Skills.
Give your AI a better way to work.
A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.
Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.
Category: Security
1,833 results · page 51 of 62
- View details
deep-security-scanSkillSecurity
Use when the user asks for a deep, exhaustive, multi-pass, or variance-reducing repository-wide or scoped-path Codex Security scan. Run repeated complete independent Standard scans with the Codex Security deep-scan tool, which aggregates their validated findings and prepares the canonical artifacts;
Ready to connect
- View details
define-security-policySkillSecurity
Define, review, or update SECURITY.md guidance for a repository or component. Use when the user wants to clarify what Codex Security should review, what is out of scope, which security properties must hold, or whether existing guidance still matches the code.
Ready to connect
- View details
finding-discoverySkillSecurity
Use when Codex is already in the finding-discovery phase of a security scan or the user explicitly asks to discover candidate security findings in a repository or code change. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.
Ready to connect
- View details
fix-findingSkillSecurity
Use when the user explicitly asks to fix and verify a validated or plausible security finding. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.
Ready to connect
- View details
Human Risk ScoringSkillSecurity
Explainable per-user and per-org human risk scoring from training-completion status, phishing-simulation failure history, and optional real-world click/attack-targeting signal: the weighted factor table, three-tier bucketing, per-org rollup as a distribution rather than a blended number, and gracefu
Ready to connect
- View details
KnowBe4 PhishingSkillSecurity
KnowBe4 phishing simulations: campaign creation and lifecycle, security test management, recipient interaction tracking (sent, opened, clicked, reported), phish-prone percentage calculation, template selection, landing pages, and click tracking.
Ready to connect
- View details
loop-workerSkillSecurity
Autonomously work a `.pm` workstream to completion — pick the next pending milestone, implement every task end to end, /ship it, then move to the next until none remain. Use when the user asks to "loop", drain, or work through a whole workstream's backlog (e.g. `/loop-worker w1`). Sequential, not in
Ready to connect
- View details
merge-upstream-mainSkillSecurity
Merge the public openai/codex-security main branch into this fork's main branch and push the result to the fork remote. Use when asked to sync or merge upstream main for this repository.
Ready to connect
- View details
Proofpoint PeopleSkillSecurity
Proofpoint People-Centric Security fundamentals: Very Attacked People (VAP) reports, attack index scoring, click susceptibility, top clickers, and user risk categorization for targeting security controls and training.
Ready to connect
- View details
Proofpoint Threat IntelligenceSkillSecurity
Proofpoint Threat Intelligence fundamentals: campaign tracking, threat families and actors, indicators of compromise (IOCs), and how campaign/IOC data enriches individual TAP threat events.
Ready to connect
- View details
security-diff-scanSkillSecurity
Review a pull request, commit, branch diff, or working-tree patch for security vulnerabilities.
Ready to connect
- View details
shellSkillSecurity
Shell and session operations after an attack module already established command execution, a raw shell, webshell channel, container/runner shell, or remote session. This module does not own exploitation and should not pull SSH/WinRM/RDP authentication or vulnerability-to-shell chains out of Web/AD/C
Ready to connect
- View details
shipSkillSecurity
Safely bring main up to date, commit intended pending changes, and push to origin/main. Use when the user explicitly asks to ship the current main branch or invokes the repository's ship workflow.
Ready to connect
- View details
test-case-writerSkillSecurity
Test case generator — converts a PRD's acceptance criteria and rules into test cases that QA can execute directly: happy paths, boundary values, error paths, concurrency/idempotency, permissions and security. Use this skill whenever the user says things like "幫我寫測試案例", "這份 PRD 的 test case", "QA 測試計畫
Ready to connect
- View details
track-findingsSkillSecurity
Track validated Codex Security findings in Linear, Jira, GitHub issues, or draft GitHub security advisories. Use it for one finding or an explicitly selected batch of up to 25 findings tracked as Linear, Jira, or GitHub issues. Includes duplicate checks, exact previews, approval-gated writes, and re
Ready to connect
- View details
Training Completion TrackingSkillSecurity
Security-awareness training completion across whatever training/awareness platform is connected: assignment-overdue versus cadence-overdue detection, per-campaign and per-org completion-rate calculation, ranking clients that have fallen behind a contracted cadence, and the unmeasured-versus-0% disti
Ready to connect
- View details
triage-findingSkillSecurity
Use when the user supplies or imports existing security findings, vulnerability reports, or security/vulnerability Jira/Linear tickets from scanners, advisories, GitHub, Atlassian Rovo, Linear, or similar backlog sources and wants static repo-impact triage. Do not use for discovery, duplicate-bug tr
Ready to connect
- View details
validationSkillSecurity
Use when Codex is already in the validation phase of a security scan or the user explicitly asks to determine whether one or more candidate security findings are valid. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.
Ready to connect
- View details
verify-fixSkillSecurity
Use when the user asks whether an existing security fix, patch, finding, or completed issue actually remediates the original vulnerability without modifying the repository. Do not use to validate candidate findings, implement patches, or run full repository scans.
Ready to connect
- View details
WYRE MCP Gateway TroubleshootingSkillSecurity
WYRE MCP Gateway diagnostics: missing vendor tools, OAuth failures, "Failed to update tool access" errors, expired credentials, and the request flow through mcp-remote to gateway to vendor container to external API.
Ready to connect
- View details
Code ReviewerSkillSecurity
Professional code review expert providing constructive, actionable feedback focused on correctness, maintainability, security, and performance rather than code style preferences.
Ready to connect
- View details
roblox-cloudSkillSecurity
Use for Roblox Open Cloud APIs, API keys, OAuth 2.0, webhooks, scopes, token lifecycle, or in-experience HttpService calls.
Ready to connect
- View details
roblox-code-reviewSkillSecurity
Use when reviewing Roblox or Luau code for security, performance, monetization, data persistence, or architecture risks.
Ready to connect
- View details
roblox-securitySkillSecurity
Use when auditing Roblox code for exploit vectors, authority models, remotes, economy, and DataStore flows.
Ready to connect
- View details
verificationSkillSecurity
Full agent verification suite. Runs security, patterns, quality, and language-specific checks. Use when asked to "verify agent", "verify my agent", "audit agent", or "full verification".
Ready to connect
- View details
verify-securitySkillSecurity
Verify code for security issues including hardcoded secrets, input validation, error exposure, and dependency vulnerabilities. Use when asked to "verify security", "check for secrets", or "scan for vulnerabilities".
Ready to connect
- View details
ci-cd-reliability-architectureSkillSecurity
Establishes idempotency, self-containment, immutable artifacts, self-healing, zero-downtime, and zero-knowledge security for CI/CD pipelines, including delivery-strategy choice, evidence-gated release, and production promotion. Use this skill when designing, auditing, or debugging any workflow, rele
Ready to connect
- View details
review-advancedSkillSecurity
Rigorous sequential-audit code review with a dedicated security block and cited pedagogical lessons. Customize for your project.
Ready to connect
- View details
review-fullstackSkillSecurity
Complete code review of a fullstack MR/PR with 8 sequential audits (Clean Architecture, DDD, React Best Practices, SOLID, Testing, Code Quality, Security, Performance). The audit set is the deduplicated union of review-front and review-back — no audit runs twice. An orchestrator runs each audit one
Ready to connect
- View details
spark-recipe-unsubscribe-auditSkillSecurity
Full unsubscribe audit: scan inbox, archive, and GateKeeper for newsletter senders, classify by volume and engagement, detect phishing and duplicate subscriptions, then unsubscribe via the action tool or extracted footer links.
Ready to connect
What is a skill?
A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.
55,111 of the 55,543 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.
Install one and every AI you use gets it
Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.
Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.