Skills.
Give your AI a better way to work.
A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.
Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.
Category: Security
1,738 results · page 6 of 58
- View details
mid-engagement-ir-detectionSkillSecurity
Guides your agent through spotting client-side detection and patching activity during a red-team engagement.
Ready to connect★ 4k
- View details
security-arsenalSkillSecurity
Lets your agent look up security testing payloads, bypass techniques, and wordlists for hunting web vulnerabilities.
Ready to connect★ 4k
- View details
supply-chain-attack-reconSkillSecurity
Lets your agent scan a company's software supply chain from the outside for weaknesses attackers could exploit.
Ready to connect★ 4k
- View details
web3-auditSkillSecurity
Lets your agent audit smart contracts for 10 common DeFi bug classes using checklists, grep patterns, and PoC templates.
Ready to connect★ 4k
- View details
sqlx-query-validatorSkillSecurity
Checks your Rust code changes for SQLx query issues like missing compile-time macros and security problems.
Ready to connect★ 4k
- View details
ci-security-complianceSkillSecurity
Guides your agent to review third-party GitHub Actions, pin them safely, set minimal permissions, and handle secrets.
Ready to connect★ 4k
- View details
archestra-dev-override-sweepSkillSecurity
Use when asked to sweep, clean up, or revisit pnpm overrides and minimumReleaseAge exclusions in platform/pnpm-workspace.yaml — unwinding a matured temporary CVE pin once its fix has cleared the 7-day window, or removing an override the dependency graph has made redundant. This skill only sweeps exi
Ready to connect★ 4k
- View details
octopus-security-auditSkillSecurity
OWASP compliance, vulnerability scanning, and adversarial red team testing — use for security reviews
Ready to connect★ 4k
- View details
skill-code-reviewSkillSecurity
Expert multi-AI code review with inline PR comments — use for thorough quality and security analysis
Ready to connect★ 4k
- View details
skill-native-escalation-routingSkillSecurity
Use when choosing native or multi-LLM handling for init, review, or security requests
Ready to connect★ 4k
- View details
skill-security-framingSkillSecurity
URL validation and content sanitization for untrusted sources — use when handling external input safely
Ready to connect★ 4k
- View details
releaseSkillSecurity
Lets your agent run a release workflow with security audit, end-to-end tests, review, changelog, and docs.
Ready to connect★ 4k
- View details
securitySkillSecurity
Runs a security audit workflow that scans for vulnerabilities and verifies findings.
Ready to connect★ 4k
- View details
cws-iouring-coverageSkillSecurity
Lets your agent audit which io_uring operations have functional tests and write tests for uncovered ones.
Ready to connect★ 4k
- View details
offensive-api-abuseSkillSecurity
Teaches your agent API attack techniques like business logic abuse and GraphQL exploitation for security testing.
Ready to connect★ 3k
- View details
offensive-business-logicSkillSecurity
Lets your agent test web, mobile, and API apps for business logic flaws like workflow bypass, price manipulation, and race conditions.
Ready to connect★ 3k
- View details
offensive-deauth-disassocSkillSecurity
Lets your agent run Wi-Fi deauthentication and disassociation attacks for security testing.
Ready to connect★ 3k
- View details
offensive-evil-twinSkillSecurity
Lets your agent run rogue Wi-Fi access point attacks like KARMA probe responses, captive portals, and deauth coercion.
Ready to connect★ 3k
- View details
offensive-graphqlSkillSecurity
Gives your agent a methodology for testing GraphQL APIs for security flaws during pentests.
Ready to connect★ 3k
- View details
offensive-krack-fragattacksSkillSecurity
Gives your agent reference material on KRACK and FragAttacks Wi-Fi attacks, including test scripts and patch status.
Ready to connect★ 3k
- View details
offensive-phishingSkillSecurity
Lets your agent plan and run authorized phishing campaign tests, including infrastructure setup and payload delivery methods.
Ready to connect★ 3k
- View details
offensive-tls-attacksSkillSecurity
Gives your agent methods for testing TLS/SSL setups for known weaknesses and misconfigurations.
Ready to connect★ 3k
- View details
offensive-windows-privescSkillSecurity
Comprehensive Windows privilege escalation methodology for offensive security engagements. Covers the full attack surface from a standard user shell to NT AUTHORITY\\SYSTEM: token impersonation via SeImpersonate and SeAssignPrimaryToken privileges using JuicyPotato, PrintSpoofer, GodPotato, SweetPot
Ready to connect★ 3k
- View details
offensive-wpa2-pskSkillSecurity
Guides your agent through capturing and cracking WPA/WPA2 Wi-Fi passwords using handshake and PMKID attacks.
Ready to connect★ 3k
- View details
offensive-wpa3-saeSkillSecurity
Gives your agent methods for testing Wi-Fi networks against WPA3/SAE security flaws like downgrade and side-channel attacks.
Ready to connect★ 3k
- View details
offensive-wpsSkillSecurity
Lets your agent attempt WPS PIN attacks to recover Wi-Fi passwords from vulnerable routers.
Ready to connect★ 3k
- View details
aurakitSkillSecurity
Lets your agent write and fix fullstack code with built-in security checks and guided modes.
Ready to connect★ 3k
- View details
release-checkSkillSecurity
Runs a pre-release checklist that verifies features, tests, docs, security, and quality gates before shipping.
Ready to connect★ 3k
- View details
security-auditSkillSecurity
Lets your agent run a security audit checking vulnerabilities, auth, data protection, dependencies, and exposed secrets.
Ready to connect★ 3k
- View details
doca-flow-grpc-serverSkillSecurity
Lets your agent set up and configure NVIDIA's DOCA Flow gRPC server for network flow programming on a trusted segment.
Ready to connect★ 3k
What is a skill?
A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.
52,524 of the 52,958 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.
Install one and every AI you use gets it
Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.
Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.