Skills.

Give your AI a better way to work.

A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.

Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.

Category: Security

1,738 results · page 15 of 58

  • Sparc Security ReviewSkillSecurity

    🛡️ Security Reviewer - You perform static and dynamic audits to ensure secure code practices. You flag secrets, poor mod...

    ★ 804

    github.com/ruvnet/agentic-flow770 stars

    View details
  • cyrus-setup-claude-authSkillSecurity

    Configure Claude Code authentication for Cyrus — API key, OAuth token, or third-party provider.

    Ready to connect★ 802

    github.com/cyrusagents/cyrus796 stars

    View details
  • cyrus-setup-gitlabSkillSecurity

    Configure GitLab authentication for Cyrus — glab CLI login and git config for creating merge requests.

    Ready to connect★ 802

    github.com/cyrusagents/cyrus796 stars

    View details
  • dependency-managerSkillSecurity

    Safely resolve and install isolated dependencies for isolated sandboxes (PoC execution).

    Ready to connect★ 791

    github.com/gemini-cli-extensions/security791 stars

    View details
  • pocSkillSecurity

    Sets up the necessary workspace, directories, and dependencies to test a vulnerability and generates a Proof-of-Concept.

    Ready to connect★ 791

    github.com/gemini-cli-extensions/security791 stars

    View details
  • security-patcherSkillSecurity

    Invoke this as your absolute first action before using any other tools whenever a user requests to fix, patch, or remediate a vulnerability. Do not perform manual research first.

    Ready to connect★ 791

    github.com/gemini-cli-extensions/security791 stars

    View details
  • active-directory-kerberos-attacksSkillSecurity

    Kerberos attack playbook for Active Directory. Use when targeting AD authentication via AS-REP roasting, Kerberoasting, golden/silver/diamond tickets, delegation abuse, or pass-the-ticket attacks.

    Ready to connect★ 777

    github.com/zyrexnn/cybermes730 stars

    View details
  • ai-ml-securitySkillSecurity

    AI/ML security playbook. Use when assessing model supply chain attacks (pickle RCE, poisoned weights), adversarial examples, model poisoning, model stealing, data privacy attacks (membership inference, model inversion), and autonomous agent security risks.

    Ready to connect★ 777

    github.com/zyrexnn/cybermes730 stars

    View details
  • android-pentesting-tricksSkillSecurity

    Android pentesting playbook. Use when testing Android applications for SSL pinning bypass, exported component abuse, WebView vulnerabilities, intent redirection, root detection bypass, tapjacking, and backup extraction during authorized mobile security assessments.

    Ready to connect★ 777

    github.com/zyrexnn/cybermes730 stars

    View details
  • api-auth-and-jwt-abuseSkillSecurity

    API authentication and JWT abuse playbook. Use when testing bearer tokens, API keys, claim trust, header spoofing, rate limits, and API auth boundary weaknesses.

    Ready to connect★ 777

    github.com/zyrexnn/cybermes730 stars

    View details
  • api-secSkillSecurity

    Entry P1 category router for API security. Use when choosing between API recon, authorization, token abuse, and hidden-parameter workflows before any deeper API topic skill.

    Ready to connect★ 777

    github.com/zyrexnn/cybermes730 stars

    View details
  • auth-secSkillSecurity

    Entry P1 category router for authentication and authorization. Use when testing login flows, sessions, object authorization, JWT, OAuth, CORS, CSRF, and enterprise SSO weaknesses before any deeper auth topic skill.

    Ready to connect★ 777

    github.com/zyrexnn/cybermes730 stars

    View details
  • authbypass-authentication-flawsSkillSecurity

    Authentication bypass testing playbook. Use when assessing login flows, password reset logic, account recovery, MFA bypass, token predictability, brute-force resistance, and session boundary flaws.

    Ready to connect★ 777

    github.com/zyrexnn/cybermes730 stars

    View details
  • business-logic-vulnerabilitiesSkillSecurity

    Business logic vulnerability playbook. Use when reasoning about workflows, race conditions, price manipulation, coupon abuse, state machines, and multi-step authorization gaps.

    Ready to connect★ 777

    github.com/zyrexnn/cybermes730 stars

    View details
  • csp-bypass-advancedSkillSecurity

    Advanced Content Security Policy bypass techniques. Use when XSS or data exfiltration is blocked by CSP and you need to find policy weaknesses, trusted endpoint abuse, nonce leakage, or exfiltration channels that CSP cannot block.

    Ready to connect★ 777

    github.com/zyrexnn/cybermes730 stars

    View details
  • csrf-cross-site-request-forgerySkillSecurity

    CSRF testing playbook. Use when reviewing state-changing web flows, anti-CSRF defenses, SameSite behavior, JSON CSRF, login CSRF, and OAuth state handling.

    Ready to connect★ 777

    github.com/zyrexnn/cybermes730 stars

    View details
  • defi-attack-patternsSkillSecurity

    DeFi attack pattern playbook. Use when analyzing flash loan attacks, price oracle manipulation, MEV sandwich attacks, governance exploits, bridge vulnerabilities, and token standard edge cases in decentralized finance protocols.

    Ready to connect★ 777

    github.com/zyrexnn/cybermes730 stars

    View details
  • hackSkillSecurity

    Entry P0 primary router for HackSkills. Use when the task involves web application testing, API security assessment, recon, vulnerability triage, exploit path planning, or choosing the right next category skill before any deep topic skill.

    Ready to connect★ 777

    github.com/zyrexnn/cybermes730 stars

    View details
  • authz-checkSkillSecurity

    Verify that an endpoint checks ownership, not just authentication. Use on any handler that reads or mutates user data.

    Ready to connect★ 754

    github.com/archive228/loopkit755 stars

    View details
  • owasp-reviewSkillSecurity

    Security-review a diff against the OWASP Top 10. Use before merging anything that touches auth, input handling, queries, or external calls.

    Ready to connect★ 754

    github.com/archive228/loopkit755 stars

    View details
  • dependency-auditorSkillSecurity

    Scans your project's dependencies for known vulnerabilities, license conflicts, and safe upgrade paths across 8+ languages.

    Ready to connect★ 740

    github.com/borghei/claude-skills743 stars

    View details
  • google-workspace-cliSkillSecurity

    Lets your agent set up and use Google's gws command-line tool to automate Gmail, Drive, Sheets, Calendar, Docs, Chat, and Tasks.

    Ready to connect★ 740

    github.com/borghei/claude-skills743 stars

    View details
  • prompt-governanceSkillSecurity

    Lets your agent version production prompts, build eval pipelines, and set up prompt registries to catch quality regressions.

    Ready to connect★ 740

    github.com/borghei/claude-skills743 stars

    View details
  • red-teamSkillSecurity

    Helps your agent plan authorized red team exercises, scoring attack techniques and mapping kill-chain phases.

    Ready to connect★ 740

    github.com/borghei/claude-skills743 stars

    View details
  • scenario-war-roomSkillSecurity

    Lets your agent model what-if scenarios where multiple business problems hit at once and map how one failure triggers the next.

    Ready to connect★ 740

    github.com/borghei/claude-skills743 stars

    View details
  • senior-secopsSkillSecurity

    Lets your agent scan code and dependencies for security flaws, check compliance rules, and plan CVE fixes.

    Ready to connect★ 740

    github.com/borghei/claude-skills743 stars

    View details
  • senior-securitySkillSecurity

    STRIDE threat modeling, DREAD risk scoring, secret detection, and secure architecture design. Use when conducting threat models, reviewing code for vulnerabilities, designing defense-in-depth, or scanning for hardcoded secrets.

    Ready to connect★ 740

    github.com/borghei/claude-skills743 stars

    View details
  • signup-flow-croSkillSecurity

    Signup and registration flow optimization covering SSO strategy, progressive profiling, field reduction, multi-step flow design, authentication UX, post-submit experience, and mobile registration patterns.

    Ready to connect★ 740

    github.com/borghei/claude-skills743 stars

    View details
  • skill-security-auditorSkillSecurity

    Security audit and vulnerability scanning for AI agent skills before install. Detects prompt injection, dangerous code, exfiltration, credential harvesting, and supply chain risks. Use when evaluating untrusted skills or gating installs.

    Ready to connect★ 740

    github.com/borghei/claude-skills743 stars

    View details
  • maven-dependency-auditSkillSecurity

    Audit Maven dependencies for outdated versions, security vulnerabilities, and conflicts. Use when user says "check dependencies", "audit dependencies", "outdated deps", or before releases.

    Ready to connect★ 735

    github.com/decebals/claude-code-java738 stars

    View details

What is a skill?

A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.

52,524 of the 52,958 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.

Install one and every AI you use gets it

Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.

Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.

See how to connect your AI