Skills.
Give your AI a better way to work.
A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.
Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.
Category: Security
1,840 results · page 28 of 62
- View details
CodeQL Security AnalysisSkillSecurity
Advanced security analysis using GitHub CodeQL to find zero-day vulnerabilities, injection flaws, and security anti-patterns in source code.
Ready to connect★ 224
- View details
Compliance-as-Code TestingSkillSecurity
Automated compliance testing using Open Policy Agent, Chef InSpec, and custom policy engines for security baseline validation.
Ready to connect★ 224
- View details
CORS Security TestingSkillSecurity
Testing Cross-Origin Resource Sharing configurations for misconfigurations, overly permissive policies, and credential handling vulnerabilities.
Ready to connect★ 224
- View details
CSP Security TestingSkillSecurity
Content Security Policy testing and validation to prevent XSS attacks, data injection, and clickjacking through proper CSP header configuration.
Ready to connect★ 224
- View details
Dependency Vulnerability ScannerSkillSecurity
Automated scanning of project dependencies for known vulnerabilities using tools like npm audit, Snyk, and Dependabot patterns.
Ready to connect★ 224
- View details
Express.js Testing PatternsSkillSecurity
Express.js API testing with supertest, middleware testing, route handler testing, error handling verification, and authentication testing.
Ready to connect★ 224
- View details
hazard-gauntlet-to-scale-threatSkillSecurity
Create original short videos using the 连续脱险|假安全后升级为尺度威胁 Creative DNA for MiniMax H3 or Seedance 2.0. Use when the user wants this causal, camera, motion, rhythm, or payoff structure with new subjects and surfaces.
Ready to connect★ 225
- View details
gitSkillSecurity
Git operations with conventional commits. Use for staging, committing, pushing, PRs, merges. Auto-splits commits by type/scope. Security scans for secrets.
Ready to connect★ 224
- View details
researchSkillSecurity
Research technical solutions, analyze architectures, gather requirements thoroughly. Use for technology evaluation, best practices research, solution design, scalability/security/maintainability analysis.
Ready to connect★ 224
- View details
requesting-code-reviewSkillSecurity
Pre-commit review: security scan, quality gates, auto-fix.
Ready to connect★ 220
- View details
mcp-creatorSkillSecurity
Expert MCP (Model Context Protocol) server developer creating safe, performant, production-ready servers with proper security, error handling, and developer experience. Activate on 'create
Ready to connect★ 221
- View details
modern-auth-2026SkillSecurity
Modern authentication implementation for 2026 - passkeys (WebAuthn), OAuth (Google, Apple), magic links, and cross-device sync. Use for passwordless-first authentication, social login setup,
Ready to connect★ 221
- View details
new-device-supportSkillSecurity
Full workflow to add support for a new Eufy Security device type (cameras, locks, sensors, and other devices) across eufy-security-client and homebridge-eufy-security. Covers exploration, implementation, build verification, and git/PR creation.
Ready to connect★ 221
- View details
oauth-oidc-implementerSkillSecurity
Expert in implementing OAuth 2.0 and OpenID Connect (OIDC) authentication flows. Specializes in secure token handling, social login integration, API authorization, and identity provider configuration.
Ready to connect★ 221
- View details
security-auditorSkillSecurity
Security vulnerability scanner and OWASP compliance auditor for codebases. Dependency scanning (npm audit, pip-audit), secret detection (high-entropy strings, API keys), SAST for injection/XSS
Ready to connect★ 221
- View details
dv-connectSkillSecurity
One-step setup for a Dataverse environment — installs tools, authenticates, registers the MCP server, and writes `.env`. Use when starting a new project, switching environments, fixing authentication, or troubleshooting an MCP connection that won't come up.
Ready to connect★ 219
- View details
dv-securitySkillSecurity
Security-role assignment, user access, application users, business units, and admin self-elevation in Dataverse environments. Use when the user wants to give someone access, grant a role, become an admin, or add a service principal.
Ready to connect★ 219
- View details
api-testingSkillSecurity
HTTP API testing for TypeScript (Supertest) and Python (httpx, pytest). Test REST APIs, GraphQL, request/response validation, authentication, and error handling.
Ready to connect★ 218
- View details
claude-code-bash-patternsSkillSecurity
Claude Code Bash tool patterns with hooks, automation, git workflows. Use for PreToolUse hooks, command chaining, CLI orchestration, custom commands, or encountering bash permissions, command failures, security guards, hook configurations.
Ready to connect★ 218
- View details
csrf-protectionSkillSecurity
Implements CSRF protection using synchronizer tokens, double-submit cookies, and SameSite attributes. Use when securing web forms, protecting state-changing endpoints, or implementing defense-in-depth authentication.
Ready to connect★ 218
- View details
cybersecuritySkillSecurity
OSS-only security for OWASP Top 10, pentest, vuln testing (XSS, SSRF, CSRF, business-logic, Host header), threat modeling (STRIDE, ATT&CK), Sigma rules, SAST, code audit, AI/LLM red-team, or replacing paid tools (Burp, Nessus, Splunk) with OSS.
Ready to connect★ 218
- View details
dependency-upgradeSkillSecurity
Secure dependency upgrades with supply chain protection, cooldowns, and staged rollout. Use when upgrading deps, configuring security policies, or preventing supply chain attacks.
Ready to connect★ 218
- View details
gemini-cliSkillSecurity
Google Gemini CLI for second opinions, architectural advice, code reviews, security audits. Leverage 1M+ context for comprehensive codebase analysis via command-line tool.
Ready to connect★ 218
- View details
github-project-automationSkillSecurity
GitHub repository automation (CI/CD, issue templates, Dependabot, CodeQL). Use for project setup, Actions workflows, security scanning, or encountering YAML syntax, workflow configuration, template structure errors.
Ready to connect★ 218
- View details
multi-ai-consultantSkillSecurity
Consult external AIs (Gemini 2.5 Pro, OpenAI Codex, Claude) for second opinions. Use for debugging failures, architectural decisions, security validation, or need fresh perspective with synthesis.
Ready to connect★ 218
- View details
oauth-implementationSkillSecurity
OAuth 2.0 and OpenID Connect authentication with secure flows. Use for third-party integrations, SSO systems, token-based API access, or encountering authorization code flow, PKCE, token refresh, scope management errors.
Ready to connect★ 218
- View details
fix-vulnerabilitiesSkillSecurity
Triage and fix dependency vulnerabilities in an npm project. Use when the user asks to fix, address, or patch dependency/dependabot/npm audit vulnerabilities.
Ready to connect★ 215
- View details
llmquant-equity-derivativesSkillSecurity
Router skill for LLMQuant equity derivatives workflows. Use when the user needs single-stock derivative, convertible, warrant, structured payoff, or hybrid security analysis.
Ready to connect★ 214
- View details
telnyx-account-access-curlSkillSecurity
Configure account addresses, authentication providers, IP access controls, billing groups, and integration secrets. This skill provides REST API (curl) examples.
Ready to connect★ 214
- View details
telnyx-account-access-goSkillSecurity
Configure account addresses, authentication providers, IP access controls, billing groups, and integration secrets. This skill provides Go SDK examples.
Ready to connect★ 214
What is a skill?
A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.
54,764 of the 55,196 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.
Install one and every AI you use gets it
Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.
Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.