skills — security grade SAFE, quality 73/100

Security audit verdict: SAFE · quality 73/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by semgrep · Agent Tool · ★ 262

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is skills safe to install? View the security audit →

About skills

Agent Skills [Beta] A collection of skills for AI coding agents. Skills are packaged instructions and scripts that extend agent capabilities. This should be considered beta-level software; it's primarily generated by transforming open-source Semgrep rules into skill format. Skills follow the Agent Skills format. Installation Available Skills code-security Comprehensive code security guidelines from Semgrep Engineering covering OWASP Top 10, infrastructure security, and secure coding best practices across 15+ languages. Use when: Writing new code Reviewing code for security vulnerabilities Asking about secure coding practices Configuring cloud infrastructure (Terraform, Kubernetes, Docker) Categories covered: Memory Saf

agentsclaude-codesecurityskills

Quick Facts

Stars262
Forks28
LanguageJavaScript
CategoryAgent Tool
Quality Score73.3546593553767/100
Open Issues6
Last Updated2026-07-28
Created2026-01-15
Platformsclaude-code, node
Est. Tokens~14k

skills alternative? Top 6 similar tools

Looking for a skills alternative? If you're comparing skills with other agent tool tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • JoySafeter by jd-opensource · ⭐ 300

    🚀 JoySafeter: An enterprise AI Agent Platform—Not just chatting. building、running、testing, and tracing autono

  • orchestkit by yonatangross · ⭐ 283

    The Complete AI Development Toolkit for Claude Code. 106 skills, 36 agents, 171 hooks. Install `ork` for stabl

  • SecOpsAgentKit by AgentSecOps · ⭐ 184

    Security operations toolkit for AI coding agents. Give Claude Code 25+ skills to catch vulnerabilities, scan c

  • ios-simulator-skill by conorluddy · ⭐ 1.2k

    An IOS Simulator Skill for ClaudeCode. Use it to optimise Claude's ability to build, run and interact with you

  • agentshield by affaan-m · ⭐ 1.2k

    AI agent security scanner. Detect vulnerabilities in agent configurations, MCP servers, and tool permissions.

  • mcp-scanner by cisco-ai-defense · ⭐ 1.1k

    Scan MCP servers for potential threats & security findings.

More Agent Tool Tools

Explore other popular agent tool tools:

View all Agent Tool tools →

Popular JavaScript Agent Tools

Frequently Asked Questions

What is skills?

skills is A collection of skills for AI coding agents from Semgrep. It is categorized as a Agent Tool with 262 GitHub stars.

What programming language is skills written in?

skills is primarily written in JavaScript. It covers topics such as agents, claude-code, security.

How do I install or use skills?

You can find installation instructions and usage details in the skills GitHub repository at github.com/semgrep/skills. The project has 262 stars and 28 forks, indicating an active community.

What are the best alternatives to skills?

The top alternatives to skills on Agent Skills Hub include JoySafeter, orchestkit, SecOpsAgentKit. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse Agent Tool tools