AgentSkills.site

The Best Cursor Skills

A task-first decision guide to Cursor skills: which are already built in, which depend on Cursor's native subagents and browser, which travel across agents, and how to choose between overlapping options.

Published

Updated

AgentSkills.site editorial

The decision matrix: which skill for which job?

Most skill roundups present arbitrary lists sorted by repository popularity. This guide organizes skills by the job you are trying to do, distinguishes between what is already built into Cursor versus what requires installation, and flags critical runtime dependencies:

Developer job Top recommendation Tier / Source Runtime Key dependencies Overlap rule / When to choose
Standard Code Review /review & /review-bugbot Built-in (Ships with Cursor) Cursor-Native None Start here. Pre-installed in every session; do not install third-party review tools for basic PR checks.
Multi-Perspective Review parallel-code-review Community (awesome-cursor-skills) Cursor-Native Parallel subagents Reach for this when you want 4 parallel subagents (security, performance, correctness, style) merged into a single report.
Quick Security Check /review-security Built-in (Ships with Cursor) Cursor-Native None Instant security review without configuring external tools or credentials.
Deep Security Branch Audit thermos Marketplace Plugin (cursor/plugins) Cursor-Native Parallel subagents Choose for extensive, pre-merge branch audits across full repositories using subagent swarms.
AppSec Threat Modeling trailofbits/skills Portable Repo Portable Python / security CLIs Choose when conducting formal threat modeling or vulnerability research using standardized procedures.
PR & Team CI Lifecycle cursor-team-kit Marketplace Plugin (cursor/plugins) Cursor-Native gh CLI, Git worktrees Full team workflow suite handling CI failure diagnosis, review, and shipping without separate scripts.
Automated Test Fixing parallel-test-fixing Community (awesome-cursor-skills) Cursor-Native Parallel subagents Dispatches one isolated subagent per failing test to fix test suites concurrently.
UI, Visual & Accessibility QA visual-qa-testing & accessibility-auditing Community (awesome-cursor-skills) Cursor-Native Built-in Cursor Browser Leverages Cursor's embedded browser and accessibility tree. Cannot run on terminal-only agents.
Authoring Skills & Rules /create-skill, /create-rule, /migrate-to-skills Built-in (Ships with Cursor) Cursor-Native None Zero install. Cursor already bundles interactive generators and converters in the box.
Rule & Hook Optimization suggesting-cursor-rules Community (awesome-cursor-skills) Cursor-Native .cursor/rules/ Analyzes repeated developer corrections during a chat and drafts .mdc rules or hooks automatically.
Office Documents (PDF/DOCX) anthropics/skills (document-skills) Portable Repo Portable Python libraries Handles docx, pptx, xlsx, and visual pdf layout. Operates seamlessly in Cursor.
GPU, CUDA & Physical AI NVIDIA/skills Portable Repo Portable CUDA, Python environment NVIDIA-maintained procedures for CUDA kernel tuning, TensorRT, and robotics.
End-to-End Operating Process pstack Marketplace Plugin (cursor/plugins) Cursor-Native Subagents, Git worktrees A comprehensive, 44-skill opinionated engineering methodology. Only choose if adopting an entire workflow system.

The three selection filters

Before installing any skill, apply these three filters to avoid bloat and broken workflows:

Filter 1: Check the 19 built-in skills first

Cursor bundles 19 skills directly into the editor and CLI with zero installation:

/automate, /autopilot, /canvas, /create-hook, /create-rule, /create-skill, 
/create-subagent, /cursor-blame, /loop, /migrate-to-skills, /review, 
/review-bugbot, /review-security, /sdk, /shell, /split-to-prs, /statusline, 
/update-cli-config, /update-cursor-settings

Common listicles frequently recommend installing third-party skills for tasks that Cursor already handles natively. Always verify whether a built-in command already covers your use case before adding third-party files.

Filter 2: Cursor-native vs. portable skills

Skills fall into two distinct architectural classes:

  • Cursor-Native Skills: Depend on proprietary features unique to Cursor: parallel subagents, the built-in browser, worktree isolation, or .cursor/rules/. For example, parallel-code-review requires Cursor's subagent engine and will fail if copied into a CLI-only agent.
  • Portable Skills: Adhere strictly to the open Agent Skills specification using standard markdown instructions and shell commands. While their base format is portable across agents, discovery directories, prompt injection vs. tool execution mechanics, frontmatter extensions, and runtime environments can differ between tools.

Filter 3: Standalone skill vs. plugin bundle

In Cursor's ecosystem, a Plugin is a container that can bundle multiple skills, rules, and MCP servers.

When evaluating the official cursor/plugins marketplace (as of 16 August 2026), 19 of the 20 third-party integrations (Gmail, Slack, Salesforce, HubSpot, etc.) are pure MCP tool connections containing zero skills. First-party plugins (cursor-team-kit, thermos) and community frameworks (pstack) are where curated skill bundles reside.


Decision support by task

1. Code review & bug detection

Do you need standard review or multi-perspective auditing?
├── Single-pass diff check     → Use built-in `/review` or `/review-bugbot` (Zero install)
├── 4-way parallel audit       → Use `parallel-code-review` (Requires subagents)
├── Team PR & CI verification  → Use `cursor-team-kit` plugin (Requires `gh` CLI)
└── Deep pre-merge branch scan → Use `thermos` plugin (Requires subagents)
  • Built-in /review and /review-bugbot: Fast, built into every Cursor session, and requires zero configuration. Suitable for inline inspection of uncommitted changes and branch diffs.
  • parallel-code-review: Spawns four read-only subagents simultaneously—one each for security, performance, correctness, and style—merging their findings into a single structured report. Ideal for major PR reviews before merging.
  • cursor-team-kit: An 18-component plugin (as of 16 August 2026) providing end-to-end workflows for diagnosing CI failures, reviewing incoming PRs, and verifying code changes before shipping.

2. Security auditing & threat modeling

What depth of security analysis do you require?
├── Quick inline sanity check   → Use built-in `/review-security` (Zero install)
├── Repository branch audit     → Use `thermos` plugin (Cursor-native subagents)
└── Formal threat modeling/AppSec → Use `trailofbits/skills` (Portable standards)
  • Built-in /review-security: Examines current workspace diffs for obvious vulnerabilities, leaked secrets, and insecure patterns.
  • thermos: A first-party Cursor plugin designed for exhaustive security audits across large branches using parallel subagents.
  • trailofbits/skills: Maintained by security firm Trail of Bits (CC-BY-SA-4.0). Contains structured procedures for repository threat modeling, invariant validation, and vulnerability triage. Portable across all agents.

3. Automated testing & browser QA

  • parallel-test-fixing (awesome-cursor-skills): When a test suite fails across multiple files, this skill launches an independent subagent for each broken test, resolving failures concurrently in isolated passes.
  • visual-qa-testing & accessibility-auditing (awesome-cursor-skills): Unlike terminal-bound agents, Cursor embeds a Chromium-based browser. These skills drive the built-in browser and inspect the accessibility tree to detect layout regressions, broken viewports, and WCAG accessibility violations.

4. Authoring, converting, and maintaining rules

  • Built-in /create-skill: The recommended path for scaffolding new skills. It interactively generates SKILL.md frontmatter, instructions, and file layouts adhering to the official specification.
  • Built-in /migrate-to-skills: The official conversion tool. Analyzes existing .cursor/rules/ and slash commands, automatically converting eligible dynamic rules into skills. See Cursor Skills vs Rules.
  • suggesting-cursor-rules: Watches for repetitive developer corrections in chat (e.g., repeatedly requesting specific imports or test patterns) and suggests an appropriate .mdc rule or hook.

5. Cross-agent portable collections

When looking for domain-specific skills, these upstream repositories provide verified, portable procedures:

Repository Focus Stars Licence Last push
anthropics/skills Document processing (docx, xlsx, pdf), design, skill authoring 169,642 Per-skill LICENSE.txt 2026-08-13
trailofbits/skills AppSec, threat modeling, code auditing 6,612 CC-BY-SA-4.0 2026-08-14
NVIDIA/skills CUDA optimization, physical AI, robotics 2,967 Apache-2.0 2026-08-14
awslabs/agent-plugins AWS architecture, CloudFormation, and operations 862 Apache-2.0 2026-08-14

Note: Star counts and metadata retrieved via GitHub API on 16 August 2026.

6. Comprehensive workflows: pstack

pstack (MIT, © 2026 Lauren Tan) is the largest community plugin in the official marketplace (44 skills as of 16 August 2026):

  • Scope: Bundles 44 skills (including 21 architectural principles) and 2 subagents.
  • Workflow: Enforces an opinionated, phased engineering process: Plan -> Spec -> Test-Driven Development -> Review.
  • Decision Rule: Do not install pstack if you are only looking for a standalone review or linting utility. Adopt pstack only if your entire team intends to follow its structured development methodology.

The 6-step audit checklist for third-party skills

Cursor does not statically audit or vet third-party skills at install time. Bundled scripts in a skill's scripts/ directory are executable code; when run, they are governed by Cursor's Run Modes (Auto-review, Allowlist, or Ask before running) and terminal command sandboxing (via sandbox.json). However, commands can request approvals or run outside the sandbox for full machine access. Audit all unvetted community skills using this checklist:

  1. Check for negative triggers in description: A well-crafted skill explicitly specifies when it should not fire, preventing false-positive activations that waste context.
  2. Verify runtime requirements: Check whether the skill requires Cursor-specific features (subagents, browser, worktrees) or external CLIs (gh, docker, aws).
  3. Read all files in scripts/: Review every bash, python, or node script before execution. Verify what commands and network calls they invoke.
  4. Inspect required environment variables: Ensure the skill does not request unnecessary API tokens or elevated privileges.
  5. Check maintenance date: Coding CLIs evolve rapidly. A third-party skill untouched for over six months may reference deprecated CLI flags or obsolete APIs.
  6. Confirm publisher provenance: Prioritize first-party plugins and established organizations over anonymous multi-skill repositories.

Caveats

  • We have not run Cursor or executed these skills. Descriptions and capabilities are verified from official documentation, publisher manifests, and the GitHub API.
  • Star counts and repository metadata were captured on 16 August 2026 and will fluctuate over time.
  • The 19 built-in skills reflect Cursor 2.4+ and may be modified in future releases.
  • "Manually reviewed" reflects Cursor's stated marketplace policy; the exact review criteria are proprietary.

Sources