Skills.
Give your AI a better way to work.
A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.
Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.
Category: Security
1,840 results · page 19 of 62
- View details
implementing-complianceSkillSecurity
Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection. Use when building systems requiring regulatory compliance, implementing security controls across multiple frameworks, or automating aud
Ready to connect★ 518
- View details
securing-authenticationSkillSecurity
Authentication, authorization, and API security implementation. Use when building user systems, protecting APIs, or implementing access control. Covers OAuth 2.1/OIDC, JWT patterns, sessions, Passkeys/WebAuthn, RBAC/ABAC/ReBAC, policy engines (OPA, Casbin, SpiceDB), managed auth (Clerk, Auth0), self
Ready to connect★ 518
- View details
writing-github-actionsSkillSecurity
Write GitHub Actions workflows with proper syntax, reusable workflows, composite actions, matrix builds, caching, and security best practices. Use when creating CI/CD workflows for GitHub-hosted projects or automating GitHub repository tasks.
Ready to connect★ 518
- View details
snapshotSkillSecurity
Run snapshot regression tests after changes to OPA rules, scanners, analyzers, or formatters to detect output regressions.
Ready to connect★ 513
- View details
pb-apiSkillSecurity
Operate PocketBase via its REST API. Use for CRUD operations on collections, authentication, querying records with filters, and managing PocketBase data.
Ready to connect★ 507
- View details
root-cause-remediationSkillSecurity
Mandatory for every Nomi corrective change: user-reported bugs, regressions, CI-only failures, flaky tests, performance or security defects, review/audit findings, and compatibility failures in any production path. Classify one_off versus recurring before implementation. Recurring and high-risk repa
Ready to connect★ 507
- View details
use-avibe-vaultSkillSecurity
Use Avibe Vault for API keys, tokens, passwords, protected credentials, authenticated HTTP requests, or digest signing without exposing secret values to the agent.
Ready to connect★ 505
- View details
hf-cliSkillSecurity
Use the `hf` CLI for Hub authentication, downloads, uploads, repositories, cache, jobs, buckets, webhooks, and endpoint administration. Use for CLI operations, not model recommendations, paper analysis, training design, or building a Space.
Ready to connect★ 504
- View details
supply-chain-risk-auditorSkillSecurity
Identifies dependencies at heightened risk of exploitation or takeover. Use when assessing supply chain attack surface, evaluating dependency health, or scoping security engagements.
Ready to connect★ 504
- View details
variant-analysisSkillSecurity
Find similar vulnerabilities and bugs across codebases using pattern-based analysis. Use when hunting bug variants, building CodeQL/Semgrep queries, analyzing security vulnerabilities, or performing systematic code audits after finding an initial issue.
Ready to connect★ 504
- View details
vuln-reportSkillSecurity
Turn one confirmed security finding into a disclosure-ready GitHub advisory with root cause, proof of concept, impact, and source evidence. Use for reporting an established vulnerability, not discovering or validating one.
Ready to connect★ 504
- View details
audit-depsSkillSecurity
Audit dependencies for vulnerabilities, outdated packages, and license compliance.
Ready to connect★ 501
- View details
dfdSkillSecurity
DFD with trust boundaries + data classifications (Mermaid + optional Threat Dragon JSON). Source-of-truth for /threat-model.
Ready to connect★ 501
- View details
threat-modelSkillSecurity
STRIDE threat modelling — spoofing, tampering, repudiation, disclosure, DoS, EoP. Deep-dive for /launch-check security.
Ready to connect★ 501
- View details
iom-opsecSkillSecurity
IoM Operational Security (OPSEC) advisor. Provides OPSEC methodology guidance, helps users understand operational risks, build secure operating habits, and accumulate experience through a case library. Does not execute commands directly; serves as decision support. Concrete technical specifications
Ready to connect★ 500
- View details
iom-pentestSkillSecurity
Autonomous penetration testing via IoM C2 MCP tools. Adaptively executes based on user intent: situational awareness, reconnaissance, privilege escalation, credential harvesting, lateral movement, persistence, and more. Presents an execution plan and waits for user confirmation before sensitive oper
Ready to connect★ 500
- View details
critical-code-reviewerSkillSecurity
Rigorously review code or pull requests for correctness, security, accessibility, maintainability, tests, and edge cases. Use when users request a critical code review, want a guided walkthrough of findings, need implementer-facing feedback, or want to prepare, create, or submit a GitHub pull reques
Ready to connect★ 498
- View details
aqe-review-qualitySkillSecurity
Review Agentic QE changes and issue an evidence-backed quality verdict. Use for code review, regression-risk assessment, release readiness, quality-gate evaluation, security/performance/testability review, or checking whether a change has sufficient verification. Do not use when the user primarily a
Ready to connect★ 478
- View details
n8n-integration-testing-patternsSkillSecurity
API contract testing, authentication flows, rate limit handling, and error scenario coverage for n8n integrations with external services. Use when testing n8n node integrations.
Ready to connect★ 478
- View details
n8n-security-testingSkillSecurity
Credential exposure detection, OAuth flow validation, API key management testing, and data sanitization verification for n8n workflows. Use when validating n8n workflow security.
Ready to connect★ 478
- View details
pentest-validationSkillSecurity
Use when validating security findings from SAST/DAST scans, proving exploitability of reported vulnerabilities, eliminating false positives, or running the 4-phase pentest pipeline (recon, analysis, validation, report).
Ready to connect★ 478
- View details
security-visual-testingSkillSecurity
Security-first visual testing combining URL validation, PII detection, and visual regression with parallel viewport support. Use when testing web applications that handle sensitive data, need visual regression coverage, or require WCAG accessibility compliance.
Ready to connect★ 478
- View details
security-watchSkillSecurity
Use when working on security-sensitive code to catch secrets, eval(), innerHTML, and other dangerous patterns before they're written. Activate with /security-watch for real-time security scanning.
Ready to connect★ 478
- View details
abp-vulnerability-classificationSkillSecurity
Classify assumptions on 2 axes — load-bearing (how much conclusion depends
Ready to connect★ 469
- View details
assumption-auditSkillSecurity
Surface all assumptions, classify by vulnerability (load-bearing × likely-false),
Ready to connect★ 469
- View details
assumption-constraintSkillSecurity
Which assumptions are most fragile? — Vulnerability ranking + impact
Ready to connect★ 469
- View details
assumption-stress-testSkillSecurity
Systematic stress testing of assumptions — surface, classify by vulnerability,
Ready to connect★ 469
- View details
attack-vector-generationSkillSecurity
Generate specific attack strategies for a given threat surface, producing
Ready to connect★ 469
- View details
challenge-operationSkillSecurity
Non-threatening 'Why?' questioning of current practices (de Bono Challenge)
Ready to connect★ 469
- View details
challenge-questioningSkillSecurity
Non-threatening 'Why?' questioning of current practices to reveal historical
Ready to connect★ 469
What is a skill?
A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.
54,764 of the 55,196 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.
Install one and every AI you use gets it
Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.
Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.