Agent Library

21,500+ skills & agents. Every one governed.

5,814 pre-built agents and 15,654 library skills across 24 industries and 12 roles per industry — installable from the catalog, connected to your systems, and run through the same fail-closed gate chain as everything else on Cortex.

21,511 governed library items · counted live from the catalog, not a marketing number

Agent Studio
skills
Search KBCreate ticketSend email add
Publishedv4 · reliability 96
Where is order #4471?
Shipped, arriving Thursday.tools: Search KB · $0.004
studio ▸ build → publish → chat-test
Collections

Start from a curated collection.

Hand-built suites for the jobs enterprises automate first — every collection ships governed, with policies and audit built in.

Wealth & Retirement · 121 skills
  • Retirement income & withdrawal strategy
  • Tax: Roth/RRSP, loss harvesting, rule changes
  • Estate, insurance & cross-border planning
  • Advisor tools: meeting prep, compliance pre-screen
Enterprise Role Packs · 11 roles
  • Service, Sales & Customer Success
  • IT Service Desk, HR & Finance Ops
  • Legal Intake, Procurement & Field Ops
  • Risk & Compliance
Productivity Pack · 9 agents
  • Inbox triage & email drafting
  • Meeting prep, notes & follow-up
  • Smart scheduling & daily brief
  • Executive assistant orchestration
Gene collection · 630 agents
  • Smart claims, actuarial & AML
  • Audit, GRC & ESG reporting
  • ITAM / ITSM & security operations
  • Data & analytics workbenches
Browse the library

Find the skill your team needs.

Search 21,500+ governed skills and agents, or filter by industry and type — every result installs from the catalog and runs through the same gates.

skill

Summarize supplied request context — Threat Hunter, Cybersecurity

Summarize supplied request context for Threat Hunter teams in Cybersecurity, delivered by the Intake Review & Triage pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterIntake Review & Triage
skill

Assess urgency and risk — Threat Hunter, Cybersecurity

Assess urgency and risk for Threat Hunter teams in Cybersecurity, delivered by the Intake Review & Triage pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterIntake Review & Triage
skill

Recommend a review priority — Threat Hunter, Cybersecurity

Recommend a review priority for Threat Hunter teams in Cybersecurity, delivered by the Intake Review & Triage pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterIntake Review & Triage
skill

Condense supplied content — Threat Hunter, Cybersecurity

Condense supplied content for Threat Hunter teams in Cybersecurity, delivered by the Document Summarizer pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterDocument Summarizer
skill

Surface key points — Threat Hunter, Cybersecurity

Surface key points for Threat Hunter teams in Cybersecurity, delivered by the Document Summarizer pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterDocument Summarizer
skill

Produce a concise brief — Threat Hunter, Cybersecurity

Produce a concise brief for Threat Hunter teams in Cybersecurity, delivered by the Document Summarizer pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterDocument Summarizer
skill

Search approved knowledge — Threat Hunter, Cybersecurity

Search approved knowledge for Threat Hunter teams in Cybersecurity, delivered by the Q&A Assistant pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterQ&A Assistant
skill

Draft a grounded response — Threat Hunter, Cybersecurity

Draft a grounded response for Threat Hunter teams in Cybersecurity, delivered by the Q&A Assistant pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterQ&A Assistant
skill

Prepare a review-ready answer — Threat Hunter, Cybersecurity

Prepare a review-ready answer for Threat Hunter teams in Cybersecurity, delivered by the Q&A Assistant pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterQ&A Assistant
skill

Draft from supplied context — Threat Hunter, Cybersecurity

Draft from supplied context for Threat Hunter teams in Cybersecurity, delivered by the Drafting & Generation pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterDrafting & Generation
skill

Follow configured behavior guidance — Threat Hunter, Cybersecurity

Follow configured behavior guidance for Threat Hunter teams in Cybersecurity, delivered by the Drafting & Generation pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterDrafting & Generation
skill

Prepare copy for revision — Threat Hunter, Cybersecurity

Prepare copy for revision for Threat Hunter teams in Cybersecurity, delivered by the Drafting & Generation pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterDrafting & Generation
skill

Summarize a supplied record — Threat Hunter, Cybersecurity

Summarize a supplied record for Threat Hunter teams in Cybersecurity, delivered by the Record Review pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterRecord Review
skill

Assess possible risk — Threat Hunter, Cybersecurity

Assess possible risk for Threat Hunter teams in Cybersecurity, delivered by the Record Review pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterRecord Review
skill

Flag items for human review — Threat Hunter, Cybersecurity

Flag items for human review for Threat Hunter teams in Cybersecurity, delivered by the Record Review pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterRecord Review
skill

Run a parameterized read query — Threat Hunter, Cybersecurity

Run a parameterized read query for Threat Hunter teams in Cybersecurity, delivered by the Data Query & Summary pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterData Query & Summary
skill

Summarize returned records — Threat Hunter, Cybersecurity

Summarize returned records for Threat Hunter teams in Cybersecurity, delivered by the Data Query & Summary pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterData Query & Summary
skill

Prepare a result-set overview — Threat Hunter, Cybersecurity

Prepare a result-set overview for Threat Hunter teams in Cybersecurity, delivered by the Data Query & Summary pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterData Query & Summary
skill

Check supplied context against policy — Threat Hunter, Cybersecurity

Check supplied context against policy for Threat Hunter teams in Cybersecurity, delivered by the Compliance Checker pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterCompliance Checker
skill

Surface potential policy issues — Threat Hunter, Cybersecurity

Surface potential policy issues for Threat Hunter teams in Cybersecurity, delivered by the Compliance Checker pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterCompliance Checker
skill

Recommend review items — Threat Hunter, Cybersecurity

Recommend review items for Threat Hunter teams in Cybersecurity, delivered by the Compliance Checker pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterCompliance Checker
skill

Assess supplied risk context — Threat Hunter, Cybersecurity

Assess supplied risk context for Threat Hunter teams in Cybersecurity, delivered by the Risk Assessment pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterRisk Assessment
skill

Explain assessment drivers — Threat Hunter, Cybersecurity

Explain assessment drivers for Threat Hunter teams in Cybersecurity, delivered by the Risk Assessment pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterRisk Assessment
skill

Recommend human review — Threat Hunter, Cybersecurity

Recommend human review for Threat Hunter teams in Cybersecurity, delivered by the Risk Assessment pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterRisk Assessment
Governed by default

Install is the easy part. Governance comes with it.

Library agents aren't scripts — they're governed identities. Installing one registers it with an owner, a budget, allowed models and actions, and a place in the audit ledger.

1 · Pick

Choose from the catalog

Filter by your industry and role; every item lists the systems it connects to and the skills it invokes.

2 · Connect

Wire it to your stack

Connectors, MCP servers, and OpenAPI imports — scoped by allowlists and DLP at the gateway.

3 · Run governed

Every run through the gates

Identity, budget, guardrails, policy, oversight — then a signed receipt in the Trust Ledger. On every plan.

Don't see the skill you need?

The visual skill builder ships new skills without code — or tell us what's missing and we'll point you at the closest governed pattern.

Agent Library — 21,500+ skills & agents | Cortex AI OS