AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in

Ai And Ml for AI agents

100 security-reviewed ai and ml listings, skills, MCP servers, and toolkits you can install into Claude Code, Cursor, and other agents with one command.

100+ results
Self-run
SKILL Apache-2.0 today

Td Feature Survey

Survey one surface of tdmcp (artist controls, library/packaging, CLI/DX, AI/LLM, or TouchDesigner depth) for candidate NEW features — inventory what exists, cross-check the roadmap, apply the gap-finding lenses, vet each idea, and emit a structured, novelty- and confidence-labelled candidate list to _workspace/discovery/. Use when a td-surveyor agent is scouting a surface during the feature-disco…

Local-only
0
4
Free
Self-run
SKILL Apache-2.0 today

Connectors Directory Spec

Authoritative reference for submitting tdmcp to the Anthropic Connectors Directory as a Claude Desktop Extension (MCPB). Use whenever drafting, checking, or fixing the submission — it defines the two submission paths, why tdmcp is a Desktop Extension (never a remote connector), every form field, the rejection-causing gates, and the local-only compliance story. Read this before writing any submiss…

Local-only
0
6
Free
Self-run
SKILL Apache-2.0 today

Tdmcp Feature Discovery

Survey the whole tdmcp project and produce a prioritized list of NEW features it could implement — across artist controls, CLI/DX, AI/LLM integration, and TouchDesigner depth. Use whenever the user wants to brainstorm, discover, survey, list, or audit what features/tools/effects/controls/commands/prompts/capabilities tdmcp *could* add, asks 'what could we build / what's missing / what are the opp…

Local-only
0
3
Free
Self-run
SKILL Apache-2.0 today

Tdmcp Submission

Orchestrates the tdmcp Anthropic Connectors Directory (Desktop Extension / MCPB) submission prep — designs the package, writes the privacy page, migrates .dxt→.mcpb, drafts all form answers, and QAs the result. Use for ANY work on the tdmcp directory/marketplace submission, including re-runs after a rejection ("update the submission", "redo the form answers", "re-migrate the bundle", "fix the pri…

Local-only
0
3
Free
Self-run
SKILL MIT 1mo ago

Api Scam Hunter

>

env
0
3
Free
Self-run
SKILL MIT 2mo ago

Axure Rp Html Ingest

MUST USE when the task mentions Axure, RP, published HTML prototype, html_export, index.html prototype packages, data/document.js, files/*/data.js, extracting prototype structure, or converting prototype pages into LLM-ready context. Ingest and parse Axure RP exported HTML prototypes into structured JSON and Markdown.

fs
0
3
Free
Self-run
SKILL MIT 4d ago

Scanpy Sc Analyzer

Autonomous single-cell RNA-seq quality control filtering, Harmony batch-effect correction, Leiden clustering, UMAP visualization, and marker gene annotation.

Local-only
0
6
Free
Self-run
SKILL MIT 4d ago

Alphafold Pocket Evaluator

Parses AlphaFold2 PDB files, computes per-residue pLDDT confidence scores, and evaluates Solvent Accessible Surface Area (SASA) of active site pockets.

fs
0
3
Free
Self-run
SKILL MIT 4d ago

Pubmed Rag Synthesizer

Vectorizes PubMed abstracts using PubMedBERT, builds FAISS indices, and instructs agents to synthesize clinical evidence with exact PMID citations.

Local-only
0
3
Free
Self-run
SKILL MIT 4d ago

Diffdock Virtual Screener

Runs DiffDock generative diffusion models for blind protein-ligand docking against AlphaFold structures and ranks candidates by confidence scores.

Local-only
0
0
Free
Self-run
SKILL MIT 4d ago

Pydeseq2 Bulk Rna

Automated negative binomial differential gene expression analysis, log2 fold-change calculation, p-value adjustment (FDR), and Volcano plot generation.

Local-only
0
3
Free
Self-run
MCP MIT 1mo ago

Jarvis Ai

Local voice-driven AI operator (JARVIS) for Linux & Windows — Claude Pro / OpenRouter / Ollama, wake word, piper TTS, Iron Man-style HUD, Hyprland integration, WhatsApp & Telegram, Agentic Task Engine with live progress tracking.

netenv
0
2
Free
Self-run
SKILL MIT 4d ago

Gatk4 Somatic Variant Caller

Executes GATK4 Mutect2 tumor-normal paired variant calling, applies LearnReadOrientationModel, and runs FilterMutectCalls for somatic SNV filtering.

Local-only
0
3
Free
Self-run
SKILL MIT 4d ago

Ensembl Vep Variant Annotator

Parses multi-sample VCF files, queries Ensembl VEP REST API, filters ClinVar pathogenicity ratings, and maps driver mutations to FDA targeted drugs.

net
0
3
Free
Self-run
SKILL MIT 4d ago

Qiime2 16s Microbiome

DADA2 amplicon sequence variant (ASV) dereplication, Alpha/Beta diversity index calculation, SILVA taxonomy classification, and 3D PCoA projections.

Local-only
0
3
Free
Self-run
SKILL MIT 4d ago

Rdkit Qsar Pharmacophore

Computes 2048-bit ECFP4 Morgan fingerprints from SMILES, trains LightGBM regressors for pIC50 prediction, and extracts SHAP feature attributions.

Local-only
0
3
Free
Self-run
SKILL MIT 4d ago

Tcga Cibersort Deconv

Downloads TCGA RNA-Seq datasets via TCGAbiolinks, normalizes log2(TPM+1) counts, and calculates tumor-infiltrating immune cell fractions (CIBERSORT).

Local-only
0
3
Free
Self-run
SKILL MIT 5d ago

Bazi

Use when the user asks for bazi, 八字, Four Pillars, BaZi, Chinese astrology birth chart, 生辰八字, 命盘, day master, or interpretation from a Gregorian birth date and time.

Local-only
0
0
Free
Self-run
SKILL MIT 5d ago

Xiaoliuren

Use when the user asks for Xiao Liu Ren, 小六壬, xiaoliuren, quick symbolic timing reflection, daily guidance, folk-style yes/no reflection, or interpretation from lunar month/day/hour inputs.

Local-only
0
0
Free
Self-run
SKILL MIT 5d ago

Tarot

Use when the user asks for tarot, a card pull, a card reading, symbolic reframing, decision reflection, creative blocks, project reflection, or interpretation of a user-provided tarot draw.

Local-only
0
0
Free
Self-run
SKILL MIT 5d ago

Iching

Use when the user asks for I Ching, Yi Jing, Zhouyi, 易经, 周易, hexagrams, coin casting, yarrow-style casting, change analysis, or interpretation of user-provided line values.

Local-only
0
0
Free
Self-run
SKILL MIT 2d ago

Better Prompt

Optimize and refine AI prompts through a two-phase expert pipeline. Phase 1 (Lyra) builds a structured draft from rough ideas, Phase 2 (Meta) deeply refines it with advanced prompt engineering techniques. Use this skill when the user wants to improve a prompt, write a better system prompt, optimize LLM instructions, or craft high-quality AI prompts. Also trigger when users ask about prompt engine…

Local-only
0
0
Free
Self-run
SKILL MIT 21d ago

Resource2skill

把人类创作的资源(教程视频/文章/代码仓库/成品参考)蒸馏成可复用的 skill——Resource2Skill 论文 (arXiv:2606.29538) 构建算子的本地实现。触发场景:用户说"把这个视频/教程/文章变成 skill"、"蒸馏这个资源"、"入库这个教程"、给出教程链接并希望沉淀为规范/技能,或要为某领域批量建技能库时。产物形态按目标域适配(Claude Code skill / PPT 版式技能 / n8n 工作流模式等)。

Local-only
0
0
Free
Self-run
SKILL Apache-2.0 2d ago

Init Merlean

Set up the MerLEAN system in this repo (replaces the old src/deploy.sh) — build the shared Python .venv from src/requirements.txt, write the root .mcp.json for the lean-lsp MCP server, ensure an OpenAI key in .env, and prepare the root Lean + Mathlib workspace (lake update / cache get / build). Use when asked to install, set up, initialize, or (re)deploy MerLEAN, or when a fresh clone needs its r…

env
0
0
Free
Self-run
SKILL Apache-2.0 2d ago

Plan Graph

Read, edit, and SEMANTICALLY SEARCH the formalization statement plan stored in the Mem0-g plan graph (the replacement for statements.json). Use whenever you need to inspect, query, or modify statements, dependencies, status, or informal notes; run the Lean dependency sync; or find statements/notes by MEANING (LeanSearch-v2-style two-stage retrieval: OpenAI embedding recall → LLM rerank) — e.g. to…

env
0
0
Free
Self-run
MCP MIT 2mo ago

Skim

Runtime token proxy + intelligence dashboard for LLM tools. Intercepts API calls, strips waste, tracks costs — for individual developers and Fortune 500 teams.

Local-only
0
1
Free
Self-run
MCP MIT yesterday

Turbovec MCP Tiar

Turbovec MCP Server: A local Retrieval-Augmented Generation (RAG) tool that allows AI to seamlessly read, chunk, remember, and semantically search through large project codebases.

Local-only
0
1
Free
Self-run
SKILL Apache-2.0 1mo ago

Godot Plugin

Control Godot Editor via OpenClaw Godot Plugin. Use for Godot game development tasks including scene management, node manipulation, input simulation, debugging, and editor control. Can modify, save, and delete scenes/nodes and capture project metadata and screenshots — destructive operations should be confirmed with the user. Use only on explicit Godot Editor requests like inspecting scenes, crea…

net
0
0
Free
Self-run
SKILL MIT 13d ago

Person To Skill

Builds or updates a source-grounded advisor skill from one person's books, documents, local transcript files, and YouTube video URLs. Extracts PDF/EPUB/DOCX/HTML/Markdown/text/RTF/MOBI/AZW sources, retrieves available YouTube captions, reconciles evolving or conflicting ideas, and generates a compact `/ask-name`-style skill with citations, framework notes, decision rules, source provenance, and c…

Local-only
0
1
Free
Self-run
MCP MIT yesterday

Docsift

Convert documents once. Give agents only what they need — PDFs and Office files to clean Markdown, chunks and local search.

net
0
0
Free
Self-run
SKILL MIT 3d ago

Trapstreet Task Scaffold

Design and scaffold a NEW trapstreet.run task to evaluate a given agent/skill/tool -- the reverse of trapstreet-solution-scaffold (which builds a solution against an existing task). Generates the mechanical parts (traptask.yaml, judge.py/grader.py matching the TRAPTASK_MANIFEST contract, build_cases.py's validate-then-render pipeline) and guides the judgment-heavy parts through a structured inter…

Local-only
0
0
Free
Self-run
SKILL MIT 3d ago

Trapstreet Solution Scaffold

>-

netenv
0
0
Free
Self-run
SKILL Apache-2.0 6d ago

Unreal Plugin

Control Unreal Engine Editor via OpenClaw Unreal Plugin. Use for Unreal development tasks including level/actor management, transforms, PIE control, debugging, input simulation, and console commands. Can create/delete actors, save levels, run console commands, simulate input, and capture viewport screenshots and logs — destructive operations should be confirmed with the user. Use only on explicit…

Local-only
0
0
Free
Self-run
SKILL MIT 4d ago

Life Paths

Structured process for mapping realistic long-term life and career paths for a person, grounded in their actual record and finances rather than generic advice. Use this whenever someone asks for help figuring out what to do with their life or career, wants a long-term or phased plan, mentions retirement or FIRE timing alongside career choices, asks whether they could realistically become or achie…

Local-only
0
0
Free
Self-run
SKILL MIT 4d ago

Financial Planning

Build a grounded, verified long-horizon financial plan for a person - accumulation, financial-independence timing, drawdown, and the decision rules to run it by. Use this whenever someone asks when they can retire or go work-optional, wants a FIRE or retirement plan built or reviewed, brings a spreadsheet or planner document to audit, asks about safe withdrawal rates, savings schedules, drawdown…

Local-only
0
0
Free
Self-run
SKILL MIT 4d ago

Writing Axes

Audience-and-goal-first drafting, review, and rewriting for any human-facing prose. Use whenever the user asks to write, rewrite, draft, critique, review, or edit a document, including blog posts, READMEs, papers, emails, docs, runbooks, error messages, release notes, incident reports, announcements, and forum posts. Also use when asked for a title, headline, or subject line, or to check somethin…

Local-only
0
0
Free
Self-run
SKILL MIT yesterday

Huggingface

>

Local-only
0
1
Free
Self-run
SKILL MIT yesterday

Huggingface

>

net
0
0
Free
Self-run
SKILL MIT yesterday

Huggingface

>

net
0
0
Free
Self-run
MCP MIT 3mo ago

Cowork Tasks

The kanban that fills itself in. Watches your email, Slack, meetings, Linear, Jira - reads, writes, and moves cards as work evolves. Open-source, MIT, local-first. Built on Claude Cowork's Live Artifacts.

Local-only
0
1
Free
Self-run
SKILL Apache-2.0 6d ago

Unity Plugin

Control Unity Editor via OpenClaw Unity Plugin. Use for Unity game development tasks including scene management, GameObject/Component manipulation, debugging, input simulation, and Play mode control — including arbitrary C# execution (script.execute) and reflection-based editor calls, which can modify scenes, assets, and settings. Use only in trusted local projects; destructive operations (delete…

net
0
0
Free
Self-run
SKILL MIT 2mo ago

Anti Slop Fr

>

Local-only
0
0
Free
Self-run
SKILL MIT 2d ago

Optimize Prompt

One deliberate rewrite pass that applies Anthropic's current prompt-engineering best practices to an existing draft prompt (SKILL.md, scheduled-task prompt, API/system prompt, one-off task prompt). Use when the user types /optimize-prompt or says "optimize this prompt" / "improve this prompt" / "tune this prompt" / "apply prompt best practices to X". Input is a pasted prompt, @-mentioned file, or…

Local-only
0
0
Free
Self-run
SKILL Apache-2.0 3d ago

Instrument Data To Allotrope

Convert laboratory instrument output files (PDF, CSV, Excel, TXT) to Allotrope Simple Model (ASM) JSON format or flattened 2D CSV. Use this skill when scientists need to standardize instrument data for LIMS systems, data lakes, or downstream analysis. Supports auto-detection of instrument types. Outputs include full ASM JSON, flattened CSV for easy import, and exportable Python code for data engi…

Local-only
0
3
Free
Self-run
SKILL Apache-2.0 3d ago

Start

Set up your bio-research environment and explore available tools. Use when first getting oriented with the plugin, checking which literature, drug-discovery, or visualization MCP servers are connected, or surveying available analysis skills before starting a new project.

Local-only
0
3
Free
Self-run
SKILL Apache-2.0 3d ago

Scientific Problem Selection

This skill should be used when scientists need help with research problem selection, project ideation, troubleshooting stuck projects, or strategic scientific decisions. Use this skill when users ask to pitch a new research idea, work through a project problem, evaluate project risks, plan research strategy, navigate decision trees, or get help choosing what scientific problem to work on. Typical…

Local-only
0
3
Free
Self-run
SKILL Apache-2.0 3d ago

Scvi Tools

Deep learning for single-cell analysis using scvi-tools. This skill should be used when users need (1) data integration and batch correction with scVI/scANVI, (2) ATAC-seq analysis with PeakVI, (3) CITE-seq multi-modal analysis with totalVI, (4) multiome RNA+ATAC analysis with MultiVI, (5) spatial transcriptomics deconvolution with DestVI, (6) label transfer and reference mapping with scANVI/scAr…

Local-only
0
4
Free
Self-run
SKILL Apache-2.0 3d ago

Single Cell Rna Qc

Performs quality control on single-cell RNA-seq data (.h5ad or .h5 files) using scverse best practices with MAD-based filtering and comprehensive visualizations. Use when users request QC analysis, filtering low-quality cells, assessing data quality, or following scverse/scanpy best practices for single-cell analysis.

Local-only
0
4
Free
Self-run
SKILL Apache-2.0 3d ago

Clinical Trial Protocol Skill

Generate clinical trial protocols for medical devices or drugs. This skill should be used when users say "Create a clinical trial protocol", "Generate protocol for [device/drug]", "Help me design a clinical study", "Research similar trials for [intervention]", or when developing FDA submission documentation for investigational products.

Local-only
0
3
Free
Self-run
SKILL MIT 7d ago

Weckr Integration

Helps developers integrate Weckr, an AI cost and margin tracking SDK, into their application. Use this skill when a user is building an AI feature that calls OpenAI, Anthropic, Gemini, or Kimi and wants to track cost, margin, or spending caps per user, or when a user asks about tracking AI costs, agent loop detection, or per user profitability in their SaaS product.

env
0
0
Free
Self-run
SKILL MIT 7d ago

Weckr Model Pricing

Provides current per-token API prices for large language models across OpenAI, Anthropic, Gemini, and Kimi (Moonshot). Use this skill when a user asks what a model costs, how much input or output tokens cost, which model is cheapest for a task, or wants to compare prices between models or providers. Prices are per million tokens and were verified in mid 2026, so always tell the user to confirm ag…

Local-only
0
0
Free
Self-run
SKILL MIT 7d ago

Weckr Cost Estimator

Estimates what an AI feature will cost per call, per user, and per month before it ships. Use this skill when a user is building or planning an LLM feature and asks how much it will cost to run, whether it is affordable at their price point, how a model choice changes cost, or what per user spend to expect. It reads the feature's code or description, estimates token usage, and projects cost using…

Local-only
0
0
Free
Self-run
SKILL MIT 7d ago

Weckr Margin Audit

Audits whether a SaaS product's pricing plans stay profitable once LLM costs are counted. Use this skill when a user wants to know which of their plans lose money, whether flat or unlimited pricing is sustainable, how much AI cost eats into a plan's margin, or whether their price points cover model spend. It compares each plan's price against the AI cost of a typical and a heavy user and flags pl…

Local-only
0
0
Free
Self-run
SKILL MIT 2d ago

Upgrade

Upgrade an existing project's managed llm-wiki structure without rerunning broad wiki bootstrap. Use when a user asks to migrate, update, or upgrade project-local .llm-wiki scripts, hooks, or changelog structure after installing a newer llm-wiki release.

Local-only
0
0
Free
Self-run
SKILL MIT 2d ago

Wiki Bootstrap

Bootstrap an LLM-maintained wiki for the current project from Pi. Use when a Pi user asks to create, initialize, refresh, or configure a project wiki, LLM wiki, QMD wiki, or codebase knowledge base.

Local-only
0
0
Free
Self-run
SKILL MIT 2d ago

Status

Check whether llm-wiki is current, detect newer marketplace or Pi package versions, and suggest or run the right update command for Claude Code, Codex, or Pi. Use when the user asks about llm-wiki version, plugin/package updates, marketplace refresh, upgrade instructions, project context setup, or whether a new llm-wiki release is available.

netfs
0
0
Free
Self-run
SKILL MIT 2d ago

Research

Search QMD-indexed project and main cross-project LLM wikis for past patterns, decisions, solutions, and pitfalls before planning or implementation. Use before feature planning, bug fixing, refactoring, architecture work, or code changes when a project wiki may exist.

Local-only
0
0
Free
Self-run
SKILL MIT 2d ago

Wiki Status

Check llm-wiki install status, version freshness, update commands, and project wiki automation from Pi. Use when a Pi user asks about llm-wiki version, package updates, refresh ownership, context setup, or whether a new llm-wiki release is available.

Local-only
0
0
Free
Self-run
SKILL MIT 2d ago

Wiki Research

Search project and main cross-project LLM wikis from Pi for past patterns, decisions, solutions, and pitfalls before planning or implementation. Use before feature planning, bug fixing, refactoring, architecture work, or code changes when wiki context may exist.

Local-only
0
0
Free
Self-run
SKILL MIT 2d ago

Wiki Upgrade

Upgrade an existing project's managed llm-wiki structure from Pi without rerunning broad bootstrap.

Local-only
0
0
Free
Self-run
SKILL MIT 2d ago

Bootstrap

Bootstrap an LLM-maintained wiki for the current project. Use when a user asks to create, initialize, or refresh a project wiki, LLM wiki, QMD wiki, or codebase knowledge base for Claude Code, Codex, or Pi.

Local-only
0
0
Free
Self-run
SKILL MIT 5d ago

Layerkit Fix From Dry Run

Fix failed integration verification from logs, tests, and docs evidence; edit real package files, no invention.

net
0
0
Free
Self-run
SKILL MIT 5d ago

Layerkit Discover Data Layer

Read customer code for domain events/fields; deny secrets; emit domain_spec proposal with source:code.

netenv
0
0
Free
Self-run
SKILL MIT 5d ago

Layerkit Source Edit Client

Integrate vendors by editing the production datalayer directly; style-match; run the client package verification command.

Local-only
0
0
Free
Self-run
SKILL MIT 5d ago

Layerkit Orchestrate Integration

Master skill — same pipeline for first integrate and contract heal (agent status/next/mark-done).

Local-only
0
0
Free
Self-run
SKILL MIT 5d ago

Layerkit Multi Agent

Coordinate specialist agents for integrate or contract heal; brownfield production code.

Local-only
0
1
Free
Self-run
SKILL MIT 5d ago

Layerkit Privacy Review

Review and update client-owned privacy, consent, hashing, redaction, and egress checks before vendor integration changes ship.

Local-only
0
0
Free
Self-run
SKILL MIT 5d ago

Layerkit Author Map

Draft vendor_map proposal with sources from research evidence; never invent without evidence.

net
0
0
Free
Self-run
SKILL MIT 5d ago

Layerkit Design Flow

Decide the simplest client-owned integration shape from code and vendor evidence; prefer updating existing mappers/adapters.

Local-only
0
0
Free
Self-run
SKILL MIT 5d ago

Layerkit Deletion First

Deletion-first change discipline for Layerkit work. Use before adding code, files, exports, docs, tests, or abstractions; during heal/integration updates; and whenever Codex should prefer modifying or deleting existing code over additive implementation.

Local-only
0
0
Free
Self-run
SKILL MIT 5d ago

Layerkit Research Vendor

Evidence-first vendor research and contract updates (docs/OpenAPI → structured contract → drift vs map); residual human only.

net
0
0
Free
Self-run
SKILL MIT 5d ago

Layerkit Author Processor

Author or update client-side transform/helper code from vendor docs with mandatory citations.

net
0
0
Free
Self-run
SKILL MIT 5d ago

Layerkit Checker Assist

Read-only checker assistant — risk checklist only; never approve, apply, or write checks[].

Local-only
0
0
Free
Self-run
SKILL MIT 5d ago

Layerkit Align Client Style

Analyze existing client package patterns from source evidence; write style notes before source edits.

netenv
0
0
Free
Self-run
SKILL MIT 5d ago

Layerkit Bootstrap

Install Layerkit into the current repo; seed project store + memory; run doctor.

Local-only
0
1
Free
Self-run
SKILL MIT 5d ago

Layerkit Inventory Surfaces

Inventory package languages/surfaces for multi-lang heals; session file used by Layerkit to enforce all languages updated before PR.

Local-only
0
0
Free
Self-run
SKILL MIT 5d ago

Layerkit Session Handoff

Write a runbook to memory so the next agent can resume the integration loop safely.

Local-only
0
0
Free
Self-run
SKILL MIT 5d ago

Layerkit Design Integration

Choose linear map vs flow (route/foreach/if), multi-step, batch; write design decision to memory.

net
0
0
Free
Self-run
SKILL Apache-2.0 3d ago

Analyzing Malware

Analyze suspected malware safely — containment, static triage, sandboxed detonation, unpacking, capability and C2 extraction, IOC production, and YARA rule authoring. Use when handed a suspicious file, hash, or sample, when triaging an alert artifact, or when producing detection content from a specimen.

net
0
1
Free
Self-run
SKILL Apache-2.0 3d ago

Triaging Security Alerts

Work a security alert queue to a defensible disposition — separating true positives from false positives and benign true positives, reasoning about base rates before escalating, ordering enrichment by cheapest discriminator, time-boxing, and documenting negative results so a closed alert is evidence rather than a guess. Use when triaging SOC or EDR alerts, deciding whether an alert warrants incid…

net
0
0
Free
Self-run
SKILL Apache-2.0 3d ago

Investigating M365 Entra

Investigate a Microsoft 365 and Entra ID compromise where the only evidence is cloud logs — the Unified Audit Log, Entra sign-in and audit logs, OAuth app-consent grants, and mailbox inbox/forwarding rules — to reconstruct business email compromise, token and session theft, and consent abuse. Use for a suspected M365/Entra account takeover with no host or memory to image. Preserve the Unified Aud…

Local-only
0
0
Free
Self-run
SKILL Apache-2.0 3d ago

Attacking Active Directory

Attack and enumerate Active Directory environments using Kerberos attacks (Kerberoasting, ASREPRoasting), credential dumping (DCSync, Mimikatz), lateral movement (PtH, PtT), and BloodHound analysis. Use when pentesting Windows domains or exploiting AD misconfigurations.

Local-only
0
0
Free
Self-run
SKILL Apache-2.0 3d ago

Analyzing Phishing Emails

Analyze a reported or suspected phishing email safely — parse the Received chain and Return-Path, validate SPF/DKIM/DMARC alignment, extract and defang URLs and attachments, detonate payloads in a sandbox, and pivot on sender infrastructure to produce IOCs and a disposition. Use when a user-reported email, a mailbox artifact, or a `.eml`/`.msg` needs a verdict. Every link is live until proven oth…

netfs
0
0
Free
Self-run
SKILL Apache-2.0 3d ago

Establishing Persistence

Maintain authorized access across reboots and credential changes during red-team post-exploitation — Windows autostart (Run keys, services, scheduled tasks, WMI subscriptions), Linux (cron, systemd, shell profiles, SSH keys), Active Directory (accounts, DCSync rights, tickets), and cloud identity — chosen least-aggressive first, logged for cleanup, and paired with the detection each leaves. Use p…

Local-only
0
0
Free
Self-run
SKILL Apache-2.0 3d ago

Writing Yara Rules

Author durable YARA detection rules — meta/strings/condition anatomy, string types and modifiers, structural conditions with file magic and offsets, the PE/ELF/math/hash modules, specificity-vs-durability tuning, atom-aware performance, memory and process scanning, and YARA-X. Use when writing a YARA rule, creating a signature for a malware family or a file/memory artifact, turning IOCs or a capt…

net
0
0
Free
Self-run
SKILL Apache-2.0 3d ago

Cracking Passwords

Crack password hashes using hashcat/john, perform password spraying, brute force authentication, and execute pass-the-hash attacks. Use when cracking credentials or performing password-based attacks.

Local-only
0
0
Free
Self-run
SKILL Apache-2.0 3d ago

Escalating Windows Privileges

Escalate privileges on Windows systems using service misconfigurations, DLL hijacking, token manipulation, UAC bypasses, registry exploits, and credential dumping. Use when performing Windows post-exploitation or privilege escalation.

Local-only
0
0
Free
Self-run
SKILL Apache-2.0 3d ago

Orchestrating Vulnerability Research

Run a sustained, multi-agent vulnerability-discovery campaign against a target — split its attack surface into slices, hunt each slice with a builder agent, and have a separate critic with fresh context adversarially refute every candidate against the real artifact (a reproduced crash, a working request, a proven bypass) before it counts as a finding. Use when tasked to find previously-unknown bu…

Local-only
0
0
Free
Self-run
SKILL Apache-2.0 3d ago

Managing Vulnerabilities

Prioritize and drive remediation of a vulnerability backlog by real risk, not raw CVSS — combining severity with exploitation signals (EPSS, CISA KEV), asset exposure and business context, using SSVC-style decisions, distinguishing reachable from merely present, and tracking remediation and exceptions. Use when triaging scanner output, deciding what to patch first, building a risk-based vulnerabi…

net
0
0
Free
Self-run
SKILL Apache-2.0 3d ago

Performing Social Engineering

Run authorized social-engineering assessments — pretext development from OSINT, phishing and spearphishing campaigns (Gophish), vishing and smishing, and physical pretexting — to measure the human attack surface and produce awareness-driving metrics. Use when the engagement scope explicitly authorizes testing people, with organizational sign-off and HR/legal coordination. You are testing a consen…

Local-only
0
0
Free
Self-run
SKILL Apache-2.0 3d ago

Mapping Attack Techniques

Navigate security work by MITRE ATT&CK tactic and technique — resolve a technique ID or name to the right skill, map a threat intel report or adversary emulation plan to procedures, and run the purple-team loop from technique to detection to validation. Use when a request names an ATT&CK ID like T1003.001, a tactic like lateral movement, an APT group or intel report, or when planning coverage aga…

net
0
0
Free
Self-run
SKILL Apache-2.0 3d ago

Engineering Detections

Build, test, and tune detection content — Sigma, YARA, Suricata, and EDR/SIEM queries — mapped to MITRE ATT&CK with explicit false-positive analysis and detection-as-code practices. Use when writing or reviewing a detection rule, converting IOCs or TTPs into alerts, measuring detection coverage, or reducing alert fatigue.

net
0
0
Free
Self-run
SKILL Apache-2.0 3d ago

Testing Ics Ot Protocols

Safely assess industrial control system and OT networks and their protocols (Modbus, DNP3, S7comm, EtherNet/IP-CIP, OPC UA, IEC 60870-5-104, BACnet) using a passive-first, safety-gated methodology aligned to the Purdue model and IEC 62443. Use when mapping an OT network, evaluating IT/OT segmentation and zone/conduit rules, or inventorying industrial assets — where a probe that is routine on IT c…

net
0
0
Free
Self-run
SKILL Apache-2.0 3d ago

Reviewing Cryptography

Review cryptographic implementations and protocol usage for misuse — weak primitives, nonce and IV handling, key management, authentication of ciphertext, randomness, timing side channels, TLS and JWT configuration, and password storage. Use when auditing code that encrypts, signs, hashes, or authenticates, or when assessing TLS and token configurations.

net
0
1
Free
Self-run
SKILL Apache-2.0 3d ago

Producing Threat Intelligence

Turn raw observations, extracted IOCs, and open sources into finished threat intelligence — running the intelligence cycle (direction, collection, processing, analysis, dissemination, feedback), enriching and grading indicators, pivoting on TTPs over atomic IOCs, structuring attribution with calibrated confidence, and packaging tactical/operational/strategic products with TLP and sourcing. Use wh…

net
0
0
Free
Self-run
SKILL Apache-2.0 3d ago

Writing Sigma Rules

Author and maintain Sigma detection rules — structure, logsource taxonomy, detection logic with modifiers, false-positive filtering, backend conversion with pySigma, and offline validation with Hayabusa or Chainsaw. Use when translating threat intel into vendor-agnostic detection logic, building a detection-as-code pipeline around Sigma, reviewing or tuning existing Sigma rules, or converting rul…

net
0
0
Free
Self-run
SKILL Apache-2.0 3d ago

Testing Web Applications

Test web applications for security vulnerabilities including SQLi, XSS, command injection, JWT attacks, SSRF, file uploads, XXE, and API flaws. Use when pentesting web apps, analyzing authentication, or exploiting OWASP Top 10 vulnerabilities.

net
0
0
Free
Self-run
SKILL Apache-2.0 3d ago

Attacking Wireless Networks

Attack WiFi networks using WPA/WPA2 cracking, WPS exploitation, Evil Twin attacks, deauthentication, and wireless reconnaissance. Use when pentesting wireless networks or performing WiFi security assessments.

Local-only
0
1
Free
Self-run
SKILL Apache-2.0 3d ago

Threat Modeling

Systematic threat modeling skill for applications, APIs, and systems using STRIDE, PASTA, Attack Trees, DREAD, LINDDUN, and OCTAVE. Use when assessing security architecture, creating data flow diagrams (Mermaid), enumerating threats from OpenAPI specs or architecture docs, building attack trees, mapping threats to NIST/CIS/OWASP ASVS controls, or producing a threat model report. Triggers on reque…

Local-only
0
0
Free
Self-run
SKILL Apache-2.0 3d ago

Auditing Mcp Servers

Audit a Model Context Protocol server's own implementation for how it can subvert or exfiltrate from the agent that connects to it — tool-description injection (tool poisoning), tool shadowing and rug pulls, per-tool authorization and input schemas, SSRF via URL-fetching tools, transport and authentication exposure, secrets handling, and toxic tool-flow combinations. Use when the MCP server imple…

net
0
0
Free