Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Skill Creator

ASecurity

Create or update an agent skill with appropriately scoped instructions and necessary resources. Use for skills; not policies, plugins, or project implementation.

2 stars
0 votes
0 copies
1 views
Added 9/22/2026
ai-agentstestinggitdocumentation

Security Analysis

A100/100

Scanned 9/29/2026

$npx -y skills add Catherine1401/agent-skills --skill skill-creator --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Skill Creator?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Skill Creator
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/catherine1401-skill-creator/badge)](https://www.skillsdirectory.com/skills/catherine1401-skill-creator)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: skill-creator
description: Create or update an agent skill with appropriately scoped instructions and necessary resources. Use for skills; not policies, plugins, or project implementation.
---

- Optimize for agent execution: retain only instructions that change decisions or improve results. Remove prose, headings, examples, alternatives, and files unless they resolve an operational ambiguity. Assume the agent is capable; omit generic advice, repeated rules, and speculative edge cases.
- Preserve the user's intent, scope, product choices, and authorization boundaries. Do not turn examples, past failures, or preferences into universal requirements, or imply permission to change unrelated configuration or perform additional external actions.
- For retrying or externally mutating workflows, define a stopping condition proportional to the risk. Approval to complete a task does not expand its scope or execution permissions.
- Match specificity to risk: describe outcomes and decision criteria for open-ended work; require fixed sequences, parameters, or deterministic scripts only when deviation would cause a concrete correctness, safety, or permissions problem. Preserve non-obvious operational invariants; distinguish requirements from recommendations and local conventions.
- Keep names and descriptions concise and discriminating about capability and applicability. Add exclusions only to prevent likely misrouting; avoid exhaustive capability lists and catchalls for unrelated tasks.
- Keep skills self-contained. Depend on another skill or tool only when the workflow genuinely requires it and the target environment provides it. Require specialized review only when requested or genuinely needed.
- Adapt the work to the request; narrow updates need only focused edits and validation. Ask only when missing information matters and cannot reasonably be inferred; do not request more examples when the task is clear.
- Respect the user's chosen location and preserve an existing skill's location when updating. For new skills, use a directory discoverable by the target agent; for Codex, default to `$CODEX_HOME/skills`, or `~/.codex/skills` when unset.
- Use lowercase letters, digits, and hyphens in names under 64 characters; prefer short action-oriented names. Namespace by tool or domain when it improves discovery; name the folder after the skill.
- Include YAML frontmatter with `name` and `description` in `SKILL.md`. Preserve supported optional fields such as `metadata` when appropriate; do not change unrelated files or metadata.
- Keep purpose, essential constraints, shared workflow, and mode-selection criteria in `SKILL.md`. Move substantial conditional detail into linked resources with reading conditions; do not load every resource by default or duplicate content. Short skills do not need a routing layer.
- Add `scripts/` only to avoid repeatedly rewriting the same logic or when deterministic execution improves reliability. Run new or changed scripts to validate behavior.
- Use `references/` for task-specific information needed in particular contexts; keep one source for each piece of information. For large references, add search terms or a short contents section when useful. Inspect callers and purpose before removing existing resources.
- Use `assets/` for files included in generated output; do not load them as instructions unless inspection is needed. Do not create directories, placeholders, READMEs, installation guides, or auxiliary documentation without a concrete need.
- For `agents/openai.yaml`, add UI metadata only when useful and optional interface fields only when the user provides or requests them. If the bundled toolkit includes `references/openai_yaml.md`, read it before editing; keep values consistent with the skill and preserve unrelated policy, dependencies, and fields.
- Preserve existing invocation policy unless the user requests a change. New skills allow automatic selection by default; set `policy.allow_implicit_invocation: false` only when the user explicitly requests explicit-only invocation. Do not infer this mode from sensitive operations or approval requirements; require authorization immediately before the actual mutation.
- Use a bundled initializer when available and useful for creating a new skill consistently; do not reinitialize existing skills. Request only necessary resources; replace or remove placeholders before finishing. Do not use a generator that replaces all metadata when existing policy or dependencies must be preserved.
- Use a bundled validator when available to check frontmatter, naming, and unfinished placeholders. Also check description precision, scope, resource discoverability, and script behavior; structural validation does not prove decision quality.
- When behavioral testing is warranted, verify observable outcomes or meaningful invariants; avoid tests that merely match wording, headings, or regex patterns. Improve from real usage or demonstrated failures; prefer narrow corrections over accumulating universal rules.
- Use independent subagent evaluation only when complexity or risk makes behavioral validation useful and delegation is available and authorized. Provide a realistic request, the skill, and minimum raw artifacts; withhold intended answers, suspected bugs, and prior conclusions unless needed. Use an isolated temporary workspace and constrain resources and side effects; ask for approval if additional authorization, production impact, or substantial time or cost is involved. Change only what observed outcomes and artifacts support.

Attribution

Catherine1401Catherine1401
View sourceSee grades on GitHubMore from Catherine1401 →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698621 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →