Skills.
Give your AI a better way to work.
A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.
Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.
Category: Dev tools
16,902 results · page 115 of 564
- View details
cmdi-command-injectionSkillDev tools
Teaches your agent to spot and prevent cases where user input could run shell commands.
Ready to connect★ 842
- View details
code-obfuscation-deobfuscationSkillDev tools
Lets your agent analyze and reverse obfuscated code like junk code, control flow flattening, and string encryption.
Ready to connect★ 842
- View details
custom-ai-router-assessmentSkillDev tools
Lets your agent assess self-hosted AI API gateways built on custom Next.js-style web stacks.
Ready to connect★ 842
- View details
dangling-markup-injectionSkillDev tools
Lets your agent learn how to test for dangling markup attacks that leak page data when JavaScript execution is blocked.
Ready to connect★ 842
- View details
graphql-and-hidden-parametersSkillDev tools
Guides your agent through probing GraphQL APIs for introspection, hidden parameters, and authorization flaws.
Ready to connect★ 842
- View details
hash-attack-techniquesSkillDev tools
Lets your agent apply hash attack techniques like length extension, MD5/SHA1 collisions, and HMAC timing leaks in CTFs.
Ready to connect★ 842
- View details
http-host-header-attacksSkillDev tools
Lets your agent follow a playbook for testing and exploiting HTTP Host header injection flaws in web apps.
Ready to connect★ 842
- View details
http-parameter-pollutionSkillDev tools
Lets your agent test how duplicate HTTP parameters are handled to spot security bypass risks.
Ready to connect★ 842
- View details
http2-specific-attacksSkillDev tools
Gives your agent a playbook of HTTP/2-specific attacks like request smuggling and header injection for testing targets.
Ready to connect★ 842
- View details
hunt-deserializationSkillDev tools
Lets your agent hunt insecure deserialization flaws like Java gadget chains and Python pickle RCE.
Ready to connect★ 842
- View details
hunt-http-smugglingSkillDev tools
Lets your agent test websites for HTTP request smuggling vulnerabilities caused by header parsing mismatches.
Ready to connect★ 842
- View details
hunt-sstiSkillDev tools
Lets your agent test web apps for server-side template injection flaws across many template engines.
Ready to connect★ 842
- View details
idor-broken-object-authorizationSkillDev tools
Gives your agent a playbook for testing apps for IDOR and broken object-level authorization flaws.
Ready to connect★ 842
- View details
injection-checkingSkillDev tools
Lets your agent route web injection testing tasks to the right workflow for XSS, SQL injection, SSRF, XXE, SSTI, command, and NoSQL injection.
Ready to connect★ 842
- View details
insecure-source-code-managementSkillDev tools
Lets your agent check websites for exposed source code folders, backup files, and config files during security testing.
Ready to connect★ 842
- View details
js-recon-secret-huntingSkillDev tools
Lets your agent download website JavaScript files and scan them for leaked API keys, tokens, and hidden endpoints.
Ready to connect★ 842
- View details
macos-process-injectionSkillDev tools
Gives your agent a playbook for injecting code into running or launching macOS processes using several exploitation techniques.
Ready to connect★ 842
- View details
mobile-ssl-pinning-bypassSkillDev tools
Guides your agent through bypassing SSL certificate pinning to intercept HTTPS traffic from mobile apps.
Ready to connect★ 842
- View details
network-protocol-attacksSkillDev tools
Gives your agent step-by-step playbooks for network attacks like ARP spoofing, DNS spoofing, and IDS evasion.
Ready to connect★ 842
- View details
oast-blind-testingSkillDev tools
Lets your agent generate out-of-band test payloads to detect blind SSRF, blind RCE, and data leaks.
Ready to connect★ 842
- View details
cli-skillsSkillDev tools
Gives your agent guidance on writing Go command-line tools using LlamaFarm's Cobra, Bubbletea, and Lipgloss patterns.
Ready to connect★ 838
- View details
designer-skillsSkillDev tools
Gives your agent design patterns and guidance for building frontends with React 18, TanStack Query, TailwindCSS, and Radix UI.
Ready to connect★ 838
- View details
generate-subsystem-skillsSkillDev tools
Lets your agent create specialized skills and checklists for each subsystem in a monorepo.
Ready to connect★ 838
- View details
go-skillsSkillDev tools
Shared Go best practices for LlamaFarm CLI. Covers idiomatic patterns, error handling, and testing.
Ready to connect★ 838
- View details
react-skillsSkillDev tools
Gives your agent React 18 coding patterns, including components, hooks, TanStack Query, and testing.
Ready to connect★ 838
- View details
server-skillsSkillDev tools
Gives your agent best-practice guidance for writing FastAPI, Celery, and Pydantic server code.
Ready to connect★ 838
- View details
typescript-skillsSkillDev tools
Lets your agent follow shared TypeScript coding conventions for the Designer and Electron subsystems.
Ready to connect★ 838
- View details
align-humanSkillDev tools
Checks whether your automatic judge's scores agree with human labels and flags where it is biased.
Ready to connect★ 836
- View details
bootstrapSkillDev tools
Lets your agent build a starter evaluation for your app from scratch, generating a v0 grader, test inputs, and a calibration roadmap.
Ready to connect★ 836
- View details
eval-reportSkillDev tools
Lets your agent combine results from multiple evaluation runs into one report with maturity scores, trends, and prioritized fixes.
Ready to connect★ 836
What is a skill?
A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.
53,788 of the 54,220 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.
Install one and every AI you use gets it
Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.
Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.