- Retirement income & withdrawal strategy
- Tax: Roth/RRSP, loss harvesting, rule changes
- Estate, insurance & cross-border planning
- Advisor tools: meeting prep, compliance pre-screen
21,500+ skills & agents. Every one governed.
5,814 pre-built agents and 15,654 library skills across 24 industries and 12 roles per industry — installable from the catalog, connected to your systems, and run through the same fail-closed gate chain as everything else on Cortex.
21,511 library templates across the catalog matrix
Start from a curated collection.
Hand-built suites for the jobs enterprises automate first — every collection ships governed, with policies and audit built in.
- Service, Sales & Customer Success
- IT Service Desk, HR & Finance Ops
- Legal Intake, Procurement & Field Ops
- Risk & Compliance
- Inbox triage & email drafting
- Meeting prep, notes & follow-up
- Smart scheduling & daily brief
- Executive assistant orchestration
- Smart claims, actuarial & AML
- Audit, GRC & ESG reporting
- ITAM / ITSM & security operations
- Data & analytics workbenches
Find the skill your team needs.
Search 21,500+ governed skills and agents, or filter by industry and type — every result installs from the catalog and runs through the same gates.
204 results · Cybersecurity · “HR”
Search approved knowledge — Threat Hunter, Cybersecurity
Search approved knowledge for Threat Hunter teams in Cybersecurity, delivered by the Research & Discovery pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Summarize supplied findings — Threat Hunter, Cybersecurity
Summarize supplied findings for Threat Hunter teams in Cybersecurity, delivered by the Research & Discovery pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Draft a research brief — Threat Hunter, Cybersecurity
Draft a research brief for Threat Hunter teams in Cybersecurity, delivered by the Research & Discovery pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Search approved process knowledge — Threat Hunter, Cybersecurity
Search approved process knowledge for Threat Hunter teams in Cybersecurity, delivered by the Process Guidance pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Summarize supplied process context — Threat Hunter, Cybersecurity
Summarize supplied process context for Threat Hunter teams in Cybersecurity, delivered by the Process Guidance pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Draft next-step guidance — Threat Hunter, Cybersecurity
Draft next-step guidance for Threat Hunter teams in Cybersecurity, delivered by the Process Guidance pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Summarize supplied request context — Threat Intel Analyst, Cybersecurity
Summarize supplied request context for Threat Intel Analyst teams in Cybersecurity, delivered by the Intake Review & Triage pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Assess urgency and risk — Threat Intel Analyst, Cybersecurity
Assess urgency and risk for Threat Intel Analyst teams in Cybersecurity, delivered by the Intake Review & Triage pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Recommend a review priority — Threat Intel Analyst, Cybersecurity
Recommend a review priority for Threat Intel Analyst teams in Cybersecurity, delivered by the Intake Review & Triage pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Condense supplied content — Threat Intel Analyst, Cybersecurity
Condense supplied content for Threat Intel Analyst teams in Cybersecurity, delivered by the Document Summarizer pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Surface key points — Threat Intel Analyst, Cybersecurity
Surface key points for Threat Intel Analyst teams in Cybersecurity, delivered by the Document Summarizer pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Produce a concise brief — Threat Intel Analyst, Cybersecurity
Produce a concise brief for Threat Intel Analyst teams in Cybersecurity, delivered by the Document Summarizer pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Search approved knowledge — Threat Intel Analyst, Cybersecurity
Search approved knowledge for Threat Intel Analyst teams in Cybersecurity, delivered by the Q&A Assistant pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Draft a grounded response — Threat Intel Analyst, Cybersecurity
Draft a grounded response for Threat Intel Analyst teams in Cybersecurity, delivered by the Q&A Assistant pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Prepare a review-ready answer — Threat Intel Analyst, Cybersecurity
Prepare a review-ready answer for Threat Intel Analyst teams in Cybersecurity, delivered by the Q&A Assistant pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Draft from supplied context — Threat Intel Analyst, Cybersecurity
Draft from supplied context for Threat Intel Analyst teams in Cybersecurity, delivered by the Drafting & Generation pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Follow configured behavior guidance — Threat Intel Analyst, Cybersecurity
Follow configured behavior guidance for Threat Intel Analyst teams in Cybersecurity, delivered by the Drafting & Generation pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Prepare copy for revision — Threat Intel Analyst, Cybersecurity
Prepare copy for revision for Threat Intel Analyst teams in Cybersecurity, delivered by the Drafting & Generation pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Summarize a supplied record — Threat Intel Analyst, Cybersecurity
Summarize a supplied record for Threat Intel Analyst teams in Cybersecurity, delivered by the Record Review pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Assess possible risk — Threat Intel Analyst, Cybersecurity
Assess possible risk for Threat Intel Analyst teams in Cybersecurity, delivered by the Record Review pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Flag items for human review — Threat Intel Analyst, Cybersecurity
Flag items for human review for Threat Intel Analyst teams in Cybersecurity, delivered by the Record Review pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Run a parameterized read query — Threat Intel Analyst, Cybersecurity
Run a parameterized read query for Threat Intel Analyst teams in Cybersecurity, delivered by the Data Query & Summary pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Summarize returned records — Threat Intel Analyst, Cybersecurity
Summarize returned records for Threat Intel Analyst teams in Cybersecurity, delivered by the Data Query & Summary pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Prepare a result-set overview — Threat Intel Analyst, Cybersecurity
Prepare a result-set overview for Threat Intel Analyst teams in Cybersecurity, delivered by the Data Query & Summary pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Install is the easy part. Governance comes with it.
Library agents aren't scripts — they're governed identities. Installing one registers it with an owner, a budget, allowed models and actions, and a place in the audit ledger.
Choose from the catalog
Filter by your industry and role; every item lists the systems it connects to and the skills it invokes.
Wire it to your stack
Connectors, MCP servers, and OpenAPI imports — scoped by allowlists and DLP at the gateway.
Every run through the gates
Identity, budget, guardrails, registry, control tower, execute, output guard — then a signed receipt in the Trust Ledger. On every plan.
Don't see the skill you need?
The visual skill builder ships new skills without code — or tell us what's missing and we'll point you at the closest governed pattern.