Skills.

Give your AI a better way to work.

A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.

Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.

Category: Security

1,840 results · page 24 of 62

  • audit-xcode-security-settingsSkillSecurity

    Audit and enable security-oriented Xcode build settings. Progressively enables compiler warnings, static analyzer checkers, and Enhanced Security features. Use when: user wants to secure their Xcode project, audit security settings, enable hardening, review security posture of build configuration, s

    Ready to connect★ 317

    github.com/superagents-lab/xcode27-skills318 stars

    View details
  • dependency-vuln-auditorSkillSecurity

    Inventories project dependencies and runtimes across ecosystems and reports known CVEs, supply-chain risks and a prioritized upgrade plan. Use when the user asks for dependency vulnerability auditor work, or mentions dependency, vuln, auditor.

    Ready to connect★ 307

    github.com/criptogus/agent-evolve-network309 stars

    View details
  • osint-investigatorSkillSecurity

    Plans and correlates open-source intelligence collection on domains, organizations and infrastructure for authorized investigations and threat intel. Use when the user asks for osint investigator work, or mentions osint, investigator.

    Ready to connect★ 307

    github.com/criptogus/agent-evolve-network309 stars

    View details
  • skilldSkillSecurity

    Operate skilld CLI for Skill discovery, use, installation, inspection, updates, authentication, configuration, restoration, and removal.

    Ready to connect★ 309

    github.com/skilld-dev/skilld309 stars

    View details
  • fix-dependenciesSkillSecurity

    Fix all vulnerabilities on the current branch using npm audit. Local branch only — no ADO/GitHub queries.

    Ready to connect★ 303

    github.com/microsoft/powerplatform-build-tools303 stars

    View details
  • auth:keycloak-confidential-clientSkillSecurity

    Create confidential OAuth2 clients in Keycloak for server-to-service authentication

    Ready to connect★ 301

    github.com/rossoctl/rossoctl298 stars

    View details
  • auth:mlflow-oidc-authSkillSecurity

    Configure MLflow with mlflow-oidc-auth plugin for Keycloak OIDC authentication

    Ready to connect★ 301

    github.com/rossoctl/rossoctl298 stars

    View details
  • auth:otel-oauth2-exporterSkillSecurity

    Configure OpenTelemetry Collector with OAuth2 authentication for trace export

    Ready to connect★ 301

    github.com/rossoctl/rossoctl298 stars

    View details
  • cveSkillSecurity

    CVE awareness — scan dependencies and code for vulnerabilities, audit docs for CVE leaks, plan responsible disclosure, block public leaks

    Ready to connect★ 301

    github.com/rossoctl/rossoctl298 stars

    View details
  • cve:brainstormSkillSecurity

    Plan responsible CVE disclosure, guide silent fixes, and BLOCK all public GitHub actions until CVE is properly handled

    Ready to connect★ 301

    github.com/rossoctl/rossoctl298 stars

    View details
  • cve:scanSkillSecurity

    Scan dependencies and source code for CVEs — Trivy, LLM reasoning, WebSearch, code security review, and doc audit

    Ready to connect★ 301

    github.com/rossoctl/rossoctl298 stars

    View details
  • orchestrateSkillSecurity

    Enhance any repository with CI, tests, skills, and security through phased PRs - self-replicating

    Ready to connect★ 301

    github.com/rossoctl/rossoctl298 stars

    View details
  • orchestrate:ciSkillSecurity

    Add comprehensive CI workflows to a target repo - lint, test, build, security scanning, dependabot, scorecard, action pinning

    Ready to connect★ 301

    github.com/rossoctl/rossoctl298 stars

    View details
  • orchestrate:scanSkillSecurity

    Scan and assess a target repository - tech stack, CI maturity, security posture, test coverage, supply chain health

    Ready to connect★ 301

    github.com/rossoctl/rossoctl298 stars

    View details
  • orchestrate:securitySkillSecurity

    Add security governance to a target repo - CODEOWNERS, SECURITY.md, CONTRIBUTING.md, LICENSE, .gitignore audit

    Ready to connect★ 301

    github.com/rossoctl/rossoctl298 stars

    View details
  • php-developmentSkillSecurity

    Expert guidance for PHP 8+ development, prioritizing code quality (SOLID, PSR standards), security practices, and testing requirements

    Ready to connect★ 295

    github.com/cecilapp/cecil295 stars

    View details
  • code-review-proSkillSecurity

    Comprehensive code review covering security vulnerabilities, performance bottlenecks, best practices, and refactoring opportunities. Use when user requests code review, security audit, or performance analysis.

    Ready to connect★ 291

    github.com/onewave-ai/claude-skills291 stars

    View details
  • git-pr-reviewerSkillSecurity

    Review pull requests for code quality, security issues, and best practices. Use when reviewing PRs, checking code changes, or analyzing diffs before merge.

    Ready to connect★ 291

    github.com/onewave-ai/claude-skills291 stars

    View details
  • overnight-repo-auditorSkillSecurity

    Uses Managed Agents' 14.5-hour runtime to audit an entire codebase overnight. Security, performance, accessibility, dependency issues. You wake up to a full report.

    Ready to connect★ 291

    github.com/onewave-ai/claude-skills291 stars

    View details
  • aiscanSkillSecurity

    Use this skill for AIScan's attack surface management and penetration-testing capabilities, including scanner pseudo-commands, supporting security tools, vulnerability verification, evidence handling, and assessment reporting.

    Ready to connect★ 290

    github.com/chainreactors/aiscan274 stars

    View details
  • api-security-testingSkillSecurity

    API security testing workflow for REST and GraphQL APIs covering authentication, authorization, rate limiting, input validation, and security best practices.

    Ready to connect★ 284

    github.com/lingxling/awesome-skills-cn284 stars

    View details
  • auth-securitySkillSecurity

    OAuth 2.1 + JWT authentication security best practices. Use when implementing auth, API authorization, token management. Follows RFC 9700 (2025).

    Ready to connect★ 278

    github.com/majiayu000/spellbook278 stars

    View details
  • codebase-auditSkillSecurity

    Comprehensive codebase audit — adaptive parallel deep analysis (frontend/backend contracts, data integrity, exception handling/security, architecture/tech debt, configuration/caching), structured findings + adversarial verification + baseline comparison, producing a unified severity-sorted report an

    Ready to connect★ 278

    github.com/majiayu000/spellbook278 stars

    View details
  • codex-agentSkillSecurity

    Use when you want a second-opinion review via Codex CLI, cross-verification after another agent implements changes, debugging help, or alternative implementation proposals. Requires Codex CLI to be installed and authenticated.

    Ready to connect★ 278

    github.com/majiayu000/spellbook278 stars

    View details
  • <skill-name>SkillSecurity

    <What this skill does in 2-3 sentences. Focus on technique scope and when to use it. No trigger phrases, negative conditions, or OPSEC details here.>

    Ready to connect★ 275

    github.com/blacklanternsecurity/red-run266 stars

    View details
  • 2fa-bypassSkillSecurity

    Bypass two-factor authentication (2FA/MFA) during authorized penetration testing.

    Ready to connect★ 275

    github.com/blacklanternsecurity/red-run266 stars

    View details
  • acl-abuseSkillSecurity

    Exploits misconfigured Active Directory ACLs for privilege escalation. Covers GenericAll, GenericWrite, WriteDACL, WriteOwner, ForceChangePassword, targeted Kerberoasting via SPN manipulation, shadow credentials (msDS-KeyCredentialLink → PKINIT), and AdminSDHolder persistence.

    Ready to connect★ 275

    github.com/blacklanternsecurity/red-run266 stars

    View details
  • ad-discoverySkillSecurity

    Enumerates Active Directory domains and maps attack surface for penetration testing.

    Ready to connect★ 275

    github.com/blacklanternsecurity/red-run266 stars

    View details
  • adcs-access-and-relaySkillSecurity

    Exploits ADCS through ACL abuse on templates/CA objects and NTLM relay to enrollment endpoints. Covers ESC4 (template ACL → modify to ESC1), ESC5 (PKI object ACLs), ESC7 (ManageCA/ManageCertificates abuse), ESC8 (NTLM relay to HTTP enrollment), ESC11 (NTLM relay to ICPR RPC).

    Ready to connect★ 275

    github.com/blacklanternsecurity/red-run266 stars

    View details
  • adcs-persistenceSkillSecurity

    Establishes persistence and exploits weak certificate mapping in AD CS. Covers ESC9 (no security extension), ESC10 (weak certificate mapping), ESC12-15 (YubiHSM, issuance policy, altSecIdentities, application policies), Golden Certificate (forge with stolen CA key), certificate theft (DPAPI/CAPI/CNG

    Ready to connect★ 275

    github.com/blacklanternsecurity/red-run266 stars

    View details

What is a skill?

A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.

54,764 of the 55,196 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.

Install one and every AI you use gets it

Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.

Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.

See how to connect your AI