Skills.
Give your AI a better way to work.
A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.
Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.
Category: Security
1,833 results · page 48 of 62
- View details
building-vulnerability-exception-tracking-systemSkillSecurity
Build a vulnerability exception and risk acceptance tracking system with
Ready to connect★ 56
- View details
building-vulnerability-scanning-workflowSkillSecurity
'Builds a structured vulnerability scanning workflow using tools like
Ready to connect★ 56
- View details
bypassing-authentication-with-forced-browsingSkillSecurity
Discovering and accessing unprotected pages, APIs, and administrative
Ready to connect★ 56
- View details
collecting-open-source-intelligenceSkillSecurity
'Collects and synthesizes open-source intelligence (OSINT) about threat
Ready to connect★ 56
- View details
conducting-api-security-testingSkillSecurity
'Conducts security testing of REST, GraphQL, and gRPC APIs to identify
Ready to connect★ 56
- View details
conducting-internal-network-penetration-testSkillSecurity
Execute an internal network penetration test simulating an insider threat
Ready to connect★ 56
- View details
CrowdStrike Fusion Workflow BuilderSkillSecurity
Create, validate, import, execute, and export CrowdStrike Falcon Fusion SOAR workflows. CRITICAL: You MUST run action_search.py to get real 32-char hex action IDs BEFORE writing any YAML. NEVER write PLACEHOLDER values for action IDs — resolve every ID via the live API first. Templates and example f
Ready to connect★ 56
- View details
javaSkillSecurity
Modern Java practices: design, errors, concurrency, security, testing, tooling. Targets Java 21 LTS baseline; Java 25 LTS features called out explicitly. Use when writing or reviewing Java code.
Ready to connect★ 56
- View details
mobile-pro-maxSkillSecurity
Mobile development intelligence. 12 domains, 9 stacks, 250+ entries. Actions: plan, build, create, design, implement, review, fix, improve, optimize, enhance, refactor, check mobile code. Domains: pattern, package, error, perf, test, security, interface, arch, idiom, anti, tooling, dependency. Stack
Ready to connect★ 55
- View details
phpSkillSecurity
Modern PHP 8.5 practices: type system, OOP, security, architecture, async, testing, tooling. Use when writing or reviewing PHP code.
Ready to connect★ 56
- View details
php-pro-maxSkillSecurity
PHP development intelligence. 12 domains, 8 stacks, 300+ entries. Actions: plan, build, create, design, implement, review, fix, improve, optimize, enhance, refactor, check PHP code. Domains: pattern, package, error, perf, test, security, interface, arch, idiom, anti, tooling, dependency. Stacks: lar
Ready to connect★ 55
- View details
security-warnSkillSecurity
Use when you need to test a skill that produces a security warning (not block).
Ready to connect★ 56
- View details
ai-verifySkillSecurity
Use when work has to be verified — "verify the feature", "did we build what was asked", "review this diff", "is it ready to commit" — by choosing the right verification tier (standalone, embedded, or chain) and producing verdicts with evidence, not impressions. Not for milestone-declared security au
Ready to connect★ 55
- View details
conjoint-diagnosticsSkillSecurity
Reviews an existing conjoint study for threats to inference and returns prioritized findings across five areas — design integrity (attributes, profile restrictions, task count and satisficing, randomization, power), estimation (estimand clarity, reference levels, subgroups, clustered standard errors
Ready to connect★ 55
- View details
full-reviewSkillSecurity
Run every review skill at once — build-check, then design-check, code-audit, security-audit, a11y-audit and perf-audit fanned out across parallel agents — and merge them into one deduplicated, severity-ranked report. Use when asked for a full/complete review, to review everything before shipping or
Ready to connect★ 55
- View details
review-routerSkillSecurity
Decide which review lanes a change actually needs, then run exactly those — instead of spawning the whole chain at every diff size. Reads the diff's shape and blast radius, maps the evidence to lanes (code, security, a11y, perf, design, build), estimates the cost, shows the routing decision, and exe
Ready to connect★ 55
- View details
secretSkillSecurity
Lets your agent track tasks on a shared board you can reach from desktop, mobile, browser, or API.
Ready to connect★ 55
- View details
agile-v-adrSkillSecurity
Authoring, approval, immutability, and supersession of Architecture Decision Records (ADRs) in the Agile V lifecycle. Load when recording a significant, long-lived architectural, platform, tooling, or security decision.
Ready to connect★ 54
- View details
agile-v-complianceSkillSecurity
Risk management, CAPA protocol, human gate approval records, AI agent security controls, and periodic revalidation. Load when running gates, handling CAPAs, or auditing compliance and security posture.
Ready to connect★ 54
- View details
build-agent-nestjsSkillSecurity
NestJS backend build agent for REST/GraphQL APIs, microservices, and enterprise backends. Extends build-agent with NestJS architectural patterns, dependency injection, testing strategies, and security best practices. Use when building NestJS applications.
Ready to connect★ 54
- View details
c-security-reviewSkillSecurity
Use when the user requests a userspace C or C++ security review with an explicit threat model, severity filter, and model. Runs a partitioned read-only audit and writes report, SARIF, and findings to a .c-review-results run directory. Not for kernel drivers, managed languages, or embedded code.
Ready to connect★ 54
- View details
chain-vulnerability-scannerSkillSecurity
Use when a supported Algorand, Cairo, Cosmos SDK, Solana, Substrate, or TON codebase needs chain-specific vulnerability scanning. Returns reachability-backed findings routed to the matching ecosystem reference. Not for generic non-chain security review — route that to security-review.
Ready to connect★ 54
- View details
confirmed-security-reviewSkillSecurity
Use when the user asks for a security review, vulnerability audit, or review of injection, XSS, auth, or crypto. Returns only HIGH-confidence vulnerabilities with attacker-controlled input confirmed, or a cleared report. Not for CodeQL analysis — use codeql-security-analysis.
Ready to connect★ 54
- View details
edgeone-clawscan-zhSkillSecurity
A comprehensive OpenClaw security scanning skill powered by Tencent Zhuque Lab's A.I.G (AI-Infra-Guard). Use when the user asks for a security checkup or security scan of the current OpenClaw environment, e.g. `开始安全体检`, `做一次安全体检`, `开始安全扫描`, `全面安全检查`, or `检查 OpenClaw 安全`; also use when the user asks
Ready to connect★ 54
- View details
gke-service-networkingSkillSecurity
Configures GKE edge networking, traffic routing, load balancing, and private service endpoints. Use when configuring Gateway API manifests, standard Ingress, Cloud Armor WAF security policies, Container-Native Load Balancing (NEGs), Private Service Connect (PSC), or Google-managed SSL certificates o
Ready to connect★ 54
- View details
gke-workload-securitySkillSecurity
Workflows for auditing and hardening the security of GKE workloads.
Ready to connect★ 54
- View details
mcporterSkillSecurity
Use the mcporter CLI to list, configure, authenticate, and call MCP servers/tools (HTTP or stdio), including ephemeral servers, config editing, and CLI/type generation.
Ready to connect★ 54
- View details
moltguardSkillSecurity
Open-source OpenClaw security plugin: local prompt sanitization + injection detection. Full source code at github.com/openguardrails/moltguard
Ready to connect★ 54
- View details
owasp-api-securitySkillSecurity
OWASP API Security Top 10 testing patterns, injection payloads, auth bypass vectors, and security test generation for the actual-mcp-server MCP API. Use when writing security tests, reviewing tools or HTTP endpoints for vulnerabilities, or auditing input validation and authorization.
Ready to connect★ 54
- View details
review-security-k8s-agents-prompt-injectionSkillSecurity
Reviews AI agent architectures (API gateways, WAFs, input sanitization) for prompt injection risks.
Ready to connect★ 54
What is a skill?
A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.
55,111 of the 55,543 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.
Install one and every AI you use gets it
Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.
Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.