Agent Skills Directories and Marketplaces
Claude skills marketplaces and directories for Claude Code and Codex on a Mac. Which to trust, and how to check a skill before you install it.
Use a skill for a repeatable task you want done the same way each time, such as correcting "AI writing" habits. A skill is like a pre-written prompt that an agent loads on its own when the task is needed.
You don't have to write every skill yourself. Other developers have written skills for common jobs, such as reviewing code, writing tests, working with Word, Excel and PDF files, or using a company's own product the way its makers intend. Installing one gives Claude Code or Codex a ready-made procedure for that job. But a skill can also run programs on your Mac, so safety awareness is important.
You'll find thousands of skills online: in marketplaces built into your AI app, in directories, and in lists on GitHub. Here I explain where to look first, to what degree a listing checks skills (most check very little), and how to check a skill before you add it. To learn how skills work and how to write your own, see Developer Setup for Agent Skills.
MCP servers are another common way to give an agent new abilities, explained in MCP or Skills or CLI?. See MCP Server Directories and Lists for ways to find MCP servers.
Finding good skills is part of setting up a Mac for AI coding. See the complete Mac setup checklist.
Before you get started
I recommend using our free app to add your first skills. It is a FREE Mac app that installs the developer tools and AI coding agents you need, adds skills to Claude Code and Codex, and verifies your setup is working. Here are all the details about the app before you download. Then download it:
Understand skill marketplaces, directories and lists
You'll see four kinds of places that list skills:
- App marketplaces - catalogs for AI apps, such as Claude Code's plugin marketplace. They are the smallest and the most carefully chosen.
- Install tools - commands such as
npx skillsandgh skill, which fetch a skill from GitHub and put it in the right folders. Some have a website that ranks skills by how often people install them. - Directories - websites that collect skills from public GitHub repositories, with search and categories. The largest list millions of skills and check almost none of them.
- Lists on GitHub - "awesome lists" are pages of links sorted by category. Anyone can suggest an addition.
The largest directory counts over 3 million SKILL.md files, including copies, experiments and abandoned projects, while the marketplace built into Claude Code lists a few hundred plugins.
Start with your AI app's own marketplace
The marketplaces built into your AI app are the best place to start. Anthropic or OpenAI chooses what they list, and many of the plugins come from the companies whose products they work with:
- Claude Code's plugin marketplace - Anthropic's official marketplace is built into Claude Code. Type
/pluginand choose Discover to browse over 300 plugins, many of which include skills, or browse them on the web at claude.com/marketplace/plugins. Anthropic marks some plugins "Anthropic verified", but it says it doesn't control what other publishers put inside their plugins. - Anthropic's own skills - Anthropic's skills repository on GitHub holds its example skills, including the ones that work with Word, Excel, PowerPoint and PDF files. Anthropic says they are for demonstration and learning.
- Codex - type
$skill-installerin Codex to install skills from OpenAI's collection, or/pluginsto browse the plugin directory that Codex shares with ChatGPT. OpenAI publishes its plugins on GitHub in openai/plugins, and has marked its older openai/skills repository as deprecated. - Claude Desktop and claude.ai - your Claude account has its own skills, for Claude Desktop's Chat tab and for claude.ai. Open
Customize > Skillsto turn on Anthropic's skills or upload your own.
Add Anthropic's community marketplace
Anthropic also runs a community marketplace with over 2,000 plugins from other developers. Each one passed an automated security scan before Anthropic accepted it. Claude Code installs only the exact version the marketplace lists, so a publisher can't change a plugin after it was scanned. To add the marketplace, type /plugin marketplace add anthropics/claude-plugins-community in Claude Code, then type /plugin to browse it with the others.
Install skills across agents with skills.sh
skills.sh is Vercel's directory of skills, ranked by how many people install each one with Vercel's npx skills tool. Its Official tab lists skills published by about 100 companies, such as Anthropic, AWS and Cloudflare. Skills join the rankings automatically when someone installs them, so a listing isn't a recommendation.
Three security companies, Gen, Socket and Snyk, scan the skills listed on skills.sh, and the site hides any they flag as malicious. The scans help, but in June 2026 researchers at Trail of Bits got malicious skills past all three.
To install a skill you find there, use the npx skills tool, which needs Node.js:
$ npx skills add <owner>/<repo>
For the options that choose which agents get the skill, see Developer Setup for Agent Skills.
Install and pin skills with the GitHub CLI
The GitHub CLI, GitHub's command-line tool, has a gh skill command, still a preview. Use it to search GitHub for skills, read a skill before you install it, and install it for Claude Code, Codex and many other agents. The command records where each skill came from, and its --pin option locks a skill to one version, so an update can't change it without your knowing. GitHub warns that skills may contain prompt injections (hidden instructions to your agent). To search for skills on a topic:
$ gh skill search <topic>
GitHub's awesome-copilot collection holds over 400 skills from other publishers, and gh skill can install them for Claude Code or Codex as well as for GitHub Copilot.
Browse skills from companies' own developer teams
officialskills.sh and its GitHub list, VoltAgent/awesome-agent-skills, collect skills published by companies' own developer teams: about 660 skills from 56 companies. A skill from the company that makes a product is the safest kind to start with, but the list says it doesn't audit the skills it includes.
Use a list that people review
The security company Trail of Bits keeps a small list, skills-curated, and its staff reviews the code of every skill on it. The list is short, but it is one of the few places where a person checks each skill.
Search the large skill directories
The large directories list everything they can find on GitHub. They are useful for searching, but they check little or nothing:
- SkillsMP - over 3 million skills collected from public GitHub repositories. It says it does no safety review, and it doesn't say who runs it. Use it to search, then read the skill on its own GitHub page.
- Smithery - about 24,000 skills, listed beside its MCP servers. Smithery installs a skill with its own command-line tool.
- LobeHub - over 330,000 skills, with an install command for each one.
Neither Smithery nor LobeHub says what it checks before listing a skill.
Browse the awesome-claude-skills lists on GitHub
Awesome lists are long pages of links on GitHub. Anyone can suggest an addition, and no one checks the skills:
- ComposioHQ/awesome-claude-skills - the most popular list, with about 77,000 stars, but most of its entries are Composio's own skills for connecting your agent to apps through Composio's service.
- travisvn/awesome-claude-skills - a short list with a useful section on security. It was last updated in April 2026.
- hesreallyhim/awesome-claude-code - a wider list of Claude Code resources, including skills.
Check a skill before you install it
Skills are easy to publish and easy to fake. In February 2026, researchers at Koi Security found 341 malicious skills on ClawHub, the marketplace for an AI agent called OpenClaw, and the count later passed 800. The skills told Mac users to paste a scrambled terminal command as a "prerequisite", which installed malware that steals passwords (PolySwarm's report has the details). When Snyk scanned nearly 4,000 skills from ClawHub and skills.sh, 13% had a critical security problem.
Before you add a skill, check these things:
- Who publishes it - prefer a skill from the company that makes the product, or from Anthropic or OpenAI. For any other skill, look at the publisher's GitHub account, how many people use the skill, and how recently it was updated.
- What its files say - read
SKILL.mdand every script in the folder. Be wary of instructions to download or run something, long strings of scrambled text, and compressed files. - What it can do without asking - in Claude Code, an
allowed-toolsline lets a skill use the tools it lists without your permission. A!followed by a command in backticks runs that command before Claude reads the skill. A plugin can also include hooks (commands that run automatically) and MCP servers, which run with your permissions. - Whether it can change - a skill that updates itself can change after you've checked it. Pin it to a version where you can (
gh skill installhas a--pinoption), and leave automatic updates off for marketplaces you don't trust. - Whether it needs scripts - a skill that is only instructions is safer than one that runs programs.
Treat a security scan as one signal, not proof. Researchers at Trail of Bits got malicious skills past every scanner they tested, including the three that skills.sh uses, and most of their attacks took under an hour to build. Anthropic's own advice is to use skills you made yourself or got from Anthropic, and to treat installing a skill like installing software (Anthropic's security considerations).
Add a skill you found
I've written a how-to for Claude Code and Codex. See Developer Setup for Agent Skills for where skills go on a Mac, how to install one from GitHub, and how to share one skill between Claude Code and Codex. For when a skill is the right choice, rather than an MCP server or a command-line tool, see MCP or Skills or CLI?.
Continue setting up your Mac
Don't miss the full visual roadmap and checklist that shows how to set up a Mac for software development, with all the essential tools and settings you might not yet know about.