csharp-scripts
Supports C# language and API experiments and small file-based applications. Covers single-file apps, multi-file composition with #:include and #:exclude, and references through #:ref.
Your agent can do more. Find the skill that makes it happen.
Find your next superpower If you are an agent, refer to our llms.txt for full access."..." for exact phrases · Try typography, debugging or spreadsheetSupports C# language and API experiments and small file-based applications. Covers single-file apps, multi-file composition with #:include and #:exclude, and references through #:ref.
Offers best-practice guidance for TUnit unit testing, including data-driven tests.
Offers best-practice guidance for xUnit unit testing, including data-driven tests.
Chief Security Officer mode. (gstack)
Covers Content Security Policy weaknesses when CSP blocks XSS or data exfiltration. Examines trusted endpoint abuse, nonce leakage, and exfiltration channels outside the policy's protection.
Use when hunting Client-Side Path Traversal (CSPT) vulnerabilities where attacker- controlled input is unsafely concatenated into the path component of a JavaScript fetch() or XHR request. Trigger on: "CSPT", "client-side path traversal", "fetch path traversal", "XHR path injection", "fetch concatenation", "../ in fetch", "user input in fetch URL", "path component injection", fetch redirect chaini…
Cross-Site Request Forgery (CSRF) tricks authenticated users into submitting forged requests to a target application by exploiting browser automatic cookie attachment. Detect via missing or predictable CSRF tokens in state-changing requests (POST/PUT/DELETE), absent SameSite cookie attributes, and JSON endpoints accepting text/plain Content-Type. Test using HTML auto-submitting forms, XHR requ…
Provides a CSRF testing playbook. Covers anti-CSRF defenses, SameSite behavior, JSON CSRF, login CSRF, and OAuth state handling.
Identify and exploit Cross-Site Request Forgery (CSRF) vulnerabilities by bypassing weak or flawed anti-CSRF token implementations, SameSite cookie attributes, and Origin/Referer headers. Use this skill when testing state-changing web application endpoints for session riding attacks. Covers token removal, token fixation, multipart manipulation, and chaining with XSS for complete bypass.
Converts styles from CSS files into Tailwind utility classes.
Supports exploratory analysis of CSV files through interactive Plotly visualizations. Creates statistical plots and dashboards, analyzes distributions, and performs automatic data profiling.
Covers CSV and spreadsheet formula injection involving DDE, Excel, LibreOffice, and Google Sheets IMPORT functions. Applies where exports, imports, or user fields feed spreadsheets and reporting tools.
A growing collection of real, public skills. Descriptions and instructions indexed 25 Sept 2026.
Skills give your agent reusable instructions for a specific job. Pick one, read what it does, and bring it into your workflow.
A name only tells half the story. Search the full description and instructions to find the right fit.
Read the skill, visit its source, and see exactly what you’re adding to your agent.
Copy the install command from a skill page and run it in your project.
npx skillycli add owner/repo --skill name