The secure, validated skill registry for professional AI coding agents
In an ecosystem where over 13% of marketplace skills contain critical vulnerabilities, Agent Skills stands apart as a hardened library of verified, tested, and safe capabilities. Extend Antigravity, Claude Code, Cursor, and more with absolute confidence.
https://tech-leads-club.github.io/agent-skills/
- β¨ What are Skills?
- π‘οΈ Security & Trust
- π€ Supported Agents
- π Featured Skills
- π Quick Start
- β‘ How It Works
- π For Contributors
- π Project Structure
- π Skill Structure
- π Security Scan
- π Release Process
- π€ Contributing
- π License
Skills are packaged instructions and resources that extend AI agent capabilities. Think of them as plugins for your AI assistant β they teach your agent new workflows, patterns, and specialized knowledge.
packages/skills-catalog/skills/
(category-name)/
skill/
SKILL.md β Main instructions
templates/ β File templates
references/ β On-demand documentation
Your environment's safety is our top priority. Unlike open marketplaces where 13.4% of skills contain critical issues, agent-skills is a managed, hardened library.
We directly address the threats identified in the Snyk 2026 Agent Threat Report:
| Threat | Public Marketplaces | Agent Skills Guarantee |
|---|---|---|
| Malicious Payloads | Obfuscated code, binaries, or "black box" instructions | 100% Open Source: No binaries, fully readable text/code. Every line is auditable. |
| Credential Theft | Skills silently exfiltrating env vars to remote servers | Static Analysis: CI/CD pipeline blocks skills with suspicious network calls or secret access. |
| Supply Chain Attacks | Authors pushing malicious updates to existing skills | Immutable Integrity: Lockfiles and content-hashing ensure code never changes without your explicit upgrade. |
| Prompt Injection | Hidden instructions to hijack agent behavior ("jailbreaks") | Human Curation: Every prompt is manually code-reviewed by maintainers for safety boundaries. |
The installer itself implements strict technical controls:
- Filesystem Isolation: Recursive path traversal protection preventing access outside target directories.
- Input Sanitization: Strict validation of skill names and paths to neutralize injection vectors.
- Symlink Guard: Safe handling of symbolic links to prevent aliasing attacks.
- Integrity Verification: Lockfile-based validation ensuring reproducible and authorized skill management.
- Automated Auditing: All skills undergo continuous security scanning with mcp-scan.
Install skills to any of these AI coding agents:
| Tier 1 (Popular) | Tier 2 (Rising) | Tier 3 (Enterprise) |
|---|---|---|
| Claude Code | Aider | Amazon Q |
| Cline | Antigravity | Augment |
| Cursor | Gemini CLI | Droid (Factory.ai) |
| GitHub Copilot | Kilo Code | OpenCode |
| Windsurf | Kiro | Sourcegraph Cody |
| OpenAI Codex | Tabnine | |
| Roo Code | ||
| TRAE |
Missing your favorite agent? Open an issue and we'll add support!
A glimpse of what's available in our growing catalog:
| Skill | Category | Description |
|---|---|---|
| tlc-spec-driven | Development | Project and feature planning with 4 phases: Specify β Design β Tasks β Implement. Creates atomic tasks with verification criteria and maintains persistent memory across sessions. |
| aws-advisor | Cloud | Expert AWS Cloud Advisor for architecture design, security review, and implementation guidance. Leverages AWS MCP tools for documentation-backed answers. |
| playwright-skill | Automation | Complete browser automation with Playwright. Test pages, fill forms, take screenshots, validate UX, and automate any browser task. |
| figma | Design | Fetch design context from Figma and translate nodes into production code. Design-to-code implementation with MCP integration. |
| security-best-practices | Security | Language and framework-specific security reviews. Detect vulnerabilities, generate reports, and suggest secure-by-default fixes. |
npx @tech-leads-club/agent-skillsThis launches an interactive wizard:
- Choose Action β "Install skills" or "Update installed skills"
- Browse & Select β Filter by category or search
- Choose agents β Pick target agents (Cursor, Claude Code, etc.)
- Installation method β Copy (recommended) or Symlink
- Scope β Global (user home) or Local (project only)
Each step shows a β Back option to return and revise your choices.
Note: You can use either
npx @tech-leads-club/agent-skillsor install globally and useagent-skillsdirectly.
# Interactive mode (default)
npx @tech-leads-club/agent-skills
# or: agent-skills (if installed globally)
# List available skills
agent-skills list
agent-skills ls # Alias
# Install one skill
agent-skills install -s tlc-spec-driven
# Install multiple skills at once
agent-skills install -s aws-advisor coding-guidelines docs-writer
# Install to specific agents
agent-skills install -s my-skill -a cursor claude-code
# Install multiple skills to multiple agents
agent-skills install -s aws-advisor nx-workspace -a cursor windsurf cline
# Install globally (to ~/.gemini, ~/.claude, etc.)
agent-skills install -s my-skill -g
# Use symlink instead of copy
agent-skills install -s my-skill --symlink
# Force re-download (bypass cache)
agent-skills install -s my-skill --force
# Update a specific skill
agent-skills update -s my-skill
# Update all installed skills
agent-skills update
# Remove one skill
agent-skills remove -s my-skill
# Remove multiple skills at once
agent-skills remove -s skill1 skill2 skill3
agent-skills rm -s my-skill # Alias
# Remove from specific agents
agent-skills remove -s my-skill -a cursor windsurf
# Force removal (bypass lockfile check)
agent-skills remove -s my-skill --force
# Manage cache
agent-skills cache --clear # Clear all cache
agent-skills cache --clear-registry # Clear only registry
agent-skills cache --path # Show cache location
# View audit log
agent-skills audit # Show recent operations
agent-skills audit -n 20 # Show last 20 entries
agent-skills audit --path # Show audit log location
# Show contributors and credits
agent-skills credits
# Show help
agent-skills --helpnpm install -g @tech-leads-club/agent-skills
agent-skills # Use 'agent-skills' instead of 'npx @tech-leads-club/agent-skills'The CLI fetches skills on-demand from our CDN:
- Browse β The CLI fetches the skills catalog (~45KB)
- Select β You choose the skills you need
- Download β Selected skills are downloaded and cached locally
- Install β Skills are installed to your agent's configuration
Downloaded skills are cached in ~/.cache/agent-skills/ for offline use.
# Clear the cache
rm -rf ~/.cache/agent-skillsWe welcome contributions! Please see our CONTRIBUTING.md file for detailed guidelines on how to set up your local environment, create new skills, contribute to the marketplace, and follow our release processes.
This repository is a collection of curated skills intended to benefit the community. We deeply respect the intellectual property and wishes of all creators.
If you are the author of any content included here and would like it removed or updated, please open an issue or contact the maintainers.
- Software Engine: The application source code (CLI, scripts, tools) is licensed under the MIT License.
- Tech Leads Club Skills: Unless otherwise stated, all skill files (
SKILL.md) authored by the repository maintainers are licensed under the Creative Commons Attribution 4.0 International License (CC-BY-4.0). - Third-Party Skills: Some skills included in this catalog are created by the community or original authors. These skills retain their original licenses and copyrights. Please check the individual
SKILL.mdfiles for specific licensing and author attribution.
If you use our skills catalog, you must provide attribution to Tech Leads Club, regardless of how it is used.
Built with β€οΈ by the Tech Leads Club community
