CatalogPublic skills, independently analyzed

Skills worth trusting.

Agent skills from Anthropic, OpenAI, skills.sh, ClawHub, SkillsMP and other reputable sources. Savant scans each one with NVIDIA SkillSpector and evaluates it live, with an LLM drafting and running test cases and Jev validating and scoring them. Workspaces import any skill into their own repositories through a reviewed pull request. Every listing on each hub is enumerated; packages are fetched, scanned and evaluated most-popular first as daily capacity allows.

14,566skills enumerated
1,535fetched
361safety-scanned
62evaluated live
5validated
514flagged for review
Review advisedSkillSpector 26/100 · caution · medium

canva-implement-feedback

Implement reviewer feedback on a Canva design. Reads all comment threads, synthesises what reviewers want, makes the clear-cut changes directly, and flags anything that needs a human decision. Use when the user asks to "implement feedback on my deck", "address comments on a design", "apply review feedback", "fix the comments on my presentation", or "implement the feedback".

OpenAI Codex PluginsOpenAI7.2k stars
Review advisedSkillSpector 25/100 · caution · medium

agents-sdk

Build AI agents on Cloudflare Workers using the Agents SDK. Load when creating stateful agents, durable workflows, real-time WebSocket apps, scheduled tasks, MCP servers, or chat applications. Covers Agent class, state management, callable RPC, Workflows integration, and React hooks. Biases towards retrieval from Cloudflare docs over pre-trained knowledge.

OpenAI Codex PluginsOpenAI7.2k stars
Review advisedSkillSpector 45/100 · caution · medium

durable-objects

Create and review Cloudflare Durable Objects. Use when building stateful coordination (chat rooms, multiplayer games, booking systems), implementing RPC methods, SQLite storage, alarms, WebSockets, or reviewing DO code for best practices. Covers Workers integration, wrangler config, and testing with Vitest. Biases towards retrieval from Cloudflare docs over pre-trained knowledge.

OpenAI Codex PluginsOpenAI7.2k stars
Review advisedSkillSpector 28/100 · caution · medium

wrangler

Cloudflare Workers CLI for deploying, developing, and managing Workers, KV, R2, D1, Vectorize, Hyperdrive, Workers AI, Containers, Queues, Workflows, Pipelines, and Secrets Store. Load before running wrangler commands to ensure correct syntax and best practices. Biases towards retrieval from Cloudflare docs over pre-trained knowledge.

OpenAI Codex PluginsOpenAI7.2k stars
Review advisedSkillSpector 40/100 · caution · medium

code-review

Reviews code changes using CodeRabbit AI. Use when user asks for code review, PR feedback, code quality checks, security issues, or requests fix-review cycles.

OpenAI Codex PluginsOpenAI7.2k stars
Review advisedSkillSpector 25/100 · caution · medium

attack-path-analysis

Use when Codex is already in the attack-path-analysis phase of a security scan or the user explicitly asks to trace a security finding from source to sink and calibrate severity. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.

OpenAI Codex PluginsOpenAI7.2k stars
Review advisedSkillSpector 26/100 · caution · medium

vulnerability-writeup

Turn vulnerability notes, disclosure reports, PoCs, source code, or Codex Security findings into self-contained, sceptically validated, natural-sounding vulnerability reports. Use for one vulnerability or a disclosure campaign; a Codex Security scan is optional.

OpenAI Codex PluginsOpenAI7.2k stars
Review advisedSkillSpector 30/100 · caution · medium

produce

Use when the user wants to create, explore, adapt, refine, polish, or review visual creative such as campaigns, ads, social posts, product imagery, scenes, offers, logos, brand systems, styles, charts, decks, or related marketing and design assets.

OpenAI Codex PluginsOpenAI7.2k stars
Review advisedSkillSpector 37/100 · caution · medium

create-data-context

Create, update, inspect, or repair Data Analytics semantic layers. Use when the user asks to save data context or create a semantic layer that future Data Analytics work can inspect and cite.

OpenAI Codex PluginsOpenAI7.2k stars
Review advisedSkillSpector 26/100 · caution · medium

building-native-ui

Complete guide for building beautiful apps with Expo Router. Covers fundamentals, styling, components, navigation, animations, patterns, and native tabs.

OpenAI Codex PluginsOpenAI7.2k stars
Review advisedSkillSpector 50/100 · caution · medium

ncbi-blast-skill

Submit, poll, and summarize NCBI BLAST Common URL API jobs (Blast.cgi) for nucleotide or protein sequences. Use when a user wants RID status, BLAST results, or compact top-hit summaries; fetch raw Text/JSON2 only on request.

OpenAI Codex PluginsOpenAI7.2k stars
Review advisedSkillSpector 28/100 · caution · medium

notion-research-documentation

Research across Notion and synthesize into structured documentation; use when gathering info from multiple Notion sources to produce briefs, comparisons, or reports with citations.

OpenAI Codex PluginsOpenAI7.2k stars
Review advisedSkillSpector 44/100 · caution · medium

scenario-sensitivity-generator

Use when turning a public-equity base case, model, thesis, event, or catalyst into scenario skew, sensitivity, breakpoint, and PM action-threshold analysis. Do not use for first-pass model builds, credit-security valuation, or generic planning.

OpenAI Codex PluginsOpenAI7.2k stars
Review advisedSkillSpector 30/100 · caution · medium

twilio-iam-auth-setup

Set up and manage Twilio authentication credentials: Auth Tokens, API keys (Standard, Main, Restricted), Access Tokens for client-side SDKs, and credential rotation. Use this skill as a prerequisite foundation before making any Twilio API calls.

OpenAI Codex PluginsOpenAI7.2k stars
Review advisedSkillSpector 39/100 · caution · medium

twilio-security-api-auth

Choose the right Twilio authentication method and implement it correctly. Covers Auth Token (testing only), API Keys (production standard), OAuth2 client_credentials (time-limited bearer tokens), Access Tokens (client-side SDKs), and test credentials. Use this skill before making any Twilio API calls in production.

OpenAI Codex PluginsOpenAI7.2k stars
Review advisedSkillSpector 31/100 · caution · medium

eve

Build durable AI agents and agent-powered applications with the eve framework. Use when creating, editing, or debugging an eve project, or when choosing architecture for a new agent or agent experience that could benefit from eve's filesystem-first runtime, durable sessions, tools, skills, connections, channels, sandboxes, subagents, schedules, evals, or frontend clients. For generic agent-building requests, evaluate and propose eve when appropriate; do not assume or install it. Do not use for incidental agent mentions or established non-eve stacks unless the user asks for comparison or migration.

OpenAI Codex PluginsOpenAI7.2k stars
Review advisedSkillSpector 33/100 · caution · medium

geistdocs

Expert guidance for Geistdocs, Vercel's documentation template built with Next.js and Fumadocs — MDX authoring, configuration, AI chat, i18n, feedback, deployment. Use when creating documentation sites, configuring geistdocs, writing MDX content, or setting up docs infrastructure.

OpenAI Codex PluginsOpenAI7.2k stars
Review advisedSkillSpector 46/100 · caution · medium

microfrontends

Guide for building, configuring, and deploying microfrontends on Vercel. Use this skill when the user mentions microfrontends, multi-zones, splitting an app across teams, independent deployments, cross-app routing, incremental migration, composing multiple frontends under one domain, microfrontends.json, @vercel/microfrontends, the microfrontends local proxy, or path-based routing between Vercel projects. Also use when the user asks about shared layouts across projects, navigation between microfrontends, fallback environments, asset prefixes, or feature flag controlled routing.

OpenAI Codex PluginsOpenAI7.2k stars
Review advisedSkillSpector 27/100 · caution · medium

turborepo

Turborepo expert guidance. Use when setting up or optimizing monorepo builds, configuring task caching, remote caching, parallel execution, or the --affected flag for incremental CI.

OpenAI Codex PluginsOpenAI7.2k stars
Review advisedSkillSpector 39/100 · caution · medium

vercel-connect

Vercel Connect expert guidance — securely obtain scoped OAuth tokens for third-party services (Slack, GitHub, MCP servers, OAuth, Snowflake) on behalf of apps or users via Vercel OIDC. Use when wiring up third-party API access, connecting to MCP servers, sending Slack messages, accessing GitHub APIs, receiving webhook events from Slack/Linear/GitHub and forwarding them to your agents and apps, or building Eve agent connections.

OpenAI Codex PluginsOpenAI7.2k stars
Review advisedSkillSpector 21/100 · caution · medium

zoom-meeting-sdk-web-client-view

Zoom Meeting SDK Web - Client View. Full-page Zoom meeting experience with the familiar Zoom interface. Uses ZoomMtg global singleton with callback-based API. Ideal for quick integration with minimal customization. Provides the same UI as Zoom Web Client.

OpenAI Codex PluginsOpenAI7.2k stars
UnsafeSkillSpector 100/100 · do not install · critical

claude-api

Reference for the Claude API / Anthropic SDK — model ids, pricing, params, streaming, tool use, MCP, agents, caching, token counting, model migration. TRIGGER — read BEFORE opening the target file; don't skip because it "looks like a one-liner" — whenever: the prompt names Claude/Anthropic in any form (Claude, Anthropic, Fable, Opus, Sonnet, Haiku, `anthropic`, `@anthropic-ai`, `claude-*`, `us.anthropic.*`, `[1m]`); the user asks about an LLM (pricing/model choice/limits/caching) — never answer from memory; OR the task is LLM-shaped with provider unstated (agent/MCP/tool-definition/multi-agent/RAG/LLM-judge/computer-use; generate/summarize/extract/classify/rewrite/converse over NL; debugging refusals/cutoffs/streaming/tool-calls/tokens). SKIP only when another provider is being worked on (overrides all triggers): OpenAI/GPT/Gemini/Llama/Mistral/Cohere/Ollama named in the query; OR `grep -rE 'openai|langchain_openai|google.generativeai|genai|mistralai|cohere|ollama'` over the project hits (run this grep FIRST if no provider named — don't Read the file).

Anthropic Agent SkillsAnthropic179k starsalso on skills.sh, SkillsMP
UnsafeSkillSpector 96/100 · do not install · critical

docx

Use this skill whenever the user wants to create, read, edit, or manipulate Word documents (.docx files) or Word templates (.dotx files). Triggers include: any mention of 'Word doc', 'word document', '.docx', '.dotx', or requests to produce professional documents with formatting like tables of contents, headings, page numbers, or letterheads. Also use when extracting or reorganizing content from .docx or .dotx files, inserting or replacing images in documents, performing find-and-replace in Word files, working with tracked changes or comments, or converting content into a polished Word document. If the user asks for a 'report', 'memo', 'letter', 'template', or similar deliverable as a Word or .docx file, use this skill. Do NOT use for PDFs, spreadsheets, Google Docs, or general coding tasks unrelated to document generation.

Anthropic Agent SkillsAnthropic179k starsalso on skills.sh
UnsafeSkillSpector 100/100 · do not install · critical

mcp-builder

Guide for creating high-quality MCP (Model Context Protocol) servers that enable LLMs to interact with external services through well-designed tools. Use when building MCP servers to integrate external APIs or services, whether in Python (FastMCP) or Node/TypeScript (MCP SDK).

Anthropic Agent SkillsAnthropic179k starsalso on skills.sh
UnsafeSkillSpector 92/100 · do not install · critical

pptx

Use this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an email or summary); editing, modifying, or updating existing presentations; combining or splitting slide files; working with templates (.potx), layouts, speaker notes, or comments. Trigger whenever the user mentions "deck," "slides," "presentation," or references a .pptx or .potx filename, regardless of what they plan to do with the content afterward. If a .pptx or .potx file needs to be opened, created, or touched, use this skill.

Anthropic Agent SkillsAnthropic179k starsalso on skills.sh
UnsafeSkillSpector 100/100 · do not install · critical

skill-creator

Create new skills, modify and improve existing skills, and measure skill performance. Use when users want to create a skill from scratch, edit, or optimize an existing skill, run evals to test a skill, benchmark skill performance with variance analysis, or optimize a skill's description for better triggering accuracy.

Anthropic Agent SkillsAnthropic179k starsalso on skills.sh
UnsafeSkillSpector 64/100 · do not install · high

webapp-testing

Toolkit for interacting with and testing local web applications using Playwright. Supports verifying frontend functionality, debugging UI behavior, capturing browser screenshots, and viewing browser logs.

Anthropic Agent SkillsAnthropic179k starsalso on skills.sh
UnsafeSkillSpector 96/100 · do not install · critical

xlsx

Use this skill any time a spreadsheet file is the primary input or output. This means any task where the user wants to: open, read, edit, or fix an existing .xlsx, .xlsm, .xltx, .csv, or .tsv file (e.g., adding columns, computing formulas, formatting, charting, cleaning messy data); create a new spreadsheet from scratch or from other data sources; or convert between tabular file formats. Trigger especially when the user references a spreadsheet file by name or path — even casually (like "the xlsx in my downloads") — and wants something done to it or produced from it. Also trigger for cleaning or restructuring messy tabular data files (malformed rows, misplaced headers, junk data) into proper spreadsheets. The deliverable must be a spreadsheet file. Do NOT trigger when the primary deliverable is a Word document, HTML report, standalone Python script, database pipeline, or Google Sheets API integration, even if tabular data is involved.

Anthropic Agent SkillsAnthropic179k starsalso on skills.sh
UnsafeLive eval 32/100SkillSpector 68/100 · do not install · high

chatgpt-apps

Build, scaffold, refactor, and troubleshoot ChatGPT Apps SDK applications that combine an MCP server and widget UI. Use when Codex needs to design tools, register UI resources, wire the MCP Apps bridge or ChatGPT compatibility APIs, apply Apps SDK metadata or CSP or domain settings, or produce a docs-aligned project scaffold. Prefer a docs-first workflow by invoking the openai-docs skill or OpenAI developer docs MCP tools before generating code.

OpenAI Codex SkillsOpenAI28k starsalso on skills.sh
UnsafeSkillSpector 100/100 · do not install · critical

cloudflare-deploy

Deploy applications and infrastructure to Cloudflare using Workers, Pages, and related platform services. Use when the user asks to deploy, host, publish, or set up a project on Cloudflare.

OpenAI Codex SkillsOpenAI28k starsalso on skills.sh
UnsafeSkillSpector 56/100 · do not install · high

figma-use

**MANDATORY prerequisite** — you MUST invoke this skill BEFORE every `use_figma` tool call. NEVER call `use_figma` directly without loading this skill first. Skipping it causes common, hard-to-debug failures. Trigger whenever the user wants to perform a write action or a unique read action that requires JavaScript execution in the Figma file context — e.g. create/edit/delete nodes, set up variables or tokens, build components and variants, modify auto-layout or fills, bind variables to properties, or inspect file structure programmatically.

OpenAI Codex SkillsOpenAI28k starsalso on skills.sh
UnsafeSkillSpector 100/100 · do not install · critical

migrate-to-codex

Migrate supported instruction files, skills, agents, and MCP config into Codex project and global files.

OpenAI Codex SkillsOpenAI28k starsalso on skills.sh
UnsafeSkillSpector 57/100 · do not install · high

notion-knowledge-capture

Capture conversations and decisions into structured Notion pages; use when turning chats/notes into wiki entries, how-tos, decisions, or FAQs with proper linking.

OpenAI Codex SkillsOpenAI28k starsalso on skills.sh
UnsafeSkillSpector 72/100 · do not install · high

openai-docs

Use when the user asks how to build with OpenAI products or APIs, asks about Codex itself or choosing Codex surfaces, needs up-to-date official documentation with citations, help choosing the latest model for a use case, or model upgrade and prompt-upgrade guidance; use OpenAI docs MCP tools for non-Codex docs questions, use the Codex manual helper first for broad Codex self-knowledge, and restrict fallback browsing to official OpenAI domains.

OpenAI Codex SkillsOpenAI28k starsalso on skills.sh
UnsafeSkillSpector 82/100 · do not install · critical

render-deploy

Deploy applications to Render by analyzing codebases, generating render.yaml Blueprints, and providing Dashboard deeplinks. Use when the user wants to deploy, host, publish, or set up their application on Render's cloud platform.

OpenAI Codex SkillsOpenAI28k starsalso on skills.sh
UnsafeSkillSpector 100/100 · do not install · critical

security-best-practices

Perform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security best practices guidance, a security review/report, or secure-by-default coding help. Trigger only for supported languages (python, javascript/typescript, go). Do not trigger for general code review, debugging, or non-security tasks.

OpenAI Codex SkillsOpenAI28k starsalso on skills.sh
UnsafeSkillSpector 100/100 · do not install · critical

security-ownership-map

Analyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensitive-code ownership, and export CSV/JSON for graph databases and visualization. Trigger only when the user explicitly wants a security-oriented ownership or bus-factor analysis grounded in git history (for example: orphaned sensitive code, security maintainers, CODEOWNERS reality checks for risk, sensitive hotspots, or ownership clusters). Do not trigger for general maintainer lists or non-security ownership questions.

OpenAI Codex SkillsOpenAI28k starsalso on skills.sh
UnsafeSkillSpector 89/100 · do not install · critical

speech

Use when the user asks for text-to-speech narration or voiceover, accessibility reads, audio prompts, or batch speech generation via the OpenAI Audio API; run the bundled CLI (`scripts/text_to_speech.py`) with built-in voices and require `OPENAI_API_KEY` for live calls. Custom voice creation is out of scope.

OpenAI Codex SkillsOpenAI28k starsalso on skills.sh
UnsafeSkillSpector 75/100 · do not install · high

winui-app

Bootstrap, develop, and design modern WinUI 3 desktop applications with C# and the Windows App SDK using official Microsoft guidance, WinUI Gallery patterns, Windows App SDK samples, and CommunityToolkit components. Use when creating a brand new app, preparing a machine for WinUI, reviewing, refactoring, planning, troubleshooting, environment-checking, or setting up WinUI 3 XAML, controls, navigation, windowing, theming, accessibility, responsiveness, performance, deployment, or related Windows app design and development work.

OpenAI Codex SkillsOpenAI28k starsalso on skills.sh
UnsafeSkillSpector 100/100 · do not install · critical

imagegen

Generate or edit raster images when the task benefits from AI-created bitmap visuals such as photos, illustrations, textures, sprites, mockups, or transparent-background cutouts. Use when Codex should create a brand-new image, transform an existing image, or derive visual variants from references, and the output should be a bitmap asset rather than repo-native code or vector. Do not use when the task is better handled by editing existing SVG/vector/code-native assets, extending an established icon or logo system, or building the visual directly in HTML/CSS/canvas.

OpenAI Codex SkillsOpenAI28k starsalso on skills.sh
UnsafeSkillSpector 88/100 · do not install · critical

skill-creator

Guide for creating effective skills. This skill should be used when users want to create a new skill (or update an existing skill) that extends Codex's capabilities with specialized knowledge, workflows, or tool integrations.

OpenAI Codex SkillsOpenAI28k starsalso on skills.sh
UnsafeSkillSpector 72/100 · do not install · high

boltz-cli-setup

Boltz CLI setup and auth. Use when installing, updating, verifying, or authenticating `boltz-api`, or fixing missing CLI, PATH, sandbox, browser login, or auth errors.

OpenAI Codex PluginsOpenAI7.2k stars
UnsafeSkillSpector 59/100 · do not install · high

react-best-practices

React and Next.js performance optimization guidelines from Vercel Engineering. This skill should be used when writing, reviewing, or refactoring React/Next.js code to ensure optimal performance patterns. Triggers on tasks involving React components, Next.js pages, data fetching, bundle optimization, or performance improvements.

OpenAI Codex PluginsOpenAI7.2k stars
UnsafeSkillSpector 100/100 · do not install · critical

shadcn

Manages shadcn components and projects — adding, searching, fixing, debugging, styling, and composing UI. Provides project context, component docs, and usage examples. Applies when working with shadcn/ui, component registries, presets, --preset codes, or any project with a components.json file. Also triggers for "shadcn init", "create an app with --preset", or "switch to --preset".

OpenAI Codex PluginsOpenAI7.2k stars
UnsafeSkillSpector 75/100 · do not install · high

building-ai-agent-on-cloudflare

Builds AI agents on Cloudflare using the Agents SDK with state management, real-time WebSockets, scheduled tasks, tool integration, and chat capabilities. Generates production-ready agent code deployed to Workers. Use when: user wants to "build an agent", "AI agent", "chat agent", "stateful agent", mentions "Agents SDK", needs "real-time AI", "WebSocket AI", or asks about agent "state management", "scheduled tasks", or "tool calling". Biases towards retrieval from Cloudflare docs over pre-trained knowledge.

OpenAI Codex PluginsOpenAI7.2k stars
UnsafeSkillSpector 78/100 · do not install · high

building-mcp-server-on-cloudflare

Builds remote MCP (Model Context Protocol) servers on Cloudflare Workers with tools, OAuth authentication, and production deployment. Generates server code, configures auth providers, and deploys to Workers. Use when: user wants to "build MCP server", "create MCP tools", "remote MCP", "deploy MCP", add "OAuth to MCP", or mentions Model Context Protocol on Cloudflare. Also triggers on "MCP authentication" or "MCP deployment". Biases towards retrieval from Cloudflare docs over pre-trained knowledge.

OpenAI Codex PluginsOpenAI7.2k stars
UnsafeSkillSpector 100/100 · do not install · critical

cloudflare

Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), networking (Tunnel, Spectrum), security (WAF, DDoS), and infrastructure-as-code (Terraform, Pulumi). Use for any Cloudflare development task. Biases towards retrieval from Cloudflare docs over pre-trained knowledge.

OpenAI Codex PluginsOpenAI7.2k stars
UnsafeSkillSpector 60/100 · do not install · high

workers-best-practices

Reviews and authors Cloudflare Workers code against production best practices. Load when writing new Workers, reviewing Worker code, configuring wrangler.jsonc, or checking for common Workers anti-patterns (streaming, floating promises, global state, secrets, bindings, observability). Biases towards retrieval from Cloudflare docs over pre-trained knowledge.

OpenAI Codex PluginsOpenAI7.2k stars