Agent Library

21,500+ skills & agents. Every one governed.

5,814 pre-built agents and 15,654 library skills across 24 industries and 12 roles per industry — installable from the catalog, connected to your systems, and run through the same fail-closed gate chain as everything else on Cortex.

21,511 library templates across the catalog matrix

Agent Studio
skills
Search KBCreate ticketSend email add
Publishedv4 · reliability 96
Where is order #4471?
Shipped, arriving Thursday.tools: Search KB · $0.004
studio ▸ build → publish → chat-test
Collections

Start from a curated collection.

Hand-built suites for the jobs enterprises automate first — every collection ships governed, with policies and audit built in.

Wealth & Retirement · 121 skills
  • Retirement income & withdrawal strategy
  • Tax: Roth/RRSP, loss harvesting, rule changes
  • Estate, insurance & cross-border planning
  • Advisor tools: meeting prep, compliance pre-screen
Enterprise Role Packs · 11 roles
  • Service, Sales & Customer Success
  • IT Service Desk, HR & Finance Ops
  • Legal Intake, Procurement & Field Ops
  • Risk & Compliance
Productivity Pack · 9 agents
  • Inbox triage & email drafting
  • Meeting prep, notes & follow-up
  • Smart scheduling & daily brief
  • Executive assistant orchestration
Gene collection · 630 agents
  • Smart claims, actuarial & AML
  • Audit, GRC & ESG reporting
  • ITAM / ITSM & security operations
  • Data & analytics workbenches
Browse the library

Find the skill your team needs.

Search 21,500+ governed skills and agents, or filter by industry and type — every result installs from the catalog and runs through the same gates.

skill

Query supplied record data — Threat Hunter, Cybersecurity

Query supplied record data for Threat Hunter teams in Cybersecurity, delivered by the Reconciliation Brief pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterReconciliation Brief
skill

Summarize potential discrepancies — Threat Hunter, Cybersecurity

Summarize potential discrepancies for Threat Hunter teams in Cybersecurity, delivered by the Reconciliation Brief pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterReconciliation Brief
skill

Prepare a reconciliation brief — Threat Hunter, Cybersecurity

Prepare a reconciliation brief for Threat Hunter teams in Cybersecurity, delivered by the Reconciliation Brief pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterReconciliation Brief
skill

Assess a supplied exception — Threat Hunter, Cybersecurity

Assess a supplied exception for Threat Hunter teams in Cybersecurity, delivered by the Exception Review pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterException Review
skill

Summarize the assessment — Threat Hunter, Cybersecurity

Summarize the assessment for Threat Hunter teams in Cybersecurity, delivered by the Exception Review pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterException Review
skill

Recommend follow-up review — Threat Hunter, Cybersecurity

Recommend follow-up review for Threat Hunter teams in Cybersecurity, delivered by the Exception Review pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterException Review
skill

Run an on-demand read query — Threat Hunter, Cybersecurity

Run an on-demand read query for Threat Hunter teams in Cybersecurity, delivered by the On-demand Reporting & Insights pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterOn-demand Reporting & Insights
skill

Summarize query results — Threat Hunter, Cybersecurity

Summarize query results for Threat Hunter teams in Cybersecurity, delivered by the On-demand Reporting & Insights pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterOn-demand Reporting & Insights
skill

Highlight supplied exceptions — Threat Hunter, Cybersecurity

Highlight supplied exceptions for Threat Hunter teams in Cybersecurity, delivered by the On-demand Reporting & Insights pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterOn-demand Reporting & Insights
skill

Assess supplied context — Threat Hunter, Cybersecurity

Assess supplied context for Threat Hunter teams in Cybersecurity, delivered by the Decision Support pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterDecision Support
skill

Draft a recommended response — Threat Hunter, Cybersecurity

Draft a recommended response for Threat Hunter teams in Cybersecurity, delivered by the Decision Support pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterDecision Support
skill

Prepare rationale for review — Threat Hunter, Cybersecurity

Prepare rationale for review for Threat Hunter teams in Cybersecurity, delivered by the Decision Support pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterDecision Support
skill

Summarize supplied work — Threat Hunter, Cybersecurity

Summarize supplied work for Threat Hunter teams in Cybersecurity, delivered by the Routing Advisor pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterRouting Advisor
skill

Assess priority and risk — Threat Hunter, Cybersecurity

Assess priority and risk for Threat Hunter teams in Cybersecurity, delivered by the Routing Advisor pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterRouting Advisor
skill

Recommend a routing decision — Threat Hunter, Cybersecurity

Recommend a routing decision for Threat Hunter teams in Cybersecurity, delivered by the Routing Advisor pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterRouting Advisor
skill

Query supplied historical data — Threat Hunter, Cybersecurity

Query supplied historical data for Threat Hunter teams in Cybersecurity, delivered by the Trend Briefing pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterTrend Briefing
skill

Summarize observed trends — Threat Hunter, Cybersecurity

Summarize observed trends for Threat Hunter teams in Cybersecurity, delivered by the Trend Briefing pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterTrend Briefing
skill

Prepare questions for forecast review — Threat Hunter, Cybersecurity

Prepare questions for forecast review for Threat Hunter teams in Cybersecurity, delivered by the Trend Briefing pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterTrend Briefing
skill

Search approved onboarding knowledge — Threat Hunter, Cybersecurity

Search approved onboarding knowledge for Threat Hunter teams in Cybersecurity, delivered by the Onboarding Guide pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterOnboarding Guide
skill

Draft step-by-step guidance — Threat Hunter, Cybersecurity

Draft step-by-step guidance for Threat Hunter teams in Cybersecurity, delivered by the Onboarding Guide pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterOnboarding Guide
skill

Prepare a review checklist — Threat Hunter, Cybersecurity

Prepare a review checklist for Threat Hunter teams in Cybersecurity, delivered by the Onboarding Guide pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterOnboarding Guide
skill

Summarize supplied feedback — Threat Hunter, Cybersecurity

Summarize supplied feedback for Threat Hunter teams in Cybersecurity, delivered by the Feedback Summary pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterFeedback Summary
skill

Surface recurring points — Threat Hunter, Cybersecurity

Surface recurring points for Threat Hunter teams in Cybersecurity, delivered by the Feedback Summary pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterFeedback Summary
skill

Prepare follow-up questions — Threat Hunter, Cybersecurity

Prepare follow-up questions for Threat Hunter teams in Cybersecurity, delivered by the Feedback Summary pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.

CybersecurityThreat HunterFeedback Summary
Governed by default

Install is the easy part. Governance comes with it.

Library agents aren't scripts — they're governed identities. Installing one registers it with an owner, a budget, allowed models and actions, and a place in the audit ledger.

1 · Pick

Choose from the catalog

Filter by your industry and role; every item lists the systems it connects to and the skills it invokes.

2 · Connect

Wire it to your stack

Connectors, MCP servers, and OpenAPI imports — scoped by allowlists and DLP at the gateway.

3 · Run governed

Every run through the gates

Identity, budget, guardrails, registry, control tower, execute, output guard — then a signed receipt in the Trust Ledger. On every plan.

Don't see the skill you need?

The visual skill builder ships new skills without code — or tell us what's missing and we'll point you at the closest governed pattern.

Agent Library — 21,500+ skills & agents | Cortex AI OS