Skills.

Give your AI a better way to work.

A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.

Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.

Category: Security

1,840 results · page 33 of 62

  • accountable-engineeringSkillSecurity

    Guides disciplined AI-assisted engineering that avoids cognitive surrender and keeps humans accountable. Use for non-trivial implementation, architecture, security, or operational tasks.

    Ready to connect★ 120

    github.com/jellydn/my-ai-tools119 stars

    View details
  • backend-fastapi-pythonSkillSecurity

    Use this skill for any Python backend work in this project: building FastAPI endpoints, writing service functions, defining Pydantic/SQLModel schemas, running Alembic migrations, or debugging 422 errors. Essential for authentication and authorization patterns — setting up get_current_user, is_superu

    Ready to connect★ 120

    github.com/avibebuilder/claude-prime120 stars

    View details
  • sailSkillSecurity

    Apply the SAIL (Secure AI Lifecycle) V2 framework by Pillar Security to secure AI applications and agents. Use this skill whenever the user asks about AI or agent security — assessing an AI system or agent architecture for risks, building an AI security roadmap or maturity assessment, writing or rev

    Ready to connect★ 119

    github.com/pillar-labs/sail-skill119 stars

    View details
  • emby-integrationSkillSecurity

    Emby API, authentication flow, rating scale, streaming, scrobbling, and video playback. Use when working on Emby integration, library browsing, playback reporting, or video casting.

    Ready to connect★ 118

    github.com/ad-repo/nullplayer116 stars

    View details
  • jellyfin-integrationSkillSecurity

    Jellyfin API, authentication flow, rating scale, streaming, scrobbling, and video playback. Use when working on Jellyfin integration, library browsing, playback reporting, or video casting.

    Ready to connect★ 118

    github.com/ad-repo/nullplayer116 stars

    View details
  • plex-integrationSkillSecurity

    Plex API endpoints, authentication, filtering, music radio, and video content. Use when working on Plex integration, library browsing, track queries, radio features, or video playback.

    Ready to connect★ 118

    github.com/ad-repo/nullplayer116 stars

    View details
  • subsonic-integrationSkillSecurity

    Subsonic/Navidrome API, authentication, music folder selection, streaming, and scrobbling. Use when working on Subsonic/Navidrome integration, library browsing, music folder filtering, or playback reporting.

    Ready to connect★ 118

    github.com/ad-repo/nullplayer116 stars

    View details
  • janitor-securitySkillSecurity

    Heuristic security scan of installed skills — prompt-injection phrases, hidden unicode instructions, credential-store access, network-pipe-to-shell and payload-smuggling patterns. Use when the user asks 'are my skills safe', wants to scan skills for prompt injection or malware patterns, or before tr

    Ready to connect★ 117

    github.com/khendzel/skills-janitor117 stars

    View details
  • api-fuzzingSkillSecurity

    API fuzzing for bug bounty. Use when the user asks to test API security,

    Ready to connect★ 116

    github.com/langbyyi/cyberstrikeai-src110 stars

    View details
  • burp-mcp-vuln-checkSkillSecurity

    Automate low-impact web vulnerability verification through Burp MCP. Use when Codex is asked to check, reproduce, triage, or write evidence for vulnerabilities using Burp Suite proxy history, Repeater, Collaborator/OOB payloads, HTTP replay, parameter mutation, response diffing, or scanner issues. A

    Ready to connect★ 116

    github.com/langbyyi/cyberstrikeai-src110 stars

    View details
  • fastjson-exploitationSkillSecurity

    Fastjson/Fastjson2反序列化漏洞深度利用专业技能:版本探测、AutoType全版本绕过、JNDI/BCEL/TemplatesImpl/c3p0利用链、1.2.83 Gadget-free RCE(CVE-2026-16723)、Fastjson2 FNV-1a哈希碰撞绕过(QVD-2026-45876)、不出网利用、WAF绕过、从探测到RCE完整攻击链

    Ready to connect★ 116

    github.com/langbyyi/cyberstrikeai-src110 stars

    View details
  • jwt-oauth-token-attacksSkillSecurity

    JWT and OAuth token attack playbook. Use when validating token trust, signing algorithms, key handling, claim abuse, bearer flows, and OAuth account-binding weaknesses.

    Ready to connect★ 116

    github.com/langbyyi/cyberstrikeai-src110 stars

    View details
  • ldap-injection-testingSkillSecurity

    LDAP注入深度测试与域渗透联动高级技能:RFC 4515过滤器语义深度、AND/OR注入、通配符滥用横向接管、认证绕过、RDN/过滤器混淆、盲注高效提取(二分/位运算OID/OAST外带)、非标准属性与AD专属属性利用、LDAPS/StartTLS/通道绑定与NTLM Relay、Spring Data LDAP/ldap3/ldapjs等框架注入差异、WAF绕过、LDAP注入→域枚举→Kerberoasting/noPac/gMSA→提权完整攻击链、2025-2026新CVE实战(CVE-2026-46619/CVE-2026-40459/CVE-2026-58222/CVE-2026-4

    Ready to connect★ 116

    github.com/langbyyi/cyberstrikeai-src110 stars

    View details
  • log4shell-exploitationSkillSecurity

    Log4Shell(CVE-2021-44228)及 Log4j2 全漏洞家族深度利用专业技能:JNDI Lookup 全链路原理与利用、全变体家族(44228/45046/45105/44832/4104)、现代 JDK 高版本绕过矩阵(8u191/17/21+)、Lookup 扩展攻击面(env/sys/ctx/k8s 信息泄露)、WAF 绕过全技术、不出网利用、供应链场景、Log4Shell→RCE→内网渗透完整链、带内/带外检测方法论、AI 大模型辅助攻防

    Ready to connect★ 116

    github.com/langbyyi/cyberstrikeai-src110 stars

    View details
  • mobile-app-security-testingSkillSecurity

    移动应用安全深度测试专业技能(v3.0):移动端深层攻击链(App→API→后端→云)、Android/iOS深度逆向与动态调试、Frida全面对抗与加固脱壳、iOS越狱检测绕过/ObjC Runtime/LLDB调试/证书固定绕过、跨平台框架漏洞(Flutter/React Native/uni-app/小程序)、移动端存储密钥(Keystore/Keychain/硬编码)、WebView与深链/IPC攻击面、移动端AI应用攻击面(端侧LLM/Agent提示注入/隐私数据)、AI大模型辅助逆向与API调用链分析、供应链SDK投毒与云凭据、模拟器/root/越狱检测绕过,从信息收集到漏洞利用完

    Ready to connect★ 116

    github.com/langbyyi/cyberstrikeai-src110 stars

    View details
  • pentest-blackboardSkillSecurity

    CyberStrikeAI 跨会话项目状态:Fact 图、漏洞记录、关系边与多代理落库边界。 Use when managing project facts, evidence state, or context recovery.

    Ready to connect★ 116

    github.com/langbyyi/cyberstrikeai-src110 stars

    View details
  • security-automationSkillSecurity

    安全自动化顶级专业技能:DevSecOps全流程集成、CI/CD安全管道、SAST/DAST/SCA/容器/IaC自动化扫描编排、安全工具链集成实战、攻防双视角自动化(红队打点/蓝队检测响应)、SOAR深度编排、Agentic AI安全自动化(LLM Agent编排扫描与响应)、大模型安全运营(AI告警降噪/剧本生成)、误报治理与质量保障、合规自动化(证据收集/报告)

    Ready to connect★ 116

    github.com/langbyyi/cyberstrikeai-src110 stars

    View details
  • security-awareness-trainingSkillSecurity

    安全意识培训深度专业技能(v3.0高级版):AI时代社工威胁升级、深度伪造语音/视频钓鱼、AI生成个性化钓鱼、Evilginx2全链路仿真演练、防御方角色化培训体系、Kirkpatrick四层量化效果评估、AI大模型结合(LLM生成教材/演练内容/数据分析/大模型使用安全规范)、新威胁面培训(提示注入/Deepfake识别/供应链/QR钓鱼)、红蓝对抗演练组织方法论,从"意识培训"升级为"行为安全工程"的完整攻防培训体系

    Ready to connect★ 116

    github.com/langbyyi/cyberstrikeai-src110 stars

    View details
  • shiro-exploitationSkillSecurity

    Apache Shiro安全框架深度利用专业技能v3.0:rememberMe Cookie AES-CBC/CBC-GCM双模式深挖、密钥爆破方法论升级(Padding Oracle深度解密原理/工具选型/并行加速)、Gadget链版本兼容矩阵、Shiro-550/721、认证绕过全系列(CVE-2020-1957至CVE-2026-56091)、Tomcat内存马/错链回显、Shiro+Fastjson/Log4j组合链、Spring Boot生态实战面、AI大模型辅助攻击载荷生成与配置审计、从指纹识别到RCE完整攻击链

    Ready to connect★ 116

    github.com/langbyyi/cyberstrikeai-src110 stars

    View details
  • spring-exploitationSkillSecurity

    Spring Framework漏洞深度利用专业技能:全年代CVE时间线(2016-2026)、Spring Boot Actuator深度利用与heapdump凭据链、SpEL注入全家族、Spring4Shell数据绑定RCE、Spring Security认证/授权绕过面、Spring内存马全谱系(Filter/Servlet/Interceptor/ControllerAdvice/WebFlux)、Spring Cloud组件漏洞、Spring AI/LLM集成框架攻击面、环境变量/配置注入、Log4Shell组合利用、AI大模型辅助攻防、WAF绕过与不出网利用

    Ready to connect★ 116

    github.com/langbyyi/cyberstrikeai-src110 stars

    View details
  • type-jugglingSkillSecurity

    PHP type juggling and weak comparison (`==`) bypass. Use when authentication, HMAC/signature checks, or token validation uses loose equality, numeric coercion, or hash comparisons without strict types — common in legacy PHP and CTF-style code paths.

    Ready to connect★ 116

    github.com/langbyyi/cyberstrikeai-src110 stars

    View details
  • vulnerability-assessmentSkillSecurity

    漏洞评估高级专业技能:CVSS 3.1/4.0评分体系深度与滥用案例、EPSS/KEV/VPT漏洞优先级技术融合、攻击面管理与扫描器深度配置(Nessus/OpenVAS/Nuclei自动化与误报治理)、漏洞验证与真实可利用性分析、供应链SBOM与云容器漏洞评估专项、AI大模型辅助漏洞研判与报告生成、从发现到闭环的漏洞全生命周期管理

    Ready to connect★ 116

    github.com/langbyyi/cyberstrikeai-src110 stars

    View details
  • web-cache-deceptionSkillSecurity

    Web cache deception and poisoning playbook. Use when CDN, reverse proxy, or application caching may serve sensitive authenticated content to other users due to path confusion or cache key manipulation.

    Ready to connect★ 116

    github.com/langbyyi/cyberstrikeai-src110 stars

    View details
  • xpath-injection-testingSkillSecurity

    XPath/XQuery注入深度攻防专业技能:认证绕过、盲注高效提取(二分/字符集二分/位运算/超时外带/OAST)、任意节点读取完整攻击链、XPath 1.0/2.0/3.1差异、XQuery注入面(BaseX/eXist/MarkLogic)、XML安全联动(XXE/XInclude/XSLT RCE)、现代语言库差异(Python lxml/Java XPathFactory/PHP DOMXPath/.NET XPathNavigator)、WAF绕过、SAML/SSO认证滥用(XSW签名包装)、信息泄露→敏感数据提取攻击链(CVE-2026-53582/CVE-2026-44962)

    Ready to connect★ 116

    github.com/langbyyi/cyberstrikeai-src110 stars

    View details
  • pushbackSkillSecurity

    Use when reviewing a spec, PRD, requirements doc, or design plan before implementation begins — especially when the doc feels too big, bundles unrelated features, may contradict the current codebase, or seems vague, infeasible, or thin on security and error handling. Not for cross-checking a spec ag

    Ready to connect★ 115

    github.com/ovid/paad115 stars

    View details
  • abi-to-mcp-guideSkillSecurity

    Guide to UCAI (Universal Contract AI Interface) — the ABI-to-MCP server generator. Point it at any smart contract ABI and get a working MCP server. One command, any contract, Claude speaks it. Supports Uniswap, Aave, ERC20, NFTs, all EVM chains. Security scanner included.

    Ready to connect★ 114

    github.com/nirholas/three.ws110 stars

    View details
  • agenti-mcp-guideSkillSecurity

    Guide to Agenti — a universal MCP server for AI agents to interact with 20+ blockchains. 380+ tools for DeFi, DEX aggregation, security scanning, cross-chain bridges, QR payments. x402 enabled for autonomous agent-to-agent payments. Works with Claude, ChatGPT, Cursor, and any MCP-compatible client.

    Ready to connect★ 114

    github.com/nirholas/three.ws110 stars

    View details
  • bitquery-graphql-skillSkillSecurity

    Use Bitquery GraphQL through UXC for onchain trades, transfers, token holder analysis, balances, and market structure queries across supported networks, with OAuth client_credentials authentication and query-first execution.

    Ready to connect★ 114

    github.com/holon-run/uxc113 stars

    View details
  • chainlink-oracle-guideSkillSecurity

    How Chainlink oracle price feeds work — architecture, reading feeds on-chain, available pairs, the aggregator model, and oracle security. Covers how DeFi protocols (Aave, Sperax, Compound) rely on Chainlink for accurate pricing. Use when explaining oracles, price feeds, or DeFi infrastructure.

    Ready to connect★ 114

    github.com/nirholas/three.ws110 stars

    View details
  • cross-chain-bridge-guideSkillSecurity

    Guide to cross-chain bridges — bridge architectures, trust assumptions, security risks, major bridges comparison, and bridging best practices. Covers Stargate, Across, Hop, Wormhole, and official L2 bridges. Use when helping users move assets between chains safely.

    Ready to connect★ 114

    github.com/nirholas/three.ws110 stars

    View details

What is a skill?

A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.

54,764 of the 55,196 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.

Install one and every AI you use gets it

Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.

Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.

See how to connect your AI