4 min read

Anthropic Agent Skills: Ready-Made Skills for Claude (GitHub, Scanned)

Anthropic's public library of Agent Skills, including the document skills Claude itself uses.

Anthropic Agent Skills logo
✅
Scan: safe. Nothing to warn about. The repository is instructions and small helper scripts with no dependencies to install and no network code beyond fonts and the Claude API in examples. Scanned Sep 29, 2026; the full report is below.

A skill is a folder with a SKILL.md file of instructions, plus any scripts or reference files it needs, which Claude loads only when a task calls for it. This repository is Anthropic's public set of them: about 19 skills covering creative work (algorithmic art, canvas design, Slack GIFs, themes), development (an MCP server builder, web app testing, frontend design, web artifacts, the Claude API), business writing (brand guidelines, internal comms, document co-authoring), and a skill-creator for writing your own. It also holds the Agent Skills specification and a starter template.

For many people the most useful part is the four document skills, docx, pdf, pptx and xlsx, which power Claude's own file creation. Anthropic publishes those as source-available references rather than open source, while most of the other skills are Apache-2.0, which is why GitHub shows no single licence for the repository.

At about 179,400 stars it is one of the most-starred repositories on GitHub. Anthropic describes the contents as demonstrations and asks you to test them before relying on them. The format is an open standard published at agentskills.io, so the same folders also work in other agents that support skills.

Who it is for

Claude Code and Claude API users who want working skills to install or copy, and anyone writing their own skills who wants solid examples of how to structure instructions, scripts and reference files.

Getting started

1. In Claude Code, add the repository as a plugin marketplace

/plugin marketplace add anthropics/skills

2. Install the document skills (Word, PDF, PowerPoint, Excel)

/plugin install document-skills@anthropic-agent-skills

3. Or install the example skills (art, design, testing, MCP builder and more)

/plugin install example-skills@anthropic-agent-skills

4. Start a skill of your own from the template

git clone https://github.com/anthropics/skills && cp -r skills/template my-skill

The /plugin commands are typed inside Claude Code, not a shell. On Claude.ai these example skills are already available on paid plans, and custom skills can be uploaded there or through the Claude API.

Safety scan

We cloned anthropics/skills at commit 8a1541c on Sep 29, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.

  • No secrets, no suspicious code patterns, no installers, no committed binaries and no bare-IP URLs across 430 files, about 29,000 lines of them Markdown and 18,000 Python.
  • The Python and JavaScript files are helper scripts the skills ask Claude to run, for example to unpack and repack Office files or validate a PowerPoint. They run with your agent's permissions, so the habit worth keeping is to read any skill's scripts before installing it, from this repository or anyone else's.
  • No lockfiles, so no dependency advisories. The only external hosts in the code are Google Fonts, shadcn/ui documentation, openoffice.org references and api.anthropic.com in the Claude API skill.
  • No GitHub workflows at all. There is no licence file at the root, which is why GitHub shows none: licences sit in each skill folder, Apache-2.0 for most and a source-available licence for docx, pdf, pptx and xlsx. No security policy or contributing guide in the repository itself.

What the scanner counted

CheckResult
SecretsNone found.
Suspicious codeNone found.
Install-time codeNone: nothing runs at install beyond the package manager itself.
Committed binariesNone.
CI workflowsNo GitHub Actions workflows.
Network hosts5 distinct hosts referenced from source; most often openoffice.org, fonts.googleapis.com, api.anthropic.com, fonts.gstatic.com. No URLs to bare IP addresses.
Known vulnerabilitiesNo lockfile to check: dependencies are declared as ranges, so what gets installed is whatever is current on the day.
Project hygieneHas none of the usual files. Missing security policy, automated dependency updates, CodeQL, licence file, contributing guide.
OpenSSF ScorecardNot scored: the project is not in Scorecard's weekly index.

By the numbers

Stars179.5K
Forks21.2K
Contributors16
Commits57
Open issues391
Open pull requests1,003
Releases0
Latest releasenone tagged
Licencenone
Main languagePython
Project age1 year
Last pushSep 29, 2026
Tracked files430
Lines of code50.7K
Checkout size12 MB

Lines by language: Markdown 28.8K, Python 18K, HTML 2,072, JavaScript 1,315, Shell 377, JSON 74.

Questions

Are Anthropic's skills free?

The repository is free to read and use. Most skills are Apache-2.0; the docx, pdf, pptx and xlsx skills are source-available, shared as a reference rather than under an open-source licence, so read their licence files before reusing them in a product. Running any skill still needs Claude or another agent, under that product's pricing.

What is an Agent Skill?

A folder containing a SKILL.md file with a name and a description in YAML frontmatter, followed by instructions, and optionally scripts and reference files. The agent reads only the description until a task matches, then loads the rest, which keeps unused skills out of its context window.

Do these skills work outside Claude?

The format is an open standard published at agentskills.io, and other agents can load SKILL.md folders. Some skills here assume Claude's tools, such as code execution and file handling, so results elsewhere depend on what the other agent can do.


This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.