Skills.

Give your AI a better way to work.

A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.

Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.

Category: Security

1,840 results · page 42 of 62

  • hardware-securitySkillSecurity

    Lets your agent guide hardware security research like finding UART/JTAG debug pads and analyzing firmware offline.

    Ready to connect★ 71

    github.com/brucesongs/kali-claw67 stars

    View details
  • hypervisor-introspectionSkillSecurity

    Hypervisor introspection (VMI) and virtualization escape attacks — VMware ESXi, Hyper-V, KVM/QEMU, Xen, Proxmox, VirtualBox, LibVMI, DRAKVUF, VENOM CVE-2015-3456, hardware-assisted VT-x/EPT/AMD-V

    Ready to connect★ 71

    github.com/brucesongs/kali-claw67 stars

    View details
  • insecure-designSkillSecurity

    Insecure Design (OWASP A06:2025) focuses on security flaws in system architecture and design phases, rather than code implementation-level bugs.

    Ready to connect★ 71

    github.com/brucesongs/kali-claw67 stars

    View details
  • macos-securitySkillSecurity

    macOS red team and security assessment — SIP/TCC bypass, Endpoint Security framework, Apple Silicon/T2/M-series attacks, Mach-O analysis, Keychain extraction, MDM bypass, LaunchAgents/Daemons persistence, and macOS-native malware analysis.

    Ready to connect★ 71

    github.com/brucesongs/kali-claw67 stars

    View details
  • malware-analysis-advancedSkillSecurity

    Advanced malware analysis covering unpacking (UPX, VMProtect, Themida, Enigma, custom packers), sandbox-evasion detection (anti-VM, anti-debug, anti-analysis), rootkit analysis (user-mode, kernel-mode, bootkits, UEFI), YARA rule authoring and optimization, and IDA Pro / Ghidra / Binary Ninja workflo

    Ready to connect★ 71

    github.com/brucesongs/kali-claw67 stars

    View details
  • mcp-server-patternsSkillSecurity

    Building and security-testing MCP (Model Context Protocol) servers for Kali Linux security tools.

    Ready to connect★ 71

    github.com/brucesongs/kali-claw67 stars

    View details
  • mobile-securitySkillSecurity

    Mobile security covers the complete attack/defense chain of Android/iOS application security testing, APK/IPA reverse engineering, runtime manipulation, certificate pinning bypass, and mobile data protection.

    Ready to connect★ 71

    github.com/brucesongs/kali-claw67 stars

    View details
  • network-pentestSkillSecurity

    Network penetration testing covering the full attack chain from reconnaissance, port scanning, and service fingerprinting through vulnerability assessment, exploitation, traffic sniffing, and MITM attacks.

    Ready to connect★ 71

    github.com/brucesongs/kali-claw67 stars

    View details
  • open-banking-attackSkillSecurity

    Open Banking / PSD2 / Open Finance attacks — FAPI (Financial-grade API), OpenID Connect for Financial APIs, OAuth2 PKCE, Strong Customer Authentication (SCA) bypass, AIS/PIS/CBPII API abuse, payment redirection, consent manipulation. Covers UK Open Banking, US FDX, Brazil Open Finance, India Account

    Ready to connect★ 71

    github.com/brucesongs/kali-claw67 stars

    View details
  • pam-privilege-attackSkillSecurity

    Privileged Access Management (PAM) vendor abuse — CyberArk PVWA/PSM/EPV/AIM/CFE, BeyondTrust PRA/Password Safe/Identity Security Insights, Delinea Secret Server/Privilege Manager, One Identity Safeguard, ManageEngine Password Manager Pro, WALLIX Bastion, Devolutions Server, Xton Core. Covers PVWA au

    Ready to connect★ 71

    github.com/brucesongs/kali-claw67 stars

    View details
  • patch-to-poc-pipelineSkillSecurity

    The end-to-end patch-diff vulnerability reproduction workflow — patch analysis (read diff, identify protective pattern, hypothesize bug class), source or binary-only code path walking (Ghidra + BinDiff), PoC generation (manual craft OR AFL++/libFuzzer harness with ASan/UBSan), CyberGym-style differe

    Ready to connect★ 71

    github.com/brucesongs/kali-claw67 stars

    View details
  • payment-securitySkillSecurity

    Payment systems security — PCI-DSS compliance testing, payment API security (Stripe/Adyen/PayPal), EMV chip/PIN, 3-D Secure, mobile wallets (Apple Pay/Google Pay), and fraud system assessment.

    Ready to connect★ 71

    github.com/brucesongs/kali-claw67 stars

    View details
  • pentest-reportingSkillSecurity

    Initialize Dradis for collaborative report authoring and Faraday for vulnerability correlation before testing begins.

    Ready to connect★ 71

    github.com/brucesongs/kali-claw67 stars

    View details
  • protocol-state-exploitationSkillSecurity

    Protocol state exploitation targets vulnerabilities in network protocol state machines including SSH/TLS/HTTP2/DNS, covering illegal state transitions, stateful fuzzing, and protocol-level race conditions.

    Ready to connect★ 71

    github.com/brucesongs/kali-claw67 stars

    View details
  • satellite-leo-securitySkillSecurity

    Satellite and LEO communication security — Starlink, Kuiper, OneWeb, Iridium, Inmarsat, Viasat KA-SAT, HughesNet, DVB-S/S2, VSAT (iDirect/Hughes), GNSS receiver attacks, AcidRain wiper (Viasat 2022)

    Ready to connect★ 71

    github.com/brucesongs/kali-claw67 stars

    View details
  • scada-ics-securitySkillSecurity

    SCADA/ICS security assessment covering industrial control system protocols including Modbus TCP, S7comm (Siemens), DNP3, EtherNet/IP (CIP), OPC UA, BACnet, and GOOSE.

    Ready to connect★ 71

    github.com/brucesongs/kali-claw67 stars

    View details
  • security-bounty-hunterSkillSecurity

    Hunt for exploitable, bounty-worthy security issues in target systems. Focuses on remotely reachable vulnerabilities that qualify for real reports and responsible disclosure, not broad best-practices reviews or theoretical findings.

    Ready to connect★ 71

    github.com/brucesongs/kali-claw67 stars

    View details
  • social-engineeringSkillSecurity

    Social engineering is the art of exploiting human psychological weaknesses rather than technical vulnerabilities to execute attacks. Attack vectors encompass Phishing, Pretexting, Baiting, Tailgating, Vishing, and other techniques.

    Ready to connect★ 71

    github.com/brucesongs/kali-claw67 stars

    View details
  • terminal-opsSkillSecurity

    Evidence-first execution workflow for running security commands, inspecting system state, debugging tool failures, and making verified changes. This skill enforces a disciplined approach: inspect before acting, keep changes narrow, and report exact execution state.

    Ready to connect★ 71

    github.com/brucesongs/kali-claw67 stars

    View details
  • tool-masterySkillSecurity

    Verification and assessment of practical proficiency with Kali Linux security tools. Covers tool classification, proficiency levels, verification methods, and combination strategies across the 518-tool Kali arsenal.

    Ready to connect★ 71

    github.com/brucesongs/kali-claw67 stars

    View details
  • uav-drone-securitySkillSecurity

    UAV/drone security testing — PX4/ArduPilot autopilot attacks, MAVLink protocol fuzzing, RF link hijacking (2.4GHz control / 5.8GHz video), GPS spoofing/jamming, DroneSploit framework, DJI hardware reversing, and counter-UAS methodologies.

    Ready to connect★ 71

    github.com/brucesongs/kali-claw67 stars

    View details
  • vpn-attackSkillSecurity

    Virtual Private Networks (VPNs) are a critical component of enterprise network security, providing encrypted tunnels for remote access and site-to-site connectivity.

    Ready to connect★ 71

    github.com/brucesongs/kali-claw67 stars

    View details
  • web-auth-bypassSkillSecurity

    Authentication Bypass refers to attackers exploiting design flaws or implementation vulnerabilities in authentication mechanisms to bypass the normal authentication process and gain unauthorized access.

    Ready to connect★ 71

    github.com/brucesongs/kali-claw67 stars

    View details
  • web-deserializationSkillSecurity

    Deserialization vulnerabilities arise when an application reconstructs objects from byte streams (Java), serialized strings (PHP), Base64 blobs (.NET), or pickle data (Python) supplied by the client.

    Ready to connect★ 71

    github.com/brucesongs/kali-claw67 stars

    View details
  • wifi-pentestSkillSecurity

    WiFi security assessment skills: covering wireless network reconnaissance, WPA/WPA2 handshake capture and offline cracking, WPS PIN brute forcing, Evil Twin attacks, wireless sniffing, and deauthentication attacks.

    Ready to connect★ 71

    github.com/brucesongs/kali-claw67 stars

    View details
  • abusing-shadow-credentials-for-privescSkillSecurity

    Take over Active Directory accounts by writing attacker-controlled public keys to msDS-KeyCredentialLink (Shadow Credentials) with pyWhisker, Whisker, or Certipy, then authenticate via PKINIT to recover the target's NT hash without a password reset. Use when BloodHound shows GenericWrite/GenericAll/

    Ready to connect★ 70

    github.com/costrict-plugins-repo/mukul975-anthropic-cybersecurity-skills-cybersecurity-skills67 stars

    View details
  • attacking-oauth-with-device-code-phishingSkillSecurity

    Run OAuth 2.0 device-code and illicit-consent phishing attacks against

    Ready to connect★ 70

    github.com/costrict-plugins-repo/mukul975-anthropic-cybersecurity-skills-cybersecurity-skills67 stars

    View details
  • auditing-entra-id-with-aadinternalsSkillSecurity

    Drive the AADInternals PowerShell toolkit to perform Microsoft Entra ID tenant reconnaissance, access-token acquisition across Microsoft APIs, and federation/AD FS backdoor testing (Golden SAML, T1606.002) for defensive validation. Use during an authorized Entra ID/Microsoft 365 red-team assessment

    Ready to connect★ 70

    github.com/costrict-plugins-repo/mukul975-anthropic-cybersecurity-skills-cybersecurity-skills67 stars

    View details
  • building-c2-redirector-infrastructureSkillSecurity

    Build dumb-pipe and traffic-filtering C2 redirectors with nginx (proxy_pass) and Apache (mod_rewrite), deriving filter rules from a Malleable C2 profile, layering Let's Encrypt TLS, and applying OPSEC controls like domain fronting and UA/geo filtering. Use when standing up red-team C2 that must surv

    Ready to connect★ 70

    github.com/costrict-plugins-repo/mukul975-anthropic-cybersecurity-skills-cybersecurity-skills67 stars

    View details
  • cloud-identity-and-authSkillSecurity

    Identity, authentication, authorization, and token management for cloud platforms. Covers Keystone-style scoped tokens, OAuth 2.0 flows, OpenID Connect, JWT structure and pitfalls, federation with SAML/OIDC, service-to-service auth with mTLS and SPIFFE, principle of least privilege, IAM role design,

    Ready to connect★ 70

    github.com/tibsfox/gsd-skill-creator70 stars

    View details

What is a skill?

A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.

54,764 of the 55,196 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.

Install one and every AI you use gets it

Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.

Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.

See how to connect your AI