Skills.
Give your AI a better way to work.
A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.
Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.
Category: Security
1,738 results · page 5 of 58
- View details
a2a-protocolSkillSecurity
Lets your agent discover, authenticate with, and delegate work to other agents over the A2A protocol.
Ready to connect★ 5k
- View details
authenticationSkillSecurity
Guides your agent through adding login, signup, organizations, and session handling to agent-native apps.
Ready to connect★ 5k
- View details
onboardingSkillSecurity
Guides your agent to add user setup steps (API keys, OAuth, service connections) to an app's setup checklist.
Ready to connect★ 5k
- View details
secretsSkillSecurity
Lets your agent register API keys and service credentials so they appear in settings and onboarding checklists.
Ready to connect★ 5k
- View details
contrib-pr-reviewSkillSecurity
Lets your agent review a contribution pull request for security, tests, size, and intent.
Ready to connect★ 5k
- View details
fallowSkillSecurity
Lets your agent analyze a TypeScript or JavaScript codebase for risk, duplication, complexity, and cleanup opportunities.
Ready to connect★ 4k
- View details
bug-bountySkillSecurity
Guides your agent through bug bounty hunting: recon, learning from disclosed reports, and finding vulnerabilities.
Ready to connect★ 4k
- View details
enterprise-vpn-attackSkillSecurity
Gives your agent a reference of known attack techniques and CVEs for enterprise VPN appliances like Cisco ASA and FortiGate.
Ready to connect★ 4k
- View details
hunt-api-misconfigSkillSecurity
Lets your agent test APIs for security flaws like privilege escalation via mass assignment and JWT forgery.
Ready to connect★ 4k
- View details
hunt-auth-bypassSkillSecurity
Lets your agent hunt for authentication bypass vulnerabilities using techniques from real bug bounty reports.
Ready to connect★ 4k
- View details
hunt-business-logicSkillSecurity
Guides your agent to find business logic flaws like coupon stacking and price tampering in web apps.
Ready to connect★ 4k
- View details
hunt-clickjackingSkillSecurity
Lets your agent check web pages for missing clickjacking protections that could let attackers trick users into hidden clicks.
Ready to connect★ 4k
- View details
hunt-csrfSkillSecurity
Lets your agent hunt for CSRF vulnerabilities using patterns from public bug bounty reports.
Ready to connect★ 4k
- View details
hunt-fintech-graphqlSkillSecurity
Lets your agent hunt fintech GraphQL vulnerabilities like transfer mutations, IDOR queries, and double-spend bugs.
Ready to connect★ 4k
- View details
hunt-graphqlSkillSecurity
Lets your agent hunt for GraphQL vulnerabilities like IDOR, SSRF, and auth bypass using patterns from real bug bounty reports.
Ready to connect★ 4k
- View details
hunt-host-headerSkillSecurity
Lets your agent test websites for host header attacks like password reset poisoning and cache poisoning.
Ready to connect★ 4k
- View details
hunt-html-injectionSkillSecurity
Guides your agent to find HTML injection flaws where user input is rendered as raw HTML in web responses.
Ready to connect★ 4k
- View details
hunt-idorSkillSecurity
Guides your agent through testing websites for IDOR access-control bugs using patterns from real bug bounty reports.
Ready to connect★ 4k
- View details
hunt-jwt-cryptoSkillSecurity
Lets your agent find JWT authentication flaws that let attackers forge tokens for any identity.
Ready to connect★ 4k
- View details
hunt-laravelSkillSecurity
Lets your agent scan Laravel apps for common vulnerabilities like debug mode leaks and known exploits.
Ready to connect★ 4k
- View details
hunt-miscSkillSecurity
Guides your agent through hunting miscellaneous vulnerabilities using patterns from 225 public bug bounty reports.
Ready to connect★ 4k
- View details
hunt-nextjsSkillSecurity
Lets your agent scan a Next.js app for known vulnerabilities like auth bypass, cache poisoning, and SSRF.
Ready to connect★ 4k
- View details
hunt-oauthSkillSecurity
Lets your agent hunt for OAuth login vulnerabilities using lessons from 19 public bug bounty reports.
Ready to connect★ 4k
- View details
hunt-open-redirectSkillSecurity
Lets your agent find open redirect vulnerabilities in web apps, including chains leading to account takeover.
Ready to connect★ 4k
- View details
hunt-race-conditionSkillSecurity
Guides your agent to find and test race condition bugs in web apps using techniques from real bug bounty reports.
Ready to connect★ 4k
- View details
hunt-rceSkillSecurity
Guides your agent through finding remote code execution vulnerabilities using patterns from 67 public bug bounty reports.
Ready to connect★ 4k
- View details
hunt-sharepointSkillSecurity
Lets your agent scan on-prem SharePoint servers for known vulnerabilities and exposed login endpoints.
Ready to connect★ 4k
- View details
hunt-springbootSkillSecurity
Lets your agent scan Spring Boot apps for known vulnerabilities like exposed actuator endpoints and remote code execution flaws.
Ready to connect★ 4k
- View details
ios-redteam-pipelineSkillSecurity
Lets your agent run iOS app security tests, from pulling app packages to analyzing code and extracting stored secrets.
Ready to connect★ 4k
- View details
meme-coin-auditSkillSecurity
Lets your agent analyze meme coins and tokens for scams like honeypots, hidden minting, and liquidity risks.
Ready to connect★ 4k
What is a skill?
A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.
52,524 of the 52,958 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.
Install one and every AI you use gets it
Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.
Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.