AGENT SKILLS DIRECTORY

Code Review & Testing Agent Skills

Find Skills that help inspect changes, design tests, challenge assumptions, and verify software work before it ships.

63
indexed Skills
27
Top 100 entries
4
native Agent signals

JOBS TO BE DONE

Start with the outcome

  1. 01Review code and architecture decisions
  2. 02Generate and maintain focused tests
  3. 03Add evidence to development handoffs

SELECTION CHECKS

Reduce the decision before install

  1. 01Confirm which files and commands the Skill may access.
  2. 02Separate review guidance from tools that can modify code.
  3. 03Run the first test in a disposable branch or workspace.

THE COMPLETE CATEGORY

Code review & testing

Ordered by SkillSignal's published metadata signals. A score is not a security certification—open the full profile before installing.

0196

frontend-design

Design constraints that push generated interfaces beyond generic AI UI.

Main limitation
Aesthetic judgments remain subjective and still need stakeholder review.
First risk
Style over function · Medium
Source
Pinned · 34040c9c
Open full profile ↗
0294

web-design-guidelines

Review interfaces against practical web design and accessibility rules.

Main limitation
It depends on network access and a live guideline document whose contents can change over time.
First risk
Rule drift or context-free findings · Medium
Source
Pinned · 063bee94
Open full profile ↗
0394

mcp-builder

Plan, implement, and evaluate high-quality MCP servers in Python or TypeScript.

Main limitation
The guide cannot replace current MCP SDK or target-API documentation.
First risk
Overpowered external-service tools · High
Source
Pinned · 34040c9c
Open full profile ↗
0494

skill-creator

Create, improve, and benchmark Agent Skills with trigger tests and comparative evaluation.

Main limitation
Meaningful benchmarks require representative prompts, repeat runs, and careful human judgment.
First risk
Untrusted evaluation prompts and artifacts · High
Source
Pinned · 34040c9c
Open full profile ↗
0593

grill-me

Relentless decision interviews for sharper plans and designs.

Main limitation
The package is a launcher that calls the separate grilling Skill; installing grill-me alone may not include the interview itself.
First risk
Decision fatigue · Low
Source
Pinned · c55ee460
Open full profile ↗
0693

codeql

Interprocedural security analysis with explicit database-quality and query-suite gates.

Main limitation
Requires CodeQL, jq, uv, a buildable target, and potentially long database construction.
First risk
Build and scan side effects · High
Source
Pinned · 32e34f81
Open full profile ↗
0793

semgrep

Approval-gated Semgrep security scans with telemetry disabled and auditable SARIF output.

Main limitation
Requires Semgrep and network access for registry or third-party rules; Pro-only cross-file analysis may be unavailable.
First risk
Third-party rules and source exposure · High
Source
Pinned · 32e34f81
Open full profile ↗
0893

differential-review

Risk-first security review for diffs, commits, and pull requests with blast-radius analysis.

Main limitation
Not intended for greenfield code or broad initial vulnerability discovery.
First risk
False assurance from incomplete context · High
Source
Pinned · 32e34f81
Open full profile ↗
0993

autoresearch

Autonomous, metric-driven code experiments that keep improvements and discard regressions.

Main limitation
Only fits tasks with a stable, representative numeric metric.
First risk
Autonomous repository mutation · High
Source
Pinned · 1f564408
Open full profile ↗
1093

anti-ui-slop

Instruction-only, product-specific UI design contracts with optional real-interface evidence and a hard finish gate.

Main limitation
Repository evidence is required; UIZZE references or user-provided screenshots are optional, and missing reference evidence should be labeled rather than guessed.
First risk
Copying external interface patterns too literally · Medium
Source
Pinned · 1f564408
Open full profile ↗
1193

bigquery-pipeline-audit

A targeted Python and BigQuery audit for runaway cost, unsafe reruns, scan size, writes, and observability.

Main limitation
Specialized to Python plus BigQuery and does not validate the live project configuration or billing account.
First risk
Audit estimates mistaken for billing guarantees · High
Source
Pinned · 1f564408
Open full profile ↗
1292

variant-analysis

Systematic hunts for other instances of a known bug or vulnerability root cause.

Main limitation
Requires one validated bug in hand; it is not an initial discovery workflow.
First risk
Overbroad automated matches · Medium
Source
Pinned · 32e34f81
Open full profile ↗
1392

web-design-reviewer

Browser-based visual review for responsive, accessible, consistent web interfaces with source-level fixes.

Main limitation
Requires a running target, browser automation, and source access for fixes.
First risk
Unintended changes during remote review · High
Source
Pinned · 1f564408
Open full profile ↗
1492

create-implementation-plan

Machine-readable implementation plans with atomic phases, dependencies, tests, risks, and unique identifiers.

Main limitation
Demanding zero ambiguity can create oversized plans or false precision for exploratory work.
First risk
False certainty from generated detail · Medium
Source
Pinned · 1f564408
Open full profile ↗
1592

create-technical-spike

Time-boxed technical research documents that turn one critical unknown into an evidence-backed decision.

Main limitation
Provides a document structure, not proof that experiments are representative or complete.
First risk
Prototype work affects real systems · High
Source
Pinned · 1f564408
Open full profile ↗
1691

tdd

A practical test-driven development workflow for coding agents.

Main limitation
The workflow needs a functioning test runner and clear public behavior.
First risk
False confidence · Medium
Source
Pinned · c55ee460
Open full profile ↗
1791

context-map

A pre-change map of files, dependencies, tests, reference patterns, and implementation risks.

Main limitation
The workflow is intentionally brief and may miss dynamic dependencies or runtime ownership.
First risk
Incomplete map treated as full scope · Medium
Source
Pinned · 1f564408
Open full profile ↗
1891

mcp-copilot-studio-server-generator

Generate an MCP server shaped for Copilot Studio integration.

Main limitation
Detailed package files are not fully catalogued.
First risk
Review before install · Medium
Source
Pinned · 1f564408
Open full profile ↗
1991

bug-receipt

Close defects with a structured diagnosis and verification receipt.

Main limitation
Detailed package files are not fully catalogued.
First risk
Review before install · Medium
Source
Pinned · 1f564408
Open full profile ↗
2091

csharp-async

Apply safe, modern asynchronous programming patterns in C#.

Main limitation
Detailed package files are not fully catalogued.
First risk
Review before install · Medium
Source
Pinned · 1f564408
Open full profile ↗
2191

csharp-mstest

Write modern MSTest tests with data-driven patterns.

Main limitation
Detailed package files are not fully catalogued.
First risk
Review before install · Medium
Source
Pinned · 1f564408
Open full profile ↗
2291

javascript-typescript-jest

Write maintainable Jest tests for JavaScript and TypeScript.

Main limitation
Detailed package files are not fully catalogued.
First risk
Review before install · Medium
Source
Pinned · 1f564408
Open full profile ↗
2391

mcp-security-audit

Audit MCP configuration for secrets, injection, and supply-chain risk.

Main limitation
Detailed package files are not fully catalogued.
First risk
Review before install · Medium
Source
Pinned · 1f564408
Open full profile ↗
2490

find-skills

Find Skills is Vercel's discovery workflow for locating and installing reusable Agent Skills.

Main limitation
Discovery quality depends on skills.sh coverage and current network access.
First risk
Unreviewed installation · Medium
Source
Pinned · 7407f389
Open full profile ↗
2590

vercel-react-best-practices

Vercel React Best Practices is a maintained performance guide for React and Next.js.

Main limitation
Rules need interpretation against the application's React, Next.js, and deployment versions.
First risk
Context-free optimization · Low
Source
Pinned · 063bee94
Open full profile ↗
2690

acquire-codebase-knowledge

Map an unfamiliar codebase before changing it.

Main limitation
Detailed package files are not fully catalogued.
First risk
Review before install · Medium
Source
Pinned · 1f564408
Open full profile ↗
2790

copilot-sdk

Build agentic applications with the GitHub Copilot SDK.

Main limitation
Detailed package files are not fully catalogued.
First risk
Review before install · Medium
Source
Pinned · 1f564408
Open full profile ↗
2890

mcp-cli

Inspect and call MCP servers from a command-line workflow.

Main limitation
Detailed package files are not fully catalogued.
First risk
Review before install · Medium
Source
Pinned · 1f564408
Open full profile ↗
2990

mcp-create-declarative-agent

Scaffold a declarative agent around MCP capabilities.

Main limitation
Detailed package files are not fully catalogued.
First risk
Review before install · Medium
Source
Pinned · 1f564408
Open full profile ↗
3090

bug-reproduction-brief

Turn a vague bug report into an evidence-backed reproduction.

Main limitation
Detailed package files are not fully catalogued.
First risk
Review before install · Medium
Source
Pinned · 1f564408
Open full profile ↗
3190

create-spring-boot-java-project

Scaffold a Spring Boot Java project with a coherent baseline.

Main limitation
Detailed package files are not fully catalogued.
First risk
Review before install · Medium
Source
Pinned · 1f564408
Open full profile ↗
3290

create-spring-boot-kotlin-project

Scaffold a Spring Boot Kotlin project with a coherent baseline.

Main limitation
Detailed package files are not fully catalogued.
First risk
Review before install · Medium
Source
Pinned · 1f564408
Open full profile ↗
3390

csharp-nunit

Apply current NUnit testing patterns and assertions.

Main limitation
Detailed package files are not fully catalogued.
First risk
Review before install · Medium
Source
Pinned · 1f564408
Open full profile ↗
3490

csharp-tunit

Build TUnit suites with modern test organization.

Main limitation
Detailed package files are not fully catalogued.
First risk
Review before install · Medium
Source
Pinned · 1f564408
Open full profile ↗
3590

csharp-xunit

Build maintainable xUnit tests including data-driven cases.

Main limitation
Detailed package files are not fully catalogued.
First risk
Review before install · Medium
Source
Pinned · 1f564408
Open full profile ↗
3690

java-junit

Apply JUnit 5 testing patterns including parameterized cases.

Main limitation
Detailed package files are not fully catalogued.
First risk
Review before install · Medium
Source
Pinned · 1f564408
Open full profile ↗
3790

java-mcp-server-generator

Generate a Java MCP server with the official SDK.

Main limitation
Detailed package files are not fully catalogued.
First risk
Review before install · Medium
Source
Pinned · 1f564408
Open full profile ↗
3890

kotlin-mcp-server-generator

Generate a Kotlin MCP server with the official SDK.

Main limitation
Detailed package files are not fully catalogued.
First risk
Review before install · Medium
Source
Pinned · 1f564408
Open full profile ↗
3990

mcp-implementation-security-review

Review MCP implementations for auth, validation, and code-execution risks.

Main limitation
Detailed package files are not fully catalogued.
First risk
Review before install · Medium
Source
Pinned · 1f564408
Open full profile ↗
4090

mcp-release-qa

Exercise a real MCP protocol session before release.

Main limitation
Detailed package files are not fully catalogued.
First risk
Review before install · Medium
Source
Pinned · 1f564408
Open full profile ↗
4186

improve-codebase-architecture

Improve Codebase Architecture explores code for architectural friction and proposes deeper modules with smaller interfaces.

Main limitation
Architecture quality depends on change history and domain context that may be incomplete.
First risk
Premature refactoring · Medium
Source
Pinned · c55ee460
Open full profile ↗
4286

setup-matt-pocock-skills

Setup Matt Pocock Skills is a repository configuration scaffold for a family of engineering workflows.

Main limitation
The output is tailored to Matt Pocock's Skill family rather than a universal standard.
First risk
Repository configuration changes · Medium
Source
Pinned · c55ee460
Open full profile ↗
4386

handoff

Handoff turns the current conversation into a compact continuation document for a fresh agent.

Main limitation
Compression can omit nuance that mattered in the original conversation.
First risk
Sensitive context leakage · High
Source
Pinned · c55ee460
Open full profile ↗
4486

triage

Matt Pocock's Triage Skill guides maintainers through incoming project issues—and external pull requests when the tracker config includes them.

Main limitation
The workflow requires correctly configured tracker operations and label vocabulary.
First risk
External tracker mutation · High
Source
Pinned · c55ee460
Open full profile ↗
4586

prototype

Prototype creates throwaway code to answer one design or logic question.

Main limitation
Prototype code intentionally omits production hardening, persistence, and broad edge-case coverage.
First risk
Prototype promoted to production · Medium
Source
Pinned · c55ee460
Open full profile ↗
4686

grilling

Grilling stress-tests a plan, decision, or idea as a dependency-aware design tree.

Main limitation
It deliberately delays implementation until the decision tree is complete and explicitly confirmed.
First risk
Decision fatigue or recommendation anchoring · Low
Source
Pinned · c55ee460
Open full profile ↗
4786

teach

Teach turns the current directory into a persistent learning workspace for one topic across many sessions.

Main limitation
It is for a sustained learning project, not a one-off explanation or an instant answer.
First risk
Untrusted teaching sources or unwanted workspace writes · Medium
Source
Pinned · c55ee460
Open full profile ↗
4886

domain-modeling

Domain Modeling turns a codebase's ubiquitous language into an actively maintained engineering artifact.

Main limitation
It documents language and decisions; it does not replace implementation design or domain-expert validation.
First risk
Institutionalizing the wrong model · Medium
Source
Pinned · c55ee460
Open full profile ↗
4986

ai-music

AI Music is a RunComfy CLI guide that routes song generation and editing across ElevenLabs Music and ACE Step models.

Main limitation
Generation and editing run through an authenticated hosted service; model capabilities and per-call prices differ and can change.
First risk
Copyright and remote generation · High
Source
Pinned · c163a9fd
Open full profile ↗
5086

codebase-design

Codebase Design supplies a shared vocabulary for reviewing modules, interfaces, seams, adapters, leverage, locality, and testability.

Main limitation
The vocabulary helps critique design but does not produce a correct architecture automatically.
First risk
Premature abstraction · Medium
Source
Pinned · c55ee460
Open full profile ↗
5185

diagnosing-bugs

Diagnosing Bugs is an evidence-first loop for difficult defects and performance regressions.

Main limitation
It requires a repeatable pass/fail signal; intermittent production-only failures may need observability or human evidence first.
First risk
Secrets captured in diagnostic evidence · High
Source
Pinned · c55ee460
Open full profile ↗
5285

reddit-automation

Reddit Automation finds recent high-intent Reddit discussions and drafts short, relevant replies for a human to review.

Main limitation
The Skill only drafts; it does not log in, store credentials, or post on Reddit. A person must review and publish each reply.
First risk
Spam, undisclosed promotion, and reputation damage · High
Source
Pinned · 0c9e2b63
Open full profile ↗
5385

code-review

Code Review is a two-axis review workflow for checking a diff against repository standards and its originating specification.

Main limitation
A meaningful review needs a non-empty diff, a fixed comparison point, and access to the relevant specification and standards.
First risk
False confidence from an incomplete review · Medium
Source
Pinned · c55ee460
Open full profile ↗
5485

implement

Implement turns an approved spec or ticket into code changes.

Main limitation
It needs a sufficiently clear spec or ticket and a working test toolchain; TDD may not fit every repository or change.
First risk
Unreviewed code and branch commits · High
Source
Pinned · c55ee460
Open full profile ↗
5585

ask-matt

Ask Matt is a router for Matt Pocock's engineering Skills: it maps a situation to a recommended workflow such as grilling, prototyping, specifying, ticketing, implementation, or review.

Main limitation
Recommendations are scoped to the workflows documented in the Matt Pocock repository and assume relevant companion Skills exist.
First risk
Following a workflow without its prerequisites · Medium
Source
Pinned · c55ee460
Open full profile ↗
5685

wayfinder

Wayfinder plans a large, unclear effort as a shared map of decision tickets on an issue tracker.

Main limitation
This workflow assumes a configured issue tracker or its documented local-markdown fallback and is intended for work too large for one session.
First risk
Confusing decisions with delivery · Medium
Source
Pinned · c55ee460
Open full profile ↗
5785

to-spec

To Spec synthesizes the current discussion and repository understanding into a project specification without conducting another interview.

Main limitation
It should synthesize what is already known rather than fill gaps through an interview; important ambiguities may remain unresolved.
First risk
Publishing unstated assumptions · High
Source
Pinned · c55ee460
Open full profile ↗
5885

to-tickets

To Tickets breaks an agreed plan, specification, or conversation into small, verifiable tracer-bullet tickets.

Main limitation
The configured tracker and label conventions must be known; the Skill asks the user to review ticket granularity and dependencies first.
First risk
Creating tracker work before it is approved · High
Source
Pinned · c55ee460
Open full profile ↗
5985

resolving-merge-conflicts

Resolving Merge Conflicts is a narrow workflow for an already-in-progress Git merge or rebase.

Main limitation
It is intended only for a merge or rebase already in progress, not as a general repository cleanup or reset workflow.
First risk
Finishing a conflict resolution incorrectly · High
Source
Pinned · c55ee460
Open full profile ↗
6085

twitter-automation

Twitter Automation from skills-101/superpowers uses the belt CLI to perform X account actions such as posting, liking, reposting, following, and direct messaging.

Main limitation
It performs account actions rather than merely drafting copy; availability and permissions depend on the current X integration and account access.
First risk
Public posting and account-control actions · High
Source
Pinned · becc2564
Open full profile ↗
6184

Minimal Run and Audit

Run a bounded research-code check and record the result, deviations, and evidence.

Main limitation
Detailed package files are not fully catalogued.
First risk
Review before install · Medium
Source
Pinned · fb3ccdf5
Open full profile ↗
6284

Repo Intake and Plan

Map research-code entry points and choose a minimal, trustworthy reproduction target.

Main limitation
Detailed package files are not fully catalogued.
First risk
Review before install · Medium
Source
Pinned · fb3ccdf5
Open full profile ↗
6383

caveman

Caveman is a persistent response-compression mode with lite, full, ultra, and classical-Chinese variants.

Main limitation
Compression can omit nuance, ambiguity, or rationale that mattered in the original conversation.
First risk
Critical nuance hidden by compression · Medium
Source
Pinned · 2fd153c6
Open full profile ↗