Skills.

Give your AI a better way to work.

A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.

Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.

Category: Security

1,840 results · page 28 of 62

  • CodeQL Security AnalysisSkillSecurity

    Advanced security analysis using GitHub CodeQL to find zero-day vulnerabilities, injection flaws, and security anti-patterns in source code.

    Ready to connect★ 224

    github.com/pramoddutta/qaskills225 stars

    View details
  • Compliance-as-Code TestingSkillSecurity

    Automated compliance testing using Open Policy Agent, Chef InSpec, and custom policy engines for security baseline validation.

    Ready to connect★ 224

    github.com/pramoddutta/qaskills225 stars

    View details
  • CORS Security TestingSkillSecurity

    Testing Cross-Origin Resource Sharing configurations for misconfigurations, overly permissive policies, and credential handling vulnerabilities.

    Ready to connect★ 224

    github.com/pramoddutta/qaskills225 stars

    View details
  • CSP Security TestingSkillSecurity

    Content Security Policy testing and validation to prevent XSS attacks, data injection, and clickjacking through proper CSP header configuration.

    Ready to connect★ 224

    github.com/pramoddutta/qaskills225 stars

    View details
  • Dependency Vulnerability ScannerSkillSecurity

    Automated scanning of project dependencies for known vulnerabilities using tools like npm audit, Snyk, and Dependabot patterns.

    Ready to connect★ 224

    github.com/pramoddutta/qaskills225 stars

    View details
  • Express.js Testing PatternsSkillSecurity

    Express.js API testing with supertest, middleware testing, route handler testing, error handling verification, and authentication testing.

    Ready to connect★ 224

    github.com/pramoddutta/qaskills225 stars

    View details
  • hazard-gauntlet-to-scale-threatSkillSecurity

    Create original short videos using the 连续脱险|假安全后升级为尺度威胁 Creative DNA for MiniMax H3 or Seedance 2.0. Use when the user wants this causal, camera, motion, rhythm, or payoff structure with new subjects and surfaces.

    Ready to connect★ 225

    github.com/t8mars/minimax-h3-prompt-skill-t8225 stars

    View details
  • gitSkillSecurity

    Git operations with conventional commits. Use for staging, committing, pushing, PRs, merges. Auto-splits commits by type/scope. Security scans for secrets.

    Ready to connect★ 224

    github.com/typv/nest-turbo-starter224 stars

    View details
  • researchSkillSecurity

    Research technical solutions, analyze architectures, gather requirements thoroughly. Use for technology evaluation, best practices research, solution design, scalability/security/maintainability analysis.

    Ready to connect★ 224

    github.com/typv/nest-turbo-starter224 stars

    View details
  • requesting-code-reviewSkillSecurity

    Pre-commit review: security scan, quality gates, auto-fix.

    Ready to connect★ 220

    github.com/hezaohezao/poirot223 stars

    View details
  • mcp-creatorSkillSecurity

    Expert MCP (Model Context Protocol) server developer creating safe, performant, production-ready servers with proper security, error handling, and developer experience. Activate on 'create

    Ready to connect★ 221

    github.com/curiositech/some_claude_skills209 stars

    View details
  • modern-auth-2026SkillSecurity

    Modern authentication implementation for 2026 - passkeys (WebAuthn), OAuth (Google, Apple), magic links, and cross-device sync. Use for passwordless-first authentication, social login setup,

    Ready to connect★ 221

    github.com/curiositech/some_claude_skills209 stars

    View details
  • new-device-supportSkillSecurity

    Full workflow to add support for a new Eufy Security device type (cameras, locks, sensors, and other devices) across eufy-security-client and homebridge-eufy-security. Covers exploration, implementation, build verification, and git/PR creation.

    Ready to connect★ 221

    github.com/homebridge-plugins/homebridge-eufy221 stars

    View details
  • oauth-oidc-implementerSkillSecurity

    Expert in implementing OAuth 2.0 and OpenID Connect (OIDC) authentication flows. Specializes in secure token handling, social login integration, API authorization, and identity provider configuration.

    Ready to connect★ 221

    github.com/curiositech/some_claude_skills209 stars

    View details
  • security-auditorSkillSecurity

    Security vulnerability scanner and OWASP compliance auditor for codebases. Dependency scanning (npm audit, pip-audit), secret detection (high-entropy strings, API keys), SAST for injection/XSS

    Ready to connect★ 221

    github.com/curiositech/some_claude_skills209 stars

    View details
  • dv-connectSkillSecurity

    One-step setup for a Dataverse environment — installs tools, authenticates, registers the MCP server, and writes `.env`. Use when starting a new project, switching environments, fixing authentication, or troubleshooting an MCP connection that won't come up.

    Ready to connect★ 219

    github.com/microsoft/dataverse-skills219 stars

    View details
  • dv-securitySkillSecurity

    Security-role assignment, user access, application users, business units, and admin self-elevation in Dataverse environments. Use when the user wants to give someone access, grant a role, become an admin, or add a service principal.

    Ready to connect★ 219

    github.com/microsoft/dataverse-skills219 stars

    View details
  • api-testingSkillSecurity

    HTTP API testing for TypeScript (Supertest) and Python (httpx, pytest). Test REST APIs, GraphQL, request/response validation, authentication, and error handling.

    Ready to connect★ 218

    github.com/secondsky/claude-skills218 stars

    View details
  • claude-code-bash-patternsSkillSecurity

    Claude Code Bash tool patterns with hooks, automation, git workflows. Use for PreToolUse hooks, command chaining, CLI orchestration, custom commands, or encountering bash permissions, command failures, security guards, hook configurations.

    Ready to connect★ 218

    github.com/secondsky/claude-skills218 stars

    View details
  • csrf-protectionSkillSecurity

    Implements CSRF protection using synchronizer tokens, double-submit cookies, and SameSite attributes. Use when securing web forms, protecting state-changing endpoints, or implementing defense-in-depth authentication.

    Ready to connect★ 218

    github.com/secondsky/claude-skills218 stars

    View details
  • cybersecuritySkillSecurity

    OSS-only security for OWASP Top 10, pentest, vuln testing (XSS, SSRF, CSRF, business-logic, Host header), threat modeling (STRIDE, ATT&CK), Sigma rules, SAST, code audit, AI/LLM red-team, or replacing paid tools (Burp, Nessus, Splunk) with OSS.

    Ready to connect★ 218

    github.com/secondsky/claude-skills218 stars

    View details
  • dependency-upgradeSkillSecurity

    Secure dependency upgrades with supply chain protection, cooldowns, and staged rollout. Use when upgrading deps, configuring security policies, or preventing supply chain attacks.

    Ready to connect★ 218

    github.com/secondsky/claude-skills218 stars

    View details
  • gemini-cliSkillSecurity

    Google Gemini CLI for second opinions, architectural advice, code reviews, security audits. Leverage 1M+ context for comprehensive codebase analysis via command-line tool.

    Ready to connect★ 218

    github.com/secondsky/claude-skills218 stars

    View details
  • github-project-automationSkillSecurity

    GitHub repository automation (CI/CD, issue templates, Dependabot, CodeQL). Use for project setup, Actions workflows, security scanning, or encountering YAML syntax, workflow configuration, template structure errors.

    Ready to connect★ 218

    github.com/secondsky/claude-skills218 stars

    View details
  • multi-ai-consultantSkillSecurity

    Consult external AIs (Gemini 2.5 Pro, OpenAI Codex, Claude) for second opinions. Use for debugging failures, architectural decisions, security validation, or need fresh perspective with synthesis.

    Ready to connect★ 218

    github.com/secondsky/claude-skills218 stars

    View details
  • oauth-implementationSkillSecurity

    OAuth 2.0 and OpenID Connect authentication with secure flows. Use for third-party integrations, SSO systems, token-based API access, or encountering authorization code flow, PKCE, token refresh, scope management errors.

    Ready to connect★ 218

    github.com/secondsky/claude-skills218 stars

    View details
  • fix-vulnerabilitiesSkillSecurity

    Triage and fix dependency vulnerabilities in an npm project. Use when the user asks to fix, address, or patch dependency/dependabot/npm audit vulnerabilities.

    Ready to connect★ 215

    github.com/itsbencodes/cookies215 stars

    View details
  • llmquant-equity-derivativesSkillSecurity

    Router skill for LLMQuant equity derivatives workflows. Use when the user needs single-stock derivative, convertible, warrant, structured payoff, or hybrid security analysis.

    Ready to connect★ 214

    github.com/llmquant/skills215 stars

    View details
  • telnyx-account-access-curlSkillSecurity

    Configure account addresses, authentication providers, IP access controls, billing groups, and integration secrets. This skill provides REST API (curl) examples.

    Ready to connect★ 214

    github.com/team-telnyx/ai214 stars

    View details
  • telnyx-account-access-goSkillSecurity

    Configure account addresses, authentication providers, IP access controls, billing groups, and integration secrets. This skill provides Go SDK examples.

    Ready to connect★ 214

    github.com/team-telnyx/ai214 stars

    View details

What is a skill?

A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.

54,764 of the 55,196 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.

Install one and every AI you use gets it

Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.

Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.

See how to connect your AI