Skills.
Give your AI a better way to work.
A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.
Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.
Category: Security
1,840 results · page 26 of 62
- View details
red-run-ctfSkillSecurity
Multi-phase penetration test orchestrator. Handles recon, assessment surface mapping, vulnerability chaining, and routes to technique skills for execution. Invoke via /red-run-ctf slash command only.
Ready to connect★ 275
- View details
red-run-legacySkillSecurity
Legacy subagent-based orchestrator. Superseded by /red-run-ctf (agent teams). Use /red-run-legacy to invoke manually. Does not auto-trigger.
Ready to connect★ 275
- View details
remote-access-enumerationSkillSecurity
Enumeration of remote access services: FTP, SSH, RDP, VNC, and WinRM. Checks anonymous access, default credentials, version vulnerabilities, and authentication methods. Use after network-recon identifies remote access ports.
Ready to connect★ 275
- View details
request-smugglingSkillSecurity
Guide HTTP request smuggling exploitation during authorized penetration testing.
Ready to connect★ 275
- View details
retrospectiveSkillSecurity
Post-engagement lessons-learned retrospective. Reads the engagement directory, analyzes skill routing decisions, identifies knowledge gaps and missing skills, and produces an actionable improvement report.
Ready to connect★ 275
- View details
sccm-exploitationSkillSecurity
Enumerates and exploits Microsoft SCCM/MECM (System Center Configuration Manager / Microsoft Endpoint Configuration Manager) infrastructure for credential harvesting, lateral movement, and domain escalation. Covers SCCM enumeration (sccmhunter, SharpSCCM), Network Access Account (NAA) credential ext
Ready to connect★ 275
- View details
smb-exploitationSkillSecurity
Exploit remote SMB vulnerabilities for unauthenticated code execution on Windows hosts.
Ready to connect★ 275
- View details
source-code-reviewSkillSecurity
Security-focused source code review. Identifies hardcoded credentials, injection sinks, authentication weaknesses, and framework-specific vulnerabilities. Use when application source code is available for review.
Ready to connect★ 275
- View details
ssrfSkillSecurity
Guide server-side request forgery (SSRF) exploitation during authorized penetration testing.
Ready to connect★ 275
- View details
ssti-freemarkerSkillSecurity
Guide Freemarker/Java server-side template injection exploitation during authorized penetration testing.
Ready to connect★ 275
- View details
ssti-jinja2SkillSecurity
Guide Jinja2/Python server-side template injection exploitation during authorized penetration testing.
Ready to connect★ 275
- View details
ssti-twigSkillSecurity
Guide Twig/PHP server-side template injection exploitation during authorized penetration testing.
Ready to connect★ 275
- View details
trust-attacksSkillSecurity
Enumerates Active Directory trust relationships and exploits them for cross-domain and cross-forest privilege escalation. Covers trust enumeration (nltest, PowerView, BloodHound), SID history injection (child domain to forest root via golden/diamond ticket with extra SIDs), inter-realm TGT forging u
Ready to connect★ 275
- View details
unknown-vector-analysisSkillSecurity
Analyze custom applications, scripts, and binaries that standard technique skills could not exploit. Performs source code review, attack surface mapping, CVE research, and PoC adaptation. Route here when ANY technique agent returns saying standard patterns do not match, the target uses a custom/unkn
Ready to connect★ 275
- View details
web-discoverySkillSecurity
Discover web application injection points and route to the correct exploitation skill during authorized penetration testing.
Ready to connect★ 275
- View details
windows-credential-harvestingSkillSecurity
Harvest stored credentials from a Windows system for privilege escalation or lateral movement.
Ready to connect★ 275
- View details
windows-discoverySkillSecurity
Windows local privilege escalation enumeration and attack surface mapping.
Ready to connect★ 275
- View details
windows-service-dll-abuseSkillSecurity
Exploit Windows service misconfigurations and DLL hijacking for local privilege escalation.
Ready to connect★ 275
- View details
windows-token-impersonationSkillSecurity
Exploit Windows token privileges for local privilege escalation to SYSTEM.
Ready to connect★ 275
- View details
windows-uac-bypassSkillSecurity
Bypass Windows User Account Control to escalate from medium to high integrity.
Ready to connect★ 275
- View details
xmpp-enumerationSkillSecurity
XMPP/Jabber service enumeration for Openfire, ejabberd, Prosody, and other XMPP servers. Trigger when ports 5222 (client), 5223 (legacy TLS), or 5269 (server-to-server) are found open. Covers authentication testing, user enumeration, MUC room discovery, and server fingerprinting. Do NOT use for AD e
Ready to connect★ 275
- View details
xss-domSkillSecurity
Guide DOM-based XSS exploitation during authorized penetration testing.
Ready to connect★ 275
- View details
xss-reflectedSkillSecurity
Guide reflected XSS exploitation during authorized penetration testing.
Ready to connect★ 275
- View details
xss-storedSkillSecurity
Guide stored (persistent) and blind XSS exploitation during authorized penetration testing.
Ready to connect★ 275
- View details
xxeSkillSecurity
Guide XML External Entity (XXE) injection exploitation during authorized penetration testing.
Ready to connect★ 275
- View details
basecamp-doctorSkillSecurity
Diagnose Basecamp CLI, authentication, and agent-plugin health.
Ready to connect★ 272
- View details
aikido-securitySkillSecurity
Aikido Security integration. Manage data, records, and automate workflows. Use when the user wants to interact with Aikido Security data.
Ready to connect★ 270
- View details
bash-herestring-newline-secretsSkillSecurity
Fix password/secret authentication failures caused by trailing newlines when creating Google Cloud secrets (or similar) with bash here-strings. Use when: (1) Password authentication fails with correct password, (2) Secret created with `<<< "value"` syntax, (3) Error like "password authentication fai
Ready to connect★ 264
- View details
wayback-api-archive-recoverySkillSecurity
Recover data from archived REST APIs using Wayback Machine. Use when: (1) Recovering data from defunct services like Vine, Twitter, or other platforms, (2) Need to find which API endpoints were archived vs which require authentication, (3) Building data recovery pipelines from web.archive.org. Cover
Ready to connect★ 264
- View details
mcp-serverSkillSecurity
Use when exposing Spring Boot 3 application capabilities through Model Context Protocol tools, resources, or prompts. Covers Spring AI 1.x tool callback registration, transports, schemas, errors, security, and standalone MCP Java SDK compatibility.
Ready to connect★ 263
What is a skill?
A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.
54,764 of the 55,196 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.
Install one and every AI you use gets it
Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.
Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.