Agent skill

Find Skills

by burkeholland in burkeholland/max

Helps users discover agent skills when they ask questions like "how do I do X", "find a skill for X", "is there a skill that can...", or express interest in extending capabilities.

MITAuto-check passedSecurity

Install Find Skills

skills CLI
$ npx skills add burkeholland/max --skill find-skills -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install burkeholland/max find-skills --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/burkeholland/max.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/find-skills .claude/skills/find-skills && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
find-skills
GitHub stars
142
Token cost
~1.5k tokens
SKILL.md length
641 words
Files
2
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

Helps users discover agent skills when they ask questions like "how do I do X", "find a skill for X", "is there a skill that can...", or express interest in extending capabilities.

  • Works in 3 steps: Search the API → Fetch Security Audits → Present Combined Results
  • Tasks that involve Security review
  • SKILL.md covers When to Use, Search & Present, Install and Behavioral Security Review, plus 2 more sections
  • Calls curl; reaches skills.sh and raw.githubusercontent.com

What it does

Find Skills is an agent skill from burkeholland/max. Helps users discover agent skills when they ask questions like "how do I do X", "find a skill for X", "is there a skill that can...", or express interest in extending capabilities. Always ask the user for permission before installing any skill, and flag security risks.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `_meta.json`).

It sits in Security, covering Security review. The repository describes itself as: Personal AI daemon built on the GitHub Copilot SDK — control via Telegram or terminal. The licence is MIT.

When your agent uses it

  • Tasks that involve Security review

Example prompts

  • “how do I do X”
  • “find a skill for X”
  • “is there a skill that can...”
  • “/find-skills”

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Search the API
  2. Fetch Security Audits
  3. Present Combined Results

What it can do on your machine

Read from SKILL.md and the folder at commit 9b388db. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • skills.sh
    • raw.githubusercontent.com
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Find Skills loads about 1.5k tokens when it runs. Until then it costs about 70 tokens; SKILL.md has 641 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~70
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from burkeholland/max at commit 9b388db, republished under its MIT licence (© burkeholland). 641 words, ~1,523 tokens.

Download SKILL.mdSave it as .claude/skills/find-skills/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
find-skills
description
Helps users discover agent skills when they ask questions like "how do I do X", "find a skill for X", "is there a skill that can...", or express interest in extending capabilities. Always ask the user for permission before installing any skill, and flag security risks.

Find Skills

Discover and install skills from the open agent skills ecosystem at https://skills.sh/.

When to Use

Use this skill when the user:

  • Asks "how do I do X" where X might be a common task with an existing skill
  • Says "find a skill for X" or "is there a skill for X"
  • Asks "can you do X" where X is a specialized capability
  • Expresses interest in extending agent capabilities
  • Wants to search for tools, templates, or workflows

Search & Present

Do these two steps in a worker session — they can run in parallel:

1. Search the API
bash
curl -s "https://skills.sh/api/search?q=QUERY"

Replace QUERY with a URL-encoded search term (e.g., react, email, pr+review). The response is JSON with skills sorted by installs (most popular first):

json
{
  "skills": [
    {
      "id": "vercel-labs/agent-skills/vercel-react-best-practices",
      "skillId": "vercel-react-best-practices",
      "name": "vercel-react-best-practices",
      "installs": 174847,
      "source": "vercel-labs/agent-skills"
    }
  ]
}
2. Fetch Security Audits

Required — do not skip. Use the web_fetch tool to get the audits page:

web_fetch url="https://skills.sh/audits"

If web_fetch fails or returns unexpected content, still present the search results but show "⚠️ Audit unavailable" for all security columns and include a link to https://skills.sh/audits so the user can check manually.

This returns markdown where each skill has a heading (### skill-name) followed by its source, then three security scores:

  • Gen Agent Trust Hub: Safe / Med Risk / Critical
  • Socket: Number of alerts (0 is best)
  • Snyk: Low Risk / Med Risk / High Risk / Critical

Scan the returned markdown to find scores for each skill from your search results. Match by both skill name and full source (owner/repo) to avoid misattribution — different repos can have skills with the same name.

3. Present Combined Results

Cross-reference the search results with the audit data and format as a numbered table. Show the top 6-8 results sorted by installs:

#  Skill                         Publisher      Installs   Gen    Socket  Snyk
─  ─────────────────────────────  ─────────────  ────────   ─────  ──────  ────────
1  vercel-react-best-practices   vercel-labs     175.3K    ✅Safe  ✅ 0    ✅Low
2  web-design-guidelines         vercel-labs     135.8K    ✅Safe  ✅ 0    ⚠️Med
3  frontend-design               anthropics      122.6K    ✅Safe  ✅ 0    ✅Low
4  remotion-best-practices       remotion-dev    125.2K    ✅Safe  ✅ 0    ⚠️Med
5  browser-use                   browser-use      45.0K    ⚠️Med  🔴 1    🔴High

Formatting:

  • Sort by installs descending
  • Format counts: 1000+ → "1.0K", 1000000+ → "1.0M"
  • ✅ for Safe / Low Risk / 0 alerts, ⚠️ for Med Risk, 🔴 for High Risk / Critical / 1+ alerts
  • If a skill has no audit data, show "⚠️ N/A" — never leave security blank
  • Publisher = first part of source field (before /)

After the table:

🔗 Browse all: https://skills.sh/

Pick a number to install (or "none")

Install

NEVER install without the user picking a number first.

When the user picks a skill:

Security Gate

If ANY of its three audit scores is not green (Safe / 0 alerts / Low Risk), warn before proceeding:

⚠️ "{skill-name}" has security concerns:
  • Gen Agent Trust Hub: {score}
  • Socket: {count} alerts
  • Snyk: {score}

Want to proceed anyway, or pick a different skill?

Wait for explicit confirmation. Do not install if the user says no.

Show full SKILL.md (273 more words)Show less
Fetch & Install
  1. Fetch the SKILL.md from GitHub. The source field is owner/repo and skillId is the directory:
bash
curl -fsSL "https://raw.githubusercontent.com/{source}/main/{skillId}/SKILL.md" || \
curl -fsSL "https://raw.githubusercontent.com/{source}/master/{skillId}/SKILL.md"

If both fail, tell the user and link to https://github.com/{source}.

  1. Validate the fetched content: it must not be empty and should contain meaningful instructions (more than just a title). If the content is empty, an HTML error page, or clearly not a SKILL.md, do NOT install — tell the user it couldn't be fetched properly.

  2. Install using the learn_skill tool:

    • slug: the skillId from the API
    • name: from the SKILL.md frontmatter name: field (between --- markers). If no frontmatter, use skillId.
    • description: from the SKILL.md frontmatter description: field. If none, use the first sentence.
    • instructions: if frontmatter exists, use the content after the closing ---. If no frontmatter, use the full fetched content as instructions.

Always install to ~/.max/skills/ via learn_skill. Never install globally.

Behavioral Security Review

In addition to audit scores, review the fetched SKILL.md content before installing. Flag concerns if the skill:

  • Runs arbitrary shell commands or executes code on the user's machine
  • Accesses sensitive data — credentials, API keys, SSH keys, personal files
  • Makes network requests to external services (data exfiltration risk)
  • Comes from an unknown or unverified source with no audit data

If any of these apply, warn the user with specifics even if audit scores are green:

⚠️ Note: "{skill-name}" requests shell access and reads files from your home directory.
This is common for CLI-integration skills, but worth knowing. Proceed?

When No Skills Are Found

If the API returns no results:

  1. Tell the user no existing skill was found
  2. Offer to help directly with your general capabilities
  3. Suggest building a custom skill if the task is worth automating

Uninstalling

Use the uninstall_skill tool with the skill's slug to remove it from ~/.max/skills/.

© burkeholland, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/find-skills of burkeholland/max.

  • SKILL.md
  • _meta.json

Open the folder on GitHubat commit 9b388db

Compare with similar skills

Find Skills next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Find Skills compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Find Skills this skillburkeholland/max142—~1.5kAutomated safety check: PassMIT
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Kubernetes Network Security Auditkubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0
Native Dependency Updatemono/SkiaSharp5.6k—~4.1kAutomated safety check: PassMIT
Semgrep Security Scantrailofbits/skills7.5k—~3.7kAutomated safety check: NotesCC-BY-SA-4.0
Skillward AuditFangcun-AI/SkillWard143—~2.9kAutomated safety check: PassCustom licence

Similar skills

  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 12 days ago
    SecurityAuto-check passed
  • Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

    12k GitHub stars~7.3k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

    5.6k GitHub stars~4.1k tokensUpdated yesterday
    SecurityAuto-check passed
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.5k GitHub stars~3.7k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Skillward Audit

    Fangcun-AI/SkillWard

    Security-audit a third-party skill bundle (folder with SKILL.md, or .zip / .tar.gz archive) before installing it, using the SkillWard cloud scanner.

    143 GitHub stars~2.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    551 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes

Categories

Questions about Find Skills

What does Find Skills do?

Helps users discover agent skills when they ask questions like "how do I do X", "find a skill for X", "is there a skill that can...", or express interest in extending capabilities. Find Skills is an agent skill from burkeholland/max.", or express interest in extending capabilities.

When should I use Find Skills?

Find Skills fits situations like: tasks that involve Security review.

How do I install Find Skills in Claude Code?

Run `npx skills add burkeholland/max --skill find-skills -a claude-code`. Or copy the skill folder (skills/find-skills in burkeholland/max) into .claude/skills/find-skills in your project. Claude Code loads it when a task matches its description.

How do I install Find Skills in Codex?

Run `npx skills add burkeholland/max --skill find-skills -a codex`. Or copy the skill folder (skills/find-skills in burkeholland/max) into .agents/skills/find-skills in your project. Codex loads it when a task matches its description.

Can I use Find Skills in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add burkeholland/max --skill find-skills -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/find-skills, .gemini/skills/find-skills, .github/skills/find-skills and .opencode/skills/find-skills in your project.

What does Find Skills need to run?

Going by SKILL.md and its folder, Find Skills needs the command-line tools its instructions call (curl).

Does Find Skills access the network?

SKILL.md names 3 domains. In commands or code: skills.sh, raw.githubusercontent.com and github.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Find Skills safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Find Skills use?

Find Skills is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Find Skills use?

About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Find Skills?

Skills that share tags, products or a category with Find Skills: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars), Native Dependency Update (mono/SkiaSharp, 5.6k stars) and Semgrep Security Scan (trailofbits/skills, 7.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Find Skills?

burkeholland (a GitHub user) maintains it in burkeholland/max, which has 142 GitHub stars. The repository was last updated on May 23, 2026.

Source: burkeholland/max on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.