-land-attacksmukul975/Anthropic-Cybersecurity-Skills

    Detect abuse of legitimate Windows binaries (LOLBins) used for living off the land attacks. Monitors process creation, command-line arguments, and parent-child relationships to ide

    pluginpowershellpythonxmlyaml

Browse all 69,865 skills200 at a time, grouped by owner. The list above is the skills with the highest standing; this is every one of them.

The whole corpus is one call away through the search API, or ask a question of it on the index itself.