Skills.

Give your AI a better way to work.

A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.

Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.

Category: Security

1,833 results · page 48 of 62

  • building-vulnerability-exception-tracking-systemSkillSecurity

    Build a vulnerability exception and risk acceptance tracking system with

    Ready to connect★ 56

    github.com/26zl/cybersec-toolkit56 stars

    View details
  • building-vulnerability-scanning-workflowSkillSecurity

    'Builds a structured vulnerability scanning workflow using tools like

    Ready to connect★ 56

    github.com/26zl/cybersec-toolkit56 stars

    View details
  • bypassing-authentication-with-forced-browsingSkillSecurity

    Discovering and accessing unprotected pages, APIs, and administrative

    Ready to connect★ 56

    github.com/26zl/cybersec-toolkit56 stars

    View details
  • collecting-open-source-intelligenceSkillSecurity

    'Collects and synthesizes open-source intelligence (OSINT) about threat

    Ready to connect★ 56

    github.com/26zl/cybersec-toolkit56 stars

    View details
  • conducting-api-security-testingSkillSecurity

    'Conducts security testing of REST, GraphQL, and gRPC APIs to identify

    Ready to connect★ 56

    github.com/26zl/cybersec-toolkit56 stars

    View details
  • conducting-internal-network-penetration-testSkillSecurity

    Execute an internal network penetration test simulating an insider threat

    Ready to connect★ 56

    github.com/26zl/cybersec-toolkit56 stars

    View details
  • CrowdStrike Fusion Workflow BuilderSkillSecurity

    Create, validate, import, execute, and export CrowdStrike Falcon Fusion SOAR workflows. CRITICAL: You MUST run action_search.py to get real 32-char hex action IDs BEFORE writing any YAML. NEVER write PLACEHOLDER values for action IDs — resolve every ID via the live API first. Templates and example f

    Ready to connect★ 56

    github.com/eth0izzle/security-skills56 stars

    View details
  • javaSkillSecurity

    Modern Java practices: design, errors, concurrency, security, testing, tooling. Targets Java 21 LTS baseline; Java 25 LTS features called out explicitly. Use when writing or reviewing Java code.

    Ready to connect★ 56

    github.com/sumonmselim/agentguard56 stars

    View details
  • mobile-pro-maxSkillSecurity

    Mobile development intelligence. 12 domains, 9 stacks, 250+ entries. Actions: plan, build, create, design, implement, review, fix, improve, optimize, enhance, refactor, check mobile code. Domains: pattern, package, error, perf, test, security, interface, arch, idiom, anti, tooling, dependency. Stack

    Ready to connect★ 55

    github.com/vurakit/agentup56 stars

    View details
  • phpSkillSecurity

    Modern PHP 8.5 practices: type system, OOP, security, architecture, async, testing, tooling. Use when writing or reviewing PHP code.

    Ready to connect★ 56

    github.com/sumonmselim/agentguard56 stars

    View details
  • php-pro-maxSkillSecurity

    PHP development intelligence. 12 domains, 8 stacks, 300+ entries. Actions: plan, build, create, design, implement, review, fix, improve, optimize, enhance, refactor, check PHP code. Domains: pattern, package, error, perf, test, security, interface, arch, idiom, anti, tooling, dependency. Stacks: lar

    Ready to connect★ 55

    github.com/vurakit/agentup56 stars

    View details
  • security-warnSkillSecurity

    Use when you need to test a skill that produces a security warning (not block).

    Ready to connect★ 56

    github.com/8ddiehu0314/skill-lab56 stars

    View details
  • ai-verifySkillSecurity

    Use when work has to be verified — "verify the feature", "did we build what was asked", "review this diff", "is it ready to commit" — by choosing the right verification tier (standalone, embedded, or chain) and producing verdicts with evidence, not impressions. Not for milestone-declared security au

    Ready to connect★ 55

    github.com/arcasilesgroup/ai-engineering55 stars

    View details
  • conjoint-diagnosticsSkillSecurity

    Reviews an existing conjoint study for threats to inference and returns prioritized findings across five areas — design integrity (attributes, profile restrictions, task count and satisficing, randomization, power), estimation (estimand clarity, reference levels, subgroups, clustered standard errors

    Ready to connect★ 55

    github.com/scdenney/open-science-skills55 stars

    View details
  • full-reviewSkillSecurity

    Run every review skill at once — build-check, then design-check, code-audit, security-audit, a11y-audit and perf-audit fanned out across parallel agents — and merge them into one deduplicated, severity-ranked report. Use when asked for a full/complete review, to review everything before shipping or

    Ready to connect★ 55

    github.com/arcasilesgroup/ai-engineering55 stars

    View details
  • review-routerSkillSecurity

    Decide which review lanes a change actually needs, then run exactly those — instead of spawning the whole chain at every diff size. Reads the diff's shape and blast radius, maps the evidence to lanes (code, security, a11y, perf, design, build), estimates the cost, shows the routing decision, and exe

    Ready to connect★ 55

    github.com/arcasilesgroup/ai-engineering55 stars

    View details
  • secretSkillSecurity

    Lets your agent track tasks on a shared board you can reach from desktop, mobile, browser, or API.

    Ready to connect★ 55

    github.com/the-agency-ai/the-agency55 stars

    View details
  • agile-v-adrSkillSecurity

    Authoring, approval, immutability, and supersession of Architecture Decision Records (ADRs) in the Agile V lifecycle. Load when recording a significant, long-lived architectural, platform, tooling, or security decision.

    Ready to connect★ 54

    github.com/agile-v/agile_v_skills54 stars

    View details
  • agile-v-complianceSkillSecurity

    Risk management, CAPA protocol, human gate approval records, AI agent security controls, and periodic revalidation. Load when running gates, handling CAPAs, or auditing compliance and security posture.

    Ready to connect★ 54

    github.com/agile-v/agile_v_skills54 stars

    View details
  • build-agent-nestjsSkillSecurity

    NestJS backend build agent for REST/GraphQL APIs, microservices, and enterprise backends. Extends build-agent with NestJS architectural patterns, dependency injection, testing strategies, and security best practices. Use when building NestJS applications.

    Ready to connect★ 54

    github.com/agile-v/agile_v_skills54 stars

    View details
  • c-security-reviewSkillSecurity

    Use when the user requests a userspace C or C++ security review with an explicit threat model, severity filter, and model. Runs a partitioned read-only audit and writes report, SARIF, and findings to a .c-review-results run directory. Not for kernel drivers, managed languages, or embedded code.

    Ready to connect★ 54

    github.com/outlinedriven/outline-driven-development54 stars

    View details
  • chain-vulnerability-scannerSkillSecurity

    Use when a supported Algorand, Cairo, Cosmos SDK, Solana, Substrate, or TON codebase needs chain-specific vulnerability scanning. Returns reachability-backed findings routed to the matching ecosystem reference. Not for generic non-chain security review — route that to security-review.

    Ready to connect★ 54

    github.com/outlinedriven/outline-driven-development54 stars

    View details
  • confirmed-security-reviewSkillSecurity

    Use when the user asks for a security review, vulnerability audit, or review of injection, XSS, auth, or crypto. Returns only HIGH-confidence vulnerabilities with attacker-controlled input confirmed, or a cleared report. Not for CodeQL analysis — use codeql-security-analysis.

    Ready to connect★ 54

    github.com/outlinedriven/outline-driven-development54 stars

    View details
  • edgeone-clawscan-zhSkillSecurity

    A comprehensive OpenClaw security scanning skill powered by Tencent Zhuque Lab's A.I.G (AI-Infra-Guard). Use when the user asks for a security checkup or security scan of the current OpenClaw environment, e.g. `开始安全体检`, `做一次安全体检`, `开始安全扫描`, `全面安全检查`, or `检查 OpenClaw 安全`; also use when the user asks

    Ready to connect★ 54

    github.com/l-lesteryu/openclaw-hot-skills-zh53 stars

    View details
  • gke-service-networkingSkillSecurity

    Configures GKE edge networking, traffic routing, load balancing, and private service endpoints. Use when configuring Gateway API manifests, standard Ingress, Cloud Armor WAF security policies, Container-Native Load Balancing (NEGs), Private Service Connect (PSC), or Google-managed SSL certificates o

    Ready to connect★ 54

    github.com/gke-labs/kube-agents53 stars

    View details
  • gke-workload-securitySkillSecurity

    Workflows for auditing and hardening the security of GKE workloads.

    Ready to connect★ 54

    github.com/gke-labs/kube-agents53 stars

    View details
  • mcporterSkillSecurity

    Use the mcporter CLI to list, configure, authenticate, and call MCP servers/tools (HTTP or stdio), including ephemeral servers, config editing, and CLI/type generation.

    Ready to connect★ 54

    github.com/l-lesteryu/openclaw-hot-skills-zh53 stars

    View details
  • moltguardSkillSecurity

    Open-source OpenClaw security plugin: local prompt sanitization + injection detection. Full source code at github.com/openguardrails/moltguard

    Ready to connect★ 54

    github.com/l-lesteryu/openclaw-hot-skills-zh53 stars

    View details
  • owasp-api-securitySkillSecurity

    OWASP API Security Top 10 testing patterns, injection payloads, auth bypass vectors, and security test generation for the actual-mcp-server MCP API. Use when writing security tests, reviewing tools or HTTP endpoints for vulnerabilities, or auditing input validation and authorization.

    Ready to connect★ 54

    github.com/agigante80/actual-mcp-server48 stars

    View details
  • review-security-k8s-agents-prompt-injectionSkillSecurity

    Reviews AI agent architectures (API gateways, WAFs, input sanitization) for prompt injection risks.

    Ready to connect★ 54

    github.com/gke-labs/kube-agents53 stars

    View details

What is a skill?

A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.

55,111 of the 55,543 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.

Install one and every AI you use gets it

Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.

Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.

See how to connect your AI