Skills.

Give your AI a better way to work.

A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.

Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.

Category: Security

1,840 results · page 27 of 62

  • MiscSkillSecurity

    Miscellaneous techniques, including steganography, traffic analysis, encoding conversion, forensics, AI security, and other non-traditional CTF categories.

    Ready to connect★ 263

    github.com/muwinds/buuctf_agent258 stars

    View details
  • spring-security-jwtSkillSecurity

    Use when an application issues and validates its own first-party JWT access and refresh tokens, including authentication filters, password encoding, RBAC, and method security. For JWTs issued by Keycloak, Auth0, Okta, Cognito, or another authorization server, use oauth2-resource-server.

    Ready to connect★ 263

    github.com/rrezartprebreza/spring-boot-skills263 stars

    View details
  • mcp-engine-onboardingSkillSecurity

    Use when a user types onboarding, asks to set up SemanticOps MCP, wants help choosing Free vs Pro, or wants licensing, modes, masking, guardrails, preferences, model safety, tests, reporting, diagnostics, RLS testing, or Enterprise posture tailored to their workflow. For changing security, policy, o

    Ready to connect★ 256

    github.com/maxanatsko/mcp-engine-public255 stars

    View details
  • critical-interval-security-checkerSkillSecurity

    Analyzes code to identify security-critical time intervals and timing vulnerabilities in authentication, authorization, and time-sensitive security operations. Use this skill when reviewing code for proper timeout enforcement, token expiration, session management, rate limiting, password reset valid

    Ready to connect★ 252

    github.com/arabelatso/skills-4-se252 stars

    View details
  • cve-reachability-analyzerSkillSecurity

    Analyze CVE reachability in software repositories by examining how vulnerable dependencies are imported and used. Determines whether vulnerable components, classes, or functions are reachable from project code through call chain analysis, reflection detection, dynamic loading patterns, and configura

    Ready to connect★ 252

    github.com/arabelatso/skills-4-se252 stars

    View details
  • cve-watchlist-action-recommendation-generatorSkillSecurity

    Generate prioritized CVE watchlists and actionable security recommendations for repositories. Use when analyzing CVE scan results, creating security reports, prioritizing vulnerability remediation, or generating security gate reports for CI/CD. Takes CVE scan results (JSON/SARIF from npm audit, pip-

    Ready to connect★ 252

    github.com/arabelatso/skills-4-se252 stars

    View details
  • exploitability-analyzerSkillSecurity

    Analyze detected vulnerabilities to assess realistic exploitability by examining control flow, input sources, sanitization logic, and execution context. Use when users need to: (1) Determine if a vulnerability is actually exploitable in practice, (2) Assess severity and impact of security issues, (3

    Ready to connect★ 252

    github.com/arabelatso/skills-4-se252 stars

    View details
  • fuzzing-input-generatorSkillSecurity

    Generate randomized and edge-case inputs to detect unexpected failures, bugs, and security vulnerabilities through fuzz testing. Use when creating test cases for robustness testing, generating adversarial inputs, testing error handling, finding edge cases, or security testing. Produces Python test c

    Ready to connect★ 252

    github.com/arabelatso/skills-4-se252 stars

    View details
  • security-patch-advisorSkillSecurity

    Proposes secure remediation strategies for detected security vulnerabilities including buffer overflows, injection risks, insecure deserialization, improper authentication, and unsafe cryptographic usage. Provides recommended security checks, safer API alternatives, design-level changes, code exampl

    Ready to connect★ 252

    github.com/arabelatso/skills-4-se252 stars

    View details
  • using-the-mcp-serverSkillSecurity

    Use when calling LLM APIs through the liter-llm MCP server's 22 tools, and to decide when MCP beats the CLI or SDK. Covers the tool surface, the auto-installing launcher, and authentication.

    Ready to connect★ 252

    github.com/xberg-io/liter-llm252 stars

    View details
  • cli-reviewSkillSecurity

    Runs a Greptile CLI review for the current local branch, installing or authenticating the CLI when needed, then summarizes JSON findings for the user. Use when the user wants Greptile feedback before opening a PR, outside a hosted PR review flow, or directly from a local checkout.

    Ready to connect★ 244

    github.com/alvinunreal/lazyskills244 stars

    View details
  • analyzing-securitySkillSecurity

    Scans code for security vulnerabilities, detects dangerous patterns, and ensures security decisions are documented. Use when running security scans, auditing code, or checking for OWASP issues, injection risks, or sensitive data leaks. Automatically triggered on new modules, security-related changes

    Ready to connect★ 240

    github.com/telagod/code-abyss240 stars

    View details
  • defending-applicationsSkillSecurity

    Application security defense knowledge for builders. Covers Web/API/GraphQL hardening (XSS/SQLi/SSRF/IDOR/BOLA/Mass Assignment/deserialization/upload/path traversal), authentication/authorization (OAuth 2.0/OIDC/JWT/Session/Cookie/SAML/SSO), and LLM application security (prompt injection, jailbreak,

    Ready to connect★ 240

    github.com/telagod/code-abyss240 stars

    View details
  • securing-systemsSkillSecurity

    Security engineering router for penetration testing, code auditing, red/blue/purple team operations, threat intelligence, and vulnerability research. For specialized application security, cloud security, detection engineering, or security architecture, route to dedicated skills (defending-applicatio

    Ready to connect★ 240

    github.com/telagod/code-abyss240 stars

    View details
  • stella-cliSkillSecurity

    Drive the stella command-line client (@stll/cli), a legal-workspace CLI whose command surface is generated from the stella MCP tool registry. Covers install, OAuth login, the full command tree grouped by domain, JSON output for scripting, the --input escape hatch for deep payloads, cursor pagination

    Ready to connect★ 240

    github.com/stella/stella234 stars

    View details
  • oauthSkillSecurity

    A skill for security by theprimeagen.

    Ready to connect★ 233

    github.com/theprimeagen/skills233 stars

    View details
  • auditingSkillSecurity

    Use when reviewing a bundle-plugin for structural issues, version drift, skill quality, workflow integration, or security risks — before releasing, after changes, or after adding skills. Auto-detects scope (full project vs skill vs workflow)

    Ready to connect★ 230

    github.com/odradekai/bundles-forge230 stars

    View details
  • 80-20-reviewSkillSecurity

    Focus code review effort on the 20% of code that causes 80% of issues. Prioritizes data access, security, concurrency, and integration boundaries over formatting and style. Uses blast radius scoring to determine review depth. Includes checkpoint schedules, critical path identification, and a batch r

    Ready to connect★ 226

    github.com/resgrid/core225 stars

    View details
  • code-review-workflowSkillSecurity

    Structured code review workflow for .NET projects using Roslyn MCP tools. Multi-dimensional review covering correctness, security, performance, architecture compliance, and test coverage. Load when: "review PR", "review code", "code review", "PR review", "review changes", "review my code", "check co

    Ready to connect★ 226

    github.com/resgrid/core225 stars

    View details
  • verification-loopSkillSecurity

    7-phase .NET verification pipeline with structured PASS/FAIL reporting. Ensures every change is build-verified, diagnostics-clean, anti-pattern-free, test-passing, security-scanned, format-compliant, and diff-reviewed before marking work as complete. Load this skill when: "verify", "check everything

    Ready to connect★ 226

    github.com/resgrid/core225 stars

    View details
  • AFL++ Fuzzing TestingSkillSecurity

    American Fuzzy Lop Plus Plus mutation-based fuzz testing for finding crashes, hangs, and security vulnerabilities in binary programs.

    Ready to connect★ 224

    github.com/pramoddutta/qaskills225 stars

    View details
  • API FuzzingSkillSecurity

    API endpoint fuzzing for discovering unexpected behaviors, crashes, and security vulnerabilities through malformed requests, boundary values, and protocol violations.

    Ready to connect★ 224

    github.com/pramoddutta/qaskills225 stars

    View details
  • API Security TestingSkillSecurity

    Comprehensive API security testing based on OWASP API Security Top 10 including broken authentication, injection attacks, rate limiting, BOLA/BFLA vulnerabilities, and automated security scanning with ZAP and custom scripts.

    Ready to connect★ 224

    github.com/pramoddutta/qaskills225 stars

    View details
  • API Test Suite GeneratorSkillSecurity

    Automatically generate comprehensive API test suites from OpenAPI specifications covering CRUD operations, error handling, authentication, pagination, and edge cases

    Ready to connect★ 224

    github.com/pramoddutta/qaskills225 stars

    View details
  • API Testing RESTSkillSecurity

    Comprehensive RESTful API testing patterns covering HTTP methods, status codes, request/response validation, authentication, error handling, and contract testing.

    Ready to connect★ 224

    github.com/pramoddutta/qaskills225 stars

    View details
  • apparent-vulnerability-readiness-reversal-resumptionSkillSecurity

    Create original short videos using the 伪弱势反转|困境诱近—准备微证据—能力破局—继续上路 Creative DNA for MiniMax H3 or Seedance 2.0. Use when the user wants this causal, camera, motion, rhythm, or payoff structure with new subjects and surfaces.

    Ready to connect★ 225

    github.com/t8mars/minimax-h3-prompt-skill-t8225 stars

    View details
  • Auth Bypass TesterSkillSecurity

    Comprehensive authentication and authorization bypass testing including session hijacking, privilege escalation, JWT manipulation, and access control verification

    Ready to connect★ 224

    github.com/pramoddutta/qaskills225 stars

    View details
  • Authentication Testing PatternsSkillSecurity

    Comprehensive authentication testing including login flows, password policies, MFA, session management, account lockout, and SSO integration.

    Ready to connect★ 224

    github.com/pramoddutta/qaskills225 stars

    View details
  • BurpSuite Security TestingSkillSecurity

    Web application security testing using BurpSuite for proxy-based interception, scanning, and manual penetration testing of web applications.

    Ready to connect★ 224

    github.com/pramoddutta/qaskills225 stars

    View details
  • Clerk Auth TestingSkillSecurity

    Testing patterns for Clerk authentication including sign-in flow testing, protected route testing, webhook verification, middleware testing, and organization-based access control

    Ready to connect★ 224

    github.com/pramoddutta/qaskills225 stars

    View details

What is a skill?

A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.

54,764 of the 55,196 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.

Install one and every AI you use gets it

Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.

Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.

See how to connect your AI