Skills.

Give your AI a better way to work.

A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.

Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.

Category: Security

1,840 results · page 30 of 62

  • prompt-injection-defenseSkillSecurity

    Threat-model and harden AI agents, RAG systems, assistants, and tool-using workflows against direct, indirect, stored, cross-agent, and multimodal prompt injection. Use when reviewing an agent architecture, isolating untrusted content, constraining tools and egress, protecting secrets, adding inject

    Ready to connect★ 179

    github.com/seb1n/awesome-ai-agent-skills182 stars

    View details
  • static-application-security-testingSkillSecurity

    Analyze source code for security vulnerabilities using static analysis tools, custom rules, and CI-integrated scanning pipelines. Use when the user requests static application security testing or provides relevant inputs for this workflow.

    Ready to connect★ 179

    github.com/seb1n/awesome-ai-agent-skills182 stars

    View details
  • threat-modelingSkillSecurity

    Conduct structured threat modeling for software systems using established methodologies to identify, prioritize, and mitigate security threats before they are exploited. Use when the user requests threat modeling or provides relevant inputs for this workflow.

    Ready to connect★ 179

    github.com/seb1n/awesome-ai-agent-skills182 stars

    View details
  • spring-boot-skillSkillSecurity

    Build Spring Boot 4.x applications following the best practices. Use this skill: * When developing Spring Boot applications using Spring MVC, Spring Data JPA, Spring Modulith, Spring Security * To create recommended Spring Boot package structure * To implement REST APIs, entities/repositories, servi

    Ready to connect★ 181

    github.com/sivaprasadreddy/sivalabs-agent-skills181 stars

    View details
  • frappe-core-apiSkillSecurity

    Use when building ERPNext/Frappe API integrations (v14/v15/v16) including REST API, RPC API, authentication, webhooks, and rate limiting. Covers external API calls, endpoint design, token/OAuth2/session authentication. Keywords: API integration, REST endpoint, webhook, token authentication,, how to

    Ready to connect★ 178

    github.com/impertio-studio/frappe_claude_skill_package178 stars

    View details
  • frappe-core-permissionsSkillSecurity

    Use when implementing the Frappe/ERPNext permission system. Covers roles, user permissions, perm levels, data masking, and permission hooks for v14/v15/v16. Prevents common access control mistakes and security issues. Keywords: permissions, roles, user permissions, perm levels, data masking,, restri

    Ready to connect★ 178

    github.com/impertio-studio/frappe_claude_skill_package178 stars

    View details
  • frappe-errors-apiSkillSecurity

    Use when debugging or handling API errors in Frappe/ERPNext v14/v15/v16. Prevents silent failures and wrong HTTP status codes in REST endpoints. Covers 401 Unauthorized (wrong token format, expired OAuth), 403 Forbidden (missing @whitelist, allow_guest needed), 404 Not Found (wrong endpoint URL), 41

    Ready to connect★ 178

    github.com/impertio-studio/frappe_claude_skill_package178 stars

    View details
  • frappe-impl-integrationsSkillSecurity

    Use when implementing OAuth providers, Connected Apps, Webhooks, Payment Gateways, or Data Import/Export in Frappe. Prevents authentication failures from wrong OAuth flow, missed webhook deliveries, and data corruption during bulk imports. Covers OAuth2 provider/client, Connected App DocType, Webhoo

    Ready to connect★ 178

    github.com/impertio-studio/frappe_claude_skill_package178 stars

    View details
  • angular-routingSkillSecurity

    Implement routing in Angular v20+ applications with lazy loading, functional guards, resolvers, and route parameters. Use for navigation setup, protected routes, route-based data loading, and nested routing. Triggers on route configuration, adding authentication guards, implementing lazy loading, or

    Ready to connect★ 175

    github.com/kilo-org/kilo-marketplace173 stars

    View details
  • databricks-coreSkillSecurity

    Databricks CLI operations and the parent/entry-point skill for all Databricks work: authentication, profile selection, data exploration, bundles, and Genie natural-language data Q&A. Load this first for any Databricks task (CLI, auth, profiles, exploring catalogs/tables), then load the matching prod

    Ready to connect★ 175

    github.com/kilo-org/kilo-marketplace173 stars

    View details
  • fastapi-itechmeatSkillSecurity

    FastAPI Python framework. Covers REST APIs, validation, dependencies, security. Use when building Python web APIs with FastAPI, configuring Pydantic models, implementing dependency injection, or setting up OAuth2/JWT authentication. Keywords: FastAPI, Pydantic, async, OAuth2, JWT, REST API.

    Ready to connect★ 175

    github.com/kilo-org/kilo-marketplace173 stars

    View details
  • fastapi-martinholovskySkillSecurity

    REST API and WebSocket development with FastAPI emphasizing security, performance, and async patterns

    Ready to connect★ 175

    github.com/kilo-org/kilo-marketplace173 stars

    View details
  • trace-mcp-pre-commitSkillSecurity

    Run trace-mcp security, quality-gate, and antipattern checks before committing or opening a PR. Activate when the agent is about to create a commit or pull request in a project indexed by trace-mcp.

    Ready to connect★ 175

    github.com/nikolai-vysotskyi/trace-mcp175 stars

    View details
  • benignSkillSecurity

    Offline security scanner for AI-agent repos, skills, plugins, and MCP servers.

    Ready to connect★ 173

    github.com/alexgreensh/repo-forensics174 stars

    View details
  • clean-skillSkillSecurity

    A legitimate Codex skill with no threats

    Ready to connect★ 173

    github.com/alexgreensh/repo-forensics174 stars

    View details
  • repo-forensicsSkillSecurity

    Security forensics for git repos, AI skills, and MCP servers. Audits dependencies, detects prompt injection, credential theft, runtime dynamism, manifest drift, known CVEs, CISA KEV (actively exploited) vulns, and 2026 attack patterns. Not for fixing vulnerabilities or pentesting.

    Ready to connect★ 173

    github.com/alexgreensh/repo-forensics174 stars

    View details
  • lyrikSkillSecurity

    Security assessment of a codebase — minimal mode for runner validation

    Ready to connect★ 172

    github.com/gebruder/wirken170 stars

    View details
  • cve-lookupSkillSecurity

    Look up Common Vulnerabilities and Exposures (CVEs) with severity scores, affected software, exploitability status, and remediation guidance. Essential for security research, vulnerability management, and patch prioritization.

    Ready to connect★ 164

    github.com/sandbaseai/sandbase-skills170 stars

    View details
  • domain-analyzerSkillSecurity

    Comprehensive domain analysis combining WHOIS ownership, DNS infrastructure, SSL security, SEO performance, tech stack, site structure, and backlink profile. One-stop domain intelligence for acquisition research, security assessment, and competitive analysis.

    Ready to connect★ 164

    github.com/sandbaseai/sandbase-skills170 stars

    View details
  • domain-intelligenceSkillSecurity

    Research any domain with WHOIS data, DNS records, SSL certificate details, domain age, reputation scoring, and security header analysis. Covers ownership research, infrastructure mapping, security assessment, and competitive domain analysis.

    Ready to connect★ 164

    github.com/sandbaseai/sandbase-skills170 stars

    View details
  • npm-package-researchSkillSecurity

    Research npm packages — download stats, dependencies, maintainers, version history, and security advisories. Useful for technology due diligence, dependency auditing, and evaluating package reliability before adoption.

    Ready to connect★ 164

    github.com/sandbaseai/sandbase-skills170 stars

    View details
  • greenfieldSkillSecurity

    Parallel persona planning for new projects. Research agent runs first to build domain context, then Architect, PM, and Security agents run in parallel. Synthesis agent combines all perspectives into a detailed GSD-style PLAN.md with Tensions section.

    Ready to connect★ 168

    github.com/wednesday-solutions/ai-agent-skills168 stars

    View details
  • agent-tool-builderSkillSecurity

    Define agent tools using the fail-closed design pattern — unified name/schema/security/execution in one class, with three-layer execution (validate → permission → call). Use this skill whenever the user wants to define a new agent tool, add permission or validation logic to an existing tool, or asks

    Ready to connect★ 164

    github.com/simbajigege/book2skills165 stars

    View details
  • langchain-tool-builderSkillSecurity

    Build LangChain (Python) tools using Claude Code's fail-closed design pattern — unified name/schema/security/execution in one class, with automatic three-layer execution (validate → permission → call). Use this skill whenever the user wants to define a new LangChain tool, add permission or validatio

    Ready to connect★ 164

    github.com/simbajigege/book2skills165 stars

    View details
  • levyra-android-intent-securitySkillSecurity

    Automatically use for Levyra Android Intent, deep-link, PendingIntent, exported component, receiver, service, provider, URI-grant, FileProvider, caller-verification, or onNewIntent security work. Pair it with levyra-security-review and the affected Android domain skill.

    Ready to connect★ 164

    github.com/luc4n3x/levyra-deepsound44 stars

    View details
  • levyra-ci-workflowsSkillSecurity

    Automatically use for Levyra GitHub Actions, CI, F-Droid, Gradle/AGP/Kotlin/KSP compatibility, build performance, configuration/build cache, artifacts, release automation, workflow security, or configuration-sync work.

    Ready to connect★ 164

    github.com/luc4n3x/levyra-deepsound44 stars

    View details
  • levyra-motion-artworkSkillSecurity

    Implement, debug, or review Levyra decorative motion artwork, provider matching, muted media playback, prefetch, caching, lifecycle, and remote-media security.

    Ready to connect★ 164

    github.com/luc4n3x/levyra-deepsound44 stars

    View details
  • levyra-pr-reviewSkillSecurity

    Review a Levyra branch, commit, patch, or pull request for correctness, regressions, concurrency, lifecycle, security, data safety, UI behavior, CI, release risk, missing tests, and merge-readiness evidence.

    Ready to connect★ 164

    github.com/luc4n3x/levyra-deepsound44 stars

    View details
  • ai-security-engineerSkillSecurity

    Expert AI Security Engineer specializing in adversarial machine learning, LLM security, model supply chain protection, and MLSecOps. Use when: securing LLM applications, evaluating model robustness, implementing differential privacy, conducting authorized AI red-teaming, securing ML pipelines, or ma

    Ready to connect★ 163

    github.com/theneoai/awesome-skills158 stars

    View details
  • data-security-officerSkillSecurity

    Expert-level Data Security Officer with deep knowledge of data classification, DLP strategy, encryption at rest and in transit, data governance frameworks, regulatory compliance (GDPR, CCPA, PIPL, HIPAA), and data lifecycle security. Use when: data-security, data-governance, dlp, gdpr, compliance.

    Ready to connect★ 163

    github.com/theneoai/awesome-skills158 stars

    View details

What is a skill?

A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.

54,764 of the 55,196 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.

Install one and every AI you use gets it

Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.

Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.

See how to connect your AI