テックトレンド

The 52 Best Claude Code Skills: How to Pick Them and Install Them Safely

Published2026-02-16Updated2026-10-04Ryuta Hamamoto

A verified list of 52 Claude Code skills in four groups: bundled with Claude Code, Anthropic's official repository, financial services, and community-built. Every source, license, and last update was checked on October 4, 2026, alongside a practical guide to choosing, installing, and vetting skills.

The 52 Best Claude Code Skills: How to Pick Them and Install Them Safely
Share

Hello, this is Ryuta Hamamoto from TIMEWELL.

When this article first went up in February 2026, Anthropic's official skills repository on GitHub (anthropics/skills) had about 71,000 stars. On October 4, 2026, it had 179,5231. Claude Code now ships with skills of its own, and the financial-services skills I described as waitlist-only can be installed by anyone from a public repository. Meanwhile, two of the 45 skills on the original list can no longer be verified as skills at all.

So for this rewrite I checked every skill again: the public repository, the license, and the date of the last update, all on October 4, 2026. The list now has 52 entries. The number went up because I added the skills bundled with Claude Code, not to pad the count.

I also added something the first version lacked: security. A skill is a set of instructions, but it can also run scripts and shell commands. When the security company Snyk examined 3,984 skills collected from public registries, it confirmed 76 malicious payloads2. A list of recommendations that ignores that is not much use anymore.

If you want a sense of where your team stands with AI before deciding where to start, our AI literacy check takes a few minutes.

What Claude Code skills are, and where they live

A Claude Code skill is a folder built around a Markdown file called SKILL.md. Alongside it you can keep checklists, templates, and scripts. Anthropic's documentation puts the trigger plainly: if you keep pasting the same instructions or checklist into the chat, that is a skill waiting to be written3. Claude uses a skill on its own when a request matches it, and you can call one directly by typing /skill-name. The older custom commands in .claude/commands/ have been merged into skills, and existing files keep working.

Skills are also no longer a Claude Code-only idea. Claude Code follows the open Agent Skills standard3, and skills.sh, a skills directory run by Vercel, installs skills into more than 20 agents, including Claude Code, Cursor, and Codex4. A skill you write once can travel with you if your team switches or mixes tools, which matters more than it might seem when you are choosing what to invest in.

Loading works in stages. According to Anthropic's Agent Skills overview, only each skill's name and description load at startup, at roughly 100 tokens per skill. The body (ideally under 5,000 tokens) loads when a request matches, and bundled files are opened only when needed5. In Claude Code, though, that list of names and descriptions has a budget of 1% of the context window. Install too many and Claude Code starts dropping the descriptions of the skills you use least3. Hundreds of skills will still run, but the more you add, the more of them quietly stop getting picked.

Where you save a skill decides who gets it.

Location Path Available in
Personal ~/.claude/skills/<skill-name>/SKILL.md All your projects on this machine
Project .claude/skills/<skill-name>/SKILL.md That repository; commit it and your team gets it
Plugin <plugin>/skills/<skill-name>/SKILL.md Wherever the plugin is enabled, invoked as /plugin-name:skill-name
Enterprise .claude/skills/ inside the managed settings directory Every user on machines where your organization deploys it
claude.ai account Skills enabled on claude.ai Cowork, cloud sessions, and terminals signed in with that account

When the same name exists in several places, enterprise wins over personal, and personal wins over project3. It also helps to know how skills differ from the mechanisms next to them.

Mechanism Best for How it loads
CLAUDE.md Facts and conventions Claude should always follow In full, every session
Skills Procedures, checklists, reference material Description always, body only when used
MCP Connections to external services and data As tools
Subagents Work you hand off to a separate context When invoked

If your CLAUDE.md keeps growing step-by-step procedures, move those parts into skills. The documentation makes the same point: once a section of CLAUDE.md has grown from a fact into a procedure, it belongs in a skill3.

How to choose: three filters

I would not install all 52. As noted above, the description list has a budget, so skills you never use crowd out the ones you want Claude to find. Here is the order I would filter in.

First, frequency. Look for work you already repeat: the instructions you paste into the chat several times a week, the review points you explain on every pull request, the spreadsheet you reformat the same way every month. Skills that match work like this pay off right away. A skill for something you do twice a year tends to sit forgotten, never invoked, while still using up part of the list.

Second, whether you can say in one sentence when the skill should run. Claude chooses skills from their descriptions alone. Claude Code truncates the description plus the optional when_to_use text at 1,536 characters, and the documentation recommends putting the main use case first3. A vague description means the skill stays silent when you need it and interrupts when you do not. Before installing someone else's skill, read its description and ask whether it matches how you actually work.

Third, provenance and permissions. Who wrote it, what can it run, and which files can it read? I cover this in detail in the security section below, but it belongs in the selection step too. That is why every table in this article lists the license and last update as of the check date.

My own suggestion: spend the first week with only the bundled skills, write down the tasks where you wished for more, and only then go looking. With that list in hand, the 52 options usually shrink to a handful.

Setting ground rules before your team shares skills? We publish ready-to-edit templates for a generative-AI adoption proposal and a 10-article usage policy, which spell out what must never go into a prompt and how outputs are handled. They are written for companies operating under Japanese privacy rules, so teams elsewhere will need to adapt the legal references. Download the Generative-AI Adoption Proposal & Usage Policy Templates (free; company name and work email required).

Take AI-driven development all the way to production

WARP is a hands-on program for teams who want more than headlines. Former enterprise DX and data strategy leads work alongside you until it runs.

The 52 skills, in four groups

The list is split into four groups: skills bundled with Claude Code, Anthropic's official skills, financial-services skills, and community and partner skills. Sources, licenses, and last-update dates were all checked on GitHub and in Anthropic's documentation on October 4, 2026. "No license" means the repository states no license at all, so the terms of use are unclear; check with the author before relying on one at work.

1. Bundled with Claude Code (8)

The original article did not cover these. Current versions of Claude Code include a set of skills out of the box. The documentation distinguishes them from built-in commands, which run fixed logic: bundled skills are prompt-based, giving Claude detailed instructions and letting it orchestrate the work with its own tools3.

Skill What it does
/code-review Reviews your current diff or a pull request for correctness bugs; --fix applies the findings
/simplify Runs four parallel reviews of changed code (reuse of existing helpers, simplification, efficiency, level of abstraction) and applies the cleanups; it does not hunt for bugs
/batch Splits a large change into 5 to 30 independent units and, once you approve, implements them in parallel with one subagent per worktree
/run Launches your app so you can see a change working
/verify Builds and runs your app to confirm a change does what it should, without falling back on tests or type checks
/debug Starts debug logging from that point and reads the log to diagnose a problem
/loop Runs a prompt repeatedly while the session stays open; leave out the interval and Claude paces itself
/claude-api Loads Claude API and Managed Agents reference material for your project, with subcommands such as model migration

The descriptions come from the official commands reference6. If I had to pick one combination to try first, it would be /code-review plus /verify. The first asks whether the code is correct; the second asks whether it actually does what you expected when you run it. The second check is the one people skip most often with AI-written code, and this makes it a fixed step. On v2.1.200 and later, /verify writes the steps that worked to .claude/skills/verify/SKILL.md, so later runs follow the same recipe3.

/simplify and /code-review have clearly separate jobs. /simplify only tidies up and does not look for bugs, so if you use both on the same diff, run /code-review first and /simplify second. There is also /security-review, which checks your branch for vulnerabilities, but that one is a built-in command rather than a skill6.

2. Anthropic's official skills (17)

These come from Anthropic's anthropics/skills repository. On October 4, 2026, it held 19 skills: the 16 from the original article plus claude-api, discernment-nudge, and academy-guide1. claude-api is the same skill as the bundled one above, so I picked 17 from the rest.

Skill What it does Type
algorithmic-art Generative art with p5.js and seeded randomness Design
brand-guidelines Applies Anthropic's own brand colors and typography; most useful as a template for your own brand Design
canvas-design Posters and other static visuals as PNG or PDF, guided by a design philosophy Design
theme-factory Styles slides, docs, or landing pages with one of 10 preset themes or a new one Design
frontend-design Guidance on color, type, and layout that avoids the templated look when building or reshaping a UI Development
web-artifacts-builder Multi-component claude.ai artifacts with React, Tailwind CSS, and shadcn/ui Development
webapp-testing Drives a local web app with Playwright, capturing screenshots and browser logs Development
mcp-builder A guide to building MCP servers for external APIs in Python (FastMCP) or TypeScript Development
skill-creator Creates and improves skills, runs evals, benchmarks with variance analysis, and tunes descriptions for better triggering Meta
docx Creates, edits, and reads Word documents, including tables of contents and numbered headings Documents
pdf Extracts, merges, splits, fills forms, watermarks, and OCRs PDFs Documents
pptx Creates, edits, and reads PowerPoint decks and templates Documents
xlsx Creates and edits Excel and CSV files, with formulas, formatting, and charts Documents
doc-coauthoring Walks you through writing proposals and specs, from handing over context to final revisions Documents
internal-comms Status reports, leadership updates, newsletters, FAQs, and incident reports in your company's format Communication
slack-gif-creator Animated GIFs that fit Slack's constraints Communication
discernment-nudge After a substantive answer, adds two or three short questions that prompt you to check facts and assumptions (new) Review

Two things are worth knowing before you use them. The README states that these skills are provided for demonstration and educational purposes. And docx, pdf, pptx, and xlsx are source-available under a proprietary license, not open source1. If you plan to modify and redistribute them inside your company, read the LICENSE.txt first.

My top pick here is skill-creator. In February it was a guided way to write a new skill. Now it also runs evals and tunes a skill's description so Claude invokes it more reliably. Having a way to measure the quality of your own skills is a real step forward. I walk through writing skills from scratch in a separate guide to building custom Claude Code skills.

The newcomer discernment-nudge is quiet but interesting. People pasting AI answers straight into internal documents is a habit problem more than a technology problem, and a short "did you check where this number comes from?" at the end of an answer goes a long way. Note also that Anthropic says these example skills are already available on paid claude.ai plans, and if you sign in to Claude Code with a claude.ai account, skills such as pdf and xlsx sync automatically13.

3. Financial-services skills (11)

The original article described these as Enterprise-only with a waitlist. Today they live in anthropics/financial-services, a public repository Anthropic created on February 23, 2026, under the Apache-2.0 license, and you can install them as plugins in Claude Code or Cowork7. The repository contains ten end-to-end agents, such as a pitch agent and an earnings reviewer, plus plugins for investment banking, equity research, private equity, fund administration, and more. All 11 skills from the original list are still there.

Skill (folder name) Plugin What it does
3-statement-model financial-analysis Completes linked income statement, balance sheet, and cash flow templates
dcf-model financial-analysis Builds DCF models in Excel, including WACC and sensitivity analysis
comps-analysis financial-analysis Comparable company tables with operating metrics and valuation multiples
competitive-analysis financial-analysis Competitive landscape decks: positioning, competitor deep-dives, comparisons
ppt-template-creator financial-analysis Turns your PowerPoint template into a reusable skill
ib-check-deck financial-analysis Checks a pitch deck for number consistency across slides, data-narrative alignment, language, and formatting
pitch-deck investment-banking Populates pitch deck templates with data from Excel and other sources
datapack-builder investment-banking Pulls data from offering memoranda and filings into investment-committee-ready Excel data packs
strip-profile investment-banking One- to four-slide company profiles for pitch books
earnings-analysis equity-research Quarterly earnings update reports of 8 to 12 pages
initiating-coverage equity-research Initiation reports built in five tasks: research, modeling, valuation, charts, assembly

Following the README, install the core financial-analysis plugin first (it carries the shared modeling skills and data connectors), then add the vertical plugins you need7.

claude plugin marketplace add anthropics/financial-services
claude plugin install financial-analysis@claude-for-financial-services
claude plugin install investment-banking@claude-for-financial-services

In my view, 3-statement-model and dcf-model are the most useful in this group, with two caveats. 3-statement-model completes an existing template rather than building a model from a blank sheet. And dcf-model's description assumes it can pull data from SEC filings, so if you cover companies that do not file with the SEC, such as most Japanese listed companies, plan on supplying the figures yourself. The README is explicit that every output is a draft staged for review by a qualified professional, not investment advice7.

Don't skip ib-check-deck either. Numbers that disagree from one slide to the next are exactly the kind of mistake human reviewers miss. Any team that builds number-heavy proposals, finance or not, should give it a try.

4. Community and partner skills (16)

Plenty of individuals and companies publish skills outside Anthropic's repositories. Of the 18 on the original list, I could verify 16, and they stay. The section on what changed explains why the other two are gone.

Skill Source What it does Status at check
superpowers obra/superpowers Turns a development method into 15 skills, from design conversations and plans to TDD, systematic debugging, and code review MIT, updated Sep 2026 (v6.4.2)
Trail of Bits Skills trailofbits/skills 44 plugins, including static analysis with CodeQL and Semgrep, security-focused diff review, and dependency risk audits CC BY-SA 4.0, updated Sep 2026
playwright-skill lackeyjb/playwright-skill General-purpose browser automation with Playwright, for E2E tests and visual checks MIT, updated Aug 2026
ios-simulator-skill conorluddy/ios-simulator-skill Drives the iOS Simulator and trims xcodebuild output to save tokens MIT, updated Sep 2026
scientific-agent-skills K-Dense-AI/scientific-agent-skills 177 skills for scientific libraries and databases in biology, chemistry, and medicine; formerly claude-scientific-skills MIT, updated Oct 2026
web-asset-generator alonw0/web-asset-generator Favicons, app icons, and social images from a logo, text, or emoji MIT, updated Jan 2026
claude-d3js-skill chrisvoncsefalvay/claude-d3js-skill Interactive charts with D3.js No license; no updates since Oct 2025
ffuf_claude_skill jthack/ffuf_claude_skill Runs the ffuf web fuzzer and helps analyze the results No license; no updates since Oct 2025
Notion Plugin for Claude Code makenotion/claude-code-notion-plugin Official from Notion: four skills (knowledge capture, meeting notes, and more) plus the Notion MCP server in one install No license stated; updated Jan 2026
competitive-ads-extractor ComposioHQ/awesome-claude-skills Pulls competitors' ads from ad libraries and analyzes messaging and creative patterns A single SKILL.md; repo updated Jul 2026
content-research-writer Same Supports writing with research, citations, stronger hooks, and section-by-section feedback Same
invoice-organizer Same Reads invoices and receipts, extracts key fields, renames files consistently, and sorts them for tax season Same
lead-research-assistant Same Analyzes your product, finds target companies, and suggests outreach Same
article-extractor michalparkola/tapestry-skills Extracts article text and metadata from web pages MIT, updated Mar 2026
csv-data-summarizer coffeefuelbump/csv-data-summarizer-claude-skill Summary statistics, missing-data checks, and quick charts for CSV files with pandas No license; no updates since Oct 2025
deep-research sanjay3290/ai-skills Calls Google's Gemini Deep Research Agent to produce cited research reports (2 to 10 minutes) Apache-2.0, updated Sep 2026; needs a Gemini API key

superpowers stands apart in this group. It had 294,865 stars on October 4, 2026, and you can now install it from Anthropic's official plugin directory with /plugin install superpowers@claude-plugins-official8. The /brainstorm and /write-plan commands mentioned in the original article were removed in v5.1.0 on April 30, 20268. Skills such as brainstorming, writing-plans, and subagent-driven-development now activate on their own as the work moves through each stage. I cover the thinking behind it in our guide to the superpowers plugin.

For security work, the Trail of Bits collection is in a league of its own. Beyond static-analysis (CodeQL, Semgrep, and SARIF parsing), it includes supply-chain-risk-auditor, which checks npm, PyPI, and Go dependencies for known advisories, abandoned upstreams, and install scripts9. The license is CC BY-SA 4.0, so if you modify and share it, the same terms carry over.

Three entries have no license and no updates since October 2025: claude-d3js-skill, ffuf_claude_skill, and csv-data-summarizer. I would treat them as reference material for writing your own skill rather than something to install as-is. And point any ffuf-based skill only at systems you are authorized to test; fuzzing without permission may be treated as unauthorized access.

Installing skills and checking that they work

There are three main ways in: copy the folder yourself, install a plugin, or use the skills.sh CLI.

To install by hand, copy the whole skill folder into ~/.claude/skills/ for personal use or into the repository's .claude/skills/ for a project. Bring the scripts and templates along with the SKILL.md. To install a plugin, register the marketplace (the catalog the plugin comes from) and then name the plugin you want. Claude Code registers Anthropic's official marketplace, claude-plugins-official, the first time you start an interactive session10.

# Anthropic's skills repository (anthropics/skills)
/plugin marketplace add anthropics/skills
/plugin install document-skills@anthropic-agent-skills   # docx, pdf, pptx, xlsx
/plugin install example-skills@anthropic-agent-skills    # skill-creator and more

# From Anthropic's official marketplace
/plugin install superpowers@claude-plugins-official

# With the skills.sh CLI (works with agents beyond Claude Code)
npx skills add <owner/repo>

Once installed, open /skills to see which skills are available and where each came from. Press t to sort by token count and the heavy ones stand out right away6. The quickest way to test a skill is to make a request that matches its description. For pdf, try "extract the form fields from this PDF" and see whether the skill loads. If it does not, check that the description fits your request and that SKILL.md starts with --- on its first line. If the frontmatter fails to parse, the skill loads with no settings at all3.

Don't let skills pile up, either. /doctor estimates how much context the description list is using, and /skill-doctor (v2.1.252 and later) shows each skill's cost and how often it gets used3. A monthly review that removes unused skills makes the useful ones easier for Claude to find. To remove a personal or project skill, delete its folder; for a plugin, run /plugin uninstall <plugin-name>@<marketplace-name>.

Security checks before you install

This is the section I most wanted to add. Anthropic's documentation says to use skills you created yourself or obtained from Anthropic, and if you use anything else, to audit every file bundled with it: SKILL.md, scripts, images, and other resources. It warns that a malicious skill can direct Claude to invoke tools or run code in ways that do not match its stated purpose, leading to data exfiltration or unauthorized system access5.

Plugins reach further. Anthropic's page on plugin security and trust states that a plugin can execute arbitrary code on your machine with your user privileges. Plugin hooks (shell commands that run at points such as before or after a tool call) and MCP servers run outside the sandbox, and Claude Code's permission rules cover the tool calls Claude makes, not the code a plugin runs by itself. With auto-update on, the files you reviewed can change on disk later11. Auto-update is on by default for claude-plugins-official and most of Anthropic's other official marketplaces, and off by default for community and third-party ones10. For how hooks work, see our complete guide to Claude Code hooks.

One field is easy to overlook: allowed-tools in a skill's frontmatter. It lets Claude use the listed tools without asking during the turn that invokes the skill. The documentation warns that workspace trust does not gate this field, and that you should review the allowed-tools of any skills checked into a repository before running Claude Code there3. Also, a line in SKILL.md written as !`command` runs that shell command before Claude even reads the skill. Organizations that want to stop this can turn on disableSkillShellExecution in settings3.

Outside research points the same way. In a study published on February 5, 2026, Snyk examined 3,984 skills from the ClawHub and skills.sh registries. It found that 36.82% (1,467) had at least one security flaw, 13.4% (534) had at least one critical issue, and 76 contained confirmed malicious payloads aimed at credential theft, backdoors, and data exfiltration2. skills.sh now publishes combined audit results from three security vendors, including Snyk, so it is worth a look before you install4.

Be careful with secrets as well. The deep-research skill in the table, for example, reads a Gemini API key from an environment variable or from a .env file placed in the skill folder12. The second option leaves a key inside a folder Claude can read. Our guide to keeping Claude Code away from your .env files shows the settings.json rules in detail. And remember that any skill calling an external API sends your prompts, and whatever files it reads, to that provider.

Five checks cover most of the risk.

Check What to look at
Source Publisher, license, last update. An official or well-known organization, or an individual with a visible track record
Contents Read SKILL.md and every script, hook, and .mcp.json; look for unexpected network calls or file access
Permissions The scope of allowed-tools, lines starting with !, and any plugin bin/ directory or hooks
Secrets Never keep .env files or keys in a skill folder; deny reads of .env in your settings
Updates Is auto-update on? For third-party code, pin to the commit you reviewed or update by hand

A skill made of a single SKILL.md, like the ComposioHQ entries, takes a few minutes to read end to end. The more scripts and hooks a skill carries, the more time you should give it. I wrote about how software supply-chain attacks have started using AI tools as their route in a piece on AI tools becoming an infection vector. If you want consistent working practices across an organization, our WARP program offers a practical curriculum for putting AI tools to work.

What changed since the February edition

Eight months changed a lot. Here is the original edition next to the facts as of October 4, 2026.

Item Original (Feb 2026) Now (Oct 4, 2026)
anthropics/skills stars About 71,000 179,523
Skills in the official repository 16 19 (claude-api, discernment-nudge, and academy-guide added)
Skills bundled with Claude Code Not covered /code-review, /simplify, /batch, /verify, and more
Custom commands A separate feature Merged into skills; .claude/commands/ still works
Financial-services skills Described as Enterprise-only with a waitlist Installable as plugins from a public Apache-2.0 repository
superpowers /brainstorm, /write-plan, and other commands Commands removed in v5.1.0 (Apr 2026); in v6.4.2, 15 skills activate by stage; available in the official marketplace
loki-mode Listed as a 37-agent skill Now a standalone command-line tool under BUSL-1.1; removed from the list
Scientific Thinking and Analysis Listed as a community skill Source could not be verified; removed (K-Dense's scientific-critical-thinking plays a similar role)
ComposioHQ and travisvn lists 35,400 and 7,200 stars 76,425 and 15,254
Official security guidance Not covered Anthropic says to use trusted sources only and has a dedicated page on plugin trust

loki-mode is now distributed as an autonomous coding tool that takes a GitHub issue or a spec and returns a pull request13. It no longer fits the definition of a Claude Code skill, so it left the list; that says nothing about its quality as a tool. Scientific Thinking and Analysis did not appear in either of the curated lists the original article drew on, and I could not identify a publisher, so it is gone too.

The bigger story in the numbers is how far the ecosystem has spread. ComposioHQ's list alone carries 833 integration skills for external services (counting the folders in composio-skills)14, and cross-agent distribution like skills.sh has become normal. With that many options, deciding what not to install has become the harder and more valuable skill.

One thing has not changed: at the center there is still a single SKILL.md with a name and a description. The bundled skills, Anthropic's document skills, and the financial agents are all built around files like that. Which means you can read a skill and know what it does, and rewrite it if you don't like it. However large the catalog grows, I think that "you can read it and you can fix it" quality is worth holding on to.

Summary

Claude Code skills let you write down the instructions you keep repeating once, and have Claude load them only when they are needed. As of October 2026, the bundled skills alone cover a lot of ground, and Anthropic's skill-creator lets you measure the quality of the skills you write. At the same time, skills and plugins can run code on your machine, so reading them before installing is not optional.

Three things are enough to start with. Try /code-review and /verify on your next diff. Write down three tasks you repeat every week, and build a skill for any that the official ones don't cover. And when you install something from the community, run it through the five checks above. If you are planning an organization-wide rollout, our enterprise guide to Claude Code is a good next read.

The list and statuses here reflect October 4, 2026, and this space turns over in months. Before installing anything, take one more look at the repository's last update and license. I hope you use these 52 entries less as a shopping catalog and more as a table of contents for reviewing your own work. If you are building AI skills across your team and want to talk it through, book a 30-minute consultation.

Footnotes

  1. anthropics/skills (README and marketplace.json; star count retrieved via the GitHub API on 2026-10-04) — GitHub — https://github.com/anthropics/skills ↩ ↩2 ↩3 ↩4

  2. ToxicSkills: Malicious AI Agent Skills (study of 3,984 skills) — Snyk — 2026-02-05 — https://snyk.io/blog/toxicskills-malicious-ai-agent-skills-clawhub ↩ ↩2

  3. Extend Claude with skills (how skills work, locations, bundled skills, the description budget, allowed-tools, dynamic context injection, /skill-doctor) — Claude Code Docs — accessed 2026-10-04 — https://code.claude.com/docs/en/skills ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13

  4. skills.sh (operator, supported agents) and Security audits — Vercel — accessed 2026-10-04 — https://skills.sh/ and https://skills.sh/audits ↩ ↩2

  5. Agent Skills overview (progressive disclosure, security considerations) — Claude Platform Docs — accessed 2026-10-04 — https://platform.claude.com/docs/en/agents-and-tools/agent-skills/overview ↩ ↩2

  6. Commands reference (bundled skills and built-in commands) — Claude Code Docs — accessed 2026-10-04 — https://code.claude.com/docs/en/commands ↩ ↩2 ↩3

  7. anthropics/financial-services (README; created 2026-02-23; Apache-2.0) — GitHub — accessed 2026-10-04 — https://github.com/anthropics/financial-services ↩ ↩2 ↩3

  8. obra/superpowers (README and RELEASE-NOTES; v5.1.0 released 2026-04-30, v6.4.2 released 2026-09-25) — GitHub — accessed 2026-10-04 — https://github.com/obra/superpowers ↩ ↩2

  9. trailofbits/skills (README) — GitHub — accessed 2026-10-04 — https://github.com/trailofbits/skills ↩

  10. Discover and install plugins (automatic registration of the official marketplace, auto-update defaults) — Claude Code Docs — accessed 2026-10-04 — https://code.claude.com/docs/en/discover-plugins ↩ ↩2

  11. Plugin security and trust (what a plugin can do, marketplace tiers) — Claude Code Docs — accessed 2026-10-04 — https://code.claude.com/docs/en/plugins/security ↩

  12. deep-research in sanjay3290/ai-skills (SKILL.md, .env.example) — GitHub — accessed 2026-10-04 — https://github.com/sanjay3290/ai-skills/tree/main/skills/deep-research ↩

  13. asklokesh/loki-mode (README, license) — GitHub — accessed 2026-10-04 — https://github.com/asklokesh/loki-mode ↩

  14. ComposioHQ/awesome-claude-skills (README, composio-skills folder) — GitHub — accessed 2026-10-04 — https://github.com/ComposioHQ/awesome-claude-skills ↩

This article was produced with the help of AI. A human verified the primary sources and edited the text before publication.

How well do you understand AI?

Take our free 5-minute assessment covering 7 areas from AI comprehension to security awareness.

Share this article if you found it useful

Share

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

Turn AI-driven development into something you can run

WARP is a hands-on program that takes teams from reading about AI to shipping with it. Former enterprise DX and data strategy leads run the sessions.

Related Articles