microsoft/cat-agent-skills is a static website that catalogs reusable instruction sets and related packages for AI agents. People use it to search, filter, rate, and download skills for Cowork, Copilot Studio, and Scout, along with Copilot plugins and Scout automations. The catalogue entries are the skills, instructions, plugins, and settings displayed by the site.
Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add microsoft/cat-agent-skills --skill linkedin-content-writergit clone --depth 1 https://github.com/microsoft/cat-agent-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/microsoft/cat-agent-skills/linkedin-content-writer)<a href="https://agentmods.dev/skills/microsoft/cat-agent-skills/linkedin-content-writer"><img src="https://agentmods.dev/badge/skills/microsoft/cat-agent-skills/linkedin-content-writer/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/microsoft/cat-agent-skills/linkedin-content-writer"><img src="https://agentmods.dev/badge/skills/microsoft/cat-agent-skills/linkedin-content-writer.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 1 finding, up to medium
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- medium Excessive Agency · line 72 Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.Fix: Add human-in-the-loop confirmation for destructive, irreversible, or high-impact operations. Never auto-execute commands that modify files, send data, or alter system state.
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00081 | $0.03180 |
| Opus 5 | $0.00041 | $0.01590 |
| Sonnet 5 | $0.00016 | $0.00636 |
| Haiku 4.5 | $0.00008 | $0.00318 |
Grade A, and why
linkedin-content-writer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 255 lines — stays where its author put it; the contents beside it link to each section on GitHub.
LinkedIn Content Writer
Turn supplied or genuinely accessed material into ready-to-publish, text-based LinkedIn content around one supported point. Adapt to conversation-scoped preferences, and ask only when missing substance, permission, or approval blocks a credible result.
Source boundary
Before choosing an angle, silently separate the supplied material into confirmed facts and stated views, output constraints, and unknowns. Use only confirmed facts and stated views for factual or attributed claims; unknowns stay unknown. Every detail, including grammatical person, ownership, recency, scope, status, reaction, benefit, plans, and illustrative operational examples, must be traceable to the supplied material. Remove anything untraceable.
Neutral defaults
When no presentation preference is supplied, write for an interested professional non-specialist in a clear, credible, conversational tone. Preserve the source's language and spelling convention. Use plain text and natural paragraphing, omit hashtags and emojis, do not introduce em or en dashes, and avoid hype and engagement bait. For a new standard post, use a source-specific hook and one coherent closing move. These defaults do not override the operation rules or any user preference.
Workflow
- Identify the operation: draft, rewrite, polish, review, repurpose, ideate, comment, or configure preferences. Identify the requested format and constraints. On a follow-up turn, carry forward the current operation and treat a short answer as additional task material, not a standalone request. Default to one standard text post when none is specified.
- Decide whether the request is ready:
- Continue when the user supplies enough substance for a safe, useful result. Do not require configuration first.
- For broad onboarding, ask one concise choice: configure a reusable profile, or start from a topic, source, experience, draft, or point using neutral defaults. Do not explain the routes unless asked.
- Treat a topic-only drafting request as incomplete when it contains no supplied or endorsed point, evidence, experience, source, or perspective. Do not invent the author's view or experience from general knowledge; ask one focused question for the intended point or support. When the user explicitly asks for ideas, angles, or hypotheses, proceed and label them exploratory.
- An endorsed point without supporting evidence can support an opinion post, but not factual claims about what most people or organisations do. Frame it as a viewpoint, possibility, or question and do not generalise beyond it. Ask for support only when the requested result requires factual, causal, or experiential claims.
- Treat a coherent brief with related facts, or a result plus its scope or limitation, as ready for a narrow post even when no angle is supplied. If several safe angles exist, choose one rather than asking the user to choose. Only an isolated fact or count with no supported relationship, caveat, point, or publication purpose is too thin for a standard post; ask one focused question. Draft it directly when the user requests a minimal factual announcement.
- When missing information materially affects substance, safety, permission, or publishability, ask one high-leverage question. Use up to three concise questions only for independent gaps. Prioritise the core point and supporting evidence, then audience or reader response, attribution, confidentiality, permission, or approval. Do not ask for information already supplied or for optional preferences that have safe defaults.
- Return only the questions and wait. Do not draft filler alongside them.
- When one requested element is unsupported or contradicted by the supplied material but a safe result remains possible, omit that element, add a short note only if needed, and complete the task. Do not ask the user to confirm a claim that the same request says is unagreed or unknown. Treat any decision, owner, timing, or action marked unagreed or unknown as unavailable. Keep suggestions conditional; do not imply that work is planned or under way.
- Apply presentation preferences in this order:
- the latest task instruction or correction;
- an active writing profile in the request, conversation, or host agent;
- supplied brand guidance or writing examples;
- the supplied draft's voice and presentation;
- the neutral defaults below.
- When a separate writing sample is supplied as a style reference, rather than as the draft being edited, extract only low-level mechanics: sentence length, contractions, formality, cadence, and paragraph rhythm. Before drafting, deliberately choose a different opening, scaffold, sentence architecture, and rhetorical sequence. Changing only the words while retaining a distinctive grammatical pattern or rhetorical scaffold still counts as reuse. Do not import the sample's facts, claims, stance, perspective, first-person ownership, repeated openings, or distinctive devices unless the user names a device and the supplied material independently supports it.
- Apply the relevant operation rules, then run the final check.
What ships with it
2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 255 lines · 81 tokens per session scan A f500f29d7ed7
linkedin-content-writer is a skill published in the GitHub repository microsoft/cat-agent-skills (66 stars, last pushed yesterday), licensed MIT. It adds 81 tokens to every session and 3,180 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
local-ai-agents
Build local-first AI agents that run entirely on a developer workstation with Microsoft Foundry Local and Qwen function-calling models. Covers Small Language Models (SLMs), the OpenAI-compatible local endpoint, sandboxed local tools, local RAG with Chroma, local MCP servers, hybrid cloud/local routing, and the…
next-cache-components-adoption
Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…
insight-error-page
Write or audit an insight-kind error page for the Next.js dev overlay. Use when creating a new errors/ .mdx page, auditing an existing one, or checking that a page matches the framework fix cards. Covers page structure, title alignment, FixCard cards with Copy prompt button, code snippets, terminology verification…
next-cache-components-optimizer
Drive a Next.js route to instant navigation by setting up an agentic loop, under Cache Components / PPR, on initial load (hard navigation) and client-side navigation (soft navigation). Encode the goal as a failing @next/playwright instant() e2e and work it to green, one verified route at a time; the shipped test then…
next-partial-prefetching-adoption
Turn on Partial Prefetching in a Next.js app and work through the insights it surfaces. Use when the user wants to enable or adopt Partial Prefetching, flip the partialPrefetching flag, opt routes in with export const prefetch = 'partial', audit Link prefetch={true} behavior, preserve existing prefetched UI with…