Skip to content
guides

claude skills: we read the code of 20 popular skill repos before recommending any

Claude skills: glowing tool cartridges checked under a magnifier, one rejected into a red tray, a robot hand waiting guides

Claude skills are folders with a SKILL.md file: instructions, and sometimes scripts, that Claude loads when a task matches. in Claude Code you install them with /plugin install, put them in ~/.claude/skills/, or type /skill-name to run one. skills can also run code and add hooks, so before recommending any we downloaded 20 popular skill repositories from GitHub and read their hooks and scripts. we found no sign of malicious code, but most come with something you should know first, and two we wouldn't install. below: how skills work, the most installed ones, our findings repository by repository, the best skills by task, and three of our own skills you can download.

what are claude skills

a skill is a folder with a SKILL.md: a short description at the top, instructions below, and optionally reference files and scripts. Claude normally sees the descriptions; the full text loads only when a task matches, or when you call the skill with /skill-name. that makes skills cheap to keep around: long reference material costs almost nothing until it's used. skills follow the open Agent Skills standard, so the same folder also works in Codex, Cursor and other agents, though extras like hooks depend on the agent.

how skills differ from the rest of Claude Code:

what it is when to use it
skill instructions (and scripts) loaded when relevant a repeatable way of doing a job: a review checklist, a writing style, a document format
CLAUDE.md instructions loaded in every session project facts and rules that always apply
slash command now the same thing as a skill: .claude/commands/deploy.md and .claude/skills/deploy/SKILL.md both create /deploy
MCP server a connection to an outside tool or data source when Claude needs to reach Notion, a database, a browser
subagent a separate worker with its own context side tasks you don't want filling the main session
plugin a package of skills, agents, hooks and MCP servers installing someone else's setup in one step

in claude.ai and the Claude apps, skills live in settings; Anthropic's pdf, xlsx, docx and pptx skills are built in there and sync to Claude Code (version 2.1.273 or later, logged in with your Claude account, not an API key). skills in the Claude apps work on the free plan too, with code execution turned on. we covered MCP servers in how to build an MCP server and Claude Code itself in our Claude Code guide.

how to install claude skills

three ways to install them:

1. as a plugin, from inside Claude Code. Anthropic's official marketplace is added the first time you start Claude Code in a terminal:

/plugin install superpowers@claude-plugins-official

other marketplaces are added from their GitHub repository first:

/plugin marketplace add anthropics/skills
/plugin install document-skills@anthropic-agent-skills

plugin skills are called as /plugin-name:skill-name. a plugin can also switch on hooks and MCP servers, so check what it contains. a marketplace can pin a specific commit, which may differ from the latest code on GitHub.

2. by copying the folder. put it in ~/.claude/skills/<skill-name>/SKILL.md for all your projects, or in .claude/skills/ inside a project and commit it for your team. Claude Code picks up changes to skill folders while it runs; if the skills folder itself didn't exist when the session started, run /reload-skills after each change in that session.

3. with npx skills add owner/repo, the cross-agent installer behind the skills.sh catalog. it's convenient, but npx runs the installer's code on your machine, so it isn't just copying files.

avoid installs that pipe a script from the internet into your shell (curl ... | bash). several popular skill repos still offer that as an option; all the ones we checked also have a plugin or copy path.

if a skill doesn't show up or never triggers: ask Claude "what skills are available?", check that the description contains the words you'd actually use, and run claude plugin validate ~/.claude/skills. descriptions share a budget of about 1% of the context window, so with many skills installed some descriptions get cut; /doctor shows how much room they take and which skills take the most. a personal skill wins over a project skill with the same name.

the most installed claude skills and plugins

install counts on September 28, 2026 in Anthropic's official plugin marketplace (340 plugins) and in skills.sh, the biggest cross-agent catalog. the top of skills.sh, find-skills with 3.6 million installs, is the catalog's own helper for finding other skills, so it's left out here, as are two more of Matt Pocock's skills with about a million each (grill-with-docs, improve-codebase-architecture). some rows are single skills, others whole plugins:

skill what it does installs
frontend-design (Anthropic) interfaces without the generic "AI look" 1.13 million (official), 931,000 (skills.sh)
Superpowers brainstorm, plan, test-first, review and debug as a fixed workflow 1.01 million (official)
grill-me (Matt Pocock) questions you about requirements before any code 1.24 million (skills.sh)
tdd, handoff, triage (Matt Pocock) test-driven development, session handoff notes, bug triage 850,000 to 980,000 each (skills.sh)
agent-browser (Vercel) browser control for the agent 963,000 (skills.sh)
code-review (Anthropic) reviews a pull request and posts comments on it 439,000 (official)
context7 current library documentation through MCP 418,000 (official)
react-best-practices (Vercel) React and Next.js rules 750,000 (skills.sh)
ui-ux-pro-max styles, palettes, font pairs and UX rules 374,000 (skills.sh)
pptx, pdf, docx, xlsx (Anthropic) office documents 175,000 to 228,000 each (skills.sh)
seo-audit, copywriting (Corey Haines) marketing 216,000 and 210,000 (skills.sh)
chart of the most installed Claude skills: grill-me, frontend-design, Superpowers, tdd, agent-browser, react-best-practices
the most installed skills on September 28, 2026, in Anthropic's official marketplace and on skills.sh

install counts can be gamed. on the day we looked, several brand-new repositories named "superpowers", with 0 to 5 GitHub stars, showed hundreds of thousands of installs on skills.sh; they had nothing to do with the real Superpowers and repackaged another company's skills with a curl ... | sh login step. big packages also inflate numbers: a vendor's 20 skills installed as one bundle all show the same count. check the GitHub repository, its stars, age and last update before trusting an install number.

we read the code of 20 top skill repos

on September 28 we downloaded 20 popular skill repositories from GitHub, picked by stars, recent activity and the topics people search for, without installing or running anything. a script searched their text and code files for the usual warning signs: scripts piped from the internet, code downloaded and executed, reading keys, ~/.ssh or .env, writing to shell startup files or scheduled tasks, destructive commands, hidden characters, encoded payloads and instructions like "don't tell the user". then a second model, OpenAI's Codex, read the hooks and the scripts the skills tell Claude to run (for Anthropic's official marketplace, the most popular plugins in it), and flagged what they do. we checked flagged spots ourselves.

we found no sign of malicious code in any of the 20. most matches were documentation and tests: security-minded skills are full of phrases like "ignore previous instructions" precisely because they teach Claude not to follow them. but most repositories do something you should know before installing:

repository stars our verdict what to know
blader/humanizer 52,500 fine text editing only
phuryn/pm-skills 26,600 fine 69 product management skills and 42 workflows; its audit commands read the code and write a report
anthropics/skills 179,000 fine, with notes web-artifacts-builder installs pnpm globally; skill-creator stops whatever process is on the port it wants
official Anthropic plugins 37,000 fine, with notes code-review posts comments on your pull request; security-guidance sends your diffs to Anthropic's API for review and installs a Python package itself; ralph-loop can keep Claude working with no limit by default
obra/superpowers 292,000 fine, with notes the official marketplace installs a slightly older pinned version than the one we read; a startup hook adds its workflow to every session; its optional visual companion loads a logo from the author's site (SUPERPOWERS_DISABLE_TELEMETRY=1 turns it off)
mattpocock/skills 271,000 fine, with notes the wizard skill reads your .env files; don't use the repo's link-skills.sh, which deletes same-named skill folders
addyosmani/agent-skills 99,600 fine, with notes optional hooks temporarily rewrite source files on disk while Claude reads them
vercel-labs/agent-skills 31,700 fine, with notes the deploy skill uploads your project folder to Vercel and ignores .gitignore
nextlevelbuilder/ui-ux-pro-max-skill 131,000 core skill only its image generators read API keys from ~/.claude/.env and send prompts to outside services; don't copy its stack settings
Leonxlnx/taste-skill 90,800 fine, with notes tells Claude to install UI packages and to use any image generator you have connected
OthmanAdi/planning-with-files 27,200 fine, with notes hooks run at session start and around file and shell operations; the skill pre-approves broad shell access
tt-a1i/archify 73,300 fine, with notes silently checks the author's site for updates (ARCHIFY_UPDATE_CHECK_DISABLED=1 turns it off)
DietrichGebert/ponytail 147,000 fine, with notes switches the whole session, subagents included, into its minimal-code mode
kepano/obsidian-skills 49,000 fine, with notes two skills install command-line tools globally with npm
coreyhaines31/marketingskills 51,800 fine, with notes the writing skills are text only; its command-line tools really send emails and change ad campaigns once you add API keys
AgriciDaniel/claude-seo 17,800 plugin only its add-ons write API keys into your global Claude Code settings; some checks send text and images to Google's APIs
trailofbits/skills 7,300 pick single plugins security tools; some hooks change your PATH; the devcontainer plugin runs Claude with permission checks off inside a container
higgsfield-ai/skills 1,200 fine, with notes skills tell Claude to install Higgsfield's CLI with curl ... \| sh, which asks for your password (sudo) to install; face photos go to Higgsfield for training; generation spends credits
JuliusBrussee/caveman 108,000 we wouldn't install the CLI an optional hook auto-approves commands like git reset --hard and kubectl delete; its CLI sends telemetry by default; the README offers curl ... \| bash
mvanhorn/last30days-skill 63,100 we wouldn't install its optional Grok backend runs an agent with all permission checks off on untrusted posts from X; it can read your browser's cookies through the keychain
our code check of 20 Claude skill repositories: 2 fine, 16 fine with notes, 2 we wouldn't install
we found no malicious code in the 20 repositories; most have something worth knowing before you install

what we took from reading the code:

  • hooks are the part to read first. a skill's instructions only run when Claude follows them; a plugin's hooks run automatically on every session start, prompt or tool call. seven of the 20 include plugins that turn hooks on when installed, and two more offer optional hooks.
  • skills can pre-approve tools. the allowed-tools line in a SKILL.md lets Claude use the listed tools, including the shell, without asking. Anthropic's own docs say to review it for skills checked into a repository before you run Claude Code there.
  • "installs software by itself" is the common risk, not malware. several skills tell Claude to install software globally, or to fetch and run an installer, as part of doing the job.
  • stars say nothing about safety. the two we wouldn't install have 63,000 and 108,000 stars.

the best claude skills by task

picked from the repositories above, with the notes from our check in mind.

  • software development: Superpowers for a full plan, test and review workflow; Matt Pocock's skills (grill-me, tdd, handoff, triage) if you want smaller pieces; Addy Osmani's agent-skills for 25 engineering practices; Anthropic's code-review plugin for pull requests.
  • design and frontend: Anthropic's frontend-design first; ui-ux-pro-max (core skill) for palettes, fonts and UX rules; taste-skill against generic-looking pages; Vercel's react-best-practices for React and Next.js.
  • documents: Anthropic's pdf, xlsx, docx and pptx, already built into claude.ai and synced to Claude Code.
  • long tasks: planning-with-files keeps the plan in files that survive /compact and new sessions.
  • diagrams: archify for architecture, sequence and data-flow diagrams.
  • marketing, SEO and writing: Corey Haines' marketingskills (copywriting, CRO, SEO audit, programmatic SEO); claude-seo for technical SEO, schema and E-E-A-T; humanizer for removing AI patterns from text.
  • product management: pm-skills, from discovery to launch.
  • security: single plugins from Trail of Bits for vulnerability hunting and audits.
  • notes: kepano's obsidian-skills, from Obsidian's CEO.
  • writing your own: Anthropic's skill-creator (below).

higgsfield skills

Higgsfield, the AI image and video platform, publishes an official set of 8 skills: higgsfield-generate (images, video, 3D and audio on 30+ models, with a Marketing Studio mode for UGC-style ads and a virality predictor), higgsfield-soul-id (a character trained on 5 to 20 photos of a face), and higgsfield- versions of product-photoshoot, brandkit, marketplace-cards, websites, video-explainer and youtube-thumbnail. they're instructions on top of Higgsfield's own command-line tool: the work runs on Higgsfield's servers and costs Higgsfield credits, and you log in with your Higgsfield account. there's also a Higgsfield MCP server for Claude, and a catalog of about 35 ready skills and workflows for ads, motion graphics and UGC videos on Higgsfield's site.

install the skills with /plugin marketplace add higgsfield-ai/skills, then /plugin install higgsfield@higgsfield. install Higgsfield's CLI yourself first, with brew install higgsfield-ai/tap/higgsfield or npm install -g @higgsfield/cli, so Claude doesn't run the curl ... | sh installer the skills fall back to.

3 skills of ours you can download

we use these every day, rewritten for general use. each is one SKILL.md file with no scripts and no hooks.

  • fact-check: a second, independent reviewer checks every claim in a draft against its source and grades findings as false, inaccurate or wording; you fix and repeat until nothing false or inaccurate is left, or flag what's still disputed after three rounds. works with a second model's command-line tool if you have one, or a fresh subagent. every guide on this site goes through it.
  • edit-ai-draft: edits an AI-assisted draft to read like a person wrote it, with rules for school, blog, work and marketing texts. it's the checklist from our ChatGPT detector test, where our two texts edited with it passed ZeroGPT, Scribbr and Copyleaks, though not stricter detectors.
  • code-style: formatting and structure rules for PHP, JavaScript, CSS, HTML and Python, from the Airbnb and Google guides, PEP 8 and PER-CS, plus a CSS architecture with spacing tokens and layout primitives.

to install one, save the file as ~/.claude/skills/<name>/SKILL.md. for example:

mkdir -p ~/.claude/skills/fact-check
curl -fsSL https://thehype.news/content/files/2026/09/fact-check.md -o ~/.claude/skills/fact-check/SKILL.md

this only downloads a text file; nothing runs. open it before you use it, like any skill.

how to create your own claude skill

make a folder for it:

mkdir -p ~/.claude/skills/summarize-changes

create SKILL.md in it with a name and description at the top and instructions below:

---
name: summarize-changes
description: Summarize what changed in the current git branch. Use when the user asks what they changed or wants release notes.
---

Run git diff against main, group changes by feature, and write a short summary a reviewer can read in a minute.

then ask "what did I change?" or type /summarize-changes.

what makes a skill work well, per Anthropic's docs:

  • the description decides when it's used. put the main use case first, in the words people would actually say; description and when_to_use together are cut at 1,536 characters.
  • keep SKILL.md under 500 lines and move reference material to separate files the skill points to.
  • disable-model-invocation: true for skills with side effects, like deploy or commit, so only you can start them.
  • allowed-tools pre-approves tools so Claude doesn't ask; list as few as the job needs (disallowed-tools blocks them).
  • skill-creator (/plugin install skill-creator@claude-plugins-official) writes test cases, runs them with and without your skill in separate subagents, compares the results and tunes the description.

how to check a skill before you install it

  1. look at the repository: stars, age, last update, open issues. a new repository with a famous name and huge install numbers is a red flag.
  2. read SKILL.md: does it tell Claude to install anything, send data somewhere, change settings or permissions? what does allowed-tools grant?
  3. read the hooks: hooks/hooks.json or the hooks field in plugin.json and SKILL.md, and every script they run. they run without asking.
  4. read the scripts the skill runs: look for network addresses, reading files outside the project, and commands piped into a shell.
  5. install with /plugin or by copying, not with curl ... | bash.
  6. try it in a project that doesn't matter, with Claude Code's sandbox on, before your main work.

you can also ask Claude Code to do steps 2 to 4 on a downloaded repository before installing it. do it in plan mode with the sandbox on and nothing pre-approved: plan mode is meant for reading and planning, but it isn't a hard lock.

faq

what are the best claude skills?

by installs: Anthropic's frontend-design, Superpowers and Matt Pocock's grill-me, each over a million. by task, see the list above; for most developers Superpowers or Matt Pocock's skills plus frontend-design are a good start.

where are claude skills stored?

personal skills in ~/.claude/skills/<name>/SKILL.md, project skills in .claude/skills/ in the repository, plugin skills inside the plugin. skills from your claude.ai account sync to ~/.claude/skills/synced/.

what is the difference between skills and mcp?

a skill tells Claude how to do a job; an MCP server gives Claude access to a tool or data it can't reach otherwise. they often work together: Higgsfield's skills teach Claude how to use Higgsfield's tools.

are claude skills safe?

a skill is as safe as its code. in the 20 repositories we reviewed, we found no sign of malicious code, but hooks, broad permissions and self-installing tools were common, and two we wouldn't install. read the hooks and scripts first and install through /plugin.

can i use claude skills in cursor or codex?

yes. skills follow the open Agent Skills standard, and npx skills add installs them for Claude Code, Cursor, Codex, Copilot, Gemini and other agents.

do skills work on the free claude plan?

yes in the Claude apps: skills work on the free plan when code execution is on, under Customize, then Skills. Claude Code itself needs a paid Claude plan or an API account; see our Claude Code guide for prices.

how we tested

on September 28, 2026 we picked 20 skill repositories on GitHub, including Anthropic's official plugin marketplace, by stars, activity in the last three months and the topics that come up in search suggestions; it's a selection, not a complete top 20. we cloned each at its latest commit without installing or running anything, scanned their text and code files (up to 2 MB each) with our own script for risky patterns, and had OpenAI's Codex read the hooks and the scripts the skills tell Claude to run, in read-only mode, with file and line references; in Anthropic's official marketplace it read the most popular plugins, not all 340. external packages the skills download weren't part of the check. verdicts apply to the commits we read; a later update can change them. we left out K-Dense's scientific skills: 166 skills and over 500 MB were too much to read properly. install counts come from claude.com/plugins and skills.sh, stars from the GitHub API, the same day. our three skills are rewritten from the ones we use, with anything specific to our projects removed.

sources

  • Anthropic: Claude Code skills documentation, official plugin marketplace, anthropics/skills
  • skills.sh: install counts
  • GitHub: repositories, stars and code of the 20 skill sets we checked
  • Higgsfield: Higgsfield skills, CLI and MCP
  • agent Skills: the open standard
ON AIR · RADIO.THEHYPE.NEWS ↗ ai news radio — 24/7