Choose AI skills by task, output and required access
Choose an AI skill by the job it performs, the artifact you need and the access it requires. Similar labels can hide very different workflows, costs and effects on external systems.
This BB Skills editorial guide compares the packaged instructions behind selected directory entries. It is a reading and selection guide, not a benchmark or a record of executing these skills in an AI client. The October 2026 directory review corrected misleading classifications and replaced generic introductions while preserving the original packages and their licenses.
1. Start with the artifact you need
Write a one-sentence outcome before choosing a resource: “produce a transcript with speaker labels,” “identify trust boundaries in this repository,” or “publish this tested application to a preview URL.” Then name the input, the output and the evidence you will inspect. A provider name alone does not tell you whether a skill can do that job.
| Your outcome | Look for | A useful first check |
|---|---|---|
| Text from recorded speech | Audio transcription | Supported input media, speaker-label behavior and API access |
| Spoken narration from text | Speech generation | Voice choices, audio output and live API requirements |
| A repository security analysis | Threat modeling, ownership analysis or secure coding review | Which question the workflow answers and what repository history it needs |
| A repeatable experiment | Notebook authoring or experiment tracking | Runnable environment, data access and saved results |
| A deployed web application | A provider-specific deployment workflow | Target project, authentication, preview or production scope |
The broad directory categories describe the main output. Use the task and role fields to narrow the choice: a workflow entry might produce audio, documentation or a research summary; a code entry might analyze a repository rather than create an application.
2. Separate transcription, speech and screenshots
Audio and Video Transcription starts with recorded media and produces text, with optional speaker labels and known-speaker hints. Speech and Voiceover Generation starts with supplied text and produces spoken audio. Neither resource should be selected because a broad visual category happens to include it.
Desktop Screenshot Capture produces an image of a requested screen, window or region. Review what is visible before sharing that artifact: a screenshot can contain an account name, a private document or another window.
Raster Image Generation and Editing uses the built-in image tool by default. Its explicit CLI fallback has separate setup and API-key requirements. Do not assume that every way of using the packaged resource needs a key pasted into chat.
3. Match a security resource to a specific question
Security workflows have different inputs and conclusions. Pick the question first, and keep any resulting claim within the analysis actually performed.
| Resource | Question it helps answer | What you still need to establish |
|---|---|---|
| Repository Threat Modeling | What are the assets, trust boundaries, attacker capabilities and abuse paths? | Whether the described architecture and controls match the running system |
| Security Ownership and Bus-Factor Analysis | Who has changed sensitive files, and where is ownership concentrated? | Whether Git history represents current responsibility and operational knowledge |
| Language-Specific Security Review | Which supported-language or framework practices deserve review in this code? | Whether findings are valid, fixed and verified in the relevant environment |
An ownership map does not test an authorization boundary. A written threat model does not prove that a mitigation works. Review scope, assumptions and practical evidence before describing a repository as secure.
4. Distinguish notebook, dataset and model tasks
Jupyter Notebook Authoring helps create or edit notebooks for experiments and tutorials. Dataset Viewer Exploration inspects dataset splits and rows and locates supported downloads. The first organizes an experiment; the second helps inspect its potential data source.
Model Memory Estimation estimates memory from metadata and stated assumptions. Local GGUF Model Selection helps compare models and quantization choices for a local setup. Estimates and model-card information are inputs to a decision, not measurements of performance on your hardware.
Trackio Experiment Logging concerns metrics, dashboards and experiment queries. Decide where the results will be stored, who can see them and how a run can be reproduced before sharing a dashboard.
5. Check access and effects before running anything
Reading a public instruction file is different from authorizing its commands. Inspect scripts and referenced files as well as the main SKILL.md. Identify which steps read data, write local files or change an external service.
| Workflow | Access to inspect | Decision to make explicit |
|---|---|---|
| Read-Only Sentry Issue Investigation | The Sentry account and project used by authenticated queries | Which issue data may be read and included in a report |
| GitHub Commit-to-PR Workflow | Repository, branch and gh authentication | Which files to stage and whether commit, push and PR publication are requested |
| Netlify Preview and Production Deployment | Netlify CLI login and the target project | Preview or production destination and which files will be published |
| Cloudflare Workers and Pages Deployment | Cloudflare account, service and target environment | What infrastructure or application state will change |
| Render Application Deployment | Project requirements and the chosen Render account | Which configuration is being prepared and which service is being deployed |
Keep credentials in the tool's supported local configuration or environment. Do not place API keys, session cookies or private keys in a skill package, a public report or a repository. Confirm the target before a workflow writes to a service.
6. Separate a free package from runtime requirements
BB Skills acquires and redistributes resources through free channels where the license permits it. That does not establish that every external API, hosting plan, storage service or model named by a package is free to run. The speech and transcription scripts, for example, have live API requirements; this guide did not make those calls.
Before using a resource, check its dependency list, account requirements, quota and intended execution mode against current official documentation. Prefer a local dry run or a preview when the workflow supports one, and inspect the result before authorizing a production action.
A missing account, dependency or permission is a setup requirement to resolve. It is not a reason to bypass a service's access rules or buy an upgrade without deciding that the cost fits your own use case.
7. Read the evidence and license separately
A package checksum identifies the bytes reviewed by the directory. Source links and the included license explain origin and redistribution terms. They do not certify that the skill works with every client or that the provider supports your intended deployment.
Use any scenario record to identify the environment, version, observed outcome and untested boundaries. A limited local fixture should be described as a limited local fixture. Avoid turning source review, schema checks or mocked responses into a claim of end-to-end execution.
This directory revision changed titles, introductions, output categories, roles, tasks and tags for selected resources. It did not rewrite their original instructions, change their package hashes or add runtime success claims. You can compare the directory explanation with the package preview before downloading.
8. Make a small, reviewable selection
Choose one resource for the immediate job. Read its entry point and required references, write down the intended inputs and target, then decide what result would count as success. For a notebook, that might be a saved reproducible experiment; for a preview deployment, a working URL with the expected content.
Use the resource's task and role fields to find alternatives, and use the security-resource comparison to contrast those three workflows without confusing their purposes. Read how BB Skills describes evaluation evidence before interpreting scenario badges.
Prepared by BB Skills with AI assistance and editorial source review. The selection examples come from the preserved packages linked in this guide. No listed skill was executed in an AI client for this article, and no paid API or hosting action was performed. For website content and discovery practices, the editorial team consulted the Google Search SEO Starter Guide and Google's guidance on AI features and websites; this page makes no claim of indexing, ranking or AI citation.