Skills.

Give your AI a better way to work.

A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.

Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.

Category: Security

1,738 results · page 11 of 58

  • cc-multi-tenant-safetySkillSecurity

    Multi-tenant isolation security checks to prevent unauthorized cross-tenant access and data leaking between tenants.

    Ready to connect★ 1k

    github.com/doccker/cc-use-exp1k stars

    View details
  • cc-payment-callback-safetySkillSecurity

    Payment callback/webhook security checks to prevent callback forgery, replay attacks, and amount tampering.

    Ready to connect★ 1k

    github.com/doccker/cc-use-exp1k stars

    View details
  • cc-reviewSkillSecurity

    Structured code review workflow, intended for explicit quick/full/security reviews; not responsible for general implementation or bug-fixing workflows.

    Ready to connect★ 1k

    github.com/doccker/cc-use-exp1k stars

    View details
  • multi-tenant-safetySkillSecurity

    Triggers when code involves multi-tenant isolation (TenantContext, tenantId, tenant interceptors/filters, X-Tenant-Code). Prevents security issues such as unauthorized cross-tenant access and data leaking across tenants.

    Ready to connect★ 1k

    github.com/doccker/cc-use-exp1k stars

    View details
  • security-headersSkillSecurity

    Generated code must be aligned with security headers (e.g. no unsave JS eval). The permissions policy is especially relevant when changing any code related with the `navigator` object.

    Ready to connect★ 1k

    github.com/trezor/trezor-suite1k stars

    View details
  • matlab-use-opcua-clientSkillSecurity

    Discover OPC UA servers, connect MATLAB clients, and browse/navigate server nodes using opcuaserverinfo, the Local Discovery Service (LDS), opcua, connect, setSecurityModel, certificate-trust functions, findNodeById, opcuanode, and Namespace/Children traversal. Use when finding OPC UA servers on the

    Ready to connect★ 1k

    github.com/matlab/matlab-agentic-toolkit1k stars

    View details
  • asc-apple-adsSkillSecurity

    Use when managing Apple Ads with asc, including OAuth profiles, ad-account discovery, Platform API v1 campaigns and targeting, reports, assets, recommendations, guarded mutations, raw requests, and Campaign Management API v5 migration.

    Ready to connect★ 1k

    github.com/rorkai/app-store-connect-cli-skills1k stars

    View details
  • gws-installSkillSecurity

    Quick install of the Google Workspace CLI (gws) on an additional machine using existing OAuth credentials. Requires client_secret.json from a previous gws-setup. Use whenever the user wants to install gws on a new computer, reinstall after a fresh OS, configure a second workstation, or says 'install

    Ready to connect★ 1k

    github.com/jezweb/claude-skills1k stars

    View details
  • shopify-setupSkillSecurity

    Set up Shopify CLI auth and Admin API access for a store. Install CLI, authenticate, create custom app, store access token, verify. Use whenever the user wants to connect to a Shopify store, set up Shopify API access, install Shopify CLI, or troubleshoot Shopify auth / Admin API token issues.

    Ready to connect★ 1k

    github.com/jezweb/claude-skills1k stars

    View details
  • calleSkillSecurity

    Use CALL-E from Codex through the calle CLI. Use for CALL-E setup checks, authentication recovery, phone call planning, planned call execution, and call status checks.

    Ready to connect★ 985

    github.com/hashgraph-online/awesome-codex-plugins1k stars

    View details
  • getting-startedSkillSecurity

    Assess an authenticated Agiflow workspace and recommend the right next project-management workflow. Use when a user is new to Agiflow, asks what to do next, needs orientation, or is unsure whether to plan, refine, groom, triage, or review daily status.

    Ready to connect★ 985

    github.com/hashgraph-online/awesome-codex-plugins1k stars

    View details
  • vidseeds-publishingSkillSecurity

    Use for VidSeeds MCP publishing - platform connections, OAuth connect URLs, activate YouTube channel, update connection settings, preflight/confirm/cancel publish, publish status, direct YouTube upload, and updating live YouTube metadata.

    Ready to connect★ 985

    github.com/hashgraph-online/awesome-codex-plugins1k stars

    View details
  • vidseeds-setupSkillSecurity

    Use when connecting to VidSeeds.ai, getting AUTH_REQUIRED or SUBSCRIPTION_REQUIRED from the vidseeds MCP server, or setting up VIDSEEDS_PAT / OAuth for the connector. Not for workflow recipes - use vidseeds-efficiency and domain skills after connect.

    Ready to connect★ 985

    github.com/hashgraph-online/awesome-codex-plugins1k stars

    View details
  • trust-badges-generatorSkillSecurity

    When the user wants to add or optimize trust badges, "Trusted by" logos, security seals, or social proof elements. Also use when the user mentions "trust badges," "trusted by," "security badges," "payment logos," "social proof," "trust seals," "SSL badge," "customer logos," "as seen in," or "trust s

    Ready to connect★ 968

    github.com/kostja94/marketing-skills968 stars

    View details
  • skill-vetterSkillSecurity

    Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope, and suspicious patterns.

    Ready to connect★ 919

    github.com/freestylefly/wesight919 stars

    View details
  • analyzeSkillSecurity

    Analyze recon output with AI to suggest high-value targets and attack strategies. Usage: /analyze <target>

    Ready to connect★ 908

    github.com/h-mmer/pentest-agents816 stars

    View details
  • auth-testerSkillSecurity

    Authentication and session management testing agent. Use for login bypass, session fixation, password reset flow abuse, MFA bypass, OAuth flaws, and privilege escalation testing. Provide the application URL and any credentials for testing.

    Ready to connect★ 908

    github.com/h-mmer/pentest-agents816 stars

    View details
  • autopilotSkillSecurity

    Autonomous hunt orchestrator. INSATIABLE in --autonomous mode: enforces an EXHAUSTION CONTRACT (26 canonical hunter classes, surface probe A-I, depth-engine ≥25 attempts/class, wall-clock floor 90 min/target, PRE-COMPLETION GATE before any summary). No early stops, no clarifying questions, no auxili

    Ready to connect★ 908

    github.com/h-mmer/pentest-agents816 stars

    View details
  • brainSkillSecurity

    Central knowledge coordinator. Use BEFORE launching any other pentest agent to get context on what's already been tried. Also use AFTER any agent completes to record findings, exhausted vectors, and learned patterns. The brain prevents redundant work across sessions and agents.

    Ready to connect★ 908

    github.com/h-mmer/pentest-agents816 stars

    View details
  • business-logicSkillSecurity

    Business Logic vulnerability specialist (H1 #28, CWE-840/841/639/362). Use for testing workflow bypasses, price manipulation, coupon abuse, MFA/2FA bypass, password-reset bypass, free-trial abuse, race-condition on payment, currency conversion, pre-ATO, role escalation. Standalone is feeder-class on

    Ready to connect★ 908

    github.com/h-mmer/pentest-agents816 stars

    View details
  • chainSkillSecurity

    Build deep exploit chains — dispatches chain-builder agent. Given bug A, recursively walks the chain graph. Usage: /chain (then describe bug A)

    Ready to connect★ 908

    github.com/h-mmer/pentest-agents816 stars

    View details
  • chain-builderSkillSecurity

    Deep exploit chain builder. Given bug A, recursively walks the chain graph — each confirmed link becomes the new A. No depth limit. Supports 2-link to 10+ link chains. Use when you have any finding that needs escalation.

    Ready to connect★ 908

    github.com/h-mmer/pentest-agents816 stars

    View details
  • config-auditorSkillSecurity

    Security header and server configuration auditor. Use for HTTP security header analysis, CSP evaluation, CORS policy review, TLS configuration assessment, cookie security, and server hardening checks. Provide target URL or list of URLs.

    Ready to connect★ 908

    github.com/h-mmer/pentest-agents816 stars

    View details
  • correlateSkillSecurity

    Run the finding correlation engine to discover attack chains from individual findings.

    Ready to connect★ 908

    github.com/h-mmer/pentest-agents816 stars

    View details
  • correlatorSkillSecurity

    Finding correlation engine. Use AFTER multiple agents have reported findings to discover attack chains. Combines individual findings into higher-impact chains (e.g., open redirect + CORS + SSRF = token theft). Run periodically or before final reporting.

    Ready to connect★ 908

    github.com/h-mmer/pentest-agents816 stars

    View details
  • cors-hunterSkillSecurity

    CORS Misconfiguration specialist (H1 #58). Use for testing cross-origin resource sharing policies, origin reflection, null origin bypass, and credential-bearing cross-origin requests.

    Ready to connect★ 908

    github.com/h-mmer/pentest-agents816 stars

    View details
  • costSkillSecurity

    Show cost tracking and ROI for this engagement.

    Ready to connect★ 908

    github.com/h-mmer/pentest-agents816 stars

    View details
  • csrf-hunterSkillSecurity

    CSRF specialist (H1 #57). Use for testing state-changing actions without proper token validation, SameSite cookie bypass, and CSRF in JSON/API endpoints.

    Ready to connect★ 908

    github.com/h-mmer/pentest-agents816 stars

    View details
  • dast-devils-advocateSkillSecurity

    Adversarial validator for DAST findings. Attempts to DISPROVE each finding and DOWNGRADE severity. Catches inflated reports, unverified assumptions, and theoretical-only bugs. Dispatch after /validate PASS and before /report.

    Ready to connect★ 908

    github.com/h-mmer/pentest-agents816 stars

    View details
  • fullscanSkillSecurity

    Full security assessment with brain coordination. Multi-phase, skips known-exhausted areas, builds on prior knowledge.

    Ready to connect★ 908

    github.com/h-mmer/pentest-agents816 stars

    View details

What is a skill?

A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.

52,524 of the 52,958 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.

Install one and every AI you use gets it

Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.

Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.

See how to connect your AI