AI & ML
AI & ML agent skills cover the machine-learning workflow itself: writing and evaluating prompts, building RAG pipelines, running evals, and wiring up model APIs. Each one is a SKILL.md file your agent loads on demand, so the know-how travels across Claude Code, Cursor, and 60+ agents.
-
santosomar Bundle Attack Ent T1056 002 Gui Input CaptureAnalyze MITRE ATT&CK T1056.002 GUI Input Capture in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1056.002, GUI Input Capture, or enterprise ATT&CK. Adversaries may mimic common operating system GUI components to prompt users for credentials with a seemingly legitimate prompt.
-
santosomar Bundle Attack Ent T1220 Xsl Script ProcessingAnalyze MITRE ATT&CK T1220 XSL Script Processing in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1220, XSL Script Processing, or enterprise ATT&CK. Adversaries may bypass application control and obscure execution of code by embedding scripts inside XSL files.
-
santosomar Bundle Attack Ent T1036 012 Browser FingerprintAnalyze MITRE ATT&CK T1036.012 Browser Fingerprint in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1036.012, Browser Fingerprint, or enterprise ATT&CK. Adversaries may attempt to blend in with legitimate traffic by spoofing browser and system attributes like operating system, system language, platform, user-agent string, resolution, time zone, etc.
-
artemgurzhii Skill Ember 2 To 3 MigrationThe 2.18 LTS → 3.28 LTS migration path — the LTS-by-LTS sequence, ember-cli-update, the deprecation workflow, jQuery removal, the test API conversion, and the addon survival list. Use when planning, scoping, or executing a 2.x upgrade. Hands off to the ember-3-migrator agent once you reach 3.28.
-
artemgurzhii Skill Ember Polaris MigrationMigrating Ember Octane apps toward Polaris — single-file components (.gjs/.gts), the <template> tag, strict-mode templates, route templates as components, and the mental model shifts. Use when introducing template imports to a codebase, when starting a new Polaris-first project, or when you see <template> blocks and need to understand them.
-
artemgurzhii Skill Ember 2 Classic PatternsThe canonical Ember 2.x mental model — Ember.Object.extend, Ember.computed, classic components, the actions hash, mixins, observers, run loop, two-way binding. Use when reading or maintaining 2.x code, decoding deprecation messages, or explaining how a 2.x pattern maps to modern Ember.
-
artemgurzhii Skill Ember Routing And ModelsEmber Router — route definitions, route hooks (beforeModel, model, afterModel, redirect), nested routes, dynamic segments, query params, transitions, error/loading substates, and LinkTo. Use when adding URLs, fetching route-level data, handling auth redirects, or debugging "why isn't this route entering."
-
b-holanda Skill Karpathy GuidelinesBehavioral guidelines for careful coding-agent work inspired by Andrej Karpathy's observations on common LLM coding pitfalls. Use when Codex is writing, reviewing, debugging, or refactoring code and should avoid overcomplication, make surgical changes, state assumptions, preserve existing user work, and define verifiable success criteria before implementation.
-
artemgurzhii Skill Ember Octane FundamentalsCore mental model for modern Ember (Octane edition, default since 3.15) — native classes, decorators, tracked properties, actions, owner/DI, autotracking. Use when writing or reviewing any Octane-era Ember code, when explaining how reactivity works, or when migrating from classic Ember.
-
spindriftpapilio Bundle Skill测试AI IDE中终端命令过滤、allowlist与blocklist的绕过问题。适用于评估 命令执行控制、Shell注入、参数校验缺陷,以及Agent终端安全边界是否可靠。
-
spindriftpapilio Bundle MCP测试AI IDE的MCP配置投毒问题。适用于审查IDE是否会从工作区自动加载 不可信MCP服务器定义,以及审批与调用控制是否存在缺陷。评估按四个交互 层级展开,从零交互自动加载到已信任工作区中的TOCTOU。
-
spindriftpapilio Bundle AI Ide 4指导对开源AI IDE做源码安全审计。适用于审查命令过滤实现、MCP集成、 配置加载、文件写入权限模型,以及其他与Agent能力边界相关的源码路径。
-
spindriftpapilio Bundle AI Ide 5测试AI IDE中超出MCP与终端过滤范围之外的代码执行面。适用于评估Hook滥用、二进制植入、IDE设置利用、工具定义自动加载,或环境变量前缀 相关向量。模式按交互层级排序:Tier 1为零交互,Tier 4为已信任工作区 且需要特定动作。
-
ikredhat Skill Serving Runtime StrategyAnalyzes open-source model serving runtimes and generates comprehensive testing strategies and KCS drafts for Red Hat OpenShift AI integration.
-
basezh Bundle TownAn [Agent Skill](https://agentskills.io) providing comprehensive knowledge for building Towns Protocol bots. Compatible with Claude Code, OpenAI Codex, and other agents supporting the Agent Skills ...
-
spindriftpapilio Bundle Agent测试Agent或AI IDE的工作区信任、审批提示、敏感文件保护与权限缓存模型。 适用于评估首次打开项目、切换信任状态、批准工具调用、批准MCP或批准配置后, 是否存在预信任执行、审批复用、TOCTOU、提示弱化或范围漂移。
-
spindriftpapilio Bundle Agent Skill测试Agent skill、规则文件、插件、MCP配置与本地自动发现路径的供应链风险。 适用于评估SKILL.md、规则文件、marketplace来源、自动发现目录、 扫描器与基准环境,并围绕安装、更新、启用、引用四个阶段做安全审查。
-
spindriftpapilio Bundle Agent Hook Agent测试Agent的Hook、子Agent、任务Agent与工作流扩展点的安全边界。 适用于评估项目级Hook、用户级Hook、子Agent提示文件、工具权限继承、 输入传递、审批绕过与持久化执行风险。
-
nicshik Bundle Perplexity Search OnlyРежим Search only для недорогого поиска через Perplexity с preferred MCP path и direct Search API fallback. Использовать, когда нужны ссылки, сниппеты, первоисточники или быстрая проверка свежих сведений.
-
nicshik Bundle Perplexity Deep ResearchРежим Deep Research через Perplexity MCP для широких и важных multi-source вопросов, когда допустимы высокий расход и более долгое выполнение.
-
nicshik Skill Perplexity ResearchDeep Research mode through Perplexity MCP. Use only for broad, important questions where higher cost and longer runtime are acceptable.
-
basezh Skill ZoraExplore Zora coins, check prices, manage wallets, and execute trades from your AI agent.
-
basezh Bundle BankrBankr Skills equip builders with plug-and-play tools to build more powerful agents. Includes Bankr (launch tokens, earn trading fees, built-in wallet with safeguards), SIWA (agent authentication), Bankr Signals (verified trading signals), Botchan (on-chain messaging), ERC-8004 (agent identity registry), ENS Primary Name (ENS management), OnchainKit (onchain UI components), QRcoin (QR auction game), Veil (private transactions), Yoink (social token game), Neynar (Farcaster API), and Hydrex (liquidity pools).
-
basezh Bundle RemixBest practices, references, and templates for building games on Remix via API-driven agent workflows.
-
feixuecode Bundle Hound结构化招聘 Skill(Structured Hiring Skill)。用于岗位管理、简历评估、候选人历史追溯和双维议事(HR+用人部门视角)。触发词包括 "我要招聘"、"评估简历"、"evaluate resume"、"看一下候选人"、"议一下"、"设计面试问题"、"Run hound"、"hound skill"。模型无关,支持 Compact/Standard/Deep 三档自适应。/ Structured hiring skill for position management, resume evaluation, candidate history tracking, and dual-council deliberation (HR + hiring manager perspectives). Triggers include "我要招聘", "评估简历", "evaluate resume", "看一下候选人", "议一下", "设计面试问题", "Run hound", "hound skill". Model-agnostic, adapts to Compact/Standard/Deep modes.
-
basezh Bundle MorphoQuery Morpho vault APYs, market rates, and positions; prepare unsigned deposit, withdraw, and borrow flows via CLI or MCP; builder pack covers SDK, GraphQL, and contract patterns for integrations.
-
wilcorakhorst Bundle Skill BuildingStructured guide for building high-quality GitHub Copilot agent skills. Use when creating a new skill, improving an existing one, diagnosing why a skill isn't being invoked, or reviewing a skill before publishing. Triggers: 'create skill', 'build skill', 'new SKILL.md', 'improve skill', 'skill not triggering', 'skill not loading', 'validate skill', 'publish skill', 'YAML frontmatter', 'description field', 'trigger phrases', 'skill structure', 'references folder', 'progressive disclosure'.
-
testonohm Skill Jira Task WorkflowGuides end-to-end delivery starting from an assigned Jira issue: load issue context via Atlassian MCP, clarify ambiguous requirements, establish root cause for bugs before coding, resolve repo from Labels, implement locally without committing until the user finishes manual testing, then—only on explicit user request—assist with git actions if asked. The user typically commits, pushes, and opens the PR themselves; once a PR URL exists, the agent must update Jira automatically (status transitions and activity via comments). If labels do not identify exactly one repo, the agent must ask the user every time. Use for Jira-linked work, keys (e.g. PROJ-123), URLs, or phrases like "จาก Jira", "งาน SD-", "เริ่มจาก task บน Jira".
-
testonohm Skill Context EngineeringOptimizes agent context setup. Use when starting a new session, when agent output quality degrades, when switching between tasks, or when you need to configure rules files and context for a project.
-
basezh Skill BotchanCLI for the onchain agent messaging layer on the Base blockchain, built on Net Protocol. Explore other agents, post to feeds, send direct messages, and store information permanently onchain.
-
basezh Bundle Dx Terminal ProAn AI agent skill for managing autonomous memecoin trading agents on [DX Terminal Pro](https://terminal.markets).
-
basezh Skill Xmtp AgentConnect a running agent (OpenClaw, Claude Code, LangChain, custom Python, any agent runtime) to XMTP messaging so people can DM it and get responses that use the agent's full capabilities — tools, memory, session context. Provides the complete bridge pattern: XMTP CLI setup, identity registration, streaming incoming messages, routing through your agent backend, and sending replies back. Use this skill whenever someone wants to make their agent reachable over XMTP, write a bridge or listener script between an agent process and XMTP, set up xmtp init and stream-all-messages for an agent, have their agent respond to XMTP conversations continuously, wire any agent runtime to the XMTP open messaging network, or pipe XMTP messages through stdin/stdout to an agent process. This skill is specifically about connecting an existing agent to XMTP as a messaging transport — not for building XMTP client apps, looking up XMTP SDK documentation, or sending individual messages.
-
basezh Bundle Bankr SignalsTransaction-verified trading signals on Base. Register agent as signal provider, publish trades with TX hash proof, consume signals from top performers via REST API. All track records verified against blockchain data. No fake performance claims. Triggers on: "publish signal", "post trade signal", "register provider", "subscribe to signals", "copy trade", "bankr signals", "signal feed", "trading leaderboard", "read signals", "get top traders".
-
basezh Bundle Virtual Protocol AcpCLI tool for the [Agent Commerce Protocol (ACP)](https://app.virtuals.io/acp) by [Virtuals Protocol](https://virtuals.io). Works with any AI agent (Claude, Cursor, OpenClaw, etc.) and as a standalone...
-
basezh Skill AgentmailAPI-first email for AI agents. Create inboxes, send/receive emails, webhooks, agent identity. Use when agents need email identity, sending emails, or email-based workflows.
-
basezh Bundle ClawrouterThe agent-native LLM router for OpenClaw. Route every request to the right model at the right price. 15-dimension scoring, 41+ models, zero API keys.
Frequently asked questions
What are AI & ML agent skills?
AI & ML agent skills cover the machine-learning workflow itself: writing and evaluating prompts, building RAG pipelines, running evals, and wiring up model APIs. Each one is a SKILL.md file your agent loads on demand, so the know-how travels across Claude Code, Cursor, and 60+ agents.
Which AI & ML skills are most installed?
Popular AI & ML skills on SkillMD right now include attack-ent-t1056-002-gui-input-capture, attack-ent-t1220-xsl-script-processing, attack-ent-t1036-012-browser-fingerprint. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do AI & ML skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.