Skills.
Give your AI a better way to work.
A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.
Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.
Category: Docs & knowledge
4,561 results · page 54 of 153
- View details
hunt-cicdSkillDocs & knowledge
CI/CD pipeline attack hunting (GitHub Actions focus) - pwn requests (pull_request_target), script injection, self-hosted runner takeover, cache poisoning, OIDC-to-cloud token theft, poisoned pipeline execution. Wiki-first, FIND schema output.
Ready to connect★ 322
- View details
hunt-cloudSkillDocs & knowledge
Cloud attack hunting for AWS / Azure / GCP - credential discovery, metadata SSRF, IAM privesc, service enumeration, persistence. Scope + billing aware. Wiki-first, FIND schema output.
Ready to connect★ 322
- View details
hunt-coreSkillDocs & knowledge
Shared discipline for every hunt-* skill: scope and authorization gating, the two-account rule, the confirmation gate that separates a real finding from a false positive, enumeration limits, stop conditions, marker discipline, wiki-first query and self-heal, FIND output, Deadends, and wiki distillat
Ready to connect★ 322
- View details
hunt-deserializationSkillDocs & knowledge
Insecure deserialization hunting across Java / .NET / PHP / Python / Ruby / Node. Gadget-chain RCE, OOB-gated blind detection, magic-byte fingerprinting. Wiki-first, FIND schema output.
Ready to connect★ 322
- View details
hunt-federationSkillDocs & knowledge
OAuth and SAML attack hunting - redirect_uri bypass, state CSRF, SAML XSW (XSW1-XSW8), signature stripping, comment injection. Wiki-first, FIND schema output.
Ready to connect★ 322
- View details
hunt-idorSkillDocs & knowledge
IDOR / BOLA hunting - two-account methodology, identifier discovery and UUID leak chaining, the trusted-identifier test, GraphQL node and nested-object IDOR, cross-tenant escalation, write and delete operations. Bounded ID sampling, never range sweeps. Wiki-first, FIND schema output. Trigger on IDOR
Ready to connect★ 322
- View details
hunt-llmSkillDocs & knowledge
LLM / AI application attack hunting - prompt injection (direct + indirect), excessive agency, insecure output handling, system-prompt + data leakage. OWASP LLM Top 10. Wiki-first, FIND schema output.
Ready to connect★ 322
- View details
hunt-m365SkillDocs & knowledge
Microsoft 365 / Entra ID attack - tenant discovery, user enumeration via OneDrive differential (2026 verified), AADSTS code reference, Smart Lockout math (hard cap 1-2 attempts/user), ROPC validation, Conditional Access mapping. Wiki-first, FIND schema output.
Ready to connect★ 322
- View details
hunt-macosSkillDocs & knowledge
macOS attack hunting - foothold to root/persistence on a macOS host. TCC/Gatekeeper/SIP bypass, keychain + credential loot, code-signing/entitlements abuse, XPC/dylib/library injection, launch-constraint evasion, MDM/installer abuse. Wiki-first, FIND schema output.
Ready to connect★ 322
- View details
hunt-mcpSkillDocs & knowledge
MCP server attack hunting - tool poisoning, indirect prompt injection via tool output, rug-pull updates, cross-tool shadowing, over-permissioned/excessive-agency tools, lethal trifecta. Wiki-first, FIND schema output.
Ready to connect★ 322
- View details
hunt-rceSkillDocs & knowledge
RCE hunting - template injection, YAML/XML deserialization, dependency confusion, Kubernetes surfaces, CVE-specific exploits (Apache CVE-2021-41773, Spring CVE-2022-22963). OOB-mandatory for blind cases. Wiki-first, FIND schema output.
Ready to connect★ 322
- View details
hunt-smugglingSkillDocs & knowledge
HTTP request smuggling / desync hunting - CL.TE, TE.CL, TE.TE, CL.0, and HTTP/2 downgrade. Timing-based detection, differential confirmation, no-blind-claims. Wiki-first, FIND schema output.
Ready to connect★ 322
- View details
hunt-sqliSkillDocs & knowledge
SQLi and NoSQLi hunting - error-based, boolean-blind, time-based, UNION, NoSQL operator injection. sqlmap automation after manual confirmation. Wiki-first, FIND schema output.
Ready to connect★ 322
- View details
hunt-vpnSkillDocs & knowledge
Enterprise SSL VPN attack - vendor fingerprinting, CVE matrix (Cisco, Fortinet, Citrix, Palo Alto, Pulse/Ivanti), default credentials, pre-auth exploit commands. Wiki-first, FIND schema output.
Ready to connect★ 322
- View details
hunt-xssSkillDocs & knowledge
XSS hunting - reflected, stored, DOM-based. Marker discipline to avoid false positives. Blind-XSS beacons for stored contexts. SVG/markdown/redirect vectors. Wiki-first, FIND schema output.
Ready to connect★ 322
- View details
redteamleadSkillDocs & knowledge
On-demand senior red-team lead advisor. Call at a decision point or obstacle to get wiki-grounded direction instead of hammering blindly. Dispatches a fresh RTL subagent that reads the engagement state + evidence + wiki and returns ranked directions with an explicit STOP. Use for "redteamlead", "RTL
Ready to connect★ 322
- View details
research-ingestSkillDocs & knowledge
Ingest a CVE writeup, blog post, advisory, or GitHub repo into the wiki - fetch, dedup via sources:, update the right technique/tool page(s), re-index. Generic knowledge only; never client data.
Ready to connect★ 322
- View details
github-actions-logsSkillDocs & knowledge
Retrieve and diagnose GitHub Actions logs from a run, job, or signed log URL.
Ready to connect★ 316
- View details
pcvr-experiment-integrationSkillDocs & knowledge
Add TAAC PCVR experiments or change their model, configuration, or checkpoint integration contracts.
Ready to connect★ 316
- View details
taac-competition-environmentSkillDocs & knowledge
Set up or diagnose TAAC Python/CUDA environments, or change online bundle packaging and execution.
Ready to connect★ 316
- View details
taac-docs-pages-pipelineSkillDocs & knowledge
Configure or diagnose TAAC Zensical builds, navigation, and GitHub Pages deployment.
Ready to connect★ 316
- View details
taac-platform-api-inspectionSkillDocs & knowledge
Inspect TAAC/Taiji training checkpoints and scalar metrics through an authenticated platform session.
Ready to connect★ 316
- View details
vscode-devcontainer-cleanupSkillDocs & knowledge
Diagnose slow VS Code Dev Container attachment or clean stale server processes, logs, and caches inside the container.
Ready to connect★ 316
- View details
ai-act-complianceSkillDocs & knowledge
Check construction AI systems against the EU AI Act (Regulation 2024/1689): classify risk of estimation, scheduling, CV and agent tools, document transparency, keep human oversight. Use when deploying or auditing AI in construction.
Ready to connect★ 313
- View details
ai-agent-orchestrationSkillDocs & knowledge
Orchestrate multiple AI agents for construction workflows: estimator, scheduler, document, QA and safety agents coordinated by a supervisor agent, with human checkpoints. Use when automating end-to-end project processes with agentic AI.
Ready to connect★ 313
- View details
as-built-trackerSkillDocs & knowledge
Track as-built documentation and record drawings. Monitor submission status, manage revisions, and ensure completeness for handover.
Ready to connect★ 313
- View details
auto-page-syncSkillDocs & knowledge
Automatically syncs repository Markdown/JSON content to frontend pages, with GitHub Actions scheduled pull + deploy configured to keep Google SEO content fresh. Supports multiple page modes such as daily reports, blogs, Changelogs, and Landing Pages.
Ready to connect★ 314
- View details
cwicr-change-orderSkillDocs & knowledge
Process construction change orders using CWICR data. Calculate cost impact, compare to original estimate, and generate change order documentation.
Ready to connect★ 313
- View details
daily-report-generatorSkillDocs & knowledge
Automatically generate daily construction reports from field data, worker inputs, weather, and progress photos. Creates professional PDF reports.
Ready to connect★ 313
- View details
document-classification-nlpSkillDocs & knowledge
Automatically classify and extract information from construction documents using NLP. Categorize RFIs, submittals, change orders, specifications, and contracts.
Ready to connect★ 313
What is a skill?
A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.
55,111 of the 55,543 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.
Install one and every AI you use gets it
Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.
Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.