Skills.

Give your AI a better way to work.

A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.

Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.

Category: Security

1,840 results · page 39 of 62

  • anthropic-cybersecurity-skills-agent-librarySkillSecurity

    Trending Claude Code skills

    Ready to connect★ 78

    github.com/aradotso/trending-skills75 stars

    View details
  • autoteam-f-chatgpt-team-rotationSkillSecurity

    AutoTeam-F is a ChatGPT Team account rotation and authentication sync tool with batch free account generation, OAuth management, and a Web dashboard.

    Ready to connect★ 78

    github.com/aradotso/trending-skills75 stars

    View details
  • bluehammer-vulnerability-pocSkillSecurity

    Skill for working with the BlueHammer vulnerability proof-of-concept repository, covering build, usage, and code patterns.

    Ready to connect★ 78

    github.com/aradotso/trending-skills75 stars

    View details
  • cairn-ai-pentestSkillSecurity

    AI-automated penetration testing and general problem-solving system that achieved unique AK (All Killed) in Tencent Cloud Hackathon intelligent penetration challenge

    Ready to connect★ 78

    github.com/aradotso/trending-skills75 stars

    View details
  • codex-oauth-automation-extensionSkillSecurity

    Chrome extension for automating OpenAI OAuth registration flows with captcha retrieval, CPA callback verification, and auto-recovery across multiple rounds

    Ready to connect★ 78

    github.com/aradotso/trending-skills75 stars

    View details
  • copyfail-go-lpeSkillSecurity

    Go implementation of CVE-2026-31431 (CopyFail), a Linux local privilege escalation exploit targeting the AF_ALG iov_iter kernel vulnerability affecting kernels v4.14–April 2026.

    Ready to connect★ 78

    github.com/aradotso/trending-skills75 stars

    View details
  • crabtrap-llm-proxySkillSecurity

    LLM-as-a-judge HTTP/HTTPS proxy that secures AI agents by intercepting and evaluating outbound requests against security policies before they reach external APIs.

    Ready to connect★ 78

    github.com/aradotso/trending-skills75 stars

    View details
  • instance-securitySkillSecurity

    Harden a ServiceNow instance — password complexity, session timeout, MFA enforcement, input sanitization for XSS/injection, security properties, syslog events, and security health checks.

    Ready to connect★ 78

    github.com/serac-labs/serac78 stars

    View details
  • legal-strategySkillSecurity

    Analyze legal and regulatory risk, IP, contracts, privacy, governance, and employment questions as structured issue-spotting for counsel. Do not use this methodology as legal advice or for technical security implementation, CRM, or delivery execution.

    Ready to connect★ 78

    github.com/magnus919/agent-skills78 stars

    View details
  • lightfriend-add-integrationSkillSecurity

    Step-by-step guide for adding new OAuth integrations to Lightfriend

    Ready to connect★ 78

    github.com/ahtavarasmus/lightfriend78 stars

    View details
  • pier-cloudSkillSecurity

    This skill should be used when the user needs to consume the Pier Cloud (Lighthouse) API for cloud cost management — including JWT authentication, listing contexts, workspaces, and FinOps data views. Trigger whenever there is a need to integrate, automate, or debug calls to the Pier Cloud platform v

    Ready to connect★ 78

    github.com/fabricioctelles/skills78 stars

    View details
  • secure-software-engineeringSkillSecurity

    Use when designing or implementing software securely: define security requirements, threat-model a feature, choose secure defaults, design authentication and authorization, handle untrusted data and secrets, evaluate dependencies, design multi-tenant trust boundaries, or review security-sensitive ch

    Ready to connect★ 78

    github.com/magnus919/agent-skills78 stars

    View details
  • security-audit-methodologySkillSecurity

    Plan authorized security reviews with threat modeling, architecture and dependency audits, and vulnerability classification. Use for scoped defensive security assessment. Do not use for offensive operations, unauthorized testing, or security control implementation.

    Ready to connect★ 78

    github.com/magnus919/agent-skills78 stars

    View details
  • security-specialistSkillSecurity

    Runs security audits on codebases — full scans, diff reviews, threat models, vulnerability triage, remediation guidance, and finding tracking. Activate when the user says "security scan", "audit this repo", "review this PR for security", "threat model", "triage vulnerabilities", "fix this vuln", or

    Ready to connect★ 78

    github.com/fabricioctelles/skills78 stars

    View details
  • update-set-workflowSkillSecurity

    Manage ServiceNow update sets — create named sets before any development, ensure auto_switch tracks API changes under the OAuth service account, complete on done, and export for promotion. Mandatory for all change-producing work.

    Ready to connect★ 78

    github.com/serac-labs/serac78 stars

    View details
  • authz-securitySkillSecurity

    Review application source code for broken authorization — IDOR / Broken Object Level Authorization (OWASP API1), Broken Function Level Authorization (API5), mass assignment (API3), multi-tenant isolation gaps, and privilege escalation. Reads routes, controllers, resolvers, and data models offline an

    Ready to connect★ 77

    github.com/superagent-ai/skills76 stars

    View details
  • breachSkillSecurity

    Designing red team attack scenarios, threat models, MITRE ATT&CK/OWASP application, Purple Team exercises, and AI/LLM red teaming. Use when adversarial security validation is needed.

    Ready to connect★ 77

    github.com/simota/agent-skills77 stars

    View details
  • cullSkillSecurity

    Scanning and eradicating supply-chain malware (Shai-Hulud/S1ngularity npm/PyPI worms): IoC scan, OS/IDE persistence, safe credential rotation. Not for SAST (Sentinel) or skill/MCP audit (Chain).

    Ready to connect★ 77

    github.com/simota/agent-skills77 stars

    View details
  • hackerSkillSecurity

    Cursor-native offensive security engagement and exploitability autoresearch orchestrator inspired by offensive-claude. Use for an authorized offensive engagement, red-team or pentest workflow, Kill Chain style assessment, scoped web/network/cloud/mobile/AD/bug-bounty offensive plan, or exploitabilit

    Ready to connect★ 77

    github.com/superagent-ai/skills76 stars

    View details
  • pipeSkillSecurity

    Designing GitHub Actions workflows in depth: trigger strategy, security hardening, performance optimization, PR automation, and Reusable Workflow design.

    Ready to connect★ 77

    github.com/simota/agent-skills77 stars

    View details
  • pr-github-opsSkillSecurity

    Post Superagent PR security scan findings as inline GitHub pull request review comments using the authenticated gh CLI. Use whenever you need to comment on a PR scan finding, manage Superagent PR labels, complete a GitHub check run, or avoid posting findings as general PR thread comments. Trigger fo

    Ready to connect★ 77

    github.com/superagent-ai/skills76 stars

    View details
  • probeSkillSecurity

    Integrating OWASP ZAP/Burp Suite/Nuclei, planning penetration tests, executing DAST, and scanning for vulnerabilities. For runtime vulnerability validation. Complements Sentinel static analysis.

    Ready to connect★ 77

    github.com/simota/agent-skills77 stars

    View details
  • recon-securitySkillSecurity

    Guide authorized external penetration testing from recon through validation and scoped exploitation using free and open-source tools. Use for domain/IP attack surface mapping, subdomain discovery, nmap/httpx/nuclei/ffuf workflows, web app testing, SIP/NAS checks, Burp/ZAP validation, PoC documentati

    Ready to connect★ 77

    github.com/superagent-ai/skills76 stars

    View details
  • repo-security-postureSkillSecurity

    Audit a GitHub repository's security posture and hardening gaps across branch protection, CODEOWNERS, GitHub Actions, publish/release integrity, collaborator access, security features, and dependency review. Use when reviewing or hardening a repo, assessing GitHub configuration, checking CI/CD or Ac

    Ready to connect★ 77

    github.com/superagent-ai/skills76 stars

    View details
  • security-disclosure-triageSkillSecurity

    Verify whether an incoming security advisory is a real, disclosable vulnerability in a target repository checkout, and assign an honest severity. Use when triaging an advisory, GHSA, scanner finding, or draft report from the researcher/reporter side to decide if it is worth disclosing. Optimizes aga

    Ready to connect★ 77

    github.com/superagent-ai/skills76 stars

    View details
  • specialist-reviewSkillSecurity

    Conducts a focused review from ONE specific specialist's perspective (e.g., Security Specialist, Performance Expert). Use when the user requests "Ask [specialist role] to review [target]", "Get [specialist]'s opinion on [topic]", "Have [role] review [code/component]", or when they want deep expertis

    Ready to connect★ 77

    github.com/codenamev/ai-software-architect77 stars

    View details
  • superagentSkillSecurity

    Set up Superagent Context Guardrails at coding-agent tool boundaries, configure and safely use the remote MCP server, and manage signed webhooks for findings, security reports, Contributor Trust, and Runtime Guardrails. Use when the user asks to enable context scanning before an agent consumes URLs,

    Ready to connect★ 77

    github.com/superagent-ai/skills76 stars

    View details
  • vigilSkillSecurity

    Engineering detection rules (Sigma/YARA), detection coverage mapping, threat hunting hypotheses, Purple Team Blue side, Detection-as-Code CI/CD. Use when defensive verification is needed.

    Ready to connect★ 77

    github.com/simota/agent-skills77 stars

    View details
  • vulnerability-triageSkillSecurity

    Triage inbound vulnerability reports - GitHub Advisories (GHSA/CVE), bug bounty submissions, HackerOne/Bugcrowd/Intigriti exports, or a researcher's issue - to decide whether a finding is real, by-design, or noise. Reads the report offline, cross-references the project's documented intent and threat

    Ready to connect★ 77

    github.com/superagent-ai/skills76 stars

    View details
  • zenSkillSecurity

    Refactoring code: variable naming, function extraction, magic number constants, dead code removal. Does not change behavior. Not for bugs/security (Judge), tests (Radar), or features (Builder).

    Ready to connect★ 77

    github.com/simota/agent-skills77 stars

    View details

What is a skill?

A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.

54,764 of the 55,196 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.

Install one and every AI you use gets it

Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.

Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.

See how to connect your AI