Agent Library

21,500+ skills & agents. Every one governed.

5,814 pre-built agents and 15,654 library skills across 24 industries and 12 roles per industry — installable from the catalog, connected to your systems, and run through the same fail-closed gate chain as everything else on Cortex.

21,511 governed library items · counted live from the catalog, not a marketing number

Agent Studio
skills
Search KBCreate ticketSend email add
Publishedv4 · reliability 96
Where is order #4471?
Shipped, arriving Thursday.tools: Search KB · $0.004
studio ▸ build → publish → chat-test
Collections

Start from a curated collection.

Hand-built suites for the jobs enterprises automate first — every collection ships governed, with policies and audit built in.

Wealth & Retirement · 121 skills
  • Retirement income & withdrawal strategy
  • Tax: Roth/RRSP, loss harvesting, rule changes
  • Estate, insurance & cross-border planning
  • Advisor tools: meeting prep, compliance pre-screen
Enterprise Role Packs · 11 roles
  • Service, Sales & Customer Success
  • IT Service Desk, HR & Finance Ops
  • Legal Intake, Procurement & Field Ops
  • Risk & Compliance
Productivity Pack · 9 agents
  • Inbox triage & email drafting
  • Meeting prep, notes & follow-up
  • Smart scheduling & daily brief
  • Executive assistant orchestration
Gene collection · 630 agents
  • Smart claims, actuarial & AML
  • Audit, GRC & ESG reporting
  • ITAM / ITSM & security operations
  • Data & analytics workbenches
Browse the library

Find the skill your team needs.

Search 21,500+ governed skills and agents, or filter by industry and type — every result installs from the catalog and runs through the same gates.

agent

Cybersecurity: SOC Analyst Document Summarizer

Document Summarizer template for SOC Analyst teams in Cybersecurity. Condenses supplied documents and threads into a concise brief. Installing records this template for your tenant; configure a runtime agent and any supported integrations separately. Possible integration contexts include Splunk, CrowdStrike, Microsoft Sentinel.

CybersecuritySOC AnalystDocument Summarizer
agent

Cybersecurity: SOC Analyst Risk Assessment

Risk Assessment template for SOC Analyst teams in Cybersecurity. Assesses a supplied entity or transaction against policy thresholds and explains the result. Installing records this template for your tenant; configure a runtime agent and any supported integrations separately. Possible integration contexts include Splunk, CrowdStrike, Microsoft Sentinel.

CybersecuritySOC AnalystRisk Assessment
agent

Cybersecurity: Threat Hunter Intake Review & Triage

Intake Review & Triage template for Threat Hunter teams in Cybersecurity. Summarizes supplied request context and assesses urgency; it does not capture or route work. Installing records this template for your tenant; configure a runtime agent and any supported integrations separately. Possible integration contexts include Splunk, CrowdStrike, Microsoft Sentinel.

CybersecurityThreat HunterIntake Review & Triage
agent

Cybersecurity: Threat Hunter Document Summarizer

Document Summarizer template for Threat Hunter teams in Cybersecurity. Condenses supplied documents and threads into a concise brief. Installing records this template for your tenant; configure a runtime agent and any supported integrations separately. Possible integration contexts include Splunk, CrowdStrike, Microsoft Sentinel.

CybersecurityThreat HunterDocument Summarizer
agent

Cybersecurity: Threat Hunter Q&A Assistant

Q&A Assistant template for Threat Hunter teams in Cybersecurity. Searches approved Cortex knowledge and drafts a grounded response for review. Installing records this template for your tenant; configure a runtime agent and any supported integrations separately. Possible integration contexts include Splunk, CrowdStrike, Microsoft Sentinel.

CybersecurityThreat HunterQ&A Assistant
agent

Cybersecurity: Threat Hunter Drafting & Generation

Drafting & Generation template for Threat Hunter teams in Cybersecurity. Drafts correspondence and responses from supplied context for human review. Installing records this template for your tenant; configure a runtime agent and any supported integrations separately. Possible integration contexts include Splunk, CrowdStrike, Microsoft Sentinel.

CybersecurityThreat HunterDrafting & Generation
agent

Cybersecurity: Threat Hunter Record Review

Record Review template for Threat Hunter teams in Cybersecurity. Summarizes a supplied record and assesses possible risk or ambiguity; it does not apply system labels. Installing records this template for your tenant; configure a runtime agent and any supported integrations separately. Possible integration contexts include Splunk, CrowdStrike, Microsoft Sentinel.

CybersecurityThreat HunterRecord Review
agent

Cybersecurity: Threat Hunter Data Query & Summary

Data Query & Summary template for Threat Hunter teams in Cybersecurity. Runs a governed read query and summarizes the returned records; it does not write source data. Installing records this template for your tenant; configure a runtime agent and any supported integrations separately. Possible integration contexts include Splunk, CrowdStrike, Microsoft Sentinel.

CybersecurityThreat HunterData Query & Summary
agent

Cybersecurity: Threat Hunter Compliance Checker

Compliance Checker template for Threat Hunter teams in Cybersecurity. Evaluates supplied context against applicable policy and prepares review findings. Installing records this template for your tenant; configure a runtime agent and any supported integrations separately. Possible integration contexts include Splunk, CrowdStrike, Microsoft Sentinel.

CybersecurityThreat HunterCompliance Checker
agent

Cybersecurity: Threat Hunter Risk Assessment

Risk Assessment template for Threat Hunter teams in Cybersecurity. Assesses a supplied entity or transaction against policy thresholds and explains the result. Installing records this template for your tenant; configure a runtime agent and any supported integrations separately. Possible integration contexts include Splunk, CrowdStrike, Microsoft Sentinel.

CybersecurityThreat HunterRisk Assessment
agent

Cybersecurity: Threat Hunter Reconciliation Brief

Reconciliation Brief template for Threat Hunter teams in Cybersecurity. Queries supplied record data and prepares a discrepancy brief; it does not adjust source records. Installing records this template for your tenant; configure a runtime agent and any supported integrations separately. Possible integration contexts include Splunk, CrowdStrike, Microsoft Sentinel.

CybersecurityThreat HunterReconciliation Brief
agent

Cybersecurity: Threat Hunter Exception Review

Exception Review template for Threat Hunter teams in Cybersecurity. Reviews a supplied event or record for risk; it does not watch streams or raise alerts autonomously. Installing records this template for your tenant; configure a runtime agent and any supported integrations separately. Possible integration contexts include Splunk, CrowdStrike, Microsoft Sentinel.

CybersecurityThreat HunterException Review
agent

Cybersecurity: Threat Hunter On-demand Reporting & Insights

On-demand Reporting & Insights template for Threat Hunter teams in Cybersecurity. Runs an on-demand read query and summarizes the result; it does not schedule or deliver recurring reports. Installing records this template for your tenant; configure a runtime agent and any supported integrations separately. Possible integration contexts include Splunk, CrowdStrike, Microsoft Sentinel.

CybersecurityThreat HunterOn-demand Reporting & Insights
agent

Cybersecurity: Threat Hunter Decision Support

Decision Support template for Threat Hunter teams in Cybersecurity. Assesses supplied context and drafts a recommendation for a person to review. Installing records this template for your tenant; configure a runtime agent and any supported integrations separately. Possible integration contexts include Splunk, CrowdStrike, Microsoft Sentinel.

CybersecurityThreat HunterDecision Support
agent

Cybersecurity: Threat Hunter Routing Advisor

Routing Advisor template for Threat Hunter teams in Cybersecurity. Summarizes supplied work and recommends a priority; it does not assign owners or rebalance queues. Installing records this template for your tenant; configure a runtime agent and any supported integrations separately. Possible integration contexts include Splunk, CrowdStrike, Microsoft Sentinel.

CybersecurityThreat HunterRouting Advisor
agent

Cybersecurity: Threat Hunter Trend Briefing

Trend Briefing template for Threat Hunter teams in Cybersecurity. Summarizes supplied historical data and query results; it does not run a forecasting model. Installing records this template for your tenant; configure a runtime agent and any supported integrations separately. Possible integration contexts include Splunk, CrowdStrike, Microsoft Sentinel.

CybersecurityThreat HunterTrend Briefing
agent

Cybersecurity: Threat Hunter Onboarding Guide

Onboarding Guide template for Threat Hunter teams in Cybersecurity. Searches approved knowledge and drafts onboarding guidance; it does not collect inputs or track completion. Installing records this template for your tenant; configure a runtime agent and any supported integrations separately. Possible integration contexts include Splunk, CrowdStrike, Microsoft Sentinel.

CybersecurityThreat HunterOnboarding Guide
agent

Cybersecurity: Threat Hunter Feedback Summary

Feedback Summary template for Threat Hunter teams in Cybersecurity. Summarizes supplied feedback for review; it does not autonomously score sentiment or monitor conversations. Installing records this template for your tenant; configure a runtime agent and any supported integrations separately. Possible integration contexts include Splunk, CrowdStrike, Microsoft Sentinel.

CybersecurityThreat HunterFeedback Summary
agent

Cybersecurity: Threat Hunter Research & Discovery

Research & Discovery template for Threat Hunter teams in Cybersecurity. Searches approved Cortex knowledge, summarizes supplied findings, and drafts a research brief. Installing records this template for your tenant; configure a runtime agent and any supported integrations separately. Possible integration contexts include Splunk, CrowdStrike, Microsoft Sentinel.

CybersecurityThreat HunterResearch & Discovery
agent

Cybersecurity: Threat Hunter Process Guidance

Process Guidance template for Threat Hunter teams in Cybersecurity. Drafts process guidance from approved knowledge and supplied context; it does not execute steps or coordinate systems. Installing records this template for your tenant; configure a runtime agent and any supported integrations separately. Possible integration contexts include Splunk, CrowdStrike, Microsoft Sentinel.

CybersecurityThreat HunterProcess Guidance
agent

Cybersecurity: Incident Responder Document Summarizer

Document Summarizer template for Incident Responder teams in Cybersecurity. Condenses supplied documents and threads into a concise brief. Installing records this template for your tenant; configure a runtime agent and any supported integrations separately. Possible integration contexts include Splunk, CrowdStrike, Microsoft Sentinel.

CybersecurityIncident ResponderDocument Summarizer
agent

Cybersecurity: Incident Responder Risk Assessment

Risk Assessment template for Incident Responder teams in Cybersecurity. Assesses a supplied entity or transaction against policy thresholds and explains the result. Installing records this template for your tenant; configure a runtime agent and any supported integrations separately. Possible integration contexts include Splunk, CrowdStrike, Microsoft Sentinel.

CybersecurityIncident ResponderRisk Assessment
agent

Cybersecurity: Vulnerability Analyst Document Summarizer

Document Summarizer template for Vulnerability Analyst teams in Cybersecurity. Condenses supplied documents and threads into a concise brief. Installing records this template for your tenant; configure a runtime agent and any supported integrations separately. Possible integration contexts include Splunk, CrowdStrike, Microsoft Sentinel.

CybersecurityVulnerability AnalystDocument Summarizer
agent

Cybersecurity: Vulnerability Analyst Risk Assessment

Risk Assessment template for Vulnerability Analyst teams in Cybersecurity. Assesses a supplied entity or transaction against policy thresholds and explains the result. Installing records this template for your tenant; configure a runtime agent and any supported integrations separately. Possible integration contexts include Splunk, CrowdStrike, Microsoft Sentinel.

CybersecurityVulnerability AnalystRisk Assessment
Governed by default

Install is the easy part. Governance comes with it.

Library agents aren't scripts — they're governed identities. Installing one registers it with an owner, a budget, allowed models and actions, and a place in the audit ledger.

1 · Pick

Choose from the catalog

Filter by your industry and role; every item lists the systems it connects to and the skills it invokes.

2 · Connect

Wire it to your stack

Connectors, MCP servers, and OpenAPI imports — scoped by allowlists and DLP at the gateway.

3 · Run governed

Every run through the gates

Identity, budget, guardrails, policy, oversight — then a signed receipt in the Trust Ledger. On every plan.

Don't see the skill you need?

The visual skill builder ships new skills without code — or tell us what's missing and we'll point you at the closest governed pattern.

Agent Library — 21,500+ skills & agents | Cortex AI OS