Skills.
Give your AI a better way to work.
A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.
Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.
Category: Security
1,738 results · page 11 of 58
- View details
cc-multi-tenant-safetySkillSecurity
Multi-tenant isolation security checks to prevent unauthorized cross-tenant access and data leaking between tenants.
Ready to connect★ 1k
- View details
cc-payment-callback-safetySkillSecurity
Payment callback/webhook security checks to prevent callback forgery, replay attacks, and amount tampering.
Ready to connect★ 1k
- View details
cc-reviewSkillSecurity
Structured code review workflow, intended for explicit quick/full/security reviews; not responsible for general implementation or bug-fixing workflows.
Ready to connect★ 1k
- View details
multi-tenant-safetySkillSecurity
Triggers when code involves multi-tenant isolation (TenantContext, tenantId, tenant interceptors/filters, X-Tenant-Code). Prevents security issues such as unauthorized cross-tenant access and data leaking across tenants.
Ready to connect★ 1k
- View details
security-headersSkillSecurity
Generated code must be aligned with security headers (e.g. no unsave JS eval). The permissions policy is especially relevant when changing any code related with the `navigator` object.
Ready to connect★ 1k
- View details
matlab-use-opcua-clientSkillSecurity
Discover OPC UA servers, connect MATLAB clients, and browse/navigate server nodes using opcuaserverinfo, the Local Discovery Service (LDS), opcua, connect, setSecurityModel, certificate-trust functions, findNodeById, opcuanode, and Namespace/Children traversal. Use when finding OPC UA servers on the
Ready to connect★ 1k
- View details
asc-apple-adsSkillSecurity
Use when managing Apple Ads with asc, including OAuth profiles, ad-account discovery, Platform API v1 campaigns and targeting, reports, assets, recommendations, guarded mutations, raw requests, and Campaign Management API v5 migration.
Ready to connect★ 1k
- View details
gws-installSkillSecurity
Quick install of the Google Workspace CLI (gws) on an additional machine using existing OAuth credentials. Requires client_secret.json from a previous gws-setup. Use whenever the user wants to install gws on a new computer, reinstall after a fresh OS, configure a second workstation, or says 'install
Ready to connect★ 1k
- View details
shopify-setupSkillSecurity
Set up Shopify CLI auth and Admin API access for a store. Install CLI, authenticate, create custom app, store access token, verify. Use whenever the user wants to connect to a Shopify store, set up Shopify API access, install Shopify CLI, or troubleshoot Shopify auth / Admin API token issues.
Ready to connect★ 1k
- View details
calleSkillSecurity
Use CALL-E from Codex through the calle CLI. Use for CALL-E setup checks, authentication recovery, phone call planning, planned call execution, and call status checks.
Ready to connect★ 985
- View details
getting-startedSkillSecurity
Assess an authenticated Agiflow workspace and recommend the right next project-management workflow. Use when a user is new to Agiflow, asks what to do next, needs orientation, or is unsure whether to plan, refine, groom, triage, or review daily status.
Ready to connect★ 985
- View details
vidseeds-publishingSkillSecurity
Use for VidSeeds MCP publishing - platform connections, OAuth connect URLs, activate YouTube channel, update connection settings, preflight/confirm/cancel publish, publish status, direct YouTube upload, and updating live YouTube metadata.
Ready to connect★ 985
- View details
vidseeds-setupSkillSecurity
Use when connecting to VidSeeds.ai, getting AUTH_REQUIRED or SUBSCRIPTION_REQUIRED from the vidseeds MCP server, or setting up VIDSEEDS_PAT / OAuth for the connector. Not for workflow recipes - use vidseeds-efficiency and domain skills after connect.
Ready to connect★ 985
- View details
trust-badges-generatorSkillSecurity
When the user wants to add or optimize trust badges, "Trusted by" logos, security seals, or social proof elements. Also use when the user mentions "trust badges," "trusted by," "security badges," "payment logos," "social proof," "trust seals," "SSL badge," "customer logos," "as seen in," or "trust s
Ready to connect★ 968
- View details
skill-vetterSkillSecurity
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope, and suspicious patterns.
Ready to connect★ 919
- View details
analyzeSkillSecurity
Analyze recon output with AI to suggest high-value targets and attack strategies. Usage: /analyze <target>
Ready to connect★ 908
- View details
auth-testerSkillSecurity
Authentication and session management testing agent. Use for login bypass, session fixation, password reset flow abuse, MFA bypass, OAuth flaws, and privilege escalation testing. Provide the application URL and any credentials for testing.
Ready to connect★ 908
- View details
autopilotSkillSecurity
Autonomous hunt orchestrator. INSATIABLE in --autonomous mode: enforces an EXHAUSTION CONTRACT (26 canonical hunter classes, surface probe A-I, depth-engine ≥25 attempts/class, wall-clock floor 90 min/target, PRE-COMPLETION GATE before any summary). No early stops, no clarifying questions, no auxili
Ready to connect★ 908
- View details
brainSkillSecurity
Central knowledge coordinator. Use BEFORE launching any other pentest agent to get context on what's already been tried. Also use AFTER any agent completes to record findings, exhausted vectors, and learned patterns. The brain prevents redundant work across sessions and agents.
Ready to connect★ 908
- View details
business-logicSkillSecurity
Business Logic vulnerability specialist (H1 #28, CWE-840/841/639/362). Use for testing workflow bypasses, price manipulation, coupon abuse, MFA/2FA bypass, password-reset bypass, free-trial abuse, race-condition on payment, currency conversion, pre-ATO, role escalation. Standalone is feeder-class on
Ready to connect★ 908
- View details
chainSkillSecurity
Build deep exploit chains — dispatches chain-builder agent. Given bug A, recursively walks the chain graph. Usage: /chain (then describe bug A)
Ready to connect★ 908
- View details
chain-builderSkillSecurity
Deep exploit chain builder. Given bug A, recursively walks the chain graph — each confirmed link becomes the new A. No depth limit. Supports 2-link to 10+ link chains. Use when you have any finding that needs escalation.
Ready to connect★ 908
- View details
config-auditorSkillSecurity
Security header and server configuration auditor. Use for HTTP security header analysis, CSP evaluation, CORS policy review, TLS configuration assessment, cookie security, and server hardening checks. Provide target URL or list of URLs.
Ready to connect★ 908
- View details
correlateSkillSecurity
Run the finding correlation engine to discover attack chains from individual findings.
Ready to connect★ 908
- View details
correlatorSkillSecurity
Finding correlation engine. Use AFTER multiple agents have reported findings to discover attack chains. Combines individual findings into higher-impact chains (e.g., open redirect + CORS + SSRF = token theft). Run periodically or before final reporting.
Ready to connect★ 908
- View details
cors-hunterSkillSecurity
CORS Misconfiguration specialist (H1 #58). Use for testing cross-origin resource sharing policies, origin reflection, null origin bypass, and credential-bearing cross-origin requests.
Ready to connect★ 908
- View details
- View details
csrf-hunterSkillSecurity
CSRF specialist (H1 #57). Use for testing state-changing actions without proper token validation, SameSite cookie bypass, and CSRF in JSON/API endpoints.
Ready to connect★ 908
- View details
dast-devils-advocateSkillSecurity
Adversarial validator for DAST findings. Attempts to DISPROVE each finding and DOWNGRADE severity. Catches inflated reports, unverified assumptions, and theoretical-only bugs. Dispatch after /validate PASS and before /report.
Ready to connect★ 908
- View details
fullscanSkillSecurity
Full security assessment with brain coordination. Multi-phase, skips known-exhausted areas, builds on prior knowledge.
Ready to connect★ 908
What is a skill?
A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.
52,524 of the 52,958 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.
Install one and every AI you use gets it
Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.
Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.