The shared Library, from the outside

Find the capability that fits this job.

This catalog is generated from Agent Toolkit's current capability sources. A catalog entry describes what exists; it does not claim you installed it or that a provider is connected.

145 entries · refreshed from source at build

Skills · 105

review

WCAG 2.2 AA curated accessibility review — distinguishes automatically detectable, browser-assisted, and manual/human-judgment findings with evidence citations and SC mapping. Composes with design-a

accessibility

mcp-audit

MCP config + implementation security audit — config secrets/auth, unpinned versions, remote vs local, OAuth, env exposure; implementation command injection, SSRF, unsafe args, tool poisoning. Static

agentic-security

owasp-agentic-review

OWASP-mapped agentic security review — prompt injection, tool poisoning, identity, excessive agency, credential exposure, supply-chain, insecure output handling, overreliance, data leakage, insecure

agentic-security

supply-chain-audit

Inspect agent supply chain — skills/plugins/MCP/npm/py packages, hooks, scripts, remote prompts, provenance, version pins, hashes, licenses, network and dangerous permissions — before adopting.

agentic-security

threat-modeling

STRIDE + agentic threat modeling — architecture discovery → assets/trust boundaries/data flows/actors → STRIDE + agentic threats → risk-ranked mitigations → incremental review → security a

agentic-security

architecture-diagram

WHAT — Create polished dark-themed architecture diagrams as self-contained HTML+SVG files (inline SVG, CSS styling, PNG/PDF export toolbar). Use when the user asks for system, infrastructure, cloud,

architecture

c4-model

WHAT — C4 model methodology (Context, Container, Component, Code) guidance — what to draw at each level, when, and how to render C4-inspired diagrams via Mermaid (PlantUML/Structurizr optional adv

architecture

aws-well-architected-review

WHAT — AWS Well-Architected Framework review (6 pillars) — operational excellence, security, reliability, performance, cost, sustainability + WAR process. Checklist for workload evaluation on AWS;

cloud

cloud-design-patterns

WHAT — Vendor-neutral distributed cloud patterns (Retry, Bulkhead, Circuit Breaker, CQRS, Event Sourcing, etc.) abstracted from AWS/Azure/GCP sources — when to apply, tradeoffs, mapping to AWS/GCP

cloud

assistant

Assistant — on any repo, scan README→docs→AGENTS→CONTRIBUTING→PR templates→task runners→devcontainer→CI→configs before code; cite sources; prefer AGENTS.md for agent behavior; portab

core

dev-companion

WHAT — Dev Companion (general): layered companion for client delivery; modes, gates, delegation to assistant and workflow-generic-project; no CLI matrices.

core

onboarding

Getting started guide for new users. Walks through setup validation, the skill/agent hierarchy, and the three most useful commands per role (developer, PM, tech lead). Use when someone is new to the w

core

output-handshake

WHAT — Default gate for any deliverable: confirm where the final artifact will be stored and that a human will review, before writing PRDs, TRDs, ADRs, or PR bodies. Repository paths, wikis, and tic

core

pr-fallback

WHAT — When the repo has no GitHub PR template, structure the pull-request body using the default in references/pr-body-default.md. Pair with output-handshake and github-cli-workflow. Does not open

core

project

Clone, index, and orchestrate multi-repo work via agent-toolkit project — symlinks, quick access, and swarm workspaces.

core

workspace

Scaffold and manage the stateless AI workspace — context, packs, repos, and knowledge for multi-repo orchestration.

core

workspace-knowledge-sync

Syncs knowledge to the agentic-harness knowledge base and AGENTS.md learned facts. Use when the assistant discovers new patterns, learns user preferences, workspace facts, or identifies information wo

core

dbt-validation

HOW — Run dbt checks as documented in the target repo (parse, compile, test, selective run). Does not configure Snowflake accounts or change cloud security.

data

snowflake-validation

HOW — Read-only Snowflake validation patterns: use repo-documented CLI (snowflake/sql) or SQL checks. Never claim success without working credentials and evidence.

data

adr

WHAT — Create and maintain Architecture Decision Records (ADRs) per the process. Covers when to write an ADR, required sections, review, and linking to epics/PRs. English for cross-team artifacts un

delivery

agreement

WHAT - Capture explicit agreements, terms, parties involved, dates, validity, and linked work items using the Agreement Document structure.

delivery

bug

WHAT - Draft and review bugs using the Bug Template; classifies whether an issue should be escalated to incident based on production/user impact.

delivery

decision-log

WHAT - Capture lightweight project, product, or operational decisions that do not require a full ADR; includes rationale, date, owner, and references.

delivery

development-workflow

WHAT - Default development workflow, task lifecycle, DoR, DoD, validation, and evidence model when a project has no explicit override. Repository instructions still take precedence.

delivery

epic

WHAT - Draft and review epics using the Best Practices Epic Template; includes objectives, success criteria, related tasks, stakeholders, and effort metadata.

delivery

incident

WHAT - Draft and review incident reports and RCA notes using Incident Management guidance; includes detection, impact, timeline, RCA, resolution, and follow-ups.

delivery

management-unit-assessment

WHAT - Evidence-based management unit assessment for governance, delivery, collaboration, culture, and AI-native management readiness. Interactive and source-driven before any score is assigned.

delivery

meeting-minutes

WHAT - Create structured meeting minutes from notes or transcripts using meeting templates, with redaction, action items, decisions, and traceability.

delivery

planning

WHAT - Planning, estimation, task breakdown, and iteration capacity fallback based on Best Practices. Use before finalizing backlog scope, story/task estimates, or iteration commitments.

delivery

prd

WHAT — Draft and review a Product Requirements Document (PRD) using the template. Business-level requirements, acceptance criteria, and traceability. Does not replace the product owner. English for

delivery

project-assessment

WHAT - Interactive project assessment router: define assessment scope and units, collect evidence through project-assessment-evidence, then delegate to technical or management unit assessment skills.

delivery

project-assessment-evidence

WHAT - Interactive evidence intake for project assessments. Ask the user where each evidence source lives, build an evidence map, track missing evidence, assumptions, freshness, and confidence before

delivery

spike

WHAT - Produce spike and research findings using the spike template; captures purpose, findings, implementation strategy, risks, tradeoffs, open questions, and references.

delivery

task

WHAT - Draft and review technical tasks using the Best Practices Task Template; includes summary, technical notes, AC, estimate, owner, and due date.

delivery

technical-unit-assessment

WHAT - Evidence-based technical unit assessment for repositories, platforms, frontend, backend, infrastructure, data, UI/UX, and AI-native structural readiness.

delivery

trd

WHAT — Draft and review a Technical Requirements Document (TRD) using the template, typically from an agreed PRD. Covers architecture, data contracts, technical decisions, risks, and test strategy.

delivery

user-story

WHAT - Draft and review user stories using the task template plus the As a/I want/so that format from Best Practices examples.

delivery

work-item

WHAT - Router for creating and refining epics, user stories, tasks, bugs, and incidents using Best Practices work item hierarchy.

delivery

workflow-client-bootstrap

WHAT — Interactive interview to capture client delivery context and store it inside the user's ~/.ai-workspace (or similar) as packs + knowledge (no client skills). Use when onboarding a new client

delivery

workflow-generic-project

WHAT — Generic client delivery: Jira or ClickUp, full repo context, human gates, English traceability on tickets, draft PR via delegated forge skills. Use workspace packs for client/account overlays

delivery

brag

Turn the current project website into a short, polished, shareable launch video using Hyperframes. Use when someone says "/brag", "let's brag about this", "make a launch video", "turn this into a vide

design

brag-slim

Turn a project directory or a website URL into a short, shareable launch video with music, motion, and share copy. One file, no bundled assets — built entirely by the model with the tools already on

design

design-assessment

WHAT - Evidence-based design-unit assessment orchestrated by project-assessment. Evaluates visual hierarchy, UX friction, interaction, a11y, responsiveness, design-system compliance, and distinctivene

design

design-improvement

WHAT - Browser-grounded iterative design improvement. Consumes design-assessment findings, defines direction, prioritizes safe vs ambiguous changes, implements within existing design system, runs app,

design

figma

Use the Figma MCP server to fetch design context, screenshots, variables, and assets, and to translate Figma nodes into production code. Trigger when a task involves Figma URLs, node IDs, design-to-co

design

figma-code-connect-components

Connects Figma design components to code components using Code Connect mapping tools. Use when user says "code connect", "connect this component to code", "map this component", "link component to code

design

figma-create-design-system-rules

Generates custom design system rules for the user's codebase. Use when user says "create design system rules", "generate rules for my project", "set up design rules", "customize design system guidelin

design

figma-create-new-file

Create a new blank Figma file. Use when the user wants to create a new Figma design or FigJam file, or when you need a new file before calling use_figma. Handles plan resolution via whoami if needed.

design

figma-implement-design

Translates Figma designs into production-ready application code with 1:1 visual fidelity. Use when implementing UI code from Figma files, when user mentions "implement design", "generate code", "imple

design

frontend-design

Guidance for distinctive, intentional visual design when building new UI or reshaping an existing one. Helps with aesthetic direction, typography, and making choices that don't read as templated defau

design

frontend-design-review

Review and create distinctive, production-grade frontend interfaces with high design quality and design system compliance. Evaluates using three pillars: frictionless insight-to-action, quality craft,

design

web-design-guidelines

Review UI code for Web Interface Guidelines compliance. Use when asked to "review my UI", "check accessibility", "audit design", "review UX", or "check my site against best practices".

design

fix-merge-conflicts

Resolve merge conflicts non-interactively, validate build and tests, and finalize conflict resolution

forge

gh-address-comments

Triage and address open GitHub PR review and conversation comments using the gh CLI. Use when the user wants to "address PR comments", "resolve review threads", or "respond to reviewers" on the curren

forge

gh-contribution-planner

Daily GitHub contribution planner — analyzes the gh-logged-in user's non-archived repos (owned + forks) and recent contributions, produces a prioritized plan, halts for approval, then dispatches par

forge

gh-fix-ci

Diagnose failing GitHub Actions checks on a PR via gh, summarize the failure context, propose a plan, and only implement after explicit user approval. External CI providers (Buildkite, CircleCI, etc.)

forge

github-cli-workflow

HOW — GitHub CLI (gh): push branch, create draft PR with title/body from template or file; fallback untracked PR_DESCRIPTION_*.md. Use when origin is GitHub.

forge

gitlab-cli-workflow

HOW — GitLab CLI (glab): push branch, create draft MR with title/body; fallback untracked markdown. Use when origin is GitLab.

forge

worktree

Manage Git worktrees per writer for Agent Toolkit swarms — isolated branches, handoff promotion, and cleanup.

forge

clickup-cli

ClickUp CLI for managing tasks, sprints, comments, statuses, and Docs. Use when the user needs to interact with ClickUp — creating/editing tasks, checking sprint status, adding comments, linking PRs

integrations

confluence-admin

Confluence administration including users, groups, space settings, and permission diagnostics. Use when managing user access, group membership, viewing space configuration, or checking permissions.

integrations

confluence-analytics

View analytics, statistics, and popularity metrics for Confluence content. ALWAYS use when user wants to see views, popularity, or contributor stats.

integrations

confluence-assistant

Central hub for Confluence operations - routes requests to specialized skills. ALWAYS use when user mentions confluence, wiki, or Atlassian wiki operations.

integrations

confluence-attachment

Manage file attachments - upload, download, list, and delete attachments. ALWAYS use when user wants to work with files on pages.

integrations

confluence-bulk

Bulk operations for 50+ pages - updates, moves, deletions, labels, and permissions. Use when updating multiple pages simultaneously (dry-run preview included), needing rollback safety, or coordinating

integrations

confluence-comment

Manage comments on Confluence pages - add, get, update, delete, and resolve comments. ALWAYS use for feedback, discussions, and inline annotations.

integrations

confluence-hierarchy

Navigate and manage Confluence page hierarchies, ancestors, descendants, and trees. ALWAYS use for parent/child relationships and page tree navigation.

integrations

confluence-jira

JIRA integration - embed issues, create links between products. ALWAYS use when user wants to connect Confluence and JIRA.

integrations

confluence-label

Manage content labels - add, remove, and search by labels. ALWAYS use when user wants to tag, label, or categorize content.

integrations

confluence-ops

Cache management, API diagnostics, and operational utilities. Use when optimizing performance, managing cache, diagnosing API issues, or troubleshooting Confluence connectivity.

integrations

confluence-page

Manage Confluence pages and blog posts - create, read, update, delete, copy, move, and version control. ALWAYS use when user wants to work with page content, create pages, update pages, or manage page

integrations

confluence-permission

Manage space and page permissions and restrictions. ALWAYS use when user wants to control access, set restrictions, or manage who can view/edit content.

integrations

confluence-property

Manage content properties (custom metadata) on Confluence pages and blog posts. ALWAYS use for custom metadata, key-value data, or application-specific fields.

integrations

confluence-search

Search Confluence using CQL queries, validate syntax, export results, and manage search history. ALWAYS use when user wants to find, search, or query for content.

integrations

confluence-space

Manage Confluence spaces - create, list, update, delete, and configure spaces. ALWAYS use when user wants to work with spaces (not individual pages).

integrations

confluence-template

Work with page templates and blueprints. ALWAYS use when user wants to create standardized pages or manage templates.

integrations

confluence-watch

Content watching and notifications. ALWAYS use when user wants to follow content or manage notifications.

integrations

jira-assistant

Jira Cloud, Jira Software and Jira Service Management automation through the jira-as CLI (2.x). Run `jira-as help` first; find operations with `jira-as api search` and `jira-as api describe`.

integrations

linear

Manage Linear issues, projects and cycles via the Linear MCP server. Use when the user wants to read, triage, create or update Linear tickets, plan a sprint, audit Linear documentation, or rebalance t

integrations

mcp

Configure and manage MCP providers for Agent Toolkit — setup, list, doctor, and per-tool deployment.

integrations

slack-assistant

Interact with Slack workspaces for reading channels/messages, sending messages, adding reactions, and browsing canvases. Use when the user asks about Slack channels, messages, or notifications — NOT

integrations

slack-cli

Interact with the official Slack CLI to create, run, deploy, and manage Slack apps, environments, manifests, and triggers. Use when the user asks about Slack app development workflows, not workspace c

integrations

loop-runner

Execute and manage loop engineering primitives (init, run, status, audit) from an AI coding session via the agent-toolkit loop CLI.

loops

docs-generator

WHAT — Generate or update documentation from code: README.md from repo structure, CHANGELOG.md from git history, API reference from OpenAPI/GraphQL schemas, and AGENTS.md starters for new projects.

ops

llm-cost-advisor

WHAT — Recommend the most cost-effective LLM provider for a given task type. Shows estimated cost per run across available providers and integrates with devcompanion llm-status to show what is actua

ops

swarm

Launch an Agent Toolkit swarm from a natural language request using agent-toolkit swarm CLI with Herdr/tmux eager windows and file handoffs.

ops

swarm-handoff

Create artifact/commit file handoffs for Agent Toolkit swarms with worktree-per-writer, branch, and promotion integration.

ops

swarm-observer

Observe, diagnose, and recover Agent Toolkit swarm runs via status, handoffs, logs, and attach with worktree and shell awareness.

ops

triage

Workstation health triage — validate tooling, directory layout, and run doctor with remediation suggestions.

ops

blast-radius

Find what a change could break somewhere else before it ships, beyond the diff, and prove the one fact it's safe because of by running real code instead of writing it up. Use for 'blast radius of X',

quality

codeql

CodeQL operational workflow — discover/config, run/inspect, triage SARIF findings (rule/query ID, source→sink, evidence), remediate, re-validate. Distinguishes broad MegaLinter linting from semant

quality

deep-review

Evidence-based deep code review rubric — severity + confidence findings across maintainability, correctness, security, performance, and testing. Push for ambitious structural simplification (code ju

quality

deslop

Remove AI-generated code slop and clean up code style

quality

megalinter

Entry point for everything MegaLinter. Use when the user wants to lint their repository, set up MegaLinter, check or fix lint errors, make CI lint jobs pass, or says "run megalinter", "fix lint errors

quality

megalinter-check

Collect MegaLinter lint errors for the current repository. Use when the user wants to know if the code passes linting, why the MegaLinter CI job fails, or before/after fixing lint errors. Two modes -

quality

megalinter-fix

Fix the errors reported by MegaLinter. Use after megalinter-check found errors, or when the user pastes MegaLinter/CI lint errors and wants them fixed. Applies safe fixes automatically (auto-fix linte

quality

megalinter-setup

Install or upgrade MegaLinter on a repository. Use when the user wants to add MegaLinter to a project, set up linting CI, update MegaLinter configuration or version, or says "install megalinter", "set

quality

unslop

Cut AI tells from any writing. Must always apply.

quality

chrome-devtools

Use Chrome DevTools MCP to control and inspect a live Chrome instance for network, console, performance, rendering, and Deep debugging. Pairs with playwright-cli (deterministic interaction/E2E) — co

tooling

cli-for-agents

Designs or reviews CLIs so coding agents can run them reliably: non-interactive flags, layered --help with examples, stdin/pipelines, fast actionable errors, idempotency, dry-run, and predictable stru

tooling

herdr

Manage Herdr workspaces, tabs, and panes for Agent Toolkit swarms with eager windows, shell-aware execution, and reuse.

tooling

inventory

Discover installed skills, agents, loops, and platform capabilities via agent-toolkit inventory, matrix, and skills list.

tooling

jupyter-notebook

Create, scaffold, or refactor Jupyter notebooks (.ipynb) for experiments and tutorials. Prefer the bundled templates and the helper script (`new_notebook.py`, also exposed as `newnotebook`) to generat

tooling

mermaid

WHAT — Mermaid diagrams from text (flowchart, sequence, class, state, ER, gantt, gitGraph) — Markdown-native, Git-native, MIT. Primary renderer for architecture pack; renders via GitHub native or

tooling

playwright-cli

Drive a real browser from the terminal using the Playwright CLI (snapshot, click, fill, screenshots, traces). Use when the task is CLI-first browser automation (data extraction, UI debugging, form fil

tooling

Agent Definitions · 18

agentic-security-reviewer

Agentic security review specialist — prompt injection, tool poisoning, excessive agency, credential exposure, supply-chain, MCP/plugin hardening with OWASP LLM01-10 + AGNT01-06. Use when security-en

specialist

architect

Software architecture and system design specialist. Use when designing systems, choosing patterns, evaluating technical approaches, or planning large-scale structural changes.

holistic

assistant

agent-toolkit Dev Companion — follows internal conventions and best practices. Use for any work in agent-toolkit or client repositories to ensure compliance with agent-toolkit standards.

orchestrator

build-error-resolver

Build and TypeScript error resolution specialist — large diagnostic context, root-cause triage across tsc/lint/webpack/vite. Use when platform-engineer delegates CI failure logs or fix requires full

specialist

client-workflow-bootstrap

Meta-generator / orchestrator — onboarding interview that meta-generates <client>-workflow + <client>-dev-companion skills and opens a draft PR. Use when onboarding a new client project or updating

orchestrator

code-reviewer

Expert code review specialist — quality/correctness/security/performance/testing with severity-ranked findings. Use when reviewer/qa-engineer delegates deep craft or PR explicitly warrants independe

specialist

data-engineer

Data engineering specialist — dbt/Snowflake validation, Jupyter notebooks, data artifact stewardship. Use when: dbt parse/compile/test, Snowflake read-only checks, notebook scaffolding, or validatin

holistic

designer

Design routing and UI/UX specialist — owns contextual selection among design skills (frontend-design, frontend-design-review, web-design-guidelines, design-assessment, design-improvement, Figma fami

holistic

e2e-runner

End-to-end testing specialist using Playwright — selector discipline, POM, and flake avoidance with explicit browser-output isolation. Use when qa-engineer delegates E2E authoring/debugging or task

specialist

implementer

Implementation specialist — feature/bug/refactoring delivery, build/test loop, TDD-aware scaffolding and docs generation. Use when: new feature or bug fix, refactoring with behavior preservation, sc

holistic

planner

Expert planning specialist for complex features and refactoring. Use before starting any significant implementation to break down work, identify risks, and create an actionable plan.

holistic

platform-engineer

Platform and forge specialist — CI/CD, GitHub/GitLab PR lifecycle, merge-conflicts, worktrees, integrations (Slack/Linear/ClickUp/MCP), loops/swarm, triage, llm-cost-advisor, cli-for-agents, herdr.

holistic

qa-engineer

Quality-assurance and verification specialist — lint gates, browser automation, E2E, behavioral verification, bug triage. Use when: verifying behavior before ship, writing/debugging E2E tests, runni

holistic

researcher

Research and discovery specialist — spike findings, evidence-intake, framework/docs exploration, inventory, reference examples. Use when: unknown needs time-boxed investigation, implementation strat

holistic

reviewer

Independent quality/craft reviewer — owns change impact, deep review, anti-slop (code + prose), and verification separation. Use when: PR review, refactor review, prose/doc review before publish, or

holistic

security-engineer

Security hardening specialist — app + agentic security, threat modeling, supply-chain/MCP audit, SARIF triage. Use when: security-sensitive PR/endpoint, agentic/MCP/plugin change, supply-chain befor

holistic

security-reviewer

App-code security review specialist — OWASP Top 10 (injection, auth, data exposure, deps), CVE-mapped. Use when security-engineer delegates app-surface hardening or code change touches auth/data/API

specialist

tdd-guide

Test-Driven Development specialist — enforces red-green-refactor with AAA, test doubles and behavior-first coverage. Use when implementer delegates test-first discipline or task explicitly requires

specialist

Loops · 10

changelog-drafter

Draft release notes from merged PRs (L1, report-only)

L1 · 1d

ci-sweeper

Detect CI failures and propose fixes via draft PRs (L2, cautious)

L2 · 15m

daily-triage

Triage new issues and propose labels (report-only)

L1 · 1d

dep-sweeper

Apply patch-level dependency updates via draft PRs (L2)

L2 · 1d

issue-triage

Propose labels and routing for new issues (L1, propose-only)

L1 · 4h

oss-daily-briefing

Daily read-only briefing across OSS ecosystem repos (L1)

L1 · 1d

oss-pr-monitor

Monitor open PRs across OSS ecosystem repos and take action (L3, daily)

L3 · 1d

oss-triage

Triage issues across OSS ecosystem repos (L1, daily)

L1 · 1d

post-merge-cleanup

Off-peak housekeeping after merges (L2, low impact)

L2 · 6h

pr-babysitter

Monitor open PRs and post review comments (L2, PR-gated)

L2 · 15m

MCP providers · 7

Chrome DevTools

Control and inspect a live Chrome instance — network, console, performance traces, rendering diagnostics, reliable automation via Puppeteer + DevTools protocol

official

ClickUp

View and create tasks, manage lists and spaces, add comments, read and write Docs

community

Figma

Fetch design context, file structure, component metadata, and screenshots for design-to-code

official

GitHub

Access GitHub repositories, issues, PRs, code, and CI via the official GitHub MCP server

official

Linear

Create and update issues, manage projects and cycles, add comments, query sprints

official

Notion

Read and write Notion pages and databases, query blocks, and create content

official

Slack

Read channel history, post messages, add reactions, and browse Slack workspaces

official

Distributions · 5

Agent Toolkit Core

Core orchestration skills, dev companion, output handshake, PR fallback, and code-reviewer agent. The baseline install for any project.

stable

Agent Toolkit Agents

18 AI agent personas: 11 holistic (planner, architect, designer, implementer, reviewer, qa-engineer, security-engineer, platform-engineer, researcher, data-engineer) + orchestrator (assistant, client-workflow-bootstrap) + 5 specialists (code-reviewer, agentic-security-reviewer, security-reviewer, e2e-runner, tdd-guide, build-error-resolver) — 7 specialists archived to references in #865 (typescript/database/performance/refactor → reviewer/references/*; docs/reference-lookup → researcher/references/LOOKUP_GUIDE.md; tech-assistant → platform-engineer/references/WORKSTATION_OPS.md) — see docs/AGENT_TAXONOMY.md §8.

stable

Agent Toolkit Forge

GitHub and GitLab automation skills: PR workflows, CI fixes, comment resolution, and contribution planning.

stable

Agent Toolkit Craft

Writing quality and change-safety toolkit: cut AI tells (unslop), remove code slop (deslop), and prove blast radius before shipping.

stable

Agent Toolkit Complete

Full stable skill catalog coverage for consumers who want everything (#50)

experimental

Catalog metadata comes from catalogs/, mcp/registry/ and distributions/products.yaml in the Agent Toolkit repository. Installation state is intentionally not shown here.