Browse Source-Indexed Agent Skills
Find SKILL.md workflows by category, repository, and source date, then inspect the original GitHub file before installing.
Inspect the source before you use a Skill
AI Vitamin indexes original GitHub SKILL.md files and source dates. A listing improves discovery; it does not certify compatibility, security, or requested permissions.
Learn how Agent Skills workBrowse by workflow
1000 source-indexed records across 10 categories.
AI Agents & Models
Agent design, models, prompting, context, MCP, and evaluation workflows.
96 source recordsDevelopment & Engineering
Software delivery, codebases, APIs, SDKs, debugging, and developer workflows.
228 source recordsDesign & Frontend
Product design, UX, UI systems, frontend implementation, and visual work.
127 source recordsData, Research & Analysis
Research, data work, analytics, databases, visualisation, and evidence synthesis.
48 source recordsDocuments & Productivity
Documents, presentations, spreadsheets, knowledge work, and personal productivity.
41 source recordsWriting, Content & Marketing
Writing, editing, SEO, communications, content production, and marketing work.
74 source recordsCloud, DevOps & Infrastructure
Deployment, cloud platforms, CI/CD, operations, observability, and infrastructure.
74 source recordsAutomation & Integrations
Workflow automation, browser tasks, connected services, and cross-tool integrations.
45 source recordsSecurity, Quality & Compliance
Security, testing, quality assurance, accessibility, reviews, and compliance work.
207 source recordsBusiness & Operations
Product planning, sales, support, project delivery, and operational workflows.
60 source recordsSource records · Page 19
Only this page of records is included in the HTML response.
building-devsecops-pipeline-with-gitlab-ci
Configure a GitLab CI/CD pipeline that embeds SAST (Semgrep, SpotBugs, Gosec, Bandit, NodeJsScan), DAST, container scanning, dependency scanning, and secret detection via GitLab's managed security templates. Use when building a shift-left DevSecOps pipeline in GitLab, adding automated vulnerability scanning stages to .gitlab-ci.yml, or triaging scanner findings with GitLab Duo AI before deployment.
Source checked 2026-09-04building-identity-federation-with-saml-azure-ad
Configure SAML 2.0 identity federation between on-premises Active Directory (via AD FS or a third-party IdP) and Microsoft Entra ID, covering federation models (AD FS, password hash sync, pass-through auth, third-party IdP) and the SAML authentication flow. Use when extending on-premises authentication authority to cloud resources or designing hybrid identity SSO architecture for Entra ID.
Source checked 2026-09-04building-identity-governance-lifecycle-process
Design identity governance and lifecycle (IGA) programs on platforms like SailPoint, Saviynt, or Entra ID Governance, covering joiner-mover-leaver (JML) automation, role mining, access requests, periodic recertification, and orphaned-account remediation sourced from an HR feed. Use when automating cross-system JML provisioning, remediating former-employee access, or building lifecycle processes for SOX, HIPAA, or GDPR compliance.
Source checked 2026-09-04building-incident-response-dashboard
'Builds real-time incident response dashboards in Splunk, Elastic, or
Source checked 2026-09-04building-incident-response-playbook
Designs and documents structured incident response playbooks with step-by-step
Source checked 2026-09-04building-incident-timeline-with-timesketch
Build collaborative forensic incident timelines using Timesketch to ingest,
Source checked 2026-09-04building-ioc-defanging-and-sharing-pipeline
Build an automated pipeline that ingests raw IOCs (URLs, IPs, domains,
Source checked 2026-09-04building-ioc-enrichment-pipeline-with-opencti
Build an automated IOC enrichment pipeline on OpenCTI (STIX 2.1 native
Source checked 2026-09-04building-patch-tuesday-response-process
Establish a repeatable operational process for triaging, testing, and
Source checked 2026-09-04achieving-cmmc-level-2-compliance
Prepare a defense-contractor environment for CMMC Level 2 certification: scope CUI and FCI, implement the 110 NIST SP 800-171 Rev 2 security requirements across 14 families, compute the SPRS score with the DoD Assessment Methodology, manage a compliant POA&M, and ready the organization for a C3PAO assessment. Use when an organization handles Controlled Unclassified Information (CUI) under a DoD contract, when a contract carries DFARS clause 252.204-7012/7019/7020/7021, when preparing for or responding to a CMMC assessment, when computing or improving an SPRS score, when building a System Security Plan or POA&M for 800-171, or when scoping which systems are in the CUI boundary. Keywords: CMMC, CMMC Level 2, NIST 800-171, SP 800-171 Rev 2, CUI, FCI, SPRS, DFARS 7012, C3PAO, POA&M, System Security Plan, DoD Assessment Methodology, 110 controls, defense industrial base, DIB, FedRAMP equivalency.
Source checked 2026-09-01acquiring-disk-image-with-dd-and-dcfldd
Create forensically sound bit-for-bit disk images with dd or dcfldd on a Linux forensic workstation, preserving evidence integrity through hash verification (MD5/SHA) during acquisition. Use when imaging a suspect drive, USB device, or memory card for investigation, preserving volatile disk evidence during incident response, or producing a verified copy for legal or law-enforcement proceedings before any destructive analysis.
Source checked 2026-09-01analyzing-api-gateway-access-logs
'Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect
Source checked 2026-09-01analyzing-apt-group-with-mitre-navigator
Query ATT&CK data with attackcti, mitreattack-python, and stix2, then build MITRE ATT&CK Navigator layers and multi-layer heatmap overlays mapping one or more APT groups' TTPs for detection-gap analysis. Use to compare threat-actor technique coverage, find gaps in detection engineering, or produce Navigator visualizations for threat-intel reporting.
Source checked 2026-09-01analyzing-azure-activity-logs-for-threats
'Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query
Source checked 2026-09-01analyzing-browser-forensics-with-hindsight
Parse Chromium-based browser databases with Hindsight to extract and correlate browsing history, downloads, cookies, cached content, autofill data, saved passwords, and extensions from Chrome, Edge, Brave, Opera, and Vivaldi into a unified timeline (XLSX, JSON, or SQLite output). Use during incident response, insider-threat investigations, or criminal cases when you need to reconstruct a user's web activity from a browser profile.
Source checked 2026-09-01analyzing-certificate-transparency-for-phishing
Monitor Certificate Transparency logs using crt.sh and Certstream to
Source checked 2026-09-01analyzing-cobalt-strike-beacon-configuration
Extract and analyze Cobalt Strike beacon configuration from PE files
Source checked 2026-09-01analyzing-cyber-kill-chain
'Analyzes intrusion activity against the Lockheed Martin Cyber Kill Chain
Source checked 2026-09-01analyzing-disk-image-with-autopsy
Perform comprehensive forensic analysis of raw (dd), E01, or AFF disk images with Autopsy and The Sleuth Kit, recovering deleted files, examining metadata and embedded artifacts, keyword searching, and building investigation timelines with visual reports. Use for structured analysis of a forensic disk image or when stakeholders need visual reports from evidence.
Source checked 2026-09-01analyzing-docker-container-forensics
Investigate compromised Docker containers by analyzing images, layers,
Source checked 2026-09-01analyzing-email-headers-for-phishing-investigation
Parse and analyze email headers (Received chain, Return-Path, Message-ID)
Source checked 2026-09-01analyzing-ethereum-smart-contract-vulnerabilities
Perform static and symbolic analysis of Solidity smart contracts using
Source checked 2026-09-01analyzing-indicators-of-compromise
'Analyzes indicators of compromise (IOCs) including IP addresses, domains,
Source checked 2026-09-01analyzing-ios-app-security-with-objection
Runtime iOS app security testing with Objection (Frida): inspect keychain and filesystem data, explore app internals at runtime, and validate/bypass client-side protections during authorized mobile assessments.
Source checked 2026-09-01analyzing-kubernetes-audit-logs
Parses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod, secret access, RBAC modifications, privileged pod creation, and anonymous API access, and builds SIEM detection rules from the event patterns. Use when investigating a suspected cluster compromise, reconstructing what an attacker did through the API server, or writing Kubernetes-specific detection content. Keywords: audit policy, audit log, kube-apiserver, exec into pod, RBAC change, anonymous access, detection rules. Do not use for syscall-level detection inside a running container - use detecting-container-runtime-threats-with-falco. '
Source checked 2026-09-01analyzing-linux-audit-logs-for-intrusion
'Uses the Linux Audit framework (auditd) with ausearch and aureport utilities
Source checked 2026-09-01analyzing-linux-system-artifacts
Examine Linux system artifacts (auth logs, cron/systemd persistence,
Source checked 2026-09-01analyzing-lnk-file-and-jump-list-artifacts
Analyze Windows LNK shortcut files and Jump List artifacts with LECmd,
Source checked 2026-09-01analyzing-memory-forensics-with-lime-and-volatility
'Performs Linux memory acquisition using LiME (Linux Memory Extractor)
Source checked 2026-09-01analyzing-mft-for-deleted-file-recovery
Analyze the NTFS Master File Table ($MFT) with MFTECmd, analyzeMFT,
Source checked 2026-09-01analyzing-network-flow-data-with-netflow
Parse NetFlow v9 and IPFIX records to detect volumetric anomalies, port
Source checked 2026-09-01analyzing-network-packets-with-scapy
Use Scapy to craft, send, sniff, and dissect TCP/UDP/ICMP/DNS packets, analyze pcap files, implement SYN scans, and detect anomalous traffic such as fragmented or malformed packets. Use when performing authorized network reconnaissance, protocol-level forensic analysis, or building traffic anomaly detection during security testing.
Source checked 2026-09-01analyzing-network-traffic-for-incidents
'Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including
Source checked 2026-09-01analyzing-network-traffic-with-wireshark
'Captures and analyzes network packet data using Wireshark and tshark
Source checked 2026-09-01analyzing-office365-audit-logs-for-compromise
Parse Office 365 Unified Audit Logs via Microsoft Graph API to detect
Source checked 2026-09-01analyzing-outlook-pst-for-email-forensics
Parse Microsoft Outlook PST and OST files using libpff and pst-utils to extract message content, headers, attachments, deleted items, and MAPI metadata, including recovery of items from the Recoverable Items folder. Use when conducting email forensic investigations, legal e-discovery, or incident response that requires reconstructing communication patterns or tracing message routing from Outlook archives.
Source checked 2026-09-01