Skills.

Give your AI a better way to work.

A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.

Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.

Category: Security

1,840 results · page 22 of 62

  • supply-chain-hardeningSkillSecurity

    Install-time cooldowns for npm/bun plus a sandboxed pre-install scan for bypasses. Use for supply-chain attacks or npm security.

    Ready to connect★ 393

    github.com/jamditis/claude-skills-journalism393 stars

    View details
  • yao-codereview-hskillSkillSecurity

    Provides professional code review services, checking code quality, security vulnerabilities, performance issues, and best practices. Supports multiple programming languages and frameworks.

    Ready to connect★ 384

    github.com/bruc3van/agent-skills-guard385 stars

    View details
  • llm-testingSkillSecurity

    Comprehensive LLM security testing prompts for bias detection, data leakage, alignment testing, and adversarial prompt resistance.

    Ready to connect★ 383

    github.com/eyadkelleh/awesome-skills-security384 stars

    View details
  • security-passwordsSkillSecurity

    Top password lists for authorized security testing: common passwords, darkweb leaks, worst passwords. Curated essentials (<10MB).

    Ready to connect★ 383

    github.com/eyadkelleh/awesome-skills-security384 stars

    View details
  • security-usernamesSkillSecurity

    Top username lists for enumeration: common usernames, default credentials, names. Curated essentials for authorized testing.

    Ready to connect★ 383

    github.com/eyadkelleh/awesome-skills-security384 stars

    View details
  • security-webshellsSkillSecurity

    Web shell samples for detection and analysis: PHP, ASP, ASPX, JSP, Python, Perl shells. Use for security research and detection system testing.

    Ready to connect★ 383

    github.com/eyadkelleh/awesome-skills-security384 stars

    View details
  • asanaSkillSecurity

    Asana API integration with managed OAuth. Access tasks, projects, workspaces, users, and manage webhooks. Use this skill when users want to manage work items, track projects, or integrate with Asana workflows. For other third party apps, use the api-gateway skill (https://clawhub.ai/byungkyu/api-gat

    Ready to connect★ 383

    github.com/craftos-dev/craftbot376 stars

    View details
  • calendlySkillSecurity

    Calendly API integration with managed OAuth. Access event types, scheduled events, invitees, availability, and manage webhooks. Use this skill when users want to view scheduling data, check availability, book meetings, or integrate with Calendly workflows. For other third party apps, use the api-gat

    Ready to connect★ 383

    github.com/craftos-dev/craftbot376 stars

    View details
  • clickupSkillSecurity

    ClickUp API integration with managed OAuth. Access tasks, lists, folders, spaces, workspaces, users, and manage webhooks. Use this skill when users want to manage work items, track projects, or integrate with ClickUp workflows. For other third party apps, use the api-gateway skill (https://clawhub.a

    Ready to connect★ 383

    github.com/craftos-dev/craftbot376 stars

    View details
  • compliance-cert-plannerSkillSecurity

    Plan and sequence security and privacy compliance certifications (SOC 2, ISO 27001, GDPR, HIPAA, PCI DSS, CASA, etc.). Use when the user needs to scope which frameworks apply, classify each one, identify shared controls, and produce a roadmap.

    Ready to connect★ 383

    github.com/craftos-dev/craftbot376 stars

    View details
  • google-meetSkillSecurity

    Google Meet API integration with managed OAuth. Create meeting spaces, list conference records, and manage meeting participants. Use this skill when users want to interact with Google Meet. For other third party apps, use the api-gateway skill (https://clawhub.ai/byungkyu/api-gateway).

    Ready to connect★ 383

    github.com/craftos-dev/craftbot376 stars

    View details
  • google-playSkillSecurity

    Google Play Developer API (Android Publisher) integration with managed OAuth. Manage apps, subscriptions, in-app purchases, and reviews. Use this skill when users want to interact with Google Play Console programmatically. For other third party apps, use the api-gateway skill (https://clawhub.ai/byu

    Ready to connect★ 383

    github.com/craftos-dev/craftbot376 stars

    View details
  • google-workspace-adminSkillSecurity

    Google Workspace Admin SDK integration with managed OAuth. Manage users, groups, organizational units, and domain settings. Use this skill when users want to administer Google Workspace. For other third party apps, use the api-gateway skill (https://clawhub.ai/byungkyu/api-gateway).

    Ready to connect★ 383

    github.com/craftos-dev/craftbot376 stars

    View details
  • pipedriveSkillSecurity

    Pipedrive API integration with managed OAuth. Manage deals, persons, organizations, activities, and pipelines. Use this skill when users want to interact with Pipedrive CRM. For other third party apps, use the api-gateway skill (https://clawhub.ai/byungkyu/api-gateway).

    Ready to connect★ 383

    github.com/craftos-dev/craftbot376 stars

    View details
  • salesforceSkillSecurity

    Salesforce CRM API integration with managed OAuth. Query records with SOQL, manage sObjects (Contacts, Accounts, Leads, Opportunities), and perform batch operations. Use this skill when users want to interact with Salesforce data. For other third party apps, use the api-gateway skill (https://clawhu

    Ready to connect★ 383

    github.com/craftos-dev/craftbot376 stars

    View details
  • shannonSkillSecurity

    Autonomous AI pentester for web apps and APIs. Run white-box security assessments with Shannon — analyzes source code, identifies attack vectors, and executes real exploits to prove vulnerabilities. Triggered by 'shannon', 'pentest', 'security audit', 'vuln scan'.

    Ready to connect★ 383

    github.com/craftos-dev/craftbot376 stars

    View details
  • stripeSkillSecurity

    Stripe API integration with managed OAuth. Manage customers, subscriptions, invoices, products, prices, and payments. Use this skill when users want to process payments, manage billing, or handle subscriptions with Stripe. For other third party apps, use the api-gateway skill (https://clawhub.ai/byu

    Ready to connect★ 383

    github.com/craftos-dev/craftbot376 stars

    View details
  • e2eSkillSecurity

    Run end-to-end tests of SmokedMeat against the Whooli goat repos. Use when testing TUI changes, verifying exploit flows, debugging UI state, or validating Kitchen/Counter integration.

    Ready to connect★ 379

    github.com/boostsecurityio/smokedmeat376 stars

    View details
  • composio-integrationsSkillSecurity

    Use Composio-connected SaaS tools safely. Generate OAuth connect links in chat when the user's account is not connected.

    Ready to connect★ 372

    github.com/ahmadrosid/nakama286 stars

    View details
  • lean-pr-reviewSkillSecurity

    Review a GitHub PR for unnecessary complexity. For PRs authored by someone else, post short human-sounding inline review comments via gh. For PRs authored by the authenticated gh user ("me"), apply the cuts on the PR branch and push — do not post review comments. Use when the user asks for a lean PR

    Ready to connect★ 372

    github.com/ahmadrosid/nakama286 stars

    View details
  • sonarqubeSkillSecurity

    Operate SonarQube-enabled repositories through the SonarQube CLI (`sonar`): verify authentication, discover project keys, inspect project metadata, issues, measures, and quality gates, analyze changed code, scan secrets and dependency risks, call authenticated APIs, trigger remediation, configure in

    Ready to connect★ 371

    github.com/dougtrajano/pydantic-ai-skills371 stars

    View details
  • advanced-redteamSkillSecurity

    Offensive security toolkit for Claude Code covering red team, exploit dev, AD attacks, EDR bypass, mobile pentest

    Ready to connect★ 363

    github.com/hypnguyen1209/offensive-claude362 stars

    View details
  • coding-masterySkillSecurity

    Use when writing security tooling, exploits, scanners, or C2 in Python/C/Go/Rust/ASM — systems & network programming, automation, cryptography implementation

    Ready to connect★ 363

    github.com/hypnguyen1209/offensive-claude362 stars

    View details
  • engagement-flowSkillSecurity

    Use when starting, planning, or running a multi-phase pentest or red-team engagement — to sequence the Cyber Kill Chain phases with quality gates instead of jumping straight to exploitation

    Ready to connect★ 363

    github.com/hypnguyen1209/offensive-claude362 stars

    View details
  • finding-disciplineSkillSecurity

    Use when about to record, claim, rate the severity of, or report any security finding — before marking anything [CONFIRMED] or writing it into the report

    Ready to connect★ 363

    github.com/hypnguyen1209/offensive-claude362 stars

    View details
  • initial-accessSkillSecurity

    Use when gaining initial access to a target — phishing, payload delivery, HTML smuggling, ISO/IMG/MOTW bypass, supply-chain, credential stuffing, exposed-service exploitation

    Ready to connect★ 363

    github.com/hypnguyen1209/offensive-claude362 stars

    View details
  • keylogger-archSkillSecurity

    Offensive security toolkit for Claude Code covering red team, exploit dev, AD attacks, EDR bypass, mobile pentest

    Ready to connect★ 363

    github.com/hypnguyen1209/offensive-claude362 stars

    View details
  • network-attackSkillSecurity

    Use when attacking a network or moving laterally — L2/L3 poisoning (LLMNR/mDNS, ARP/DHCP, mitm6), coercion + NTLM relay (CVE-2025-33073), TUN pivoting (Ligolo-ng/Chisel), MitM, network-service RCE (CVE-2024-38077), WPA2/WPA3 wireless

    Ready to connect★ 363

    github.com/hypnguyen1209/offensive-claude362 stars

    View details
  • privesc-linuxSkillSecurity

    Use when escalating privileges on a Linux host — SUID/SGID & GTFOBins, sudo LPE (CVE-2025-32462/32463), capabilities & LD_PRELOAD, kernel LPE (CVE-2024-1086, Dirty Pipe, GameOver(lay)), service misconfig (PwnKit, Looney Tunables), container/namespace escape

    Ready to connect★ 363

    github.com/hypnguyen1209/offensive-claude362 stars

    View details
  • privesc-windowsSkillSecurity

    Use when escalating privileges on a Windows host — SeImpersonate Potato chains (GodPotato/PrintNotifyPotato), service & DLL hijacking, UAC bypass (fodhelper/ICMLuaUtil), kernel EoP + BYOVD (CVE-2025-29824), token-rights abuse, LSASS/SAM/DPAPI credential harvesting

    Ready to connect★ 363

    github.com/hypnguyen1209/offensive-claude362 stars

    View details

What is a skill?

A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.

54,764 of the 55,196 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.

Install one and every AI you use gets it

Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.

Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.

See how to connect your AI