1. Auditing-Security: Systematically Audit Code Repositories with Agent Skill
### Introduction to awesome-cursor-skills Selected Skill auditing-security: Write review steps including OWASP Top 10, key leakage, injection and dependency vulnerabilities into SKILL.md for agents such as Cursor to conduct systematic audits of business code according to the 7-step checklist. The content covers installation methods, prompt examples, and the complementary relationship with Skill supply chain security tools such as SkillScan.
Read More# cloudflare-deploy: Let AI Agents Deploy Applications to Cloudflare Edge Network
`cloudflare-deploy` is an Agent Skill under the OpenAI openai/skills curated directory. It guides AI Agents to complete full-stack deployments on Cloudflare, including Workers, Pages, and services like KV/D1/R2, via decision trees and reference documents. This article verifies the official SKILL.md, introduces its differences from vercel-deploy, the installation methods for Codex/Cursor, the Wrangler authentication process and typical deployment commands, which is suitable for developers who need edge Serverless and multi-cloud deployments.
Read More# figma-implement-design: Official OpenAI Skill that 1:1 restores Figma design drafts to production-grade code
**figma-implement-design** is an OpenAI-curated Agent Skill that works with the Figma MCP to translate design nodes into deliverable UI code within repositories. This article introduces its seven-step workflow, boundaries with other Skills such as figma-use, prerequisites for the MCP, as well as installation and typical usage in tools like Cursor (/add-plugin figma) and Codex ($skill-installer), helping developers shorten the Design-to-Code iteration cycle.
Read MoreOpenAI Official Security-Best-Practices: Performing Security Reviews of AI According to Languages and Frameworks
OpenAI has provided the `security-best-practices` Skill in the `curated` directory of the openai/skills repository. It includes 10 security specifications for common frameworks in Python, JavaScript/TypeScript and Go, and supports secure-by-default coding, passive inspection and structured security reporting. This article introduces its workflow, references library, Codex/Cursor installation methods and typical prompts, to help developers embed verifiable security review capabilities into AI-assisted programming.
Read More### 版本1(面向技术用户,贴合原文语境): `vercel-deploy`: Let AI Agents Deploy Projects to Vercel with One Click ### 版本2(更地道的技术文档译法): `vercel-deploy`: Enable AI Agents to One-Click Deploy Projects to Vercel
Vercel-deploy is a Vercel deployment Skill in the OpenAI Skills curated directory, which guides AI Agents to one-click deploy applications to Vercel. It uses preview deployment by default; prioritizes Vercel CLI, and automatically downgrades to the deploy.sh script when not logged in, and can return previewUrl and claimUrl without prior account configuration. It supports automatic detection of frameworks such as Next.js, Nuxt, Astro, etc., and is applicable to tools such as Cursor, Codex CLI, and Claude Code.
Read MoreDrive Real Browsers via Terminal: Getting Started with OpenAI's Official Playwright Skill
OpenAI's featured Skill "playwright" wraps the Playwright Agent CLI into a terminal browser automation workflow: opening pages, taking snapshots to obtain element references, filling forms and clicking, taking screenshots, and debugging with Trace. Verified based on the official SKILL.md, this article introduces the installation methods (Codex skill-installer, Cursor .cursor/skills), the usage of the wrapper script, typical command examples, as well as precautions such as re-snapshotting when refs fail and not writing @playwright/test by default. It is suitable for E2E exploratory automation and UI process troubleshooting scenarios.
Read Moregh-fix-ci: Use GitHub CLI to let AI help you debug failed CI checks on PRs
If your CI fails before a PR is merged, do you have to switch back and forth between the Actions page and your terminal to check logs? The officially curated OpenAI skill `gh-fix-ci` is specifically designed for GitHub Actions failure troubleshooting: it pulls PR checks and run logs via the GitHub CLI, uses bundled scripts to automatically extract error snippets, provides a repair plan first, and waits for approval before you modify the code. This article introduces the positioning of this skill, the usage of `inspect_pr_checks.py`, as well as the installation and enabling methods in tools such as Codex and Cursor.
Read Moregh-address-comments: Structured Processing of GitHub PR Review Comments with Agent Skill
gh-address-comments is a curated Skill by OpenAI Codex. It pulls all review and inline comments of the current branch PR via gh CLI and GraphQL scripts, summarizes them with serial numbers for users to select the entries to handle, and then hands them over to the Agent for code modification. This article introduces its three-step workflow, the capabilities of fetch_comments.py, the installation methods of Codex and Cursor, as well as applicable scenarios and precautions under the human-in-the-loop design.
Read More# doc-coauthoring: Use a three-stage structured workflow to let Agents help you write clear technical specifications and decision documents
Doc-coauthoring is a documentation co-creation Skill in Anthropic's official Skills repository, targeting structured writing scenarios such as technical specifications, decision documents, RFCs, and PRDs. Instead of generating a full article at one time, it guides the Agent through three phases: context collection, section-by-section polishing, and reader testing. It first supplements background information through meta-questions and information dumping, then conducts brainstorming, screening, drafting and iterative revision by chapter, and finally uses a context-free Claude to simulate reader questions to identify blind spots in the document. This article introduces its core capabilities, installation methods in Cursor and Claude Code, as well as typical interaction examples and applicable boundaries for writing decision docs.
Read Moreinternal-comms: Let AI Write Internal Communication Documents According to Company Format
Anthropic's official Skill internal-comms packages internal communication templates such as 3P weekly reports, all-staff newsletters, FAQs, and incident reports into the SKILL.md instruction set. This article introduces its workflow for loading examples/ guidelines by category, the installation method in Cursor / Claude Code, as well as typical prompt usages and customization suggestions.
Read More# web-artifacts-builder: Using React Stack to Enable Agents to Deliver Deployable Frontend HTML Artifacts
Anthropic’s official Skill `web-artifacts-builder` builds complex multi-component web artifacts using React 18, TypeScript, Vite, Tailwind and shadcn/ui. The `init-artifact.sh` initializes the scaffold and pre-installs over 40 components, while `bundle-artifact.sh` packages the project into a self-contained `bundle.html`. This article covers the installation and activation methods for tools like Claude Code and Cursor, a four-step workflow, and applicable scenarios, helping AI Agents deliver web pages following modern front-end engineering practices.
Read MoreTheme Factory: One-click skin changing for slides, documents and landing pages with Agent Skill
### 翻译结果: This article introduces Anthropic's official theme-factory Skill: it includes 10 preset themes (color schemes and fonts), which can apply unified styles to slides, documents, reports and HTML landing pages, and also supports custom themes. Based on the official SKILL.md and repository structure, this article explains the installation methods (CLI, manual copying, Claude Code plugin), standard skin-changing process and typical prompt examples, which is suitable for developers who need to unify the style in AI design workflows.
Read MoreLet AI Truly Excel at Writing Excel: Detailed Explanation of Anthropic's Official xlsx Skill
xlsx is an official Anthropic Agent Skill dedicated to handling reading and writing of spreadsheet files such as .xlsx/.csv, formula modeling and data cleaning, and also serves as the implementation reference behind Claude's document capabilities. This article introduces its core capabilities (division of labor among openpyxl/pandas/markitdown, formula recalculation via recalc.py, and financial model specifications), as well as the installation, activation methods and typical usage scenarios in Cursor, Claude Code and Claude.ai, to help developers enable AI to directly deliver auditable spreadsheets.
Read MoreSkill for PPTX: Let AI Agents Truly Learn to Create PowerPoint Presentations
### 译文1(标准科技文档译法,适配海外技术社区表达): > The official Anthropic PPTX Skill supports creation, editing and reading of `.pptx` and `.potx` files, with supporting scripts including `pptxgenjs`, OOXML decompression and editing utilities, and `validate.py`, as well as triple-layer QA. This article introduces its positioning, core capabilities, installation method in Cursor / Claude Code, typical usage scenarios and precautions for template filling, validation and visual QA. --- ### 译文2(更贴合海外开发者文档的口语化译法): > Anthropic's official PPTX Skill lets you build, edit and read `.pptx` and `.potx` slides, backed by supporting tools like `pptxgenjs`, OOXML decompression/editing scripts, `validate.py`, plus a three-tier QA pipeline. We'll walk through its positioning, core features, how to install it in Cursor and Claude Code, plus common workflows for template population, validation and visual QA along with key best practices.
Read MoreAnthropic PDF Skill: Enabling AI Programming Assistants to Truly Handle All Scenarios of PDF Processing
This PDF is an Agent Skill maintained officially by Anthropic, which follows the Agent Skills open standard and can be used in Cursor, Claude Code and Codex. It covers high-frequency office automation scenarios including PDF reading and extraction, merging and splitting, rotating and watermarking, form filling, encryption and decryption, OCR and image extraction, etc., and includes tool selection guides for pypdf, pdfplumber, reportlab, qpdf, pdftotext and other tools. This article introduces the positioning, core capabilities, installation methods in Claude Code/Cursor/Codex, as well as official code examples and usage notes of the Skill.
Read MoreSkill: Let AI Truly Write Deliverable Word Documents
DOCX is a Word document Agent Skill publicly released by Anthropic in the anthropics/skills repository, which supports Claude's file creation and editing capabilities. This article introduces its positioning, three technical paths of creation/reading/editing, revision annotations and bundled scripts, installation methods in Cursor and Claude Code, as well as precautions such as docx-js and unzip/XML editing, to help developers truly deliver AI-generated content into deliverable .docx files.
Read More# Claude-api Skill: A Pocket Reference Manual for Claude API Developers
Anthropic's open-source claude-api Agent Skill packages the documentation of Messages API, Managed Agents and 8 programming language SDKs including Python, TypeScript and Go into progressively loadable references, which is built into Claude Code. This article introduces its positioning, core capabilities (model migration, streaming, tool calling, Prompt Caching, MCP/Agent), installation method and typical usage, helping developers avoid writing outdated Claude API code from memory.
Read More# webapp-testing: Let AI Agents Autonomously Validate Local Web Applications with Playwright
Anthropic's official webapp-testing Skill wraps Playwright browser automation into reusable, agent-friendly test workflows. It supports starting local dev servers, taking screenshots to inspect DOM, and capturing console logs, and validates dynamic single-page applications following a "inspect first, then operate" pattern. This article introduces its core capabilities, installation methods in Cursor and Claude Code, as well as the multi-server management with `with_server.py` and typical Playwright script examples, to help developers enable AI to independently run UI regression tests after modifying front-end code.
Read Morefrontend-design: Making AI-generated interfaces no longer "cut from the same mold"
frontend-design is an Agent Skill officially maintained by Anthropic, targeting scenarios of building or retrofitting UIs. Through design planning, token system, typography and self-review process, it guides AI to avoid common default aesthetics such as warm beige serifs, dark neon colors and newspaper-style columns, and produce more recognizable interfaces. This article introduces its core principles, two-stage workflow, as well as installation and typical prompt usage in tools like Claude Code and Cursor.
Read More# Skill-Creator: Anthropic's Official "Meta-Skill" to Teach You Write Evaluable Agent Skills from Scratch
skill-creator is an Agent Skill "meta-skill" in Anthropic's open-source repository, specifically designed to guide developers in creating, testing and iterating on SKILL.md. This article introduces its core capabilities: structured creation workflow, Skill directory specifications, eval evaluation and benchmark testing, description trigger optimization, as well as the installation and activation methods in tools such as Claude Code and Cursor. If you plan to systematically get started with Agent Skills, or already have a Skill but encounter inaccurate triggering or unstable output, skill-creator provides a complete closed loop from drafting to packaging, making it one of the most worthwhile skills to install first in the Skill ecosystem.
Read More# MCP-Builder: Official Anthropic Skill to Walk You Through Building High-Quality MCP Servers
MCP-builder is an Agent Skill in Anthropic's official Skills repository, specifically designed to guide developers in creating high-quality MCP servers. Based on the official SKILL.md and reference documents, this article introduces its four-stage workflow (research and planning, implementation, testing, evaluation), dual-stack support for TypeScript/Python, installation and activation methods (Cursor, Claude Code, etc.), typical prompt examples and usage precautions, to help developers systematically encapsulate external APIs into LLM-callable MCP tools.
Read MoreClaude Code 2.1.220 Defaultly Switches to Opus 5, Nested Subagent Depth Expanded to 3 Layers
On July 24, 2026, Anthropic released the 2.1.220 series updates for Claude Code: version 2.1.219 switched the default model to Claude Opus 5 (1M context window), and expanded the default nested subagent depth from 1 to 3; version 2.1.218 changed `/code-review` to run as a background subagent. An early August evaluation showed that the gap between Opus 5 and GPT-5.6-Sol on Terminal-Bench 2.1 was less than 0.5 percentage points, and the competition for AI programming agents has shifted to focusing on both models and orchestration layers. This article sorts out the version changes based on the official CHANGELOG, and provides configuration instructions for subagent depth limits, concurrency upper limits and other parameters.
Read MoreMCP and Agent Skills Become New Attack Surface: Permission Governance, Static Scanning and ChainDrop Injection into Claude Configuration
In August 2026, the ChainDrop worm achieved persistence by injecting into `.claude/settings.json` and `.vscode/tasks.json`, with malicious execution triggered once developers opened the repository. Meanwhile, approximately 36% of MCP servers and Agent Skills have security flaws, and 80% of enterprises lack governance for Agentic AI. This article sorts out the three-layer attack surface of models/instructions/Harness, MCP Tool Poisoning and protocol approval gaps, introduces JFrog Agent Guard and skill-audit-mcp static scanning, and provides an actionable protection checklist for CI integration and runtime approval.
Read MoreHN Hot Topic: Can Manually Re-typing Every Line of Code Generated by an LLM Avoid "Cognitive Debt"?
On August 4, 2026, Ankur Sethi published a post advocating for manually retyping LLM-generated code line by line to avoid "cognitive debt", which garnered 409 points and 348 comments on Hacker News. This article outlines its core workflow (the Agent only displays changes without directly writing files), the pros and cons debates on HN, as well as more widely accepted alternatives like plan-first, design-first, and test-driven development, to help developers balance efficiency and code comprehension in the era of AI programming.
Read MorePonytail: Let AI Agents Follow the YAGNI Principle to Reduce Over-Engineering and Token Waste
# Ponytail: August 2026 GitHub Trending Project Ponytail is a YAGNI (You Aren't Gonna Need It) agent skill suite designed specifically for coding agents. Through decision ladders and commands such as `/ponytail-review` and `/ponytail-audit`, it prioritizes reuse, standard libraries and native capabilities before writing code, curbing over-engineering and unnecessary dependencies. Official agentic benchmarks conducted on real FastAPI+React repositories show an average code reduction of approximately 54%, a token reduction of around 22%, a cost reduction of roughly 20%, while maintaining 100% security. It supports over 14 hosting environments including Claude Code Plugin and Cursor rule injection. This article introduces its principles,实测 data, installation methods and applicable boundaries.
Read More