Guides building with shadcn/ui components: discovery, installation, customisation and best practices.
By agent · GitHub Copilot
GitHub Copilot skills: 1003 worth installing
Skills in the open SKILL.md format that GitHub Copilot reads. Each one has a plain-language summary and the command to install it.
Installing a skill in GitHub Copilot
$ npx skills add <author>/<skill> --agent github-copilotReplace the placeholder with the author and skill name from the skill's page. Start a new GitHub Copilot session afterwards so the skill is picked up.
Skills for GitHub Copilot
All skillsConverts frontend code from Vite, React, Angular or Vue into a Stitch design.
Extracts a design system from frontend source code into a DESIGN.md file.
Generates new screens from text prompts or images and edits existing ones with Stitch MCP.
Analyses Stitch projects and writes their design system into DESIGN.md files.
Turns a vague UI idea into a detailed prompt optimised for Stitch, with design system context.
Teaches an agent to build a website iteratively with Stitch, using an autonomous baton-passing loop.
Generates DESIGN.md files for Google Stitch that enforce strict typography, calibrated colour and asymmetric layouts.
Audits GitHub Actions workflows for vulnerabilities in AI agent integrations such as Claude Code Action and Codex.
Audit Context Building
Trail of BitsBuilds an understanding of a codebase before an audit: what each function assumes, guarantees and depends on.
Detects timing side-channel vulnerabilities in cryptographic code written in C, C++, Go and other languages.
Devcontainer Setup
Trail of BitsCreates devcontainers with Claude Code, language tooling for Python, Node, Rust or Go, and persistent volumes.
Entry Point Analyzer
Trail of BitsIdentifies the state-changing entry points of a smart contract codebase and groups them by access level.
FP Check
Trail of BitsVerifies suspected security bugs one by one and gives a true or false positive verdict with evidence.
GH CLI
Trail of BitsMakes the agent use the authenticated gh CLI for GitHub URLs, pull requests and issues instead of unauthenticated fetches.
Modern Python
Trail of BitsConfigures Python projects with uv, ruff and ty, including migration from pip, Poetry, mypy and black.
Mutation Testing
Trail of BitsConfigures mutation testing campaigns with mewt or muton and analyses the surviving mutants.
Property-Based Testing
Trail of BitsWrites, reviews and debugs property-based tests with Hypothesis, fast-check, proptest and similar tools.
Second Opinion
Trail of BitsGets an independent code review of your changes from Codex or Antigravity.
Creates custom Semgrep rules that detect security vulnerabilities and bug patterns.
Sharp Edges
Trail of BitsIdentifies error-prone APIs, dangerous configurations and designs that invite security mistakes.
Spec to Code Compliance
Trail of BitsChecks code against its specification: which requirements hold, which are contradicted and which are missing.
Scans a codebase for security vulnerabilities with CodeQL's data flow and taint tracking analysis.
SARIF Parsing
Trail of BitsParses, aggregates and deduplicates SARIF files from static analysis tools such as CodeQL and Semgrep.
Questions
GitHub Copilot and skills.
Do Claude skills work in GitHub Copilot?
Often. A skill is a folder of instructions and scripts in the open SKILL.md format, which GitHub Copilot reads. A skill that depends on tools only one agent provides will not carry over, so read the skill's source before you rely on it.
How do I install a skill in GitHub Copilot?
Each skill page has an install command. Run it in a terminal, then start a new GitHub Copilot session so the skill is picked up.
What is the difference between a skill and an instructions file such as AGENTS.md?
An instructions file is loaded in every session and describes the project. A skill is loaded only when a task calls for it, so it can be long and specific without costing context on every turn.