The open format is called Agent Skills and works in Claude Code, Codex, Cursor and other agents — most people know it as Claude Skills.
Every Agent Skill we could find on GitHub, deduplicated by content. 79 437 files from 1 744 authors, of which 61 785 are unique — the rest is the same skill repackaged into someone else's repository. For each one: what it weighs in tokens, whether it ships runnable scripts, and which MCP servers it needs.
Create detailed implementation plans with bite-sized tasks for engineers with zero codebase context
Working effectively with JSON data structures.
Safe patterns for evolving database schemas in production with decision trees and troubleshooting guidance.
Reporting pipelines for CSV/JSON/Markdown exports with timestamped outputs, summaries, and post-processing.
SEC EDGAR extraction pipeline: setup, filing discovery by CIK, recipe-driven extraction, and report generation.
Working with Excel files programmatically.
Systematically trace bugs backward through call stack to find original trigger
Step-by-step debugging workflow: reproduce the bug, isolate the failing component, trace to root cause, apply a targeted fix, and verify the fix resolves the issue without regressions. Use when you encounter a bug, error, exception, crash, or unexpected behavior that needs troubleshooting.
Run verification commands and confirm output before claiming success
Environment variable validation, security scanning, and management for Next.js, Vite, React, and Node.js applications
Terraform infrastructure-as-code workflow patterns: state and environments, module design, safe plan/apply, drift control, and CI guardrails
Kubernetes operations playbook for deploying services: core objects, probes, resource sizing, safe rollouts, and fast kubectl debugging
Suite of tools for creating elaborate, multi-component claude.ai HTML artifacts using modern frontend web technologies (React, Tailwind CSS, shadcn/ui)
Framework for writing concise 3P (Progress, Plans, Problems) team updates for executives and stakeholders
Guide for creating effective skills
MCP (Model Context Protocol) server build and evaluation guide, including local conventions for tool surfaces, config, and testing
OpenTelemetry observability patterns: traces, metrics, logs, context propagation, OTLP export, Collector pipelines, and troubleshooting
Reference implementation demonstrating the Command → Agent → Skill orchestration pattern in Claude MPM, showing both preloaded-skill and dynamic-skill-invocation styles
Severity-tagged code review checklist (CRITICAL/HIGH/MEDIUM/LOW) used by code-critic agent
Six-stage quality-gate pipeline for any code implementation task
CI security scanning: secrets, deps, SAST, triage, expiring exceptions
Vendor-neutral framework for scoring software health, estimating technical debt, assessing cloud readiness and open-source safety, and communicating quality to business stakeholders. Use when you need to quantify code health at the application or portfolio level rather than fix individual findings.
Replace arbitrary timeouts with condition polling for reliable async tests
Threat modeling workflow for software systems: scope, data flow diagrams, STRIDE analysis, risk scoring, and turning mitigations into backlog and tests. Use when designing new features, reviewing architecture changes, handling sensitive data, or hardening auth/payment/multi-tenant flows.
Comprehensive TDD patterns and practices for all programming languages, eliminating redundant testing guidance per agent.
Test quality inspection framework for reviewing test coverage, identifying gaps, and ensuring comprehensive validation
Systematic workflow for verifying bug fixes to ensure quality and prevent regres...
Never test mock behavior. Never add test-only methods to production classes. Understand dependencies before mocking. Language-agnostic principles with TypeScript/Jest and Python/pytest examples.
Comprehensive web application testing patterns with Playwright selectors, wait strategies, and best practices
Comprehensive verification workflow before merging changes to production.
Visual verification workflow for UI changes to accelerate code review and catch ...
Comprehensive API design patterns covering REST, GraphQL, gRPC, versioning, authentication, and modern API best practices
Best practices for documenting APIs and code interfaces, eliminating redundant documentation guidance per agent.
Optimize web performance using Core Web Vitals, modern patterns (View Transitions, Speculation Rules), and framework-specific techniques
> cycles, maintenance windows, backup monitoring and test restores, monitoring and alert triage, the on-call rotation, change management for risky changes, documentation currency, and vendor or license renewals. Trigger on "patch window", "maintenance window", "did the backups run", "test restore", "alert storm", "who is on call", "can we make this change", "update the firewall", or any question about the recurring delivery work between tickets. msp-helpdesk owns the reactive desk (tickets, priorities, response targets); this skill owns the scheduled work that prevents tickets. Apply alongside msp-client-comms (maintenance notices), msp-qbr (the scorecard rows this work feeds), msp-metrics (SLA and ticket data), msp-legal (the negligence carveout that makes these logs matter), and msp-pricing (after-hours multipliers for emergency work).
> Use this skill whenever the user wants marketing CONTENT produced for their managed IT services (professional network, local business listing, general social), email newsletter content, rewriting or adapting outside material (licensed MSP marketing content packs, industry articles, vendor blogs) into the company's voice, generating post ideas from the idea bank, building a content calendar, repurposing one piece into other formats, or SEO titles/descriptions for a marketing should we do", "how do we get found locally", local business listings, reviews, directories, chambers of commerce, referral partnerships with CPAs/insurance agents, workshops, or a marketing plan/rhythm for an MSP. Trigger on "write a resource", "rewrite this article", "digest this marketing pack", "what should we post", "give me this week's post", or "turn this into a social post". Sales outreach, scripts, pipeline, discovery, and the referral program mechanics belong to msp-sales; operational notices to existing clients belong to msp-client-comms. Apply alongside msp-brand (voice, naming, visuals) and msp-pricing (any number a client could see).
> Use this skill whenever the user wants to FIND new prospects for their managed IT services a prospect list, researching a specific business as a potential client, figuring out who the decision maker or "IT person" is at a company, or planning how to approach a prospect (email vs call vs professional network vs mail, and when). Trigger on "find leads", "find prospects", "who should we go after in [area]", "research this business", "build a lead list", "is [company] a good fit", "who do I contact at [company]", "sweep [town] for candidates", or any mention of generating leads, prospecting an area, or door-knocking researches prospects and plans the approach; msp-sales owns the ICP definition and all outreach copy; msp-marketing owns broad marketing channels. Apply alongside msp-brand and msp-sales.
> questioning a ticket's priority, response and resolution targets, "the client says everything is down", escalation, after-hours or emergency requests, security incident intake, triage order, your PSA (ticketing) system workflow, time entries, or ticket categories. Also trigger when drafting anything that describes support levels or response times to a client, and when training new hires on the service desk workflow (client onboarding is msp-onboarding). Apply alongside msp-client-comms (the messages clients receive during incidents), msp-legal (the SLA schedule lives in each client's Order; security incidents have contract implications), msp-pricing (after-hours billing multipliers), msp-maintenance (alerts that escalate into tickets, and the on-call rotation behind the after-hours line), and msp-metrics (ticket data feeds every business number).
> MSA, Service Order, SOW, SLA, NDA, waiver, DPA, or BAA; triaging a contract a client or vendor sends; assessing legal risk on a deal; or answering "what document do we need for this client". negotiation playbook and document map, the organization-specific positions those skills ask for. Also trigger on "is this enforceable", "what should our contract say", "the client wants to change a clause", or any mention of liability caps, indemnification, non-solicits, or contract terms for an IT services business. Apply alongside msp-brand (naming and voice), msp-pricing (any term or number a client could see), and msp-sales (how legal terms land in the sales conversation).
> outage or incident notices and updates, planned or emergency maintenance announcements, post-incident summaries, security advisories ("warn our clients about this phishing wave"), price change letters, new-user-ready or user-offboarded confirmations, and ticket closing notices. Trigger on "draft an email to the client about", "let them know", "notify clients", "tell the client", or any in-service client notification. Sales outreach to prospects belongs to msp-sales; this skill owns messages to clients already under agreement. Apply alongside msp-brand (voice and signature), msp-helpdesk (priorities set the cadence), msp-legal (anything touching breach, liability, or contract mechanics), and msp-pricing (any number).
> Use this skill whenever generating ANY document, marketing material, email, proposal, slide deck, or other customer- or internal-facing content for your MSP, so that naming, visual style, and voice stay consistent. Triggers include any request to create, write, design, or format content "for us", "for my MSP", "on brand", "branded", or anything that will carry the company's name, decks, social posts, letterhead, email signatures, or web copy (content and voice only; site build and hosting is msp-website-setup). Always load this skill before producing branded output, and apply it alongside content skills like msp-sales, msp-marketing, msp-pricing, docx, and pptx.
> Use this skill whenever measuring or judging your MSP's business health or a client money on [client]", tickets per user, SLA attainment, churn, aged receivables, revenue concentration, the monthly owner review, the underlying numbers behind the client health scorecard (msp-qbr owns the client-facing scorecard document), or any version of "should we fire this client" or "this client is a problem". Also trigger when building dashboards, review sheets, or reports about the business. Apply alongside msp-pricing (the cost model and floor that give the numbers meaning), msp-helpdesk (ticket hygiene is the data source), msp-qbr (where client-facing consequences land), msp-client-comms (the repricing letter), msp-legal (waivers and exits), and msp-offboarding (the exit path).
> Use this skill whenever pricing or packaging a managed-services or break-fix engagement for for a client, working out a price band for negotiation, or sanity-checking margin on a deal. Triggers include "how much should we charge", "price this client", "put together options for", "what should I quote", "build a package for", "what's the floor on this deal", "per-user price", "how deep can we discount", "should this include on-site", or any mention of quoting devices, seats, servers, network gear, on-site visits, contract length, or monthly recurring revenue for an IT services deal. Also trigger when reviewing or revising the price sheet or the building blocks. Always load this skill before producing any number a client could see, and apply it alongside msp-sales (the value conversation and discovery) and msp-brand (how the number is presented), and msp-client-comms (the price-increase letter, once the new number is set).
> "QBR", "quarterly review", "business review", "account review", "prep for the [client] meeting", building a client scorecard, planning a client's technology roadmap or budget, or preparing the renewal and repricing conversation. Also trigger when someone asks how often to meet with clients or what to show them. Apply alongside msp-metrics (the numbers and the client health scorecard), msp-helpdesk (performance against targets), msp-pricing (any cost band shown to the client), msp-client-comms (the price letter and follow-up), msp-legal (waivers for declined recommendations), and msp-brand (anything the client sees).
> Use this skill whenever a new client signs or client onboarding comes up in any up", "take over from their old IT guy", or names a new client that needs setting up. Also trigger for planning or quoting onboarding work, building a credential collection list, deploying agents to a new environment, or the 30-day review. This is the handoff target for msp-sales pipeline stage 7 (Closed Won). Apply alongside msp-legal (paper gates before work starts), msp-pricing (onboarding is always billed separately), msp-brand (every client-facing message), and hand off to msp-helpdesk and msp-qbr at the end.
Your MSP's standard process for setting up a new static client website hosted on your static hosting platform with a git-based dev/prod CI/CD pipeline, plus the client-practice rules around it. Use this skill whenever starting a new website project for a client, setting up a static site, initializing a website repo, connecting a site to your static hosting platform, or wiring up dev and prod deployments for a small business site, even if the user just says "let's build a site for this client" or "set up the repo for the new website". Also trigger for questions about who owns a client's site, domain, repo, or content, which agreement a website project needs and when in the sequence (drafting the document itself is msp-legal), website accessibility (WCAG, alt text, contrast), privacy policy or form-data questions on a client site, and handing a site back at offboarding. Load before writing any site code or running git init so the project starts on the standard structure.
> gives notice, says they are not renewing, is switching providers, or asks to cancel; you decide to exit a client (see msp-metrics for that decision); or anyone mentions data return, removing our access, transitioning to a successor provider, a final invoice, or "offboarding" a client. Also trigger when drafting termination acknowledgments or closure letters. Apply alongside msp-legal (the signed MSA and Order govern notice, fees, and data handling; this is a legal-adjacent workflow), msp-brand (every message), msp-client-comms (the letters), and msp-metrics (log the loss and the reason).
> Guided first-run setup for the MSP Operations Kit. Use this skill whenever the user wants to set customize these skills", "make these skills mine", "replace the placeholders", "finish setup", "resume setup", "am I ready to use this with clients", or any first-run intent after purchase. Also trigger when another msp skill surfaces an unfilled placeholder token or an unreviewed example default, since that means setup is incomplete. Works through msp-brand first, then msp-pricing, then every skill's Setup Decisions, and finishes with a readiness check.
> Use this skill whenever the user wants sales documents, content, or procedures for their tracks, case studies, pipeline documents, follow-up templates, objection handling, discovery frameworks, prospect targeting, the referral program, post-proposal negotiation, or internal sales enablement. Also trigger for "write an email to a prospect", "create a sales script", "draft a case study", "the client came back on the proposal", "they countered", "they said no because of cost", reviving a dead or gone-dark deal, or any mention of winning new clients, following up with leads, or building sales materials for an IT services business, even if the user doesn't say "MSP". Marketing content and channels belong to msp-marketing. Apply alongside msp-brand (identity, voice, visuals) and msp-pricing (any number a client could see).
Progressive UX generation — Phase 1 generates 5 B&W wireframe options instantly (1 safe + 4 exploratory), then Phase 2 renders Clean + Polished color variants via 5 parallel Task agents (one per option). Supports wireframes-only or wireframes+visuals. Extracts optimization intent from arguments when present. Maintains persistent design context. Use when user says "wireframe", "prototype", "UX options", or "layout exploration".
> details, interceptors, deadlines, streaming, health checks, and graceful shutdown. "interceptor", "gRPC streaming", "gRPC deadline", "grpc health check", "gRPC status codes". API layering (use go-architecture-review), or TLS hardening details (use go-security-audit).
> layering, separation of concerns, domain modeling, and module boundaries. Use when reviewing architecture, designing package layout, evaluating dependency graphs, or refactoring monoliths into modules. "dependency direction", "clean architecture Go", "module boundaries". Do NOT use for code-level style (use go-coding-standards) or API endpoint design (use go-api-design).
> conventions, when to use a flat layout, module naming, and main package wiring. "start a Go module", "how do I organize a new service", "set up folder structure". dependency injection wiring details (use go-dependency-injection), or CI pipeline setup (use go-ci).
> discipline, exit codes, signal handling, and when Cobra/Viper earn their weight over the standard library. "handle Ctrl+C", "cobra command", "read from stdin", "CLI UX". in general (use go-project-layout), or configuration of services (use go-architecture-review).
> REST and gRPC API design patterns for Go services. Covers HTTP handlers, middleware, routing, request/response patterns, versioning, pagination, graceful shutdown, and OpenAPI documentation. Use when designing APIs, writing HTTP handlers, implementing middleware, structuring REST endpoints, or setting up gRPC services. "middleware pattern", "graceful shutdown", "gRPC service", "API versioning". Do NOT use for general architecture (use go-architecture-review) or concurrency in handlers (use go-concurrency-review).
> interface compliance verification, composition, the accept-interfaces-return-structs principle, and common pitfalls. Use when designing interfaces, decoupling packages, defining contracts, reviewing interface usage, or refactoring for testability. "interface compliance", "consumer-side interface", "interface composition". Do NOT use for HTTP handler patterns (use go-api-design) or general code review (use go-code-review).
> Go coding standards and style conventions grounded in Effective Go, Go Code Review Comments, and production-proven idioms. Use when writing or reviewing Go code, enforcing naming conventions, import ordering, variable declarations, struct initialization, or formatting rules. Do NOT use for architecture decisions, concurrency patterns, or performance tuning — use go-architecture-review, go-concurrency-review, or go-performance-review instead.
> middleware chain, pub/sub, and other patterns adapted for Go's type system. "factory pattern", "strategy pattern", "middleware chain", "option pattern", "how to structure this". package layout (use go-architecture-review), or concurrency patterns (use go-concurrency-review).
> global state, and when frameworks (wire, fx, dig) earn their complexity. "remove global state", "singleton in Go", "use google/wire", "uber fx", "make this testable". project directory structure (use go-project-layout), or test doubles and mocks (use go-test-quality).
> Comprehensive code review checklist for Go projects. Evaluates code quality, idiomatic patterns, error handling, naming, package structure, and test coverage. Use when reviewing Go code, PRs, or before merging changes. Do NOT use for security-specific audits (use go-security-audit) or performance-specific analysis (use go-performance-review).
Answers built from the skills we actually parsed.