Discover and install skills, docs, and rules to enhance your AI agent's capabilities.
| Name | Contains | Score |
|---|---|---|
gmh5225/awesome-game-security Verify consequential or disputed game-security claims with primary sources, reproducible evidence, explicit trust boundaries, and calibrated uncertainty. Use alongside a domain skill when evidence quality affects the conclusion. | Skills | — |
gmh5225/awesome-game-security Analyze Linux, SteamOS, Steam Deck, Wine, or Proton game-security boundaries. Use for ELF/process evidence, privileges, namespaces, seccomp, LSMs, compatibility, or Linux memory forensics. | Skills | — |
gmh5225/awesome-game-security Assess game build, launcher, update, distribution, mod, plugin, dependency, signing, provenance, and recovery trust. Use when release or content ingestion is the security boundary. | Skills | — |
gmh5225/awesome-game-security Review multiplayer authority, RPCs, sessions, authorization, replication, inventory, economy, purchases, retries, and replay. Use when server or backend state is the security boundary. | Skills | — |
microsoft/apm Use this skill to cut an APM release from the current worktree: assess whether the cycle since the last tag warrants a patch or minor bump (semver discipline against the merged-since-last-tag diff), sanitize the [Unreleased] CHANGELOG block into a dated version block with one concise "so what" entry per merged PR (drop internal-only churn, consolidate duplicates), bump pyproject.toml + uv.lock, run the CI-mirror lint chain, and open the release PR. Activate on "ship a release", "cut v0.x", "release prep", "bump and PR", "open release PR", "what kind of release do we need", or any phrasing that ends in opening a release PR -- even when the user does not say "skill". Stops BEFORE tagging; tagging stays a human gate that triggers the release workflow. Refuses to bump to a major (>= 1.0.0) version without explicit operator confirmation. | Skills | |
microsoft/apm Drive ONE already selected open pull request in microsoft/apm to mergeable. Classifies copilot-pull-request-reviewer[bot] inline review, runs autopilot-pr-review-worker, folds (by default) every recommendation inside the PR's stated scope, pushes to the head branch or a superseding PR that preserves authorship via commit trailers, watches CI to green (`agent-merge` when that skill or `<agent_merge_state>` is present; otherwise `gh pr checks --watch`), and iterates under fixed caps until ready-to-merge, advisory-with-deferred, superseded, or blocked. Plan before any fold, push, or reviewer request. Never spawned by autopilot-pr-review-scheduler. That scheduler is advisory only. Invoke this skill by name when the caller asked to drive a PR to merge. | Skills | — |
microsoft/apm Use this skill to triage ONE microsoft/apm issue already selected by autopilot-issue-triage-scheduler. Return one advisory recommendation and a proposed scope brief, never human approval. Do not implement the issue, manage the backlog, or list the queue. | Skills | — |
microsoft/apm Queue open microsoft/apm issues and fan them out through an isolated pool (default 2) of autopilot-issue-triage-worker sessions. Advisory only. Never implements, never assigns, never requests reviewers. Activate on a mixed issue list or queue-all when the job is triage. Works in a local session, Copilot App automation, Cloud Agent, Remote Agent, or Agentic Workflow. | Skills | — |
linuxfoundation/crowd.dev Update, deploy, or roll out a Tinybird pipe or datasource to staging or production. Use for "update a pipe", "push to Tinybird", "tb push", "tb pull", "change a datasource", "add a field to a pipe", or anything touching the `lfx_insights` / `lfx_insights_stg` Tinybird workspaces. | Skills | — |
linuxfoundation/crowd.dev Automated vulnerability triage and dependency bumps for the git_integration worker (Python via uv + the two vendored Go modules). Fetches open Dependabot alerts scoped to git_integration manifests, correlates them with open Dependabot PRs, classifies each fix as safe or needs-human, validates safe fixes locally on the PR branches merged with latest main (uv sync / lint / pytest + full git-integration image build, which compiles both Go modules), updates safe PR branches server-side so they are one click from merge, then posts a "safe to merge" review summary to Slack and opens PRs for alerts Dependabot has no PR for. NEVER merges PRs, never dismisses alerts, never deploys without explicit user confirmation. Use when the user says "fix vulns", "bump deps", "dependabot triage", or asks about git_integration vulnerabilities. | Skills | — |
gadievron/raptor Hypothesis-driven, tool-grounded security review of coverage gaps | Skills | — |
gotalab/cc-sdd Implement approved tasks using TDD with native subagent dispatch. Runs all pending tasks autonomously or selected tasks manually. | Skills | — |
gotalab/cc-sdd Analyze implementation gap between requirements and existing codebase | Skills | — |
gotalab/cc-sdd Interactive technical design quality review and validation | Skills | — |
gotalab/cc-sdd Generate implementation tasks for a specification | Skills | — |
gotalab/cc-sdd Generate comprehensive requirements for a specification | Skills | — |
gotalab/cc-sdd Create comprehensive technical design for a specification | Skills | — |
gotalab/cc-sdd Create complete specs (requirements, design, tasks) for all features in roadmap.md using parallel sub-agent dispatch by dependency wave. | Skills | — |
gotalab/cc-sdd Implement approved tasks using TDD with subagent dispatch. Runs all pending tasks autonomously or selected tasks manually. | Skills | — |
ArcReel/ArcReel 评估 AFK 批次的工程、产品、知识与执行改进,生成可留存报告供用户裁决。 | Skills | — |
Can't find what you're looking for? Evaluate a missing skill.