Skills.

Give your AI a better way to work.

A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.

Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.

Category: Security

1,840 results · page 19 of 62

  • implementing-complianceSkillSecurity

    Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection. Use when building systems requiring regulatory compliance, implementing security controls across multiple frameworks, or automating aud

    Ready to connect★ 518

    github.com/ancoleman/ai-design-components518 stars

    View details
  • securing-authenticationSkillSecurity

    Authentication, authorization, and API security implementation. Use when building user systems, protecting APIs, or implementing access control. Covers OAuth 2.1/OIDC, JWT patterns, sessions, Passkeys/WebAuthn, RBAC/ABAC/ReBAC, policy engines (OPA, Casbin, SpiceDB), managed auth (Clerk, Auth0), self

    Ready to connect★ 518

    github.com/ancoleman/ai-design-components518 stars

    View details
  • writing-github-actionsSkillSecurity

    Write GitHub Actions workflows with proper syntax, reusable workflows, composite actions, matrix builds, caching, and security best practices. Use when creating CI/CD workflows for GitHub-hosted projects or automating GitHub repository tasks.

    Ready to connect★ 518

    github.com/ancoleman/ai-design-components518 stars

    View details
  • snapshotSkillSecurity

    Run snapshot regression tests after changes to OPA rules, scanners, analyzers, or formatters to detect output regressions.

    Ready to connect★ 513

    github.com/boostsecurityio/poutine511 stars

    View details
  • pb-apiSkillSecurity

    Operate PocketBase via its REST API. Use for CRUD operations on collections, authentication, querying records with filters, and managing PocketBase data.

    Ready to connect★ 507

    github.com/spinspire/pocketbase-sveltekit-starter508 stars

    View details
  • root-cause-remediationSkillSecurity

    Mandatory for every Nomi corrective change: user-reported bugs, regressions, CI-only failures, flaky tests, performance or security defects, review/audit findings, and compatibility failures in any production path. Classify one_off versus recurring before implementation. Recurring and high-risk repa

    Ready to connect★ 507

    github.com/aqm857886159/nomi501 stars

    View details
  • use-avibe-vaultSkillSecurity

    Use Avibe Vault for API keys, tokens, passwords, protected credentials, authenticated HTTP requests, or digest signing without exposing secret values to the agent.

    Ready to connect★ 505

    github.com/avibe-bot/avibe498 stars

    View details
  • hf-cliSkillSecurity

    Use the `hf` CLI for Hub authentication, downloads, uploads, repositories, cache, jobs, buckets, webhooks, and endpoint administration. Use for CLI operations, not model recommendations, paper analysis, training design, or building a Space.

    Ready to connect★ 504

    github.com/waybarrios/opencode-power-pack490 stars

    View details
  • supply-chain-risk-auditorSkillSecurity

    Identifies dependencies at heightened risk of exploitation or takeover. Use when assessing supply chain attack surface, evaluating dependency health, or scoping security engagements.

    Ready to connect★ 504

    github.com/waybarrios/opencode-power-pack490 stars

    View details
  • variant-analysisSkillSecurity

    Find similar vulnerabilities and bugs across codebases using pattern-based analysis. Use when hunting bug variants, building CodeQL/Semgrep queries, analyzing security vulnerabilities, or performing systematic code audits after finding an initial issue.

    Ready to connect★ 504

    github.com/waybarrios/opencode-power-pack490 stars

    View details
  • vuln-reportSkillSecurity

    Turn one confirmed security finding into a disclosure-ready GitHub advisory with root cause, proof of concept, impact, and source evidence. Use for reporting an established vulnerability, not discovering or validating one.

    Ready to connect★ 504

    github.com/waybarrios/opencode-power-pack490 stars

    View details
  • audit-depsSkillSecurity

    Audit dependencies for vulnerabilities, outdated packages, and license compliance.

    Ready to connect★ 501

    github.com/me2resh/apexyard498 stars

    View details
  • dfdSkillSecurity

    DFD with trust boundaries + data classifications (Mermaid + optional Threat Dragon JSON). Source-of-truth for /threat-model.

    Ready to connect★ 501

    github.com/me2resh/apexyard498 stars

    View details
  • threat-modelSkillSecurity

    STRIDE threat modelling — spoofing, tampering, repudiation, disclosure, DoS, EoP. Deep-dive for /launch-check security.

    Ready to connect★ 501

    github.com/me2resh/apexyard498 stars

    View details
  • iom-opsecSkillSecurity

    IoM Operational Security (OPSEC) advisor. Provides OPSEC methodology guidance, helps users understand operational risks, build secure operating habits, and accumulate experience through a case library. Does not execute commands directly; serves as decision support. Concrete technical specifications

    Ready to connect★ 500

    github.com/chainreactors/malice-network490 stars

    View details
  • iom-pentestSkillSecurity

    Autonomous penetration testing via IoM C2 MCP tools. Adaptively executes based on user intent: situational awareness, reconnaissance, privilege escalation, credential harvesting, lateral movement, persistence, and more. Presents an execution plan and waits for user confirmation before sensitive oper

    Ready to connect★ 500

    github.com/chainreactors/malice-network490 stars

    View details
  • critical-code-reviewerSkillSecurity

    Rigorously review code or pull requests for correctness, security, accessibility, maintainability, tests, and edge cases. Use when users request a critical code review, want a guided walkthrough of findings, need implementer-facing feedback, or want to prepare, create, or submit a GitHub pull reques

    Ready to connect★ 498

    github.com/posit-dev/skills498 stars

    View details
  • aqe-review-qualitySkillSecurity

    Review Agentic QE changes and issue an evidence-backed quality verdict. Use for code review, regression-risk assessment, release readiness, quality-gate evaluation, security/performance/testability review, or checking whether a change has sufficient verification. Do not use when the user primarily a

    Ready to connect★ 478

    github.com/proffesor-for-testing/agentic-qe473 stars

    View details
  • n8n-integration-testing-patternsSkillSecurity

    API contract testing, authentication flows, rate limit handling, and error scenario coverage for n8n integrations with external services. Use when testing n8n node integrations.

    Ready to connect★ 478

    github.com/proffesor-for-testing/agentic-qe473 stars

    View details
  • n8n-security-testingSkillSecurity

    Credential exposure detection, OAuth flow validation, API key management testing, and data sanitization verification for n8n workflows. Use when validating n8n workflow security.

    Ready to connect★ 478

    github.com/proffesor-for-testing/agentic-qe473 stars

    View details
  • pentest-validationSkillSecurity

    Use when validating security findings from SAST/DAST scans, proving exploitability of reported vulnerabilities, eliminating false positives, or running the 4-phase pentest pipeline (recon, analysis, validation, report).

    Ready to connect★ 478

    github.com/proffesor-for-testing/agentic-qe473 stars

    View details
  • security-visual-testingSkillSecurity

    Security-first visual testing combining URL validation, PII detection, and visual regression with parallel viewport support. Use when testing web applications that handle sensitive data, need visual regression coverage, or require WCAG accessibility compliance.

    Ready to connect★ 478

    github.com/proffesor-for-testing/agentic-qe473 stars

    View details
  • security-watchSkillSecurity

    Use when working on security-sensitive code to catch secrets, eval(), innerHTML, and other dangerous patterns before they're written. Activate with /security-watch for real-time security scanning.

    Ready to connect★ 478

    github.com/proffesor-for-testing/agentic-qe473 stars

    View details
  • abp-vulnerability-classificationSkillSecurity

    Classify assumptions on 2 axes — load-bearing (how much conclusion depends

    Ready to connect★ 469

    github.com/yogsoth-ai/de-anthropocentric-research-engine417 stars

    View details
  • assumption-auditSkillSecurity

    Surface all assumptions, classify by vulnerability (load-bearing × likely-false),

    Ready to connect★ 469

    github.com/yogsoth-ai/de-anthropocentric-research-engine417 stars

    View details
  • assumption-constraintSkillSecurity

    Which assumptions are most fragile? — Vulnerability ranking + impact

    Ready to connect★ 469

    github.com/yogsoth-ai/de-anthropocentric-research-engine417 stars

    View details
  • assumption-stress-testSkillSecurity

    Systematic stress testing of assumptions — surface, classify by vulnerability,

    Ready to connect★ 469

    github.com/yogsoth-ai/de-anthropocentric-research-engine417 stars

    View details
  • attack-vector-generationSkillSecurity

    Generate specific attack strategies for a given threat surface, producing

    Ready to connect★ 469

    github.com/yogsoth-ai/de-anthropocentric-research-engine417 stars

    View details
  • challenge-operationSkillSecurity

    Non-threatening 'Why?' questioning of current practices (de Bono Challenge)

    Ready to connect★ 469

    github.com/yogsoth-ai/de-anthropocentric-research-engine417 stars

    View details
  • challenge-questioningSkillSecurity

    Non-threatening 'Why?' questioning of current practices to reveal historical

    Ready to connect★ 469

    github.com/yogsoth-ai/de-anthropocentric-research-engine417 stars

    View details

What is a skill?

A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.

54,764 of the 55,196 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.

Install one and every AI you use gets it

Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.

Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.

See how to connect your AI