Principle Redesign From First Principles
cursor/plugins
Apply when integrating a new requirement into an existing design.
Reference for writing and editing agent skills well — the vocabulary and principles that make a skill predictable.
$ npx skills add trailofbits/skills-curated --skill writing-great-skills -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install trailofbits/skills-curated writing-great-skills --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/trailofbits/skills-curated.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/productivity/skills/writing-great-skills .claude/skills/writing-great-skills && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "writing-great-skills" agent skill from https://github.com/trailofbits/skills-curated/tree/main/plugins/productivity/skills/writing-great-skills into .claude/skills/writing-great-skills/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "writing-great-skills", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/trailofbits/skills-curated/tree/main/plugins/productivity/skills/writing-great-skillsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add trailofbits/skills-curated --skill writing-great-skills -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install trailofbits/skills-curated writing-great-skills --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills-curated.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/productivity/skills/writing-great-skills .agents/skills/writing-great-skills && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "writing-great-skills" agent skill from https://github.com/trailofbits/skills-curated/tree/main/plugins/productivity/skills/writing-great-skills into .agents/skills/writing-great-skills/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "writing-great-skills", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trailofbits/skills-curated --skill writing-great-skills -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install trailofbits/skills-curated writing-great-skills --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills-curated.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/productivity/skills/writing-great-skills .cursor/skills/writing-great-skills && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "writing-great-skills" agent skill from https://github.com/trailofbits/skills-curated/tree/main/plugins/productivity/skills/writing-great-skills into .cursor/skills/writing-great-skills/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "writing-great-skills", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/trailofbits/skills-curated.git --path plugins/productivity/skills/writing-great-skills--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add trailofbits/skills-curated --skill writing-great-skills -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install trailofbits/skills-curated writing-great-skills --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills-curated.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/productivity/skills/writing-great-skills .gemini/skills/writing-great-skills && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "writing-great-skills" agent skill from https://github.com/trailofbits/skills-curated/tree/main/plugins/productivity/skills/writing-great-skills into .gemini/skills/writing-great-skills/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "writing-great-skills", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install trailofbits/skills-curated writing-great-skillsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add trailofbits/skills-curated --skill writing-great-skills -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/trailofbits/skills-curated.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/productivity/skills/writing-great-skills .github/skills/writing-great-skills && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "writing-great-skills" agent skill from https://github.com/trailofbits/skills-curated/tree/main/plugins/productivity/skills/writing-great-skills into .github/skills/writing-great-skills/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "writing-great-skills", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trailofbits/skills-curated --skill writing-great-skills -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install trailofbits/skills-curated writing-great-skills --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills-curated.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/productivity/skills/writing-great-skills .opencode/skills/writing-great-skills && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "writing-great-skills" agent skill from https://github.com/trailofbits/skills-curated/tree/main/plugins/productivity/skills/writing-great-skills into .opencode/skills/writing-great-skills/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "writing-great-skills", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
writing-great-skillsReference for writing and editing agent skills well — the vocabulary and principles that make a skill predictable.
Writing Great Skills is an agent skill from trailofbits/skills-curated, published by the product's own GitHub organization. Reference for writing and editing agent skills well — the vocabulary and principles that make a skill predictable. Consult when authoring, reviewing, or pruning a SKILL.md.
Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/GLOSSARY.md`).
The repository describes itself as: Curated, community-vetted Claude Code plugin marketplace. The licence is CC-BY-SA-4.0.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 6d05be4. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadGrepGlobEditWriteFrom allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Writing Great Skills loads about 2.5k tokens when it runs, and up to ~7.2k if it reads all its reference files. Until then it costs about 48 tokens; SKILL.md has 1,528 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from trailofbits/skills-curated at commit 6d05be4, republished under its CC-BY-SA-4.0 licence (© trailofbits). 1,528 words, ~2,532 tokens.
.claude/skills/writing-great-skills/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.A skill exists to wrangle determinism out of a stochastic system. Predictability — the agent taking the same process every run, not producing the same output — is the root virtue; every lever below serves it.
Bold terms are defined in GLOSSARY.md; look them up there for the full meaning.
Two choices, trading different costs:
disable-model-invocation, and write a model-facing description with rich trigger phrasing ("Use when the user wants…, mentions…").disable-model-invocation: true; the description becomes human-facing — a one-line summary, trigger lists stripped.Pick model-invocation only when the agent must reach the skill on its own, or another skill must. If it only ever fires by hand, make it user-invoked and pay no context load.
When user-invoked skills multiply past what you can remember, that piled-up cognitive load is cured by a router skill: one user-invoked skill that names the others and when to reach for each.
A model-invoked description does two jobs — state what the skill is, and list the branches that should trigger it. Every word increases context load, so a description earns even harder pruning than the body:
A skill is built from two content types — steps and reference — that mix freely: a skill can be all steps, all reference, or both. The core decision is which to use and where each sits on the information hierarchy, a ladder ranked by how immediately the agent needs the material:
SKILL.md, the primary tier: what the agent does, in order. Each step ends on a completion criterion, the condition that tells the agent the work is done. Make it checkable (can the agent tell done from not-done?) and, where it matters, exhaustive ("every modified model accounted for", not "produce a change list") — a vague criterion invites premature completion.SKILL.md, consulted on demand. Often a legitimately flat peer-set (every rule of a review on one rung) — a fine arrangement, not a smell. This skill is all reference.SKILL.md into a separate file, reached by a context pointer, loaded only when the pointer fires. (Spans disclosed reference — a sibling file like GLOSSARY.md, still part of the skill — through fully external reference that lives outside the skill system and any skill can point at.)A demanding completion criterion drives thorough legwork — the digging the agent does within the work — whether the skill has steps or not, since "every rule applied" binds flat reference just as "every step done" binds a sequence.
Push too little down and the top bloats; push too much and you hide material the agent actually needs. That tension is the whole decision.
Progressive disclosure is the move down the ladder — out of SKILL.md into a linked file — so the top stays legible. Mechanics: a linked .md file in the skill folder, named for what it holds (this skill discloses its full definitions to GLOSSARY.md). Some skills are used in more than one way, and each distinct way is a branch — different runs taking different paths through the skill. Branching is the cleanest disclosure test: inline what every branch needs, and push behind a pointer what only some branches reach. A context pointer's wording, not its target, decides when and how reliably the agent reaches the material.
Where the ladder decides how far down a piece sits, co-location decides what sits beside it once there: keep a concept's definition, rules, and caveats under one heading rather than scattered, so reading one part brings its neighbours with it.
Granularity is how finely you divide skills, and each cut spends one of the two loads, so split only when the cut earns it. Two cuts:
Keep each meaning in a single source of truth: one authoritative place, so changing the behaviour is a one-place edit.
Check every line for relevance: does it still bear on what the skill does?
Then hunt no-ops sentence by sentence, not just line by line: run the no-op test on each sentence in isolation, and when one fails, delete the whole sentence rather than trim words from it. Be aggressive — most prose that fails should go, not be rewritten.
A leading word is a compact concept already living in the model's pretraining that the agent thinks with while running the skill (e.g. lesson, fog of war, tracer bullets). Repeated throughout the text (though not necessarily - a strong leading word might only be needed once), it accumulates a distributed definition and anchors a whole region of behaviour in the fewest tokens, by recruiting priors the model already holds.
It serves predictability twice. In the body it anchors execution: the agent reaches for the same behaviour every time the word appears. In the description it anchors invocation: when the same word lives in your prompts, docs, and code, the agent links that shared language to the skill and fires it more reliably.
Hunt for opportunities to refactor skills to use leading words. A triad spelled out at three sites (duplication), a description spending a sentence to gesture at one idea — each is a passage begging to collapse into a single token. Examples include:
You win twice over: fewer tokens, and a sharper hook for the agent to hang its thinking on. Assume every skill is carrying restatements that leading words retire — go find them.
Use these to diagnose issues the user may be having with the skill.
© trailofbits, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in plugins/productivity/skills/writing-great-skills of trailofbits/skills-curated.
Open the folder on GitHubat commit 6d05be4
Writing Great Skills next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Writing Great Skills this skilltrailofbits/skills-curated | 513 | — | ~2.5k | Automated safety check: Pass | CC-BY-SA-4.0 | |
| Principle Redesign From First Principlescursor/plugins | 11k | 8 repos | ~211 | Automated safety check: Pass | None | |
| Uxui Principlessickn33/agentic-awesome-skills | 47k | 2 repos | ~548 | Automated safety check: Pass | MIT | |
| Health Wellnesssickn33/agentic-awesome-skills | 47k | 1 repos | ~3.5k | Automated safety check: Pass | MIT | |
| AWS Well Architected Reviewgithub/awesome-copilot | 40k | — | ~1.9k | Automated safety check: Pass | MIT | |
| Azure Well Architected Reviewgithub/awesome-copilot | 40k | — | ~2.5k | Automated safety check: Pass | MIT |
cursor/plugins
Apply when integrating a new requirement into an existing design.
sickn33/agentic-awesome-skills
Evaluate interfaces against 168 research-backed UX/UI principles, detect antipatterns, and inject UX context into AI coding sessions.
sickn33/agentic-awesome-skills
Wellbeing check-in register: anonymous flag, department, check-in date, wellbeing score, stress and energy levels, support and resource flags, confidentiality and status.
github/awesome-copilot
Perform an AWS Well-Architected Framework review of the current workload IaC and architecture, generating findings and GitHub issues for improvements.
github/awesome-copilot
Perform an Azure Well-Architected Framework review of the current workload IaC and architecture, generating findings and GitHub issues for improvements.
mindfold-ai/Trellis
Systematic first principles thinking for any problem domain.
trailofbits/skills-curated
Analyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensitive-code ownership, and export CSV/JSON for graph databases and visualization.
trailofbits/skills-curated
A skill your agent uses when the task involves reading, creating, or editing .docx documents, especially when formatting or layout fidelity matters; prefer python-docx plus the bundled…
trailofbits/skills-curated
A skill your agent uses when the agent is building or iterating on a web game (HTML/JS) and needs a reliable development + testing loop: implement small changes, run a Playwright-based test script…
trailofbits/skills-curated
A skill your agent uses when the user asks to create, scaffold, or edit Jupyter notebooks (.ipynb) for experiments, explorations, or tutorials; prefer the bundled templates and run the helper script…
trailofbits/skills-curated
A skill your agent uses when the task requires automating a real browser from the terminal (navigation, form filling, snapshots, screenshots, data extraction, UI-flow debugging) via playwright-cli…
trailofbits/skills-curated
Searches X/Twitter for real-time perspectives, dev discussions, product feedback, breaking news, and expert opinions using the X API v2.
Reference for writing and editing agent skills well — the vocabulary and principles that make a skill predictable. Writing Great Skills is an agent skill from trailofbits/skills-curated, published by the product's own GitHub organization. Reference for writing and editing agent skills well — the vocabulary and principles that make a skill predictable.
Run `npx skills add trailofbits/skills-curated --skill writing-great-skills -a claude-code`. Or copy the skill folder (plugins/productivity/skills/writing-great-skills in trailofbits/skills-curated) into .claude/skills/writing-great-skills in your project. Claude Code loads it when a task matches its description.
Run `npx skills add trailofbits/skills-curated --skill writing-great-skills -a codex`. Or copy the skill folder (plugins/productivity/skills/writing-great-skills in trailofbits/skills-curated) into .agents/skills/writing-great-skills in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trailofbits/skills-curated --skill writing-great-skills -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/writing-great-skills, .gemini/skills/writing-great-skills, .github/skills/writing-great-skills and .opencode/skills/writing-great-skills in your project.
SKILL.md names no scripts, command-line tools or credentials: Writing Great Skills is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Grep, Glob, Edit, Write.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Writing Great Skills is published under the CC-BY-SA-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.6k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Writing Great Skills: Principle Redesign From First Principles (cursor/plugins, 11k stars), Uxui Principles (sickn33/agentic-awesome-skills, 47k stars), Health Wellness (sickn33/agentic-awesome-skills, 47k stars) and AWS Well Architected Review (github/awesome-copilot, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
trailofbits (a GitHub organization, an official publisher) maintains it in trailofbits/skills-curated, which has 513 GitHub stars. The repository holds 24 skills in this directory. The repository was last updated on July 14, 2026.
Source: trailofbits/skills-curated on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.