Find the skill for your next task.

Browse reusable Agent Skills, each with a clear purpose and practical guidance.

deep-security-scan

Use when the user asks for a deep, exhaustive, multi-pass, or variance-reducing repository-wide or scoped-path Codex Security scan. Run repeated independent discovery passes over one resolved scope with worker-specific threat models, semantically merge candidates, synthesize one canonical validation threat model, then run validation, attack-path analysis, canonical JSON completion, and generated reporting once. Do not use for PRs, commits, branch diffs, or working-tree diffs.

4.61k repo starsObserved in 2 repos
DevOps & Security

finding-discovery

Use when Codex is already in the finding-discovery phase of a security scan or the user explicitly asks to discover candidate security findings in a repository or code change. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.

4.61k repo starsObserved in 2 repos
DevOps & Security

fix-finding

Use when the user explicitly asks to fix and verify a validated or plausible security finding. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.

4.61k repo starsObserved in 2 repos
DevOps & Security

fund-comparison

Use when comparing 2 to 4 funds or ETFs with Morningstar ratings, returns, risk, and holdings data.

4.61k repo starsObserved in 2 repos
Business

fund-summarizer

Use when summarizing a fund or ETF with Morningstar ratings, returns, risk, holdings, fees, and caveats.

4.61k repo starsObserved in 2 repos
Business

grammar-of-graphics-and-declarative-visualization

Build data visualizations with declarative grammars. Use when the user needs Vega-Lite, Vega, Observable Plot, or grammar-of-graphics reasoning, especially for tabular charts that do not require bespoke rendering.

4.61k repo starsObserved in 2 repos
Design

ngs-bcl-to-fastq

Validate Illumina BCL run folders and sample sheets, plan demultiplexing, review index/UMI/lane choices, run BCL-to-FASTQ conversion, and interpret demux metrics while surfacing license/download boundaries.

4.61k repo starsObserved in 2 repos
Others

security-diff-scan

Use when the user asks for a security review of a pull request, commit, branch diff, working-tree patch, or other Git-backed change set.

4.61k repo starsObserved in 2 repos
Testing & Quality

security-scan

Use for a standard, single-pass security audit of an entire repository or a scoped path, package folder, or submodule with no diff to review. This is the default repository scan. Do not use for PR/commit/branch/working-tree diffs, or for deep, multi-pass, or variance-reducing scans.

4.61k repo starsObserved in 2 repos
DevOps & Security

statistical-and-uncertainty-visualization

Design statistically honest and uncertainty-aware visualizations. Use when the user needs help showing distributions, intervals, confidence, missingness, sampling effects, or analytical rigor in charts and dashboards.

4.61k repo starsObserved in 2 repos
Design