- Retirement income & withdrawal strategy
- Tax: Roth/RRSP, loss harvesting, rule changes
- Estate, insurance & cross-border planning
- Advisor tools: meeting prep, compliance pre-screen
21,500+ skills & agents. Every one governed.
5,814 pre-built agents and 15,654 library skills across 24 industries and 12 roles per industry — installable from the catalog, connected to your systems, and run through the same fail-closed gate chain as everything else on Cortex.
21,511 governed library items · counted live from the catalog, not a marketing number
Start from a curated collection.
Hand-built suites for the jobs enterprises automate first — every collection ships governed, with policies and audit built in.
- Service, Sales & Customer Success
- IT Service Desk, HR & Finance Ops
- Legal Intake, Procurement & Field Ops
- Risk & Compliance
- Inbox triage & email drafting
- Meeting prep, notes & follow-up
- Smart scheduling & daily brief
- Executive assistant orchestration
- Smart claims, actuarial & AML
- Audit, GRC & ESG reporting
- ITAM / ITSM & security operations
- Data & analytics workbenches
Find the skill your team needs.
Search 21,500+ governed skills and agents, or filter by industry and type — every result installs from the catalog and runs through the same gates.
864 results · Cybersecurity
Summarize supplied work — Incident Responder, Cybersecurity
Summarize supplied work for Incident Responder teams in Cybersecurity, delivered by the Routing Advisor pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Assess priority and risk — Incident Responder, Cybersecurity
Assess priority and risk for Incident Responder teams in Cybersecurity, delivered by the Routing Advisor pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Recommend a routing decision — Incident Responder, Cybersecurity
Recommend a routing decision for Incident Responder teams in Cybersecurity, delivered by the Routing Advisor pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Query supplied historical data — Incident Responder, Cybersecurity
Query supplied historical data for Incident Responder teams in Cybersecurity, delivered by the Trend Briefing pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Summarize observed trends — Incident Responder, Cybersecurity
Summarize observed trends for Incident Responder teams in Cybersecurity, delivered by the Trend Briefing pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Prepare questions for forecast review — Incident Responder, Cybersecurity
Prepare questions for forecast review for Incident Responder teams in Cybersecurity, delivered by the Trend Briefing pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Search approved onboarding knowledge — Incident Responder, Cybersecurity
Search approved onboarding knowledge for Incident Responder teams in Cybersecurity, delivered by the Onboarding Guide pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Draft step-by-step guidance — Incident Responder, Cybersecurity
Draft step-by-step guidance for Incident Responder teams in Cybersecurity, delivered by the Onboarding Guide pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Prepare a review checklist — Incident Responder, Cybersecurity
Prepare a review checklist for Incident Responder teams in Cybersecurity, delivered by the Onboarding Guide pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Summarize supplied feedback — Incident Responder, Cybersecurity
Summarize supplied feedback for Incident Responder teams in Cybersecurity, delivered by the Feedback Summary pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Surface recurring points — Incident Responder, Cybersecurity
Surface recurring points for Incident Responder teams in Cybersecurity, delivered by the Feedback Summary pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Prepare follow-up questions — Incident Responder, Cybersecurity
Prepare follow-up questions for Incident Responder teams in Cybersecurity, delivered by the Feedback Summary pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Search approved knowledge — Incident Responder, Cybersecurity
Search approved knowledge for Incident Responder teams in Cybersecurity, delivered by the Research & Discovery pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Summarize supplied findings — Incident Responder, Cybersecurity
Summarize supplied findings for Incident Responder teams in Cybersecurity, delivered by the Research & Discovery pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Draft a research brief — Incident Responder, Cybersecurity
Draft a research brief for Incident Responder teams in Cybersecurity, delivered by the Research & Discovery pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Search approved process knowledge — Incident Responder, Cybersecurity
Search approved process knowledge for Incident Responder teams in Cybersecurity, delivered by the Process Guidance pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Summarize supplied process context — Incident Responder, Cybersecurity
Summarize supplied process context for Incident Responder teams in Cybersecurity, delivered by the Process Guidance pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Draft next-step guidance — Incident Responder, Cybersecurity
Draft next-step guidance for Incident Responder teams in Cybersecurity, delivered by the Process Guidance pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Summarize supplied request context — Vulnerability Analyst, Cybersecurity
Summarize supplied request context for Vulnerability Analyst teams in Cybersecurity, delivered by the Intake Review & Triage pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Assess urgency and risk — Vulnerability Analyst, Cybersecurity
Assess urgency and risk for Vulnerability Analyst teams in Cybersecurity, delivered by the Intake Review & Triage pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Recommend a review priority — Vulnerability Analyst, Cybersecurity
Recommend a review priority for Vulnerability Analyst teams in Cybersecurity, delivered by the Intake Review & Triage pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Condense supplied content — Vulnerability Analyst, Cybersecurity
Condense supplied content for Vulnerability Analyst teams in Cybersecurity, delivered by the Document Summarizer pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Surface key points — Vulnerability Analyst, Cybersecurity
Surface key points for Vulnerability Analyst teams in Cybersecurity, delivered by the Document Summarizer pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Produce a concise brief — Vulnerability Analyst, Cybersecurity
Produce a concise brief for Vulnerability Analyst teams in Cybersecurity, delivered by the Document Summarizer pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Install is the easy part. Governance comes with it.
Library agents aren't scripts — they're governed identities. Installing one registers it with an owner, a budget, allowed models and actions, and a place in the audit ledger.
Choose from the catalog
Filter by your industry and role; every item lists the systems it connects to and the skills it invokes.
Wire it to your stack
Connectors, MCP servers, and OpenAPI imports — scoped by allowlists and DLP at the gateway.
Every run through the gates
Identity, budget, guardrails, policy, oversight — then a signed receipt in the Trust Ledger. On every plan.
Don't see the skill you need?
The visual skill builder ships new skills without code — or tell us what's missing and we'll point you at the closest governed pattern.