Skills.

Give your AI a better way to work.

A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.

Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.

Category: Security

1,833 results · page 50 of 62

  • better-your-harnessSkillSecurity

    Run an AI Harness health check on a local project and produce a visual HTML report. Scans five layers: security and hygiene (.gitignore, plaintext secrets, Agent permissions), context quality (AI readability, cold-start cost, noise ratio, directory structure), tooling (Skill/MCP/sub-agents, includin

    Ready to connect

    github.com/spacezephyr/build-your-harness51 stars

    View details
  • secscanSkillSecurity

    In-session, token-efficient LLM security scan of a repo (SAST triage). A lightweight, native Claude Code pipeline — survey → threat-model → deep-dive → adversarial-verify → report — using Read/Grep/Glob (and optional subagents), no external tooling. Use when asked to "security scan", "find vulnerabi

    Ready to connect★ 51

    github.com/atgreen/secscan-skill51 stars

    View details
  • test-specSkillSecurity

    Generate BDD test specifications for story in 6 categories (API, UI, Load, Infrastructure, Security, Integration). Use when user wants to create test cases or mentions /test-spec command.

    Ready to connect★ 51

    github.com/rakovi4/continue-framework50 stars

    View details
  • vendor-contractsSkillSecurity

    Vendor contracts, MSAs, DPAs, and procurement for B2B SaaS — master service agreements, service level agreements, data processing agreements, order forms, vendor security assessments, and contract negotiation playbooks. Use when selling to enterprise (inbound contracts), buying from vendors (outboun

    Ready to connect★ 50

    github.com/leadmagic/gtm-skills51 stars

    View details
  • work-with-authSkillSecurity

    Work on HFS authentication & authorization. Use for SMART-on-FHIR/OAuth2, JWT bearer validation, JWKS, scopes/permissions, token replay semantics, SMART discovery, and HFS_AUTH_* configuration.

    Ready to connect★ 51

    github.com/heliossoftware/hfs51 stars

    View details
  • adversarial-securitySkillSecurity

    Use when you need to audit a project's security with a Red Team / Blue Team pipeline.

    Ready to connect★ 50

    github.com/gonzalezpazmonica/pm-workspace49 stars

    View details
  • dependency-scannerSkillSecurity

    Use when scanning project dependencies (Node, Python, C#, Java, Go, Rust, Ruby) for vulnerabilities with Trivy fs. Generates a CycloneDX SBOM.

    Ready to connect★ 50

    github.com/gonzalezpazmonica/pm-workspace49 stars

    View details
  • golang-cli-reviewSkillSecurity

    Comprehensive code review for Golang CLI applications. Produces an actionable checklist covering error handling, CLI framework patterns (Cobra/urfave), testing, performance, security, and Go idioms.

    Ready to connect★ 50

    github.com/asteroid-belt/skulto50 stars

    View details
  • grill-meSkillSecurity

    Adversarial review that hunts every weakness, assumption, edge case, and missing test. Opponent mode — finds what will break before it breaks in production. Use when merging, when reviewing security-critical code, or when the solution feels too simple.

    Ready to connect★ 50

    github.com/gonzalezpazmonica/pm-workspace49 stars

    View details
  • nuclei-scanningSkillSecurity

    Usar cuando se escanean vulnerabilidades conocidas (CVEs, misconfigs) con Nuclei.

    Ready to connect★ 50

    github.com/gonzalezpazmonica/pm-workspace49 stars

    View details
  • pentestingSkillSecurity

    Usar cuando se ejecuta un pentest contra una aplicación o infraestructura.

    Ready to connect★ 50

    github.com/gonzalezpazmonica/pm-workspace49 stars

    View details
  • skulto-release-certSkillSecurity

    Certify a skulto build for Homebrew prod release. Runs three passes — unit/lint/cross-compile, clean-slate CLI walkthrough, and security audit — then produces a certification summary.

    Ready to connect★ 50

    github.com/asteroid-belt/skulto50 stars

    View details
  • claude-code-auto-advisorSkillSecurity

    Claude Code automatic advisor for security, reviews, high-risk design, substantial multi-step plans, complex refactors, recurring failures, and risky completion checks. Skip trivial work, ordinary planning, other harnesses, or sessions without an advisor tool.

    Ready to connect

    github.com/jpcaparas/skills47 stars

    View details
  • boring-google-signup-setupSkillSecurity

    Teach a boring-ui child app how to enable Google signup with @hachej/boring-core. Use when the user asks for Google auth, Google OAuth, social signup, or how to turn on Google sign-in/sign-up in a child app.

    Ready to connect

    github.com/hachej/boring-ui46 stars

    View details
  • detection-engineerSkillSecurity

    Create detection rules and hunting queries from malware analysis findings. Use when you need to write Sigma rules for SIEM, Suricata rules for network IDS, defang IOCs for safe sharing, or convert analysis findings into actionable detection content for SOC teams and threat hunters.

    Ready to connect

    github.com/gl0bal01/malware-analysis-claude-skills46 stars

    View details
  • gha-security-reviewSkillSecurity

    Use when reviewing GitHub Actions workflows for exploitable vulnerabilities — finds pwn-request patterns, expression injection, credential escalation, config poisoning, and supply chain risks, and reports only HIGH and MEDIUM confidence findings with concrete attack paths.

    Ready to connect

    github.com/drvoss/everything-copilot-cli46 stars

    View details
  • harms-checkSkillSecurity

    Use when building anything USER-FACING (or with persuasion/retention/cancellation/consent/pricing flows, or that touches vulnerable people) to surface design-level harm the security/privacy/compliance gates miss: dark/deceptive patterns and foreseeable misuse. Assumes the product works as designed a

    Ready to connect

    github.com/haabe/mycelium46 stars

    View details
  • mandu-securitySkillSecurity

    Security best practices for Mandu applications. Use when implementing authentication, authorization, input validation, or protecting against common vulnerabilities. Triggers on guard, auth, CSRF, XSS, or security tasks.

    Ready to connect

    github.com/konamgil/mandu46 stars

    View details
  • pr-security-reviewSkillSecurity

    Use when reviewing a pull request for security issues — automatically analyzes the diff for vulnerabilities, hardcoded secrets, injection risks, and broken access control before merging

    Ready to connect

    github.com/drvoss/everything-copilot-cli46 stars

    View details
  • threat-model-analystSkillSecurity

    Use when a repository, system, or major change needs a structured STRIDE-A threat model — map architecture, data flows, trust boundaries, abuse cases, and prioritized findings, or update an existing model with a change-focused diff.

    Ready to connect

    github.com/drvoss/everything-copilot-cli46 stars

    View details
  • 3CX API PatternsSkillSecurity

    3CX's native PBX MCP server: the per-PBX endpoint shape (every PBX is its own FQDN and its own OAuth authorization server — there is no shared mcp.3cx.com), the Admin Console + client setup flow, the permission model (fully inherited from the 3CX account that approved the connection), and how to dis

    Ready to connect

    github.com/wyre-ai/msp-claude-plugins45 stars

    View details
  • Abnormal Security ThreatsSkillSecurity

    Abnormal Security threat detection: threat types (BEC, phishing, malware, socially-engineered attacks, spam, graymail, credential theft), attack vectors, severity assessment, remediation actions, and investigation workflows.

    Ready to connect

    github.com/wyre-ai/msp-claude-plugins45 stars

    View details
  • ad-attackSkillSecurity

    Active Directory exploitation after domain credentials exist: Kerberos (AS-REP/Kerberoast including cracking the ticket then using the account), delegation, NTLM coercion/relay, lateral movement, ACL abuse, ADCS ESC1-ESC17 and CVE paths, dMSA/BadSuccessor, Kerberos reflection, identity confusion, ma

    Ready to connect

    github.com/pale-knight/redteam-skill45 stars

    View details
  • apple-firmware-inspectorSkillSecurity

    Apple firmware: inspect and reverse-engineer IPSWs, kernelcaches, dyld shared caches, private headers, entitlements, Mach-O binaries, KEXTs, and security internals with `ipsw`.

    Ready to connect

    github.com/xopoko/build-swift-apps45 stars

    View details
  • attack-path-analysisSkillSecurity

    Use when Codex is already in the attack-path-analysis phase of a security scan or the user explicitly asks to trace a security finding from source to sink and calibrate severity. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.

    Ready to connect

    github.com/bex-co/bex-security45 stars

    View details
  • Blackpoint Multi-Tenant OperationsSkillSecurity

    Partner-level Blackpoint Cyber (CompassOne) operations: the partner-tenant hierarchy, enumerating customer tenants, sweeping detections and vulnerabilities across all of them, spotting volume anomalies, and building per-tenant scorecards.

    Ready to connect

    github.com/wyre-ai/msp-claude-plugins45 stars

    View details
  • Blackpoint Vulnerability ManagementSkillSecurity

    Blackpoint Cyber (CompassOne) exposure data across four lenses: host vulnerability findings and the filters that matter (CVE, severity, patch and exploit availability), scan history, dark-web credential and data leaks, and internet-facing external exposures — plus how to combine them into a prioriti

    Ready to connect

    github.com/wyre-ai/msp-claude-plugins45 stars

    View details
  • cipp-groupsSkillSecurity

    Tenant-scoped Entra/M365 group enumeration and creation in CIPP, the four group types (Security, Microsoft 365, Distribution, Mail-Enabled Security) and when to pick each, and the boundary where CIPP's group surface ends and Graph/M365 takes over.

    Ready to connect

    github.com/wyre-ai/msp-claude-plugins45 stars

    View details
  • cipp-securitySkillSecurity

    Read-only access to a tenant's Conditional Access policy graph and named locations through CIPP: policy state semantics, the findings that matter in a CA review, portfolio drift detection, and why CA writes are absent from the MCP surface.

    Ready to connect

    github.com/wyre-ai/msp-claude-plugins45 stars

    View details
  • Cyber Insurance QuestionnairesSkillSecurity

    Drafting tool-verified answers to cyber-insurance renewal, new-business, and underwriter security questionnaires: the standard recurring question set (MFA everywhere including privileged accounts, EDR coverage ratio, tested and immutable backups, documented and tested IR plan, security awareness tra

    Ready to connect

    github.com/wyre-ai/msp-claude-plugins45 stars

    View details

What is a skill?

A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.

55,111 of the 55,543 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.

Install one and every AI you use gets it

Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.

Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.

See how to connect your AI