Agent Library

21,500+ skills & agents. Every one governed.

5,814 pre-built agents and 15,654 library skills across 24 industries and 12 roles per industry — installable from the catalog, connected to your systems, and run through the same fail-closed gate chain as everything else on Cortex.

21,511 library templates across the catalog matrix

Agent Studio
skills
Search KBCreate ticketSend email add
Publishedv4 · reliability 96
Where is order #4471?
Shipped, arriving Thursday.tools: Search KB · $0.004
studio ▸ build → publish → chat-test
Collections

Start from a curated collection.

Hand-built suites for the jobs enterprises automate first — every collection ships governed, with policies and audit built in.

Wealth & Retirement · 121 skills
  • Retirement income & withdrawal strategy
  • Tax: Roth/RRSP, loss harvesting, rule changes
  • Estate, insurance & cross-border planning
  • Advisor tools: meeting prep, compliance pre-screen
Enterprise Role Packs · 11 roles
  • Service, Sales & Customer Success
  • IT Service Desk, HR & Finance Ops
  • Legal Intake, Procurement & Field Ops
  • Risk & Compliance
Productivity Pack · 9 agents
  • Inbox triage & email drafting
  • Meeting prep, notes & follow-up
  • Smart scheduling & daily brief
  • Executive assistant orchestration
Gene collection · 630 agents
  • Smart claims, actuarial & AML
  • Audit, GRC & ESG reporting
  • ITAM / ITSM & security operations
  • Data & analytics workbenches
Browse the library

Find the skill your team needs.

Search 21,500+ governed skills and agents, or filter by industry and type — every result installs from the catalog and runs through the same gates.

agent

Cybersecurity: Security Engineer Routing Advisor

Working supplied-work routing advisor for Security Engineer teams in Cybersecurity. Paste the work item and available destination options when you run it; Cortex explains priority and recommends a destination for human review without assigning, transferring, queueing, notifying, or escalating anything.

CybersecuritySecurity EngineerRouting Advisor
agent

Cybersecurity: Security Engineer Trend Briefing

Trend Briefing template for Security Engineer teams in Cybersecurity. Summarizes supplied historical data and query results; it does not run a forecasting model. Use this template in Agent Builder to create and test a runtime agent; configure any supported integrations separately. Possible integration contexts include Splunk, CrowdStrike, Microsoft Sentinel.

CybersecuritySecurity EngineerTrend Briefing
agent

Cybersecurity: Security Engineer Onboarding Guide

Onboarding Guide for Security Engineer teams in Cybersecurity. Searches approved knowledge and drafts onboarding guidance; it does not collect inputs or track completion Uses supplied context and, where advertised, authorized Cortex knowledge. Provide the applicable policies or thresholds for policy and risk determinations. No external connector is required.

CybersecuritySecurity EngineerOnboarding Guide
agent

Cybersecurity: Security Engineer Feedback Summary

Working supplied-feedback summary for Security Engineer teams in Cybersecurity. Paste the respondent comments when you run it; Cortex surfaces recurring and minority viewpoints and prepares follow-up questions without scoring sentiment or contacting anyone.

CybersecuritySecurity EngineerFeedback Summary
agent

Cybersecurity: Security Engineer Research & Discovery

Research & Discovery for Security Engineer teams in Cybersecurity. Searches approved Cortex knowledge, summarizes supplied findings, and drafts a research brief Uses supplied context and, where advertised, authorized Cortex knowledge. Provide the applicable policies or thresholds for policy and risk determinations. No external connector is required.

CybersecuritySecurity EngineerResearch & Discovery
agent

Cybersecurity: Security Engineer Process Guidance

Process Guidance for Security Engineer teams in Cybersecurity. Drafts process guidance from approved knowledge and supplied context; it does not execute steps or coordinate systems Uses supplied context and, where advertised, authorized Cortex knowledge. Provide the applicable policies or thresholds for policy and risk determinations. No external connector is required.

CybersecuritySecurity EngineerProcess Guidance
agent

Cybersecurity: Threat Intel Analyst Intake Review & Triage

Working supplied-intake review and triage agent for Threat Intel Analyst teams in Cybersecurity. Paste the request or incident context when you run it; Cortex summarizes the supplied facts, identifies missing information, and recommends an advisory human-review priority without routing or assigning work.

CybersecurityThreat Intel AnalystIntake Review & Triage
agent

Cybersecurity: Threat Intel Analyst Document Summarizer

Working supplied-content summarizer for Threat Intel Analyst teams in Cybersecurity. Paste the material to summarize when you run it; no external system connection is included or required.

CybersecurityThreat Intel AnalystDocument Summarizer
agent

Cybersecurity: Threat Intel Analyst Q&A Assistant

Working supplied-reference Q&A agent for Threat Intel Analyst teams in Cybersecurity. Paste the reference material and question when you run it; Cortex answers only from that material, identifies what is not supported, and prepares a review-ready response without requiring a knowledge-base connection or taking external action.

CybersecurityThreat Intel AnalystQ&A Assistant
agent

Cybersecurity: Threat Intel Analyst Drafting & Generation

Working supplied-context drafting agent for Threat Intel Analyst teams in Cybersecurity. Paste the facts and requested message when you run it; Cortex produces a clearly labelled draft for human revision without sending it or inventing missing details.

CybersecurityThreat Intel AnalystDrafting & Generation
agent

Cybersecurity: Threat Intel Analyst Record Review

Working supplied-record review agent for Threat Intel Analyst teams in Cybersecurity. Paste the record when you run it; Cortex separates facts from interpretation, identifies missing information, and surfaces possible concerns for human review without applying labels or making decisions.

CybersecurityThreat Intel AnalystRecord Review
agent

Cybersecurity: Threat Intel Analyst Data Query & Summary

Data Query & Summary template for Threat Intel Analyst teams in Cybersecurity. Runs a governed read query and summarizes the returned records; it does not write source data. Use this template in Agent Builder to create and test a runtime agent; configure any supported integrations separately. Possible integration contexts include Splunk, CrowdStrike, Microsoft Sentinel.

CybersecurityThreat Intel AnalystData Query & Summary
agent

Cybersecurity: Threat Intel Analyst Compliance Checker

Compliance Checker for Threat Intel Analyst teams in Cybersecurity. Evaluates supplied context against applicable policy and prepares review findings Uses supplied context and, where advertised, authorized Cortex knowledge. Provide the applicable policies or thresholds for policy and risk determinations. No external connector is required.

CybersecurityThreat Intel AnalystCompliance Checker
agent

Cybersecurity: Threat Intel Analyst Risk Assessment

Risk Assessment for Threat Intel Analyst teams in Cybersecurity. Assesses a supplied entity or transaction against policy thresholds and explains the result Uses supplied context and, where advertised, authorized Cortex knowledge. Provide the applicable policies or thresholds for policy and risk determinations. No external connector is required.

CybersecurityThreat Intel AnalystRisk Assessment
agent

Cybersecurity: Threat Intel Analyst Reconciliation Brief

Reconciliation Brief template for Threat Intel Analyst teams in Cybersecurity. Queries supplied record data and prepares a discrepancy brief; it does not adjust source records. Use this template in Agent Builder to create and test a runtime agent; configure any supported integrations separately. Possible integration contexts include Splunk, CrowdStrike, Microsoft Sentinel.

CybersecurityThreat Intel AnalystReconciliation Brief
agent

Cybersecurity: Threat Intel Analyst Exception Review

Working supplied-exception review agent for Threat Intel Analyst teams in Cybersecurity. Paste an exception or event when you run it; Cortex separates facts from missing context, explains possible concerns and confidence, and recommends human follow-up without monitoring streams, creating alerts, blocking activity, notifying anyone, or escalating a case.

CybersecurityThreat Intel AnalystException Review
agent

Cybersecurity: Threat Intel Analyst On-demand Reporting & Insights

On-demand Reporting & Insights template for Threat Intel Analyst teams in Cybersecurity. Runs an on-demand read query and summarizes the result; it does not schedule or deliver recurring reports. Use this template in Agent Builder to create and test a runtime agent; configure any supported integrations separately. Possible integration contexts include Splunk, CrowdStrike, Microsoft Sentinel.

CybersecurityThreat Intel AnalystOn-demand Reporting & Insights
agent

Cybersecurity: Threat Intel Analyst Decision Support

Decision Support for Threat Intel Analyst teams in Cybersecurity. Assesses supplied context and drafts a recommendation for a person to review Uses supplied context and, where advertised, authorized Cortex knowledge. Provide the applicable policies or thresholds for policy and risk determinations. No external connector is required.

CybersecurityThreat Intel AnalystDecision Support
agent

Cybersecurity: Threat Intel Analyst Routing Advisor

Working supplied-work routing advisor for Threat Intel Analyst teams in Cybersecurity. Paste the work item and available destination options when you run it; Cortex explains priority and recommends a destination for human review without assigning, transferring, queueing, notifying, or escalating anything.

CybersecurityThreat Intel AnalystRouting Advisor
agent

Cybersecurity: Threat Intel Analyst Trend Briefing

Trend Briefing template for Threat Intel Analyst teams in Cybersecurity. Summarizes supplied historical data and query results; it does not run a forecasting model. Use this template in Agent Builder to create and test a runtime agent; configure any supported integrations separately. Possible integration contexts include Splunk, CrowdStrike, Microsoft Sentinel.

CybersecurityThreat Intel AnalystTrend Briefing
agent

Cybersecurity: Threat Intel Analyst Onboarding Guide

Onboarding Guide for Threat Intel Analyst teams in Cybersecurity. Searches approved knowledge and drafts onboarding guidance; it does not collect inputs or track completion Uses supplied context and, where advertised, authorized Cortex knowledge. Provide the applicable policies or thresholds for policy and risk determinations. No external connector is required.

CybersecurityThreat Intel AnalystOnboarding Guide
agent

Cybersecurity: Threat Intel Analyst Feedback Summary

Working supplied-feedback summary for Threat Intel Analyst teams in Cybersecurity. Paste the respondent comments when you run it; Cortex surfaces recurring and minority viewpoints and prepares follow-up questions without scoring sentiment or contacting anyone.

CybersecurityThreat Intel AnalystFeedback Summary
agent

Cybersecurity: Threat Intel Analyst Research & Discovery

Research & Discovery for Threat Intel Analyst teams in Cybersecurity. Searches approved Cortex knowledge, summarizes supplied findings, and drafts a research brief Uses supplied context and, where advertised, authorized Cortex knowledge. Provide the applicable policies or thresholds for policy and risk determinations. No external connector is required.

CybersecurityThreat Intel AnalystResearch & Discovery
agent

Cybersecurity: Threat Intel Analyst Process Guidance

Process Guidance for Threat Intel Analyst teams in Cybersecurity. Drafts process guidance from approved knowledge and supplied context; it does not execute steps or coordinate systems Uses supplied context and, where advertised, authorized Cortex knowledge. Provide the applicable policies or thresholds for policy and risk determinations. No external connector is required.

CybersecurityThreat Intel AnalystProcess Guidance
Governed by default

Install is the easy part. Governance comes with it.

Library agents aren't scripts — they're governed identities. Installing one registers it with an owner, a budget, allowed models and actions, and a place in the audit ledger.

1 · Pick

Choose from the catalog

Filter by your industry and role; every item lists the systems it connects to and the skills it invokes.

2 · Connect

Wire it to your stack

Connectors, MCP servers, and OpenAPI imports — scoped by allowlists and DLP at the gateway.

3 · Run governed

Every run through the gates

Identity, budget, guardrails, registry, control tower, execute, output guard — then a signed receipt in the Trust Ledger. On every plan.

Don't see the skill you need?

The visual skill builder ships new skills without code — or tell us what's missing and we'll point you at the closest governed pattern.

Agent Library — 21,500+ skills & agents | Cortex AI OS