Skills.
Give your AI a better way to work.
A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.
Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.
Category: Security
1,738 results · page 15 of 58
- View details
Sparc Security ReviewSkillSecurity
🛡️ Security Reviewer - You perform static and dynamic audits to ensure secure code practices. You flag secrets, poor mod...
★ 804
- View details
cyrus-setup-claude-authSkillSecurity
Configure Claude Code authentication for Cyrus — API key, OAuth token, or third-party provider.
Ready to connect★ 802
- View details
cyrus-setup-gitlabSkillSecurity
Configure GitLab authentication for Cyrus — glab CLI login and git config for creating merge requests.
Ready to connect★ 802
- View details
dependency-managerSkillSecurity
Safely resolve and install isolated dependencies for isolated sandboxes (PoC execution).
Ready to connect★ 791
- View details
pocSkillSecurity
Sets up the necessary workspace, directories, and dependencies to test a vulnerability and generates a Proof-of-Concept.
Ready to connect★ 791
- View details
security-patcherSkillSecurity
Invoke this as your absolute first action before using any other tools whenever a user requests to fix, patch, or remediate a vulnerability. Do not perform manual research first.
Ready to connect★ 791
- View details
active-directory-kerberos-attacksSkillSecurity
Kerberos attack playbook for Active Directory. Use when targeting AD authentication via AS-REP roasting, Kerberoasting, golden/silver/diamond tickets, delegation abuse, or pass-the-ticket attacks.
Ready to connect★ 777
- View details
ai-ml-securitySkillSecurity
AI/ML security playbook. Use when assessing model supply chain attacks (pickle RCE, poisoned weights), adversarial examples, model poisoning, model stealing, data privacy attacks (membership inference, model inversion), and autonomous agent security risks.
Ready to connect★ 777
- View details
android-pentesting-tricksSkillSecurity
Android pentesting playbook. Use when testing Android applications for SSL pinning bypass, exported component abuse, WebView vulnerabilities, intent redirection, root detection bypass, tapjacking, and backup extraction during authorized mobile security assessments.
Ready to connect★ 777
- View details
api-auth-and-jwt-abuseSkillSecurity
API authentication and JWT abuse playbook. Use when testing bearer tokens, API keys, claim trust, header spoofing, rate limits, and API auth boundary weaknesses.
Ready to connect★ 777
- View details
api-secSkillSecurity
Entry P1 category router for API security. Use when choosing between API recon, authorization, token abuse, and hidden-parameter workflows before any deeper API topic skill.
Ready to connect★ 777
- View details
auth-secSkillSecurity
Entry P1 category router for authentication and authorization. Use when testing login flows, sessions, object authorization, JWT, OAuth, CORS, CSRF, and enterprise SSO weaknesses before any deeper auth topic skill.
Ready to connect★ 777
- View details
authbypass-authentication-flawsSkillSecurity
Authentication bypass testing playbook. Use when assessing login flows, password reset logic, account recovery, MFA bypass, token predictability, brute-force resistance, and session boundary flaws.
Ready to connect★ 777
- View details
business-logic-vulnerabilitiesSkillSecurity
Business logic vulnerability playbook. Use when reasoning about workflows, race conditions, price manipulation, coupon abuse, state machines, and multi-step authorization gaps.
Ready to connect★ 777
- View details
csp-bypass-advancedSkillSecurity
Advanced Content Security Policy bypass techniques. Use when XSS or data exfiltration is blocked by CSP and you need to find policy weaknesses, trusted endpoint abuse, nonce leakage, or exfiltration channels that CSP cannot block.
Ready to connect★ 777
- View details
csrf-cross-site-request-forgerySkillSecurity
CSRF testing playbook. Use when reviewing state-changing web flows, anti-CSRF defenses, SameSite behavior, JSON CSRF, login CSRF, and OAuth state handling.
Ready to connect★ 777
- View details
defi-attack-patternsSkillSecurity
DeFi attack pattern playbook. Use when analyzing flash loan attacks, price oracle manipulation, MEV sandwich attacks, governance exploits, bridge vulnerabilities, and token standard edge cases in decentralized finance protocols.
Ready to connect★ 777
- View details
hackSkillSecurity
Entry P0 primary router for HackSkills. Use when the task involves web application testing, API security assessment, recon, vulnerability triage, exploit path planning, or choosing the right next category skill before any deep topic skill.
Ready to connect★ 777
- View details
authz-checkSkillSecurity
Verify that an endpoint checks ownership, not just authentication. Use on any handler that reads or mutates user data.
Ready to connect★ 754
- View details
owasp-reviewSkillSecurity
Security-review a diff against the OWASP Top 10. Use before merging anything that touches auth, input handling, queries, or external calls.
Ready to connect★ 754
- View details
dependency-auditorSkillSecurity
Scans your project's dependencies for known vulnerabilities, license conflicts, and safe upgrade paths across 8+ languages.
Ready to connect★ 740
- View details
google-workspace-cliSkillSecurity
Lets your agent set up and use Google's gws command-line tool to automate Gmail, Drive, Sheets, Calendar, Docs, Chat, and Tasks.
Ready to connect★ 740
- View details
prompt-governanceSkillSecurity
Lets your agent version production prompts, build eval pipelines, and set up prompt registries to catch quality regressions.
Ready to connect★ 740
- View details
red-teamSkillSecurity
Helps your agent plan authorized red team exercises, scoring attack techniques and mapping kill-chain phases.
Ready to connect★ 740
- View details
scenario-war-roomSkillSecurity
Lets your agent model what-if scenarios where multiple business problems hit at once and map how one failure triggers the next.
Ready to connect★ 740
- View details
senior-secopsSkillSecurity
Lets your agent scan code and dependencies for security flaws, check compliance rules, and plan CVE fixes.
Ready to connect★ 740
- View details
senior-securitySkillSecurity
STRIDE threat modeling, DREAD risk scoring, secret detection, and secure architecture design. Use when conducting threat models, reviewing code for vulnerabilities, designing defense-in-depth, or scanning for hardcoded secrets.
Ready to connect★ 740
- View details
signup-flow-croSkillSecurity
Signup and registration flow optimization covering SSO strategy, progressive profiling, field reduction, multi-step flow design, authentication UX, post-submit experience, and mobile registration patterns.
Ready to connect★ 740
- View details
skill-security-auditorSkillSecurity
Security audit and vulnerability scanning for AI agent skills before install. Detects prompt injection, dangerous code, exfiltration, credential harvesting, and supply chain risks. Use when evaluating untrusted skills or gating installs.
Ready to connect★ 740
- View details
maven-dependency-auditSkillSecurity
Audit Maven dependencies for outdated versions, security vulnerabilities, and conflicts. Use when user says "check dependencies", "audit dependencies", "outdated deps", or before releases.
Ready to connect★ 735
What is a skill?
A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.
52,524 of the 52,958 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.
Install one and every AI you use gets it
Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.
Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.