The best Claude Code skills are the ones that match a job you do every week, so this list is grouped by job: planning, debugging, review, documents, testing, building, design and security. Fourteen skills made it, drawn from the directory's top skills and its official publishers. Each entry has a "best for" line, what you need installed, and the trade-off you accept.
If you only have time for three, install brainstorming, systematic debugging and verification before completion. They change how Claude Code behaves on every task, and none of them needs an external tool.
How these Claude Code skills were chosen
Candidates came from the directory's overall top list, its official-publisher list and the agent-workflows category. A skill had to have a clear description of when it applies, a licence stated in its repository, and a pass or info result from the directory's automated safety check. Skills that failed that check are kept out of ranked lists, so none appear here.
The directory ranks with public signals: repository popularity, how many other GitHub owners keep a copy, the quality of the SKILL.md, and the safety check. That is a useful filter, not a verdict. Read how the ranking works before treating any order as a recommendation.
Facts below come from each skill's own SKILL.md and repository. The editorial team did not run every skill, so entries describe what the skill says it does, not measured results.
The best Claude Code skills at a glance
| Skill | Job | Licence | Needs |
|---|---|---|---|
| obra/brainstorming | Design before code | MIT | Nothing external |
| obra/writing-plans | Turn a spec into tasks | MIT | A spec |
| obra/systematic-debugging | Root-cause debugging | MIT | Nothing external |
| obra/verification-before-completion | Evidence before claims | MIT | Nothing external |
| obra/subagent-driven-development | Run a plan with subagents | MIT | A written plan, git worktrees |
| obra/receiving-code-review | Handle review feedback | MIT | Nothing external |
| anthropics/pdf | PDF work | Proprietary (see entry) | Python libraries, poppler tools |
| anthropics/webapp-testing | Test local web apps | Apache-2.0 | Python and Playwright |
| anthropics/skill-creator | Write and test skills | Apache-2.0 | Python |
| anthropics/mcp-builder | Build MCP servers | Apache-2.0 | Node or Python |
| nextlevelbuilder/ui-ux-pro-max | UI design guidance | MIT | Python 3 |
| vercel-labs/find-skills | Find more skills | MIT | Node (npx) |
| trailofbits/codeql | Static security scan | CC-BY-SA-4.0 | CodeQL CLI, jq, uv |
| vercel-labs/deepsec | AI security scan | Apache-2.0 | Node, model API key |
Planning and process skills
These skills slow Claude down in the right places. They come from the Superpowers collection by obra, which is MIT-licensed and updated this month.
Brainstorming
Brainstorming sorts a request into a spike, a bounded change or an architectural project, then blocks implementation until you approve the matching design. Architectural work ends in a written spec saved under docs/superpowers/specs and committed.
- Best for: new features where a wrong assumption costs a day.
- Requirements: none; it hands off to the writing-plans skill for large work.
- Trade-off: it asks questions before it writes code, which feels slow on a change you already understand.
Writing plans
Writing implementation plans converts a spec into small tasks, each with files, interfaces and checkbox steps, written for an engineer who has not seen the codebase. Plans save to docs/superpowers/plans by default.
- Best for: multi-step work you want to hand to subagents later.
- Requirements: a spec or clear requirements.
- Trade-off: it favors test-first steps and frequent commits, which you may need to relax for scripts and prototypes.
Debugging, verification and review skills
Systematic debugging
Systematic debugging states one rule: no fixes without root-cause investigation. It walks four phases, from reproducing and reading errors to writing a failing test, and says to stop and question the architecture after three failed fixes.
- Best for: failing tests and bugs where Claude tends to guess.
- Requirements: none.
- Trade-off: obvious one-line typos do not need four phases, so expect some ceremony.
Verification before completion
Verification before completion tells Claude to run the command that proves a claim, read the full output, and only then say work is done. Phrases like "should pass" are listed as red flags.
- Best for: teams tired of "fixed" messages that were never tested.
- Requirements: a test, build or lint command to run.
- Trade-off: extra command runs add time and tokens.
Subagent-driven development
Subagent-driven development gives each plan task to a fresh implementer subagent, runs a spec and quality review after every task, and finishes with a whole-branch review. For a deeper look at how subagents work, see our guide to Claude Code subagents.
- Best for: long plans with independent tasks.
- Requirements: a written plan, an isolated git worktree and a ledger file, as the skill specifies.
- Trade-off: it is the largest skill here, and each review round costs a fresh context.
Receiving code review
Receiving code review makes Claude verify feedback against the codebase before acting, ask about unclear items first, and push back with technical reasons. More options are in our roundup of code review skills.
- Best for: acting on comments from people or other bots.
- Requirements: none.
- Trade-off: it bans performative agreement, a style choice some teams will want to soften.
Document, testing and building skills
PDF processing
PDF processing covers extracting text and tables, merging, splitting, rotating, watermarking, form filling, encryption and OCR, using pypdf, pdfplumber, reportlab and command-line tools such as qpdf and pdftotext.
- Best for: repeatable PDF chores in a repository.
- Requirements: the Python libraries above, poppler tools, and pytesseract with pdf2image for OCR.
- Trade-off: the SKILL.md calls its licence proprietary and points to LICENSE.txt, and the repository README describes the document skills as source-available, not open source.
Web application testing
Web application testing drives local apps with Python Playwright scripts and ships a with_server.py helper that starts your dev server first. It inspects the rendered page before choosing selectors. Compare it with others in our browser automation and e2e testing guide.
- Best for: checking a frontend change against a running local app.
- Requirements: Python and Playwright with a browser installed.
- Trade-off: it is script-based, so it is not a full test suite for CI.
Skill creator
Skill creator drafts a skill, runs test prompts with and without it, shows results in a review viewer and tunes the description so it triggers. Its parallel test runs rely on subagents.
- Best for: writing your own skill, as covered in our guide to writing a skill.
- Requirements: Python; description tuning uses the claude CLI.
- Trade-off: the full loop is long for a ten-line skill.
MCP server builder
MCP builder works through research, implementation, review and evaluation, recommending TypeScript with the MCP SDK and offering Python with FastMCP.
- Best for: wrapping an API as an MCP server.
- Requirements: Node or Python.
- Trade-off: it is guidance rather than a generator, so you write the server.
Design and security skills
UI/UX Pro Max
UI/UX Pro Max bundles searchable local data on styles, palettes, font pairings and UX rules behind a Python search script, with accessibility ranked as its top priority category. See the frontend-design category for alternatives.
- Best for: giving Claude concrete design choices instead of default styling.
- Requirements: Python 3; the script needs no external dependencies.
- Trade-off: it adds a lot of design data, so pair it with your own brand rules.
CodeQL
CodeQL security scan builds a CodeQL database, creates project-specific data extensions and runs query suites, with a "run all" and an "important only" mode. The directory's check flags it as info.
- Best for: teams that already trust CodeQL for static analysis.
- Requirements: CodeQL CLI, jq and uv; the skill notes that commercial use needs appropriate CodeQL licensing.
- Trade-off: the skill itself is CC-BY-SA-4.0, which has share-alike terms.
Deepsec
Deepsec runs a regex pass over a repository, then has coding agents investigate flagged code. The tool is Apache-2.0.
- Best for: scanning large codebases or a diff against main.
- Requirements: Node and an OpenAI, Anthropic or Vercel AI Gateway credential.
- Trade-off: the maintainers say deep scans can be costly on large repositories.
Finding more skills
Find skills teaches Claude to search the open skills ecosystem with npx skills and to check install counts and source reputation before recommending anything. It is useful once you outgrow this list, though its own thresholds favor popular skills, which can hide good new ones.
How to install any of these skills in Claude Code
The Claude Code page documents four methods: the plugin marketplace, the skills CLI, the GitHub CLI and a manual copy. A typical flow for a single skill is:
npx skills add obra/superpowers --skill brainstorming -a claude-code
Add -g to install into ~/.claude/skills/ for all projects. Without it, the skill goes into .claude/skills/ in the current project. Anthropic's repository can also be added as a marketplace with /plugin marketplace add anthropics/skills, which then offers its document-skills and example-skills sets.
Run /skills inside Claude Code to confirm what loaded and where it came from.
Which Claude Code skills should you pick?
- Everyone: brainstorming, systematic debugging, verification before completion.
- Working from plans or in a team: writing plans, subagent-driven development and receiving code review.
- Building tools: skill creator and MCP builder.
- Frontend work: web application testing and UI/UX Pro Max.
- Handling PDFs: the PDF skill, after you check its licence fits.
- Security-minded repositories: CodeQL if you already use it, or Deepsec if API cost is acceptable.
Install two or three, use them for a week, and read the full lists at top skills before adding more. A short, distinct set triggers more reliably than a large overlapping one.
Frequently asked questions
What are the best Claude Code skills to install first?
Start with the ones that change how every task is done: a planning skill such as brainstorming, a debugging skill that insists on root causes, and a verification skill that stops Claude from claiming success without running a command. Add document, testing or design skills only when you have that kind of work.
Are Claude Code skills free to use?
Every skill in this list can be read and installed at no cost, but licences differ. Most are MIT or Apache-2.0, one is CC-BY-SA-4.0, and Anthropic's PDF skill is described as proprietary in its own file. Check the licence in the repository before using a skill in a commercial product.
How many skills can Claude Code load at once?
Claude Code keeps only the name and description of each skill in context and loads the full instructions when a skill is used. That makes a large library cheap, but vague or overlapping descriptions can make Claude pick the wrong skill, so install fewer, clearly different ones.
Where do Claude Code skills get installed?
Personal skills live in ~/.claude/skills/ and apply to every project. Project skills live in .claude/skills/ inside a repository and can be committed so the team shares them. Plugins can also bundle skills, and enabling the plugin makes them available.
Are these skills safe to install?
The directory runs an automated pattern check on each SKILL.md and shows the result, but it is not a security audit. A pass means no risky patterns matched. Read any skill that runs commands or scripts before you install it.