Skills.
Give your AI a better way to work.
A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.
Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.
Category: Security
1,840 results · page 41 of 62
- View details
agent-reachSkillSecurity
Load when a task needs read-only internet research or content retrieval through an already installed Agent Reach CLI; diagnose available backends first, never install, upgrade, authenticate, configure, or copy credentials on the user's behalf.
Ready to connect★ 72
- View details
clerk-androidSkillSecurity
Implement Clerk authentication for native Android apps using Kotlin and
Ready to connect★ 72
- View details
clerk-expoSkillSecurity
Add Clerk authentication to Expo and React Native apps using @clerk/expo.
Ready to connect★ 72
- View details
clerk-swiftSkillSecurity
Implement Clerk authentication for native Swift and iOS apps using ClerkKit
Ready to connect★ 72
- View details
config-hardenerSkillSecurity
Audit and harden your OpenClaw configuration. Checks AGENTS.md, gateway settings, sandbox config, and permission
Ready to connect★ 72
- View details
credential-scannerSkillSecurity
Scan your project for exposed credentials, API keys, and secrets before running OpenClaw skills. Prevents accidental
Ready to connect★ 72
- View details
dotnet-jwt-authenticationSkillSecurity
Configures JWT Bearer authentication for .NET APIs. Includes token generation, validation, refresh tokens, and user context extraction from claims.
Ready to connect★ 72
- View details
output-sanitizerSkillSecurity
Sanitize OpenClaw agent output before display. Strips leaked credentials, PII, internal paths, and sensitive
Ready to connect★ 72
- View details
permission-auditorSkillSecurity
Analyze OpenClaw skill permissions and explain exactly what each permission allows. Identifies over-privileged
Ready to connect★ 72
- View details
prompt-guardSkillSecurity
Detect and neutralize prompt injection attacks in OpenClaw skill content, user inputs, and external data sources.
Ready to connect★ 72
- View details
setup-auditorSkillSecurity
'Audit your OpenClaw environment for credential leaks, unsafe defaults, and missing sandbox configuration. Wizard-style:
Ready to connect★ 72
- View details
skill-auditorSkillSecurity
Comprehensive security auditor for OpenClaw skills. Checks for typosquatting, dangerous permissions, prompt injection,
Ready to connect★ 72
- View details
5g-6g-telecom-attack-advancedSkillSecurity
Advanced 5G/6G telecom attacks covering 5G Core (SBA) exploitation, IMSI catcher evolution (5G Stingray), SIP/Diameter protocol attacks, Open RAN vulnerabilities, network slicing abuse, and early 6G research vectors (THz comms, AI-native air interface).
Ready to connect★ 71
- View details
ad-cs-abuseSkillSecurity
Active Directory Certificate Services (AD CS) abuse — ESC1-ESC15 attack patterns, PKINIT, PetitPotam to AD CS to Domain Admin chains, CVE-2022-26923 (Certifried), Shadow Credentials, Golden Certificate, certificate template ACL abuse, NTLM relay to web enrollment.
Ready to connect★ 71
- View details
agentic-pentestSkillSecurity
LLM-driven autonomous penetration testing framework operations covering PentestGPT, HexStrike AI, Viper, PentestAgent, AI-Infra-Guard, AutoPWN, and custom agent harness patterns — including reasoning chain orchestration, tool delegation, context window management, output validation, multi-agent pent
Ready to connect★ 71
- View details
ai-agent-supply-chain-attackSkillSecurity
AI/ML supply chain attacks — model poisoning, Pickle RCE, Hugging Face / Ollama registry compromise, LangChain plugin backdoors, OpenClaw / ClawHub ecosystem threats. Distinguishes from ci-cd-supply-chain-attack by focusing on model weights, training data, and serialization formats. Anchored by the
Ready to connect★ 71
- View details
ai-fuzzingSkillSecurity
AI-assisted fuzzing for automated vulnerability discovery. Coverage-guided fuzzing engines, AI-driven seed generation, intelligent mutation strategies, and systematic crash triage.
Ready to connect★ 71
- View details
automotive-vehicle-securitySkillSecurity
CAN/CAN-FD bus analysis, UDS diagnostics, IVI pentest, OBD-II exploitation, key fob replay/relay attacks, GNSS spoofing, EV charging station (ISO 15118), and connected vehicle red team operations.
Ready to connect★ 71
- View details
binary-reverseSkillSecurity
Binary reverse engineering covers the complete chain from static analysis, dynamic debugging, to vulnerability discovery, exploit development, and malware analysis.
Ready to connect★ 71
- View details
blue-reconSkillSecurity
Audit existing security controls and detection coverage — find gaps against MITRE ATT&CK. Use when asked to "audit our detection coverage", "where are our security control gaps", or "check our MITRE coverage".
Ready to connect★ 71
- View details
chain-reconSkillSecurity
Audit existing dependency security — find unscanned packages, license violations, and SBOM gaps. Use when asked to "audit our dependencies", "do we have an SBOM", or "find license violations".
Ready to connect★ 71
- View details
chain-scanSkillSecurity
Design a dependency scanning program — CVE detection, license checks, and CI gates. Use when asked to "scan our dependencies", "set up CVE detection", or "add a dependency CI gate".
Ready to connect★ 71
- View details
ci-cd-supply-chain-attackSkillSecurity
CI/CD pipeline and software supply chain compromise covering Jenkins (script console, Jenkinsfile injection, shared library abuse, CVE-2024-23897 args4j), GitLab CI/CD (runner abuse, .gitlab-ci.yml injection, self-hosted runner takeover, CVE-2022-1162, OmniAuth CVE-2024-9653), GitHub Actions (self-h
Ready to connect★ 71
- View details
cloud-native-vuln-researchSkillSecurity
CVE research methodology, PoC reproduction, patch gap analysis, and exploit chain composition across container/k8s/cloud-native surfaces; SBOM-driven vuln management and nuclei template authoring.
Ready to connect★ 71
- View details
cms-framework-attackSkillSecurity
Targeted security assessment of Content Management Systems (WordPress, Joomla, Drupal) using specialized scanners and exploit techniques.
Ready to connect★ 71
- View details
codebase-onboardingSkillSecurity
Rapidly acquire a mental model of any unfamiliar codebase — from a 500-line script to a 100M+ line monorepo. This skill transforms raw code into structured intelligence: architecture maps, entry points, data flows, security surfaces, and onboarding confidence scores.
Ready to connect★ 71
- View details
concurrency-exploitationSkillSecurity
Concurrency exploitation covers race condition vulnerabilities including TOCTOU, signal handler races, thread synchronization bypasses, and timing attacks.
Ready to connect★ 71
- View details
cps-attackSkillSecurity
Cyber-Physical Systems (CPS) attacks — PLCs (Siemens S7, Rockwell ControlLogix, Schneider Modicon, Mitsubishi MELSEC), ICS protocols (Modbus, DNP3, Profinet, EtherNet/IP, IEC 61850, OPC UA), HMIs, SCADA historians, OT-to-IT pivot, SIS bypass. Distinct from scada-ics-security (broader ICS overview) —
Ready to connect★ 71
- View details
exploit-developmentSkillSecurity
Exploit development covers the full chain from vulnerability discovery through crash analysis to working exploit code, spanning buffer overflows, ROP chains, format string bugs, and shellcode injection across x86 and ARM architectures.
Ready to connect★ 71
- View details
gitops-securitySkillSecurity
Attacks against GitOps control planes (Argo CD, FluxCD, Jenkins X, Tekton, Fleet, Rancher) — repo impersonation, manifest tampering, RBAC bypass, sync-wave abuse, secret management compromise (Sealed Secrets / SOPS / External Secrets / Vault), cluster privilege escalation via Application/CRDs, and p
Ready to connect★ 71
What is a skill?
A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.
54,764 of the 55,196 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.
Install one and every AI you use gets it
Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.
Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.