📦 deps(thirdparty): update snapshots

This commit is contained in:
ci[bot]
2026-07-30 01:23:25 +00:00
parent 0c634043e3
commit a2904b069a
3368 changed files with 12954 additions and 9475 deletions
@@ -6,12 +6,12 @@
},
"metadata": {
"description": "Claude Code marketplace entries for the plugin-safe Agentic Awesome Skills library and its compatible editorial bundles.",
"version": "15.6.0"
"version": "15.7.0"
},
"plugins": [
{
"name": "agentic-awesome-skills",
"version": "15.6.0",
"version": "15.7.0",
"description": "Expose the plugin-safe Claude Code subset of Agentic Awesome Skills through a single marketplace entry.",
"author": {
"name": "sickn33 and contributors",
@@ -31,7 +31,7 @@
},
{
"name": "agentic-bundle-essentials",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"Essentials\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -51,7 +51,7 @@
},
{
"name": "agentic-bundle-security-engineer",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"Security Engineer\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -71,7 +71,7 @@
},
{
"name": "agentic-bundle-security-developer",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"Security Developer\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -91,7 +91,7 @@
},
{
"name": "agentic-bundle-web-wizard",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"Web Wizard\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -111,7 +111,7 @@
},
{
"name": "agentic-bundle-web-designer",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"Web Designer\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -131,7 +131,7 @@
},
{
"name": "agentic-bundle-full-stack-developer",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"Full-Stack Developer\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -151,7 +151,7 @@
},
{
"name": "agentic-bundle-agent-architect",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"Agent Architect\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -171,7 +171,7 @@
},
{
"name": "agentic-bundle-llm-application-developer",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"LLM Application Developer\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -191,7 +191,7 @@
},
{
"name": "agentic-bundle-indie-game-dev",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"Indie Game Dev\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -211,7 +211,7 @@
},
{
"name": "agentic-bundle-python-pro",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"Python Pro\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -231,7 +231,7 @@
},
{
"name": "agentic-bundle-typescript-javascript",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"TypeScript & JavaScript\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -251,7 +251,7 @@
},
{
"name": "agentic-bundle-systems-programming",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"Systems Programming\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -271,7 +271,7 @@
},
{
"name": "agentic-bundle-startup-founder",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"Startup Founder\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -291,7 +291,7 @@
},
{
"name": "agentic-bundle-business-analyst",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"Business Analyst\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -311,7 +311,7 @@
},
{
"name": "agentic-bundle-marketing-growth",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"Marketing & Growth\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -331,7 +331,7 @@
},
{
"name": "agentic-bundle-devops-cloud",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"DevOps & Cloud\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -351,7 +351,7 @@
},
{
"name": "agentic-bundle-observability-monitoring",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"Observability & Monitoring\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -371,7 +371,7 @@
},
{
"name": "agentic-bundle-data-analytics",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"Data & Analytics\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -391,7 +391,7 @@
},
{
"name": "agentic-bundle-data-engineering",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"Data Engineering\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -411,7 +411,7 @@
},
{
"name": "agentic-bundle-creative-director",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"Creative Director\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -431,7 +431,7 @@
},
{
"name": "agentic-bundle-qa-testing",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"QA & Testing\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -451,7 +451,7 @@
},
{
"name": "agentic-bundle-aas-web-app-builder",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"AAS Web App Builder\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -471,7 +471,7 @@
},
{
"name": "agentic-bundle-aas-product-design-studio",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"AAS Product Design Studio\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -491,7 +491,7 @@
},
{
"name": "agentic-bundle-aas-security-engineer",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"AAS Security Engineer\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -511,7 +511,7 @@
},
{
"name": "agentic-bundle-aas-secure-app-builder",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"AAS Secure App Builder\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -531,7 +531,7 @@
},
{
"name": "agentic-bundle-aas-documents-presentations",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"AAS Documents & Presentations\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -551,7 +551,7 @@
},
{
"name": "agentic-bundle-aas-data-analytics",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"AAS Data Analytics\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -571,7 +571,7 @@
},
{
"name": "agentic-bundle-aas-agent-mcp-builder",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"AAS Agent & MCP Builder\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -591,7 +591,7 @@
},
{
"name": "agentic-bundle-aas-qa-test-automation",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"AAS QA & Test Automation\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -611,7 +611,7 @@
},
{
"name": "agentic-bundle-aas-devops-cloud",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"AAS DevOps & Cloud\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -631,7 +631,7 @@
},
{
"name": "agentic-bundle-aas-marketing-seo-growth",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"AAS Marketing, SEO & Growth\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -651,7 +651,7 @@
},
{
"name": "agentic-bundle-aas-automation-builder",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"AAS Automation Builder\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -671,7 +671,7 @@
},
{
"name": "agentic-bundle-aas-observability-ir",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"AAS Observability IR\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -691,7 +691,7 @@
},
{
"name": "agentic-bundle-aas-python-api-builder",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"AAS Python API Builder\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -711,7 +711,7 @@
},
{
"name": "agentic-bundle-aas-mobile-app-builder",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"AAS Mobile App Builder\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -731,7 +731,7 @@
},
{
"name": "agentic-bundle-mobile-developer",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"Mobile Developer\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -751,7 +751,7 @@
},
{
"name": "agentic-bundle-integration-apis",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"Integration & APIs\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -771,7 +771,7 @@
},
{
"name": "agentic-bundle-architecture-design",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"Architecture & Design\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -791,7 +791,7 @@
},
{
"name": "agentic-bundle-ddd-evented-architecture",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"DDD & Evented Architecture\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -811,7 +811,7 @@
},
{
"name": "agentic-bundle-automation-builder",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"Automation Builder\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -831,7 +831,7 @@
},
{
"name": "agentic-bundle-revops-crm-automation",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"RevOps & CRM Automation\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -851,7 +851,7 @@
},
{
"name": "agentic-bundle-commerce-payments",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"Commerce & Payments\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -871,7 +871,7 @@
},
{
"name": "agentic-bundle-odoo-erp",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"Odoo ERP\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -891,7 +891,7 @@
},
{
"name": "agentic-bundle-azure-ai-cloud",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"Azure AI & Cloud\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -911,7 +911,7 @@
},
{
"name": "agentic-bundle-expo-react-native",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"Expo & React Native\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -931,7 +931,7 @@
},
{
"name": "agentic-bundle-apple-platform-design",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"Apple Platform Design\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -951,7 +951,7 @@
},
{
"name": "agentic-bundle-makepad-builder",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"Makepad Builder\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -971,7 +971,7 @@
},
{
"name": "agentic-bundle-seo-specialist",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"SEO Specialist\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -991,7 +991,7 @@
},
{
"name": "agentic-bundle-documents-presentations",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"Documents & Presentations\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -1011,7 +1011,7 @@
},
{
"name": "agentic-bundle-oss-maintainer",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"OSS Maintainer\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -1031,7 +1031,7 @@
},
{
"name": "agentic-bundle-skill-author",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"Skill Author\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -1051,7 +1051,7 @@
},
{
"name": "agentic-bundle-aas-accessibility-inclusive-ux",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"AAS Accessibility & Inclusive UX\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -1071,7 +1071,7 @@
},
{
"name": "agentic-bundle-aas-api-platform-builder",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"AAS API Platform Builder\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -1091,7 +1091,7 @@
},
{
"name": "agentic-bundle-aas-saas-launch-revenue",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"AAS SaaS Launch & Revenue\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -1111,7 +1111,7 @@
},
{
"name": "agentic-bundle-aas-ai-product-evaluation-ops",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"AAS AI Product & Evaluation Ops\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -1131,7 +1131,7 @@
},
{
"name": "agentic-bundle-aas-data-engineering-platform",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"AAS Data Engineering Platform\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -1151,7 +1151,7 @@
},
{
"name": "agentic-bundle-aas-privacy-compliance-engineering",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"AAS Privacy & Compliance Engineering\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -1171,7 +1171,7 @@
},
{
"name": "agentic-bundle-aas-localization-international-growth",
"version": "15.6.0",
"version": "15.7.0",
"description": "Install the \"AAS Localization & International Growth\" editorial skill bundle for Claude Code.",
"author": {
"name": "sickn33 and contributors",
@@ -1,7 +1,7 @@
{
"name": "agentic-awesome-skills",
"version": "15.6.0",
"description": "Plugin-safe Claude Code distribution of Agentic Awesome Skills with 1,938 supported skills.",
"version": "15.7.0",
"description": "Plugin-safe Claude Code distribution of Agentic Awesome Skills with 1,939 supported skills.",
"author": {
"name": "sickn33 and contributors",
"url": "https://github.com/sickn33/agentic-awesome-skills"
+2
View File
@@ -153,6 +153,8 @@ Before ANY commit that adds/modifies skills, run the chain:
For every canonical `SKILL.md` or tracked bundle-file change, run validation, reference validation, documentation security, changed-skill evidence, and relevant tests. Review semantics, provenance, declared risk, limitations, and bundled files directly. The separate `skill-review` workflow or an exact-head maintainer attestation remains authoritative; local heuristic scores and inferred risk labels are not merge gates.
Changed-skill evidence resolves canonical ownership from the changed path's ancestors rather than scanning the complete skill registry for every Git record. Keep this lookup bounded and preserve the five-minute trusted evaluator budget so repository-wide maintenance batches can complete without weakening fail-closed evidence checks. Legacy canonical `SKILL.md` blobs with executable mode are parsed only as private, non-executable snapshot data; they remain reported as unsafe entries, while symlinks, gitlinks, and every other executable file remain unmaterialized.
1. **CI is green** — Validation, warning-budget enforcement, README source-credit checks, reference checks, tests, and generated artifact steps passed (see [`.github/workflows/ci.yml`](workflows/ci.yml)). If the PR changes anything under `skills/**` or `plugins/**/skills/**`, the separate [`skill-review` workflow](workflows/skill-review.yml) must also report a truthful outcome.
2. **Generated drift understood** — On pull requests, generator drift is informational only. Do not block a good PR solely because canonical artifacts would be regenerated. Also do not accept PRs that directly edit `CATALOG.md`, `skills_index.json`, or `data/*.json`; those files are `main`-owned.
3. **Quality Bar** — PR description confirms the [Quality Bar Checklist](.github/PULL_REQUEST_TEMPLATE.md) (metadata, risk label, credits if applicable).
File diff suppressed because it is too large Load Diff
+45 -2
View File
@@ -9,13 +9,56 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
## [Unreleased]
## [15.7.0] - 2026-07-29 - "Risk Metadata and Installation Hardening"
> Completed semantic risk classification across the catalog, hardened skill installation and maintainer evidence boundaries, and added a consent-gated backend provisioning skill.
Start here:
- AAS Core setup: configure the exact `aas` runtime with the [Core guide](https://github.com/sickn33/agentic-awesome-skills/blob/main/docs/users/aas-core.md)
- Direct skill distribution: `npx agentic-awesome-skills`
- [Choose your tool](https://github.com/sickn33/agentic-awesome-skills#choose-your-tool)
- [Best skills by tool](https://github.com/sickn33/agentic-awesome-skills#best-skills-by-tool)
- [Bundles](https://github.com/sickn33/agentic-awesome-skills/blob/main/docs/users/bundles.md)
- [Workflows](https://github.com/sickn33/agentic-awesome-skills/blob/main/docs/users/workflows.md)
### Added
- Added [`cohesivity`](skills/cohesivity/) for consent-gated provisioning of Postgres, Redis, object and vector storage, hosting, authentication, email, managed browser, and model APIs, with private credential storage, explicit retention disclosure, and budget controls.
- Regenerated the canonical catalog and Codex/Claude distribution surfaces for 1,994 skills.
### Changed
- Updated the catalog web app from `@supabase/supabase-js` 2.110.0 to 2.111.0, including the auth fix for overlapping PKCE flows, while preserving platform-specific native package metadata in the lockfile.
- Replaced all 940 remaining `risk: unknown` declarations with individually reviewed semantic classifications: 798 `critical`, 71 `none`, 60 `safe`, and 11 `offensive`.
- Added the repository-standard authorized-use disclaimer and per-action confirmation gate to the 11 newly classified offensive skills.
- Added a pre-install audit and prominent risk summary while preserving the full-catalog installation default.
- Replaced mutable external installation guidance with approval-gated, full-commit-SHA inspect-first workflows and clarified the difference between antivirus text detections and evidence of execution.
- Bounded changed-skill ownership lookup by changed-path depth, extended the trusted evaluator budget for repository-wide reviews, and safely supported legacy executable-mode `SKILL.md` snapshots without materializing executable files, symlinks, or gitlinks.
- Updated Modellix vendored source URLs and speech defaults, upgraded the catalog web app to `@supabase/supabase-js` 2.111.0, and normalized indexable catalog links for GitHub Pages.
### Security
- Removed mutable provider instructions from BrowserAct's operating-policy boundary and required full 40-character Git commit pins for linked FindMate profiles.
- Strengthened installation safety for offensive and externally sourced skills with explicit authorization, command confirmation, provenance inspection, and immutable source pins.
- Hardened Cohesivity credential files to private permissions and documented privacy, retention, billing, overage, and x402 self-payment boundaries.
### Who should care
- Claude Code, Cursor, Codex CLI, Gemini CLI, Windsurf, and Antigravity users who want actionable risk metadata before installing or running skills.
- Security-conscious teams auditing offensive, networked, credential-bearing, or externally sourced skills.
- Maintainers running large repository-wide skill reviews through the protected evidence and merge workflow.
- Developers who need a consent-gated, agent-provisioned backend without manually copying credentials.
### Validation
- Passed the repository test suite, web-app tests and production build, dependency audit, skill/reference validation, documentation security, and warning-budget checks.
- Passed canonical skill and reference validation, documentation security, warning-budget enforcement, changed-skill evidence, repository and AAS Core tests, protected CI, and CodeQL.
- Confirmed canonical synchronization reproduced all risk labels and Cohesivity content byte-for-byte across Codex and Claude plugin distributions.
- The protected release gate binds the release PR, tag, GitHub Release, npm `latest`, CI, CodeQL, release-only Pages deployment, live catalog and legacy bridge, and every already-configured AAS MCP host to the exact released commit.
### Credits
- **[@shouryamaanjain](https://github.com/shouryamaanjain)** and **[cohesivity-org/cohesivity-skill](https://github.com/cohesivity-org/cohesivity-skill)** for `cohesivity` in [PR #1032](https://github.com/sickn33/agentic-awesome-skills/pull/1032).
- **[@alen-hh](https://github.com/alen-hh)** for the Modellix source URL and speech-default refresh in [PR #1025](https://github.com/sickn33/agentic-awesome-skills/pull/1025).
## [15.6.0] - 2026-07-28 - "Browser Automation and Performance RCA"
+28 -11
View File
@@ -1,13 +1,13 @@
<!-- registry-sync: version=15.6.0; skills=1993; stars=44069; updated_at=2026-07-28T15:21:12+00:00 -->
<!-- registry-sync: version=15.7.0; skills=1994; stars=44128; updated_at=2026-07-29T17:27:11+00:00 -->
# AAS Core — Agentic Awesome Skills
> **Local, agent-owned skill stacks for coding agents—from complete catalog access to a reproducible, reviewable plan.**
**Current release: V15.6.0.** This release includes AAS Core for complete local catalog search, agent-owned selection, manifest validation, planning, and diagnosis. Apply and recovery remain experimental and outside the supported preview path.
**Current release: V15.7.0.** This release includes AAS Core for complete local catalog search, agent-owned selection, manifest validation, planning, and diagnosis. Apply and recovery remain experimental and outside the supported preview path.
Codex or Claude inspects your project and chooses exact skills from the complete local AAS catalog. AAS Core does not rank or recommend them: its read-only `compose_stack` tool validates the agent-owned selection in memory, and a client or the `aas` CLI can persist it as `aas-stack.json` and produce an immutable plan before any target change.
**[Read the AAS Core preview guide →](https://github.com/sickn33/agentic-awesome-skills/blob/v15.6.0/docs/users/aas-core.md)**
**[Read the AAS Core preview guide →](https://github.com/sickn33/agentic-awesome-skills/blob/v15.7.0/docs/users/aas-core.md)**
```text
Project
@@ -67,7 +67,7 @@ AAS Core gives the repository one product model:
| Apply and recovery | Experimental, explicit opt-in, outside the supported safety claim |
| Semantic suitability certification | Not provided |
Read the [AAS Core guide](https://github.com/sickn33/agentic-awesome-skills/blob/v15.6.0/docs/users/aas-core.md) for the exact trust boundaries, current preview status, Codex/Claude setup model, and CLI lifecycle.
Read the [AAS Core guide](https://github.com/sickn33/agentic-awesome-skills/blob/v15.7.0/docs/users/aas-core.md) for the exact trust boundaries, current preview status, Codex/Claude setup model, and CLI lifecycle.
## Why This Repo
@@ -76,7 +76,7 @@ Read the [AAS Core guide](https://github.com/sickn33/agentic-awesome-skills/blob
- **Approval before writes**: the durable artifacts are an approved stack and immutable plan, not an opaque one-shot install.
- **Installable, not just inspirational**: use the compatible legacy installer or plugin distributions when direct delivery is the right path.
- **Built for major agent workflows**: Claude Code, Cursor, Codex CLI, Autohand Code, Gemini CLI, Antigravity, Kiro, OpenCode, Copilot, and more.
- **Broad coverage with real utility**: 1,993+ skills across development, testing, security, infrastructure, product, and marketing.
- **Broad coverage with real utility**: 1,994+ skills across development, testing, security, infrastructure, product, and marketing.
- **Inspect before installing**: the hosted [Skill Workbench](https://sickn33.github.io/agentic-awesome-skills/workbench) reviews agent-produced stack manifests and immutable plans without browser-side installation.
- **Focused delivery remains available**: specialized plugins package proven sets for web, security, data, docs, DevOps, QA, OSS, or agent/MCP workflows.
- **Useful whether you want breadth or curation**: install the full catalog, choose a specialized plugin, start with bundles, or compare alternatives before installing.
@@ -94,7 +94,7 @@ Direct file search can find candidate prose, but it leaves the result in the con
- [Choose Your Tool](#choose-your-tool)
- [Quick FAQ](#quick-faq)
- [Bundles & Workflows](#bundles--workflows)
- [Browse 1,993+ Skills](#browse-1993-skills)
- [Browse 1,994+ Skills](#browse-1994-skills)
- [Troubleshooting](#troubleshooting)
- [Stable Skills Manifest v1](#stable-skills-manifest-v1)
- [Support the Project](#support-the-project)
@@ -107,7 +107,7 @@ Direct file search can find candidate prose, but it leaves the result in the con
## Installation
For Codex and Claude, start with the [AAS Core guide](https://github.com/sickn33/agentic-awesome-skills/blob/v15.6.0/docs/users/aas-core.md): configure the local MCP, ask the agent to inspect the project and choose exact IDs from the full catalog, review the proposed `aas-stack.json`, then run CLI validation and planning. The MCP and validation are read-only. Planning writes only the requested plan artifact; it does not materialize skill payloads or AAS managed state in the target.
For Codex and Claude, start with the [AAS Core guide](https://github.com/sickn33/agentic-awesome-skills/blob/v15.7.0/docs/users/aas-core.md): configure the local MCP, ask the agent to inspect the project and choose exact IDs from the full catalog, review the proposed `aas-stack.json`, then run CLI validation and planning. The MCP and validation are read-only. Planning writes only the requested plan artifact; it does not materialize skill payloads or AAS managed state in the target.
Use direct installation when your host does not yet have a native AAS Core adapter, when you already know the exact skill IDs, or when you deliberately prefer manual selection:
@@ -127,6 +127,22 @@ npx agentic-awesome-skills --agy
The npm installer uses a shallow, release-pinned clone by default so first-run installs stay lighter than a full repository history checkout while matching the published npm package version. Use `--tag main` only when you intentionally want the current repository tip.
For backward compatibility, running the installer without selectors installs the
entire catalog. The CLI now prints the catalog's risk summary first: a full
install includes `unknown`, `critical`, and authorized-use-only `offensive`
instructions. Installation copies files; it does not execute their commands,
but an agent may act on an installed skill later. Prefer an exact reviewed set:
```bash
npx agentic-awesome-skills audit --skills brainstorming,backend-dev-guidelines
npx agentic-awesome-skills --skills brainstorming,backend-dev-guidelines --dry-run
```
The audit reads the selected skill directories without executing them and
reports command, network, credential, filesystem, privileged, destructive,
symlink, and binary signals. It is a review aid, not a safety certificate. See
[Security, trust, and antivirus alerts](docs/users/security-and-antivirus.md).
### Focused single-skill install with GitHub CLI (preview)
GitHub CLI can preview and install one exact skill for Copilot and other supported hosts. Use an exact `SKILL.md` path in this large, mirrored repository so the selected source is unambiguous and discovery stays fast:
@@ -226,7 +242,7 @@ The supported path covers complete local catalog search and inspection, agent-ow
### How do I install it?
For AAS Core, follow the [preview guide](https://github.com/sickn33/agentic-awesome-skills/blob/v15.6.0/docs/users/aas-core.md) and use only a package release whose notes explicitly state that it includes Core. Release 14.6.0 predates Core; Core-capable releases begin with the 15.x line.
For AAS Core, follow the [preview guide](https://github.com/sickn33/agentic-awesome-skills/blob/v15.7.0/docs/users/aas-core.md) and use only a package release whose notes explicitly state that it includes Core. Release 14.6.0 predates Core; Core-capable releases begin with the 15.x line.
For direct skill distribution, run `npx agentic-awesome-skills` for the default full-library install. Use a tool-specific flag such as `--codex`, `--cursor`, `--gemini`, `--claude`, or `--antigravity` when you want the legacy installer to place skills in the directory your assistant already watches.
@@ -300,7 +316,7 @@ Remove `--dry-run` only after reviewing the install, update, and removal plan. U
The hosted [Skill Workbench](https://sickn33.github.io/agentic-awesome-skills/workbench) imports and reviews AAS Core stack manifests and immutable plans in browser memory. It does not access the filesystem, generate an approved plan, or install skills.
## Browse 1,993+ Skills
## Browse 1,994+ Skills
Use the root repo as a landing page, then jump into the deeper surface that matches your intent.
@@ -338,7 +354,7 @@ Use the root repo as a landing page, then jump into the deeper surface that matc
Keep the root README short; use the dedicated docs for recovery and platform-specific guidance.
- If you are confused after installation, start with the [Usage Guide](docs/users/usage.md).
- For Core setup, trust boundaries, stack manifests, and preview status, use the [AAS Core guide](https://github.com/sickn33/agentic-awesome-skills/blob/v15.6.0/docs/users/aas-core.md).
- For Core setup, trust boundaries, stack manifests, and preview status, use the [AAS Core guide](https://github.com/sickn33/agentic-awesome-skills/blob/v15.7.0/docs/users/aas-core.md).
- On native Windows, `AAS_ADAPTER_WINDOWS_ACL_FAILED` refers to the configuration path checked with PowerShell `Get-Acl`, not the cache and not `icacls`; do not approve until preview returns an approval digest.
- If you integrate agentic-awesome-skills into a host, read the discovery contract first: [Stable Skills Manifest v1](docs/users/discovery-manifest.md).
- For Windows truncation or context crash loops, use [docs/users/windows-truncation-recovery.md](docs/users/windows-truncation-recovery.md).
@@ -349,7 +365,7 @@ Keep the root README short; use the dedicated docs for recovery and platform-spe
## Stable Skills Manifest v1
This is the stable **direct-host discovery manifest** for integrations that load individual `SKILL.md` files. It is not `aas-stack.json`, the verified AAS Core catalog, or the Core composition contract. Core users should start with the [AAS Core guide](https://github.com/sickn33/agentic-awesome-skills/blob/v15.6.0/docs/users/aas-core.md); custom host integrations can continue using the manifest below.
This is the stable **direct-host discovery manifest** for integrations that load individual `SKILL.md` files. It is not `aas-stack.json`, the verified AAS Core catalog, or the Core composition contract. Core users should start with the [AAS Core guide](https://github.com/sickn33/agentic-awesome-skills/blob/v15.7.0/docs/users/aas-core.md); custom host integrations can continue using the manifest below.
Host integrations should use:
@@ -442,6 +458,7 @@ Key source families include:
- **[pilot-protocol/pilotprotocol](https://github.com/pilot-protocol/pilotprotocol)**: Official Pilot Protocol overlay network - agent addressing, encrypted P2P messaging, NAT traversal, and an installable agent app store (AGPL-3.0).
- **[Xquik-dev/x-twitter-scraper](https://github.com/Xquik-dev/x-twitter-scraper)**: Official Xquik skill for X data workflows - tweet search, user lookup, follower export, media downloads, MCP, webhooks, OpenAPI, and SDK setup (MIT).
- **[Modellix/modellix-plugin](https://github.com/Modellix/modellix-plugin)**: Official Modellix skill - authenticated, paid AI image and video generation through the Modellix CLI (MIT).
- **[cohesivity-org/cohesivity-skill](https://github.com/cohesivity-org/cohesivity-skill)**: Official Cohesivity skill - agent provisioned backend infrastructure covering Postgres, hosting, auth, realtime, storage, cron, email, and AI model APIs over one HTTP API (MIT).
</details>
+2 -2
View File
@@ -1,8 +1,8 @@
# Source
- Repo: https://github.com/sickn33/antigravity-awesome-skills
- Ref: d737163c228391ff3159fa7e1eda94d50ed89f85
- Ref: 88a189642daea448ae0ac545dfc1b79c5a86924d
- Remove-Paths:
- Snapshot: 2026-07-29
- Snapshot: 2026-07-30
- Sync-Mode: copy_skill_dirs
- Notes: vendored into playbook branch thirdparty/skill
@@ -10,23 +10,23 @@
<meta name="apple-mobile-web-app-title" content="agentic-awesome-skills" />
<link rel="manifest" href="%BASE_URL%site.webmanifest" />
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
<meta name="description" content="Use AAS Core preview for neutral catalog retrieval, exact agent-owned selection, validation, and planning for Codex, Claude Code, and compatible clients, backed by 1,993+ cataloged skills." />
<meta name="description" content="Use AAS Core preview for neutral catalog retrieval, exact agent-owned selection, validation, and planning for Codex, Claude Code, and compatible clients, backed by 1,994+ cataloged skills." />
<meta name="author" content="Agentic Awesome Skills" />
<meta name="msvalidate.01" content="CAC904EB0D2DD1B22B5F2BC540CAD654" />
<meta property="og:title" content="AAS Core Preview | Agent-first stacks backed by 1,993+ skills" />
<meta property="og:description" content="Use AAS Core preview for neutral catalog retrieval, exact agent-owned selection, validation, and planning for Codex, Claude Code, and compatible clients, backed by 1,993+ cataloged skills." />
<meta property="og:title" content="AAS Core Preview | Agent-first stacks backed by 1,994+ skills" />
<meta property="og:description" content="Use AAS Core preview for neutral catalog retrieval, exact agent-owned selection, validation, and planning for Codex, Claude Code, and compatible clients, backed by 1,994+ cataloged skills." />
<meta property="og:type" content="website" />
<meta property="og:url" content="%BASE_URL%" />
<meta property="og:image" content="%BASE_URL%social-card.png" />
<meta name="twitter:title" content="AAS Core Preview | Agent-first stacks backed by 1,993+ skills" />
<meta name="twitter:description" content="Use AAS Core preview for neutral catalog retrieval, exact agent-owned selection, validation, and planning for Codex, Claude Code, and compatible clients, backed by 1,993+ cataloged skills." />
<meta name="twitter:title" content="AAS Core Preview | Agent-first stacks backed by 1,994+ skills" />
<meta name="twitter:description" content="Use AAS Core preview for neutral catalog retrieval, exact agent-owned selection, validation, and planning for Codex, Claude Code, and compatible clients, backed by 1,994+ cataloged skills." />
<meta name="twitter:image" content="%BASE_URL%social-card.png" />
<meta name="twitter:image:alt" content="Agentic Awesome Skills catalog preview" />
<meta name="robots" content="index, follow" />
<meta property="og:site_name" content="Agentic Awesome Skills" />
<meta name="twitter:card" content="summary_large_image" />
<meta name="theme-color" content="#0f172a" />
<title>AAS Core Preview | Agent-first stacks backed by 1,993+ skills</title>
<title>AAS Core Preview | Agent-first stacks backed by 1,994+ skills</title>
</head>
<body>
<div id="root"></div>
@@ -1,12 +1,12 @@
# Agentic Awesome Skills
> AAS Core is a local, agent-first control plane for complete catalog discovery, agent-owned skill selection, stack validation, and planning, backed by 1,993+ agentic SKILL.md playbooks.
> AAS Core is a local, agent-first control plane for complete catalog discovery, agent-owned skill selection, stack validation, and planning, backed by 1,994+ agentic SKILL.md playbooks.
## Key Facts
- Current release: V15.6.0.
- Release boundary: V15.6.0 includes AAS Core under the Agent-First Preview; pin this exact version when configuring the local MCP.
- Skill count: 1,993+.
- Current release: V15.7.0.
- Release boundary: V15.7.0 includes AAS Core under the Agent-First Preview; pin this exact version when configuring the local MCP.
- Skill count: 1,994+.
- Primary product: AAS Core preview, exposed through the `aas` CLI and local `aas-mcp` stdio server.
- Agent tools: `search_skills`, `get_skill`, `compose_stack`, `inspect_stack`, `diff_stack`, `export_selection_evidence`, and `inspect_selection_evidence`.
- Lifecycle: the client enumerates primary project capabilities, searches and compares candidates for each, covers every capability or reports a catalog gap, and chooses exact IDs. Core has no semantic policy favoring a small stack; each manifest has a technical maximum of 128 skills. Read-only `compose_stack` returns the manifest in memory, while a client or CLI persists `aas-stack.json` and optional `aas-selection-evidence.json` in an `artifact-dir` before CLI validation and immutable plan preview.
@@ -17,7 +17,7 @@
- Evidence privacy: the sidecar records raw `search_skills` queries, so catalog queries must not contain secrets or private source text.
- Preview boundary: planning may write an explicitly requested plan artifact but does not write target state; apply and recovery are not part of the supported preview path.
- Supported real clients include Codex CLI and Claude Code; the catalog also serves Cursor, Gemini CLI, Antigravity, and other compatible hosts.
- The 1,993+ skill catalog, specialized plugins, bundles, and workflows are supporting discovery and distribution surfaces.
- The 1,994+ skill catalog, specialized plugins, bundles, and workflows are supporting discovery and distribution surfaces.
- Repository: https://github.com/sickn33/agentic-awesome-skills
- Hosted catalog and companion review surface: https://sickn33.github.io/agentic-awesome-skills/
- Specialized plugin landing page: https://sickn33.github.io/agentic-awesome-skills/plugins
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
@@ -1 +1 @@
{"assets":[{"path":"data/aas-v1/skill-content-index.v1.json","sha256":"sha256-186f4a71f1a98fea3b7781c4bca9fce3573e719571e714129866e34789004f6e","size":274782},{"path":"data/aas-v1/skill-content.v1.ndjson","sha256":"sha256-b2adc6a7f443da1735d0677c2ef032e661d5328897b62de80b2705528455b19d","size":19296736},{"path":"data/catalog.json","sha256":"sha256-a6ed4f223962158a24a04f99555b177e2f78ed19919db455ee76f681aea435fd","size":1650960},{"path":"tools/lib/aas-v1/ontology.v1.json","sha256":"sha256-25169aad0a3d2e8420b0acd65a35f7ce4ecb08fcbe0018ee978808ce0c8944ed","size":7109}],"catalogDigest":"sha256-9afdf0003586bead0abff216a19d379b8a066333b51ef47b5eb7521fd2aac220","catalogSchemaVersion":"2.0.0","digestVersion":1,"package":"agentic-awesome-skills","packageVersion":"15.6.0","schemaVersion":1,"skillCount":1993}
{"assets":[{"path":"data/aas-v1/skill-content-index.v1.json","sha256":"sha256-c88e466037397c60570e44f49dbacfcb0345c7b45b6907942ef321624caea173","size":274920},{"path":"data/aas-v1/skill-content.v1.ndjson","sha256":"sha256-1ff8d44bbf116c39d97adb2d277a858816f32116eb9792c7abe23796f0d3b22f","size":19352025},{"path":"data/catalog.json","sha256":"sha256-b39715d069b504f67fb2b587db89127a7b4a48e70dae6db17e799ce93990e6da","size":1652638},{"path":"tools/lib/aas-v1/ontology.v1.json","sha256":"sha256-25169aad0a3d2e8420b0acd65a35f7ce4ecb08fcbe0018ee978808ce0c8944ed","size":7109}],"catalogDigest":"sha256-cf772320895a50bbe2fb905c3626386ba416f31b9a9846815a2aa411bbc5bb80","catalogSchemaVersion":"2.0.0","digestVersion":1,"package":"agentic-awesome-skills","packageVersion":"15.7.0","schemaVersion":1,"skillCount":1994}
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
+1 -1
View File
@@ -1,5 +1,5 @@
{
"generatedAt": "2026-07-28T15:21:12.000Z",
"generatedAt": "2026-07-29T17:27:11.000Z",
"aliases": {
"20-andruia-intelligence": "20-andruia-niche-intelligence",
"accessibility-compliance-audit": "accessibility-compliance-accessibility-audit",
+4 -1
View File
@@ -1,5 +1,5 @@
{
"generatedAt": "2026-07-28T15:21:12.000Z",
"generatedAt": "2026-07-29T17:27:11.000Z",
"bundles": {
"core-dev": {
"description": "Core development skills across languages, frameworks, and backend/frontend fundamentals.",
@@ -153,6 +153,7 @@
"code-documentation-doc-generate",
"code-showcase-react-ui-patterns",
"codebase-to-wordpress-converter",
"cohesivity",
"comfyui-gateway",
"context7-auto-research",
"convex",
@@ -513,6 +514,7 @@
"code-review-checklist",
"codebase-audit-pre-push",
"codebase-cleanup-deps-audit",
"cohesivity",
"comfyui-gateway",
"comprehensive-review-pr-enhance",
"container-security-hardening",
@@ -746,6 +748,7 @@
"claude-api",
"claude-d3js-skill",
"code-showcase-react-ui-patterns",
"cohesivity",
"constant-time-analysis",
"content-marketer",
"data-engineer",
File diff suppressed because it is too large Load Diff
@@ -6542,7 +6542,7 @@
"id": "blueprint",
"path": "skills/blueprint",
"targets": {
"codex": "blocked",
"codex": "supported",
"claude": "supported"
},
"setup": {
@@ -6550,13 +6550,9 @@
"summary": "",
"docs": null
},
"reasons": [
"target_specific_home_path"
],
"reasons": [],
"blocked_reasons": {
"codex": [
"target_specific_home_path"
],
"codex": [],
"claude": []
},
"runtime_files": []
@@ -8951,6 +8947,25 @@
},
"runtime_files": []
},
{
"id": "cohesivity",
"path": "skills/cohesivity",
"targets": {
"codex": "supported",
"claude": "supported"
},
"setup": {
"type": "none",
"summary": "",
"docs": null
},
"reasons": [],
"blocked_reasons": {
"codex": [],
"claude": []
},
"runtime_files": []
},
{
"id": "cold-email",
"path": "skills/cold-email",
@@ -38312,13 +38327,13 @@
}
],
"summary": {
"total_skills": 1993,
"total_skills": 1994,
"supported": {
"codex": 1916,
"claude": 1938
"codex": 1918,
"claude": 1939
},
"blocked": {
"codex": 77,
"codex": 76,
"claude": 55
},
"manual_setup": 19
File diff suppressed because it is too large Load Diff
@@ -21,8 +21,13 @@ Every offensive skill **MUST** begin with this exact disclaimer in its `SKILL.md
Offensive skills must **NEVER** run fully autonomously.
- **Requirement**: The skill description/instructions must explicitly tell the agent to _ask for user confirmation_ before executing any exploit or attack command.
- **Agent Instruction**: "Ask the user to verify the target URL/IP before running."
- **Requirement**: Before each command that probes, exploits, changes, persists
on, extracts data from, or attempts credential access against a target, the
agent must collect the exact target, written-authorization confirmation, and
permitted scope; show the exact command and expected effect; and wait for
explicit confirmation in the current conversation.
- Without that confirmation, the skill must remain read-only and provide
defensive guidance only.
### 3. Safe by Design
@@ -42,6 +47,18 @@ _Examples: Linting, Log Analysis, Configuration Auditing._
- **Documentation review**: Defensive skills with command examples must still be reviewed for unsafe command patterns.
- **High-risk examples** (`curl|bash`, `wget|sh`, etc.) must use explicit allowlisting comments and clear warning context in the skill body when retained for operational examples.
## External Source Installation
- Do not clone or download a moving branch directly into an active skills,
plugin, hook, or agent-configuration directory.
- Pin external examples to a full reviewed commit or immutable release, clone to
a temporary review directory, and inspect every bundled file before activation.
- Report scripts, package lifecycle hooks, symlinks, binaries, network access,
credential handling, privileged actions, and destructive operations.
- Obtain explicit user approval before downloading and again before copying,
installing dependencies, enabling hooks, or changing agent configuration.
- A pin provides reproducibility, not proof of trust; upgrading requires a new review.
---
## ⚖️ Legal Disclaimer
@@ -1,9 +1,9 @@
---
title: Jetski/Cortex + Gemini Integration Guide
description: "Use agentic-awesome-skills with Jetski/Cortex without hitting context-window overflow with 1,993+ skills."
description: "Use agentic-awesome-skills with Jetski/Cortex without hitting context-window overflow with 1,994+ skills."
---
# Jetski/Cortex + Gemini: safe integration with 1,993+ skills
# Jetski/Cortex + Gemini: safe integration with 1,994+ skills
> **Custom-host integration:** This guide documents a low-level, direct-manifest lazy loader for Jetski/Cortex and similar hosts. For Codex or Claude Code, the recommended path is [AAS Core](../users/aas-core.md), which provides neutral, deterministic catalog retrieval and validates exact agent-selected IDs through a bounded, read-only MCP server.
@@ -25,7 +25,7 @@ Never do:
- concatenate all `SKILL.md` content into a single system prompt;
- re-inject the entire library for **every** request.
With 1,993+ skills, this approach fills the context window before user messages are even added, causing truncation.
With 1,994+ skills, this approach fills the context window before user messages are even added, causing truncation.
---
@@ -23,7 +23,7 @@ This example shows one way to integrate **agentic-awesome-skills** with a Jetski
- How to enforce a **maximum number of skills per turn** via `maxSkillsPerTurn`.
- How to choose whether to **truncate or error** when too many skills are requested via `overflowBehavior`.
This pattern avoids context overflow when you have 1,993+ skills installed.
This pattern avoids context overflow when you have 1,994+ skills installed.
Manifest contract references:
@@ -29,7 +29,7 @@ Preferred homepage:
Preferred social preview:
- lead with `AAS Core` and the profile → stack → plan flow;
- present `1,993+ Agentic Skills` as supporting catalog evidence, not a second product;
- present `1,994+ Agentic Skills` as supporting catalog evidence, not a second product;
- mention Codex and Claude as the current Core agent path, with broader host compatibility as distribution support;
- avoid dense text and tiny logos that disappear in social cards.
@@ -72,7 +72,7 @@ The update process refreshes:
- Canonical skills index (`skills_index.json`)
- Compatibility mirror (`data/skills_index.json`)
- Web app skills data (`apps\web-app\public\skills.json`)
- All 1,993+ skills from the skills directory
- All 1,994+ skills from the skills directory
## When to Update
@@ -30,7 +30,7 @@ AAS MCP does not scan the repository and does not decide which skills are best.
> **Release boundary:** AAS Core landed after release 14.6.0. Use an exact Core-capable release rather than an unreviewed moving tag.
```bash
npm exec --yes --ignore-scripts --package=agentic-awesome-skills@15.6.0 -- aas mcp configure \
npm exec --yes --ignore-scripts --package=agentic-awesome-skills@15.7.0 -- aas mcp configure \
--host codex \
--scope user \
--config /absolute/path/to/codex/config.toml \
@@ -1062,4 +1062,4 @@ Found a skill that should be in a bundle? Or want to create a new bundle? [Open
---
_Last updated: June 2026 | Total Skills: 1,993+ | Total Bundles: 58_
_Last updated: June 2026 | Total Skills: 1,994+ | Total Bundles: 58_
@@ -17,7 +17,7 @@ Configure AAS Core for Claude Code, describe the task and constraints, let Claud
- It lets Claude search the verified local catalog without loading the full library into context.
- It preserves Claude's exact selection without using metadata as an eligibility gate.
- It keeps MCP discovery read-only and CLI changes approval-gated.
- It includes 1,993+ skills instead of a narrow single-domain starter pack.
- It includes 1,994+ skills instead of a narrow single-domain starter pack.
- It supports the standard `.claude/skills/` path and the Claude Code plugin marketplace flow.
- It also ships generated bundle plugins so teams can install focused packs like `Essentials` or `Security Developer` from the marketplace metadata.
- It includes onboarding docs, bundles, and workflows so new users do not need to guess where to begin.
+12 -2
View File
@@ -31,6 +31,11 @@ Skills are specialized instruction files that teach AI assistants how to handle
**No.** With AAS Core, ask the agent to inspect the project and choose the exact skills from the complete catalog. On a broad direct install, all skills may be present locally while the host loads only the skills it invokes.
The direct installer keeps its historical full-catalog default for compatibility,
but now shows the risk distribution before writing. Use `audit --skills <ids>` to
read an exact selection and its bundled files without executing them, then use
the same `--skills` selection with `--dry-run` before installation.
Use [Starter Packs](bundles.md) as human-curated presets when you want a fixed starting point.
If you want a narrower install surface for **Claude Code** or **Codex**, use the new plugin distributions documented in [plugins.md](plugins.md) instead of the full library install.
@@ -128,8 +133,13 @@ We classify skills so you know what you're running. These values map directly to
### Can these skills hack my computer?
**No.** Skills are text files. However, they _instruct_ the AI to run commands. If a skill says "delete all files", a compliant AI might try to do it.
_Always check the Risk label and review the code._
A Markdown file is not a running process, but calling it “just text” is not a
sufficient security model. A loaded skill can instruct an agent to run commands,
use credentials, access the network, or modify files. Installation alone is not
evidence that any of that happened; execution logs and resulting system changes
are. Review the exact skill and every bundled file before use, keep agent
permissions narrow, and require confirmation for consequential actions. See
[Security, trust, and antivirus alerts](security-and-antivirus.md).
---
@@ -12,7 +12,7 @@ Install into the Gemini skills path, then ask Gemini to apply one skill at a tim
- It installs directly into the expected Gemini skills path.
- It includes both core software engineering skills and deeper agent/LLM-oriented skills.
- It helps new users get started with bundles and workflows rather than forcing a cold start from 1,993+ files.
- It helps new users get started with bundles and workflows rather than forcing a cold start from 1,994+ files.
- It is useful whether you want a broad internal skill library or a single repo to test many workflows quickly.
## Install Gemini CLI Skills
@@ -48,6 +48,20 @@ npx agentic-awesome-skills
This clones to `~/.agents/skills` by default. Use `--cursor`, `--claude`, `--gemini`, `--codex`, `--kiro`, or `--agy` to install for a specific tool, or `--path <dir>` for a custom location. Run `npx agentic-awesome-skills --help` for details.
The installer uses a shallow clone by default so you get the current library without paying for the full git history on first install.
With no selector, the legacy-compatible default installs the complete catalog
and prints a risk summary before writing. That includes `unknown`, `critical`,
and authorized-use-only `offensive` skills. Installed text is not automatically
executed, but it can influence an agent when loaded, so review an exact set first:
```bash
npx agentic-awesome-skills audit --skills brainstorming,backend-dev-guidelines
npx agentic-awesome-skills --skills brainstorming,backend-dev-guidelines --dry-run
```
You can also ask your agent to read the selected `SKILL.md` and every bundled
file before installation. The static audit reports risky capabilities; it does
not prove that a skill is safe. See [Security, trust, and antivirus alerts](security-and-antivirus.md).
If you see a 404 error, use: `npx github:sickn33/agentic-awesome-skills`
**Option B — git clone:**
@@ -18,7 +18,7 @@ Kiro is AWS's agentic AI IDE that combines:
Kiro's agentic capabilities are enhanced by skills that provide:
- **Domain expertise** across 1,993+ specialized areas
- **Domain expertise** across 1,994+ specialized areas
- **Best practices** from Anthropic, OpenAI, Google, Microsoft, and AWS
- **Workflow automation** for common development tasks
- **AWS-specific patterns** for serverless, infrastructure, and cloud architecture
@@ -0,0 +1,63 @@
# Security, Trust, and Antivirus Alerts
## The trust boundary
A skill is instruction content, not an executable process. Copying a `SKILL.md`
does not itself run the commands it contains. The security boundary changes when
an agent loads those instructions and receives permission to use a shell,
network, credentials, filesystem, browser, MCP server, or other tool.
Treat every community skill and every bundled file as untrusted input until you
have reviewed the exact installed revision. A risk label describes intended
capability; it is not a malware verdict or safety certificate. Repository stars,
contributors, Markdown-only packaging, and a commit pin are not substitutes for
review.
## Review before installation
Use an exact selection and inspect it without execution:
```bash
npx agentic-awesome-skills audit --skills <skill-id,skill-id>
npx agentic-awesome-skills --skills <skill-id,skill-id> --dry-run
```
The audit recursively reads the selected skill directories and reports command,
network, credential, filesystem, privileged, destructive, symlink, and binary
signals. Read the files behind every finding and ask your agent to explain them.
Static pattern matching can miss dangerous logic and can flag legitimate
security examples, so a clean report does not prove safety.
For external sources, require a full commit pin or immutable release, download
to a temporary review directory, inspect package scripts and every bundled file,
and approve the final copy separately. Do not pipe remote content into a shell or
clone a moving branch directly into an active agent directory.
## If antivirus flags a skill
Security documentation often contains exploit names, commands, or payload
fragments that signature scanners recognize. A detection in Markdown can be a
correct content detection without showing that a Trojan executed. Do not dismiss
it, but distinguish content from activity:
1. Stop the agent and quarantine or move the flagged skill out of active paths.
2. Record the exact file, detector name, package version, and file hash.
3. Review the file and adjacent bundled content without executing anything.
4. Check agent transcripts, shell history, process logs, downloads, persistence
locations, credential access, and unexpected filesystem or network changes.
5. Run your operating system's trusted security scan. Rotate credentials only
when exposure or suspicious activity is plausible; reinstall the system when
forensic evidence or incident-response guidance justifies it, not solely
because a text signature matched.
6. Report reproducible findings privately through the process in
[`SECURITY.md`](../../SECURITY.md). Include evidence of execution or impact
separately from the flagged text.
## Safer operating defaults
- Install only the skills needed for the task when practical.
- Keep agent permissions least-privileged and avoid administrator access.
- Require current-conversation approval for destructive, privileged, financial,
account-write, credential, publishing, and offensive-security actions.
- Use disposable environments for offensive or untrusted workflows.
- Preserve logs and backups so actions can be audited and reversed where possible.
@@ -39,7 +39,7 @@ If you came in through a **Claude Code** or **Codex** plugin instead of AAS Core
When you ran `npx agentic-awesome-skills` or cloned the repository, you:
**Downloaded 1,993+ skill files** to your computer (default: `~/.agents/skills/`; or a custom path like `~/.agent/skills/` if you used `--path`)
**Downloaded 1,994+ skill files** to your computer (default: `~/.agents/skills/`; or a custom path like `~/.agent/skills/` if you used `--path`)
**Made them available** to your AI assistant
**Did NOT enable them all automatically** (they're just sitting there, waiting)
@@ -231,7 +231,7 @@ Let's actually use a skill right now. Follow these steps:
## Direct-install Step 5: Pick Skills Manually
Don't try to use all 1,993+ skills at once. Here's a sensible approach:
Don't try to use all 1,994+ skills at once. Here's a sensible approach:
If you want a tool-specific starting point before choosing skills, use:
@@ -362,7 +362,7 @@ Usually no, but if your AI doesn't recognize a skill:
### "Can I load all skills into the model at once?"
No. Even though you have 1,993+ skills installed locally, you should **not** concatenate every `SKILL.md` into a single system prompt or context block.
No. Even though you have 1,994+ skills installed locally, you should **not** concatenate every `SKILL.md` into a single system prompt or context block.
The intended pattern is:
@@ -40,7 +40,7 @@ agentic-awesome-skills/
├── 📄 CONTRIBUTING.md ← Contributor workflow
├── 📄 CATALOG.md ← Full generated catalog
├── 📁 skills/ ← 1,993+ skills live here
├── 📁 skills/ ← 1,994+ skills live here
│ │
│ ├── 📁 brainstorming/
│ │ └── 📄 SKILL.md ← Skill definition
@@ -53,7 +53,7 @@ agentic-awesome-skills/
│ │ └── 📁 2d-games/
│ │ └── 📄 SKILL.md ← Nested skills also supported
│ │
│ └── ... (1,993+ total)
│ └── ... (1,994+ total)
├── 📁 apps/
│ └── 📁 web-app/ ← Interactive browser
@@ -106,7 +106,7 @@ agentic-awesome-skills/
```
┌─────────────────────────┐
│ 1,993+ SKILLS │
│ 1,994+ SKILLS │
└────────────┬────────────┘
┌────────────────────────┼────────────────────────┐
@@ -207,7 +207,7 @@ If you want a workspace-style manual install instead, cloning into `.agent/skill
│ ├── 📁 brainstorming/ │
│ ├── 📁 stripe-integration/ │
│ ├── 📁 react-best-practices/ │
│ └── ... (1,993+ total) │
│ └── ... (1,994+ total) │
└─────────────────────────────────────────┘
```
+2 -2
View File
@@ -1,12 +1,12 @@
{
"name": "agentic-awesome-skills",
"version": "15.6.0",
"version": "15.7.0",
"lockfileVersion": 3,
"requires": true,
"packages": {
"": {
"name": "agentic-awesome-skills",
"version": "15.6.0",
"version": "15.7.0",
"bundleDependencies": [
"ajv",
"sanitize-filename",
+2 -2
View File
@@ -1,11 +1,11 @@
{
"name": "agentic-awesome-skills",
"version": "15.6.0",
"version": "15.7.0",
"aasCore": {
"includedFromMajor": 15,
"status": "agent-first-preview"
},
"description": "AAS Core: complete local skill discovery, agent-owned selection, stack validation, and planning, backed by 1,993+ agentic skills.",
"description": "AAS Core: complete local skill discovery, agent-owned selection, stack validation, and planning, backed by 1,994+ agentic skills.",
"license": "MIT",
"scripts": {
"validate": "node tools/scripts/run-python.js tools/scripts/validate_skills.py",
@@ -1,7 +1,7 @@
{
"name": "agentic-awesome-skills",
"version": "15.6.0",
"description": "Plugin-safe Claude Code distribution of Agentic Awesome Skills with 1,938 supported skills.",
"version": "15.7.0",
"description": "Plugin-safe Claude Code distribution of Agentic Awesome Skills with 1,939 supported skills.",
"author": {
"name": "sickn33 and contributors",
"url": "https://github.com/sickn33/agentic-awesome-skills"
@@ -4,7 +4,7 @@ description: Expert in building 3D experiences for the web - Three.js, React
Three Fiber, Spline, WebGL, and interactive 3D scenes. Covers product
configurators, 3D portfolios, immersive websites, and bringing depth to web
experiences.
risk: unknown
risk: critical
source: vibeship-spawner-skills (Apache 2.0)
date_added: 2026-02-27
---
@@ -1,7 +1,7 @@
---
name: ab-test-setup
description: "Structured guide for setting up A/B tests with mandatory gates for hypothesis, metrics, and execution readiness."
risk: unknown
risk: critical
source: community
date_added: "2026-02-27"
---
@@ -1,7 +1,7 @@
---
name: ab-testing
description: When the user wants to plan, design, or implement an A/B test or experiment, or build a growth experimentation program. Also use when the user mentions "A/B test," "split test," "experiment," "test this change," "variant copy," "multivariate test," "hypothesis," "should I test this,"...
risk: unknown
risk: critical
source: https://github.com/coreyhaines31/marketingskills/tree/main/skills/ab-testing
source_repo: coreyhaines31/marketingskills
source_type: community
@@ -1,7 +1,7 @@
---
name: accint-commitments
description: Triage acc's open promises and close them with honest real-world verdicts via acc_act(runtime="outcome").
risk: unknown
risk: critical
source: https://github.com/maxbaluev/accreted-intelligence/tree/main/plugins/claude/skills/commitments
source_repo: maxbaluev/accreted-intelligence
source_type: community
@@ -1,7 +1,7 @@
---
name: accint-frames
description: Drain acc's deliberation queue — open/waiting brain_frames checkpointed by headless runs — via acc_act(runtime="continue").
risk: unknown
risk: critical
source: https://github.com/maxbaluev/accreted-intelligence/tree/main/plugins/claude/skills/frames
source_repo: maxbaluev/accreted-intelligence
source_type: community
@@ -1,7 +1,7 @@
---
name: accint-solve
description: Route a goal through acc's scored-memory loop via acc_act(runtime="solve"); deliberate any returned brain_frame and submit via continue.
risk: unknown
risk: critical
source: https://github.com/maxbaluev/accreted-intelligence/tree/main/plugins/claude/skills/solve
source_repo: maxbaluev/accreted-intelligence
source_type: community
@@ -7,6 +7,20 @@ author: zebbern
date_added: "2026-02-27"
---
> **⚠️ AUTHORIZED USE ONLY**
> This skill is for educational purposes or authorized security assessments only.
> You must have explicit, written permission from the system owner before using this tool.
> Misuse of this tool is illegal and strictly prohibited.
> **Mandatory confirmation gate**
> Before running any command that probes, exploits, changes, persists on, extracts data from, or attempts credential access against a target:
> 1. Ask the user to state the exact target URL, IP, account, or resource.
> 2. Ask the user to confirm written authorization and the permitted scope.
> 3. Show the exact command(s) and explain their expected effect.
> 4. Wait for explicit confirmation in the current conversation.
>
> Without that confirmation, remain read-only and provide defensive guidance only. Prefer a sandbox, disposable VM, or controlled lab.
> AUTHORIZED USE ONLY: Use this skill only for authorized security assessments, defensive validation, or controlled educational environments.
<!-- security-allowlist: credential-extraction, kerberos-attacks -->
@@ -1,7 +1,7 @@
---
name: ad-creative
description: "Create, iterate, and scale paid ad creative for Google Ads, Meta, LinkedIn, TikTok, and similar platforms. Use when generating headlines, descriptions, primary text, or large sets of ad variations for testing and performance optimization."
risk: unknown
risk: critical
source: "https://github.com/coreyhaines31/marketingskills"
date_added: "2026-03-21"
metadata:
@@ -1,7 +1,7 @@
---
name: add-app-clip
description: Add an iOS App Clip target to an Expo app. Use when the user mentions App Clip, AASA, apple-app-site-association, appclips, smart app banner, or wants to ship a lightweight iOS Clip invoked from a URL alongside their parent app.
risk: unknown
risk: critical
source: https://github.com/expo/skills/tree/main/plugins/expo/skills/add-app-clip
source_repo: expo/skills
source_type: official
@@ -1,7 +1,7 @@
---
name: address-github-comments
description: "Use when you need to address review or issue comments on an open GitHub Pull Request using the gh CLI."
risk: unknown
risk: critical
source: community
date_added: "2026-02-27"
---
@@ -1,7 +1,7 @@
---
name: agent-framework-azure-ai-py
description: "Build persistent agents on Azure AI Foundry using the Microsoft Agent Framework Python SDK."
risk: unknown
risk: critical
source: community
date_added: "2026-02-27"
---
@@ -1,7 +1,7 @@
---
name: agent-manager-skill
description: "Manage multiple local CLI agents via tmux sessions (start/stop/monitor/assign) with cron-friendly scheduling."
risk: unknown
risk: critical
source: community
date_added: "2026-02-27"
---
@@ -1,7 +1,7 @@
---
name: agent-memory-mcp
description: "A hybrid memory system that provides persistent, searchable knowledge management for AI agents (Architecture, Patterns, Decisions)."
risk: unknown
risk: critical
source: community
date_added: "2026-02-27"
---
@@ -16,18 +16,29 @@ This skill provides a persistent, searchable memory bank that automatically sync
## Setup
1. **Clone the Repository**:
Clone the `agentMemory` project into your agent's workspace or a parallel directory:
1. **Review the Repository**:
Ask the user to approve network access to the named repository, then clone the
pinned revision into a temporary directory, not an active skills path:
```bash
git clone https://github.com/webzler/agentMemory.git .agent/skills/agent-memory
review_dir="$(mktemp -d)"
git clone --filter=blob:none https://github.com/webzler/agentMemory.git "$review_dir/agent-memory"
git -C "$review_dir/agent-memory" checkout --detach 0409b7b7bb6fe443d0d4b6a6b1ee0d4df214f3cd
git -C "$review_dir/agent-memory" ls-files
```
2. **Install Dependencies**:
Read all bundled files and inspect `package.json`, lockfiles, lifecycle
scripts, network behavior, credential access, and filesystem scope. Show the
findings and exact commit, then wait for explicit user approval.
2. **Install the Reviewed Revision**:
Copy the reviewed tree to a user-selected location after approval. Install
locked dependencies only after the package scripts have been reviewed:
```bash
cd .agent/skills/agent-memory
npm install
cd <approved-agent-memory-directory>
npm ci
npm run compile
```
@@ -90,3 +101,4 @@ This skill is applicable to execute the workflow or actions described in the ove
- Use this skill only when the task clearly matches the scope described above.
- Do not treat the output as a substitute for environment-specific validation, testing, or expert review.
- Stop and ask for clarification if required inputs, permissions, safety boundaries, or success criteria are missing.
- Re-review upstream before changing the pinned revision; a commit pin improves reproducibility but is not a trust guarantee.
@@ -1,7 +1,7 @@
---
name: agent-memory
description: A hybrid memory system that provides persistent, searchable knowledge management for AI agents.
risk: unknown
risk: critical
source: https://github.com/webzler/agentMemory/tree/main/
source_repo: webzler/agentMemory
source_type: community
@@ -1,7 +1,7 @@
---
name: agent-orchestration-improve-agent
description: "Systematic improvement of existing agents through performance analysis, prompt engineering, and continuous iteration."
risk: unknown
risk: critical
source: community
date_added: "2026-02-27"
---
@@ -1,7 +1,7 @@
---
name: agent-orchestration-multi-agent-optimize
description: "Optimize multi-agent systems with coordinated profiling, workload distribution, and cost-aware orchestration. Use when improving agent performance, throughput, or reliability."
risk: unknown
risk: critical
source: community
date_added: "2026-02-27"
---
@@ -1,7 +1,7 @@
---
name: agent-squad
description: Main agent orchestrator that coordinates a specialized squad of agents
risk: unknown
risk: critical
source: community
role: Orchestrator / Agent Panel
phase: all
@@ -4,7 +4,7 @@ description: Tools are how AI agents interact with the world. A well-designed
tool is the difference between an agent that works and one that hallucinates,
fails silently, or costs 10x more tokens than necessary. This skill covers
tool design from schema to error handling.
risk: unknown
risk: critical
source: vibeship-spawner-skills (Apache 2.0)
date_added: 2026-02-27
---
@@ -1,7 +1,7 @@
---
name: agents-md
description: This skill should be used when the user asks to "create AGENTS.md", "update AGENTS.md", "maintain agent docs", "set up CLAUDE.md", or needs to keep agent instructions concise. Enforces research-backed best practices for minimal, high-signal agent documentation.
risk: unknown
risk: critical
source: community
---
@@ -1,7 +1,7 @@
---
name: agents-v2-py
description: "Build container-based Foundry Agents with Azure AI Projects SDK (ImageBasedHostedAgentDefinition). Use when creating hosted agents with custom container images in Azure AI Foundry."
risk: unknown
risk: critical
source: community
date_added: "2026-02-27"
---
@@ -2,7 +2,7 @@
name: ai-agents-architect
description: Expert in designing and building autonomous AI agents. Masters tool
use, memory systems, planning strategies, and multi-agent orchestration.
risk: unknown
risk: none
source: vibeship-spawner-skills (Apache 2.0)
date_added: 2026-02-27
---
@@ -2,7 +2,7 @@
name: ai-analyzer
description: AI驱动的综合健康分析系统,整合多维度健康数据、识别异常模式、预测健康风险、提供个性化建议。支持智能问答和AI健康报告生成。
allowed-tools: Read, Grep, Glob, Write
risk: unknown
risk: critical
source: community
---
@@ -1,7 +1,7 @@
---
name: ai-engineer
description: Build production-ready LLM applications, advanced RAG systems, and intelligent agents. Implements vector search, multimodal AI, agent orchestration, and enterprise AI integrations.
risk: unknown
risk: critical
source: community
date_added: '2026-02-27'
---
@@ -10,6 +10,20 @@ tags: [prompt-engineering, rag, security, evaluation, ai-engineering, llm]
tools: [claude, cursor, gemini, copilot]
---
> **⚠️ AUTHORIZED USE ONLY**
> This skill is for educational purposes or authorized security assessments only.
> You must have explicit, written permission from the system owner before using this tool.
> Misuse of this tool is illegal and strictly prohibited.
> **Mandatory confirmation gate**
> Before running any command that probes, exploits, changes, persists on, extracts data from, or attempts credential access against a target:
> 1. Ask the user to state the exact target URL, IP, account, or resource.
> 2. Ask the user to confirm written authorization and the permitted scope.
> 3. Show the exact command(s) and explain their expected effect.
> 4. Wait for explicit confirmation in the current conversation.
>
> Without that confirmation, remain read-only and provide defensive guidance only. Prefer a sandbox, disposable VM, or controlled lab.
# AI Engineering Toolkit
## Overview
@@ -43,11 +57,6 @@ Walks through a complete architecture decision tree: document format → parsing
### Skill 4: Agent Safety Guard
> **⚠️ AUTHORIZED USE ONLY**
> This skill is for educational purposes or authorized security assessments only.
> You must have explicit, written permission from the system owner before using this tool.
> Misuse of this tool is illegal and strictly prohibited.
Executes a 65-point red-team audit across 5 attack categories: direct prompt injection, indirect prompt injection (via RAG documents), information extraction (system prompt / API key leakage), tool abuse (SQL injection, path traversal, command injection), and goal hijacking. The AI constructs adversarial test prompts for evaluation purposes, asks the user for confirmation before each test phase, judges pass/fail, and generates fix recommendations. All tests are contained within the evaluation context and do not interact with external systems. It is recommended to run audits in a sandboxed environment (Docker/VM).
### Skill 5: Eval Harness Builder
@@ -1,7 +1,7 @@
---
name: ai-seo
description: "Optimize content for AI search and LLM citations across AI Overviews, ChatGPT, Perplexity, Claude, Gemini, and similar systems. Use when improving AI visibility, answer engine optimization, or citation readiness."
risk: unknown
risk: critical
source: "https://github.com/coreyhaines31/marketingskills"
date_added: "2026-03-21"
metadata:
@@ -3,7 +3,7 @@ name: ai-wrapper-product
description: Expert in building products that wrap AI APIs (OpenAI, Anthropic,
etc. ) into focused tools people will pay for. Not just "ChatGPT but
different" - products that solve specific problems with AI.
risk: unknown
risk: critical
source: vibeship-spawner-skills (Apache 2.0)
date_added: 2026-02-27
---
@@ -2,7 +2,7 @@
name: algolia-search
description: Expert patterns for Algolia search implementation, indexing
strategies, React InstantSearch, and relevance tuning
risk: unknown
risk: critical
source: vibeship-spawner-skills (Apache 2.0)
date_added: 2026-02-27
---
@@ -1,7 +1,7 @@
---
name: algorithmic-art
description: "Algorithmic philosophies are computational aesthetic movements that are then expressed through code. Output .md files (philosophy), .html files (interactive viewer), and .js files (generative algorithms)."
risk: unknown
risk: critical
source: community
date_added: "2026-02-27"
---
@@ -1,7 +1,7 @@
---
name: alpha-vantage
description: "Access 20+ years of global financial data: equities, options, forex, crypto, commodities, economic indicators, and 50+ technical indicators."
risk: unknown
risk: critical
source: community
metadata:
skill-author: K-Dense Inc.
@@ -1,7 +1,7 @@
---
name: alternatives-pages
description: 'Create "[Competitor] alternative" and comparison pages for developer tools. Build honest, high-converting comparison content that ranks for competitive search terms. Trigger phrases: "alternatives page", "comparison page", "vs page", "[competitor] alternative", "competitor comparison",...'
risk: unknown
risk: critical
source: https://github.com/jonathimer/devmarketing-skills/tree/main/skills/alternatives-pages
source_repo: jonathimer/devmarketing-skills
source_type: community
@@ -1,7 +1,7 @@
---
name: analytics-tracking
description: Design, audit, and improve analytics tracking systems that produce reliable, decision-ready data.
risk: unknown
risk: critical
source: community
date_added: '2026-02-27'
---
@@ -1,7 +1,7 @@
---
name: analytics
description: When the user wants to set up, improve, or audit analytics tracking and measurement. Also use when the user mentions "set up tracking," "GA4," "Google Analytics," "conversion tracking," "event tracking," "UTM parameters," "tag manager," "GTM," "analytics implementation," "tracking...
risk: unknown
risk: critical
source: https://github.com/coreyhaines31/marketingskills/tree/main/skills/analytics
source_repo: coreyhaines31/marketingskills
source_type: community
@@ -1,7 +1,7 @@
---
name: angular-migration
description: "Master AngularJS to Angular migration, including hybrid apps, component conversion, dependency injection changes, and routing migration."
risk: unknown
risk: critical
source: community
date_added: "2026-02-27"
---
@@ -1,7 +1,7 @@
---
name: anti-deception
description: Use BEFORE responding when the user's request shows pressure to validate or agree ("tell them what they want", "make them happy", "convince them"), manufactured urgency (artificial deadline), authority appeals (citing investors, advisors, lawyers, experts), demands to certify without...
risk: unknown
risk: critical
source: https://github.com/ejentum/ejentum-mcp/tree/main/skills/anti-deception
source_repo: ejentum/ejentum-mcp
source_type: community
@@ -6,6 +6,20 @@ source: community
date_added: "2026-02-27"
---
> **⚠️ AUTHORIZED USE ONLY**
> This skill is for educational purposes or authorized security assessments only.
> You must have explicit, written permission from the system owner before using this tool.
> Misuse of this tool is illegal and strictly prohibited.
> **Mandatory confirmation gate**
> Before running any command that probes, exploits, changes, persists on, extracts data from, or attempts credential access against a target:
> 1. Ask the user to state the exact target URL, IP, account, or resource.
> 2. Ask the user to confirm written authorization and the permitted scope.
> 3. Show the exact command(s) and explain their expected effect.
> 4. Wait for explicit confirmation in the current conversation.
>
> Without that confirmation, remain read-only and provide defensive guidance only. Prefer a sandbox, disposable VM, or controlled lab.
> **AUTHORIZED USE ONLY**: This skill contains dual-use security techniques. Before proceeding with any bypass or analysis:
> 1. **Verify authorization**: Confirm you have explicit written permission from the software owner, or are operating within a legitimate security context (CTF, authorized pentest, malware analysis, security research)
> 2. **Document scope**: Ensure your activities fall within the defined scope of your authorization
@@ -43,6 +43,7 @@ Before changing anything:
- Run `npm run validate`, `npm run validate:references`, `npm run security:docs`, changed-skill evidence, and the relevant tests.
- Treat the entire tracked `skills/<skill-id>/**` subtree as skill content. Inspect semantics, safety, provenance, declared risk, limitations, and every bundled file directly, including nested examples, scripts, lockfiles, references, and assets. Never reduce evidence or review to `SKILL.md` or a fixed support-directory allowlist.
- Require changed-skill evidence to cover every Git record in each changed canonical skill subtree. Require the `skill-review` workflow for changes under `skills/**` or `plugins/**/skills/**`; its reusable result must be keyed by the complete nearest skill-directory fingerprint on the exact current head SHA.
- Keep canonical skill ownership lookup proportional to changed-path depth, not total registry size, and preserve the five-minute trusted evaluator budget so repository-wide evidence completes without weakening fail-closed checks. Parse a legacy executable-mode canonical `SKILL.md` only as private, non-executable snapshot data; keep it reported as unsafe and never materialize symlinks, gitlinks, or other executable files.
- `review` means Tessl semantic review actually ran or a valid identical-content result was reused.
- `manual-review-required` means Tessl credentials or credits were unavailable, or Tessl did not produce a passing result. Perform the maintainer semantic review and attest with `--reviewed-head <full-40-character-sha>`.
- Any non-passing Tessl outcome produces `manual-review-required`; complete the semantic review and bind the judgment to the exact head instead of treating a heuristic score as merge authority.
@@ -1,7 +1,7 @@
---
name: api-analyzer
description: Validates whether an API request is correct based on provided inputs (method, URL, headers, body, auth, query params). Use this skill whenever a user wants to check, validate, debug, or verify an API call — including when they paste a curl command, show endpoint details, ask "is this...
risk: unknown
risk: none
source: https://github.com/LambdaTest/agent-skills/tree/main/api-skill/api-analyzer
source_repo: LambdaTest/agent-skills
source_type: community
@@ -1,7 +1,7 @@
---
name: api-and-interface-design
description: Guides stable API and interface design. Use when designing APIs, module boundaries, or any public interface. Use when creating REST or GraphQL endpoints, defining type contracts between modules, or establishing boundaries between frontend and backend.
risk: unknown
risk: none
source: https://github.com/addyosmani/agent-skills/tree/main/skills/api-and-interface-design
source_repo: addyosmani/agent-skills
source_type: community
@@ -1,7 +1,7 @@
---
name: api-designer
description: Generates complete, production-ready REST API endpoint specifications for any system or domain the user describes. Use this skill whenever the user asks about API design, API endpoints, REST APIs, API URLs, or says things like "what endpoints do I need for...", "design an API for...",...
risk: unknown
risk: safe
source: https://github.com/LambdaTest/agent-skills/tree/main/api-skill/api-designer
source_repo: LambdaTest/agent-skills
source_type: community
@@ -1,7 +1,7 @@
---
name: api-documentation-generator
description: "Generate comprehensive, developer-friendly API documentation from code, including endpoints, parameters, examples, and best practices"
risk: unknown
risk: critical
source: community
date_added: "2026-02-27"
---
@@ -1,7 +1,7 @@
---
name: api-documenter
description: Master API documentation with OpenAPI 3.1, AI-powered tools, and modern developer experience practices. Create interactive docs, generate SDKs, and build comprehensive developer portals.
risk: unknown
risk: critical
source: community
date_added: '2026-02-27'
---
@@ -7,6 +7,20 @@ author: zebbern
date_added: "2026-02-27"
---
> **⚠️ AUTHORIZED USE ONLY**
> This skill is for educational purposes or authorized security assessments only.
> You must have explicit, written permission from the system owner before using this tool.
> Misuse of this tool is illegal and strictly prohibited.
> **Mandatory confirmation gate**
> Before running any command that probes, exploits, changes, persists on, extracts data from, or attempts credential access against a target:
> 1. Ask the user to state the exact target URL, IP, account, or resource.
> 2. Ask the user to confirm written authorization and the permitted scope.
> 3. Show the exact command(s) and explain their expected effect.
> 4. Wait for explicit confirmation in the current conversation.
>
> Without that confirmation, remain read-only and provide defensive guidance only. Prefer a sandbox, disposable VM, or controlled lab.
> AUTHORIZED USE ONLY: Use this skill only for authorized security assessments, defensive validation, or controlled educational environments.
# API Fuzzing for Bug Bounty
@@ -1,7 +1,7 @@
---
name: api-integration
description: Designs event-driven architectures, webhook systems, API chaining flows, ETL pipelines, and integration patterns between services. Use whenever the user asks about webhooks, event streaming, API composition, connecting two or more APIs, building pipelines, Pub/Sub, Kafka topics, ETL...
risk: unknown
risk: none
source: https://github.com/LambdaTest/agent-skills/tree/main/api-skill/api-integration-helper
source_repo: LambdaTest/agent-skills
source_type: community
@@ -1,7 +1,7 @@
---
name: api-onboarding
description: 'Reduce time-to-first-API-call (TTFAC) by optimizing every step of the developer onboarding journey. This skill covers authentication simplification, sandbox environments, interactive documentation, and identifying and eliminating common failure points. Trigger phrases: "API...'
risk: unknown
risk: critical
source: https://github.com/jonathimer/devmarketing-skills/tree/main/skills/api-onboarding
source_repo: jonathimer/devmarketing-skills
source_type: community
@@ -1,7 +1,7 @@
---
name: api-patterns
description: "API design principles and decision-making. REST vs GraphQL vs tRPC selection, response formats, versioning, pagination."
risk: unknown
risk: none
source: community
date_added: "2026-02-27"
---
@@ -1,7 +1,7 @@
---
name: api-sdk-generator
description: Generates client SDK code, API wrapper libraries, request/response models, and language-specific usage patterns for any REST API. Use whenever the user asks to "generate an SDK", "write a client library", "create API wrappers", "generate TypeScript types from my API", "write a Python...
risk: unknown
risk: critical
source: https://github.com/LambdaTest/agent-skills/tree/main/api-skill/api-sdk-generator
source_repo: LambdaTest/agent-skills
source_type: community
@@ -1,7 +1,7 @@
---
name: api-security-best-practices
description: "Implement secure API design patterns including authentication, authorization, input validation, rate limiting, and protection against common API vulnerabilities"
risk: unknown
risk: critical
source: community
date_added: "2026-02-27"
---
@@ -1,7 +1,7 @@
---
name: api-testing-observability-api-mock
description: "You are an API mocking expert specializing in realistic mock services for development, testing, and demos. Design mocks that simulate real API behavior and enable parallel development."
risk: unknown
risk: critical
source: community
date_added: "2026-02-27"
---
@@ -1,7 +1,7 @@
---
name: apify-actor-development
description: "Important: Before you begin, fill in the generatedBy property in the meta section of .actor/actor.json. Replace it with the tool and model you're currently using, such as \"Claude Code with Claude Sonnet 4.5\". This helps Apify monitor and improve AGENTS.md for specific AI tools and models."
risk: unknown
risk: critical
source: community
---
@@ -1,7 +1,7 @@
---
name: apify-actorization
description: "Actorization converts existing software into reusable serverless applications compatible with the Apify platform. Actors are programs packaged as Docker images that accept well-defined JSON input, perform an action, and optionally produce structured JSON output."
risk: unknown
risk: critical
source: community
---
@@ -1,7 +1,7 @@
---
name: apify-audience-analysis
description: Understand audience demographics, preferences, behavior patterns, and engagement quality across Facebook, Instagram, YouTube, and TikTok.
risk: unknown
risk: critical
source: community
---
@@ -1,7 +1,7 @@
---
name: apify-brand-reputation-monitoring
description: "Scrape reviews, ratings, and brand mentions from multiple platforms using Apify Actors."
risk: unknown
risk: critical
source: community
---
@@ -1,7 +1,7 @@
---
name: apify-competitor-intelligence
description: Analyze competitor strategies, content, pricing, ads, and market positioning across Google Maps, Booking.com, Facebook, Instagram, YouTube, and TikTok.
risk: unknown
risk: critical
source: community
---
@@ -1,7 +1,7 @@
---
name: apify-content-analytics
description: Track engagement metrics, measure campaign ROI, and analyze content performance across Instagram, Facebook, YouTube, and TikTok.
risk: unknown
risk: critical
source: community
---
@@ -1,7 +1,7 @@
---
name: apify-ecommerce
description: "Extract product data, prices, reviews, and seller information from any e-commerce platform using Apify's E-commerce Scraping Tool."
risk: unknown
risk: critical
source: community
---
@@ -1,7 +1,7 @@
---
name: apify-influencer-discovery
description: Find and evaluate influencers for brand partnerships, verify authenticity, and track collaboration performance across Instagram, Facebook, YouTube, and TikTok.
risk: unknown
risk: critical
source: community
---
@@ -1,7 +1,7 @@
---
name: apify-lead-generation
description: "Scrape leads from multiple platforms using Apify Actors."
risk: unknown
risk: critical
source: community
---
@@ -1,7 +1,7 @@
---
name: apify-market-research
description: Analyze market conditions, geographic opportunities, pricing, consumer behavior, and product validation across Google Maps, Facebook, Instagram, Booking.com, and TripAdvisor.
risk: unknown
risk: critical
source: community
---
@@ -1,7 +1,7 @@
---
name: apify-trend-analysis
description: Discover and track emerging trends across Google Trends, Instagram, Facebook, YouTube, and TikTok to inform content strategy.
risk: unknown
risk: critical
source: community
---
@@ -1,7 +1,7 @@
---
name: apify-ultimate-scraper
description: "AI-driven data extraction from 55+ Actors across all major platforms. This skill automatically selects the best Actor for your task."
risk: unknown
risk: critical
source: community
---
@@ -1,7 +1,7 @@
---
name: app-builder
description: "Main application building orchestrator. Creates full-stack applications from natural language requests. Determines project type, selects tech stack, coordinates agents."
risk: unknown
risk: critical
source: community
date_added: "2026-02-27"
---
@@ -1,7 +1,7 @@
---
name: templates
description: "Project scaffolding templates for new applications. Use when creating new projects from scratch. Contains 12 templates for various tech stacks."
risk: unknown
risk: critical
source: community
date_added: "2026-02-27"
---
@@ -1,7 +1,7 @@
---
name: app-store-optimization
description: "Complete App Store Optimization (ASO) toolkit for researching, optimizing, and tracking mobile app performance on Apple App Store and Google Play Store"
risk: unknown
risk: critical
source: community
date_added: "2026-02-27"
---

Some files were not shown because too many files have changed in this diff Show More