Skills.

Give your AI a better way to work.

A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.

Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.

Category: Security

1,833 results · page 52 of 62

  • wordpress-mcp-devSkillSecurity

    Build and maintain modern WordPress plugins and MCP servers, including hybrid WordPress+MCP products. Use when implementing plugin architecture (PHP, REST API, Gutenberg/admin/page-builder integrations), MCP tooling (TypeScript/Python, stdio/HTTP transport), security hardening, licensing/updates, an

    Ready to connect

    github.com/respira-press/agent-skills-wordpress43 stars

    View details
  • wordpress-site-dnaSkillSecurity

    Use when the user says 'analyze my wordpress site', 'what is running on my site', 'site dna', or 'what plugins are on my site'. Detects every page builder, audits active versus dead-weight plugins, maps content structure, finds orphaned shortcodes, and checks performance and security posture.

    Ready to connect

    github.com/respira-press/agent-skills-wordpress43 stars

    View details
  • audit-domain-01-securitySkillSecurity

    Audit the security domain — auth, authz, secrets, transport, sensitive data exposure, dependency CVEs. Run as part of /audit Phase E.

    Ready to connect

    github.com/wolverin0/clawtrol42 stars

    View details
  • tdmcp-quality-auditSkillSecurity

    Run or maintain the full tdmcp repo quality-audit team: command sweeps, all package/Makefile/CI gates, security review, usability/flow review, refactor/test-gap analysis, coverage hardening, QA, and follow-up fix waves. Use whenever the user asks for a complete audit, improve repo/code quality, test

    Ready to connect

    github.com/pantani/tdmcp39 stars

    View details
  • analyzing-activist-investor-vulnerabilitiesSkillSecurity

    Evaluates corporate vulnerability to shareholder activism with governance assessment, valuation gaps, and operational improvement opportunities. Use when assessing activist risk, identifying vulnerabilities, or preparing defensive analyses.

    Ready to connect

    github.com/casemark/skills40 stars

    View details
  • analyzing-competitive-landscapesSkillSecurity

    Maps competitive dynamics with market positioning, feature comparison, funding histories, and differentiation assessment. Use when analyzing startup competition, mapping market landscapes, or identifying competitive threats.

    Ready to connect

    github.com/casemark/skills40 stars

    View details
  • analyzing-sovereign-credit-riskSkillSecurity

    Evaluates sovereign creditworthiness with fiscal analysis, external vulnerability, political risk, and institutional quality assessment. Use when analyzing sovereign risk, assessing country credit, or evaluating government bond exposure.

    Ready to connect

    github.com/casemark/skills40 stars

    View details
  • ios-signing-doctorSkillSecurity

    Diagnose and fix iOS code-signing, provisioning, and entitlement failures — the "no signing certificate / no profiles / doesn't match / get-task-allow" family, using codesign/security to inspect what's actually signed. Use when an archive, upload, or CI build fails on signing.

    Ready to connect

    github.com/stevegjones/ai-first-sdlc-practices41 stars

    View details
  • mcp-server-managerSkillSecurity

    Configure and manage MCP (Model Context Protocol) servers in Claude Code CLI. Use this skill when adding, removing, listing, or troubleshooting MCP servers, or when questions arise about MCP configuration, transport types, scopes, or authentication. Essential for connecting Claude Code to external t

    Ready to connect

    github.com/tdimino/claude-code-minoan41 stars

    View details
  • particle-swarm-simSkillSecurity

    Generate 20,000+ particle swarm simulators in two modes: sandbox (complete Three.js host runtime with gesture controls, security validation, code injection pipeline) and sim (behavior function bodies that position/color particles via a sandboxed API). The AI writes ONLY a function body — the host ha

    Ready to connect

    github.com/tdimino/claude-code-minoan41 stars

    View details
  • Address GitHub PR review comments from the current branch with gh-address-commentsSkillSecurity

    Find the open PR for the current branch, gather unresolved review comments, and drive a focused comment-resolution workflow with gh-authenticated context.

    Ready to connect

    github.com/agentskillexchange/skills40 stars

    View details
  • Aperture Wallet GuideSkillSecurity

    Answer Aperture Wallet questions from first-party product, security, network, release, app-screen, and Journal sources while enforcing explicit wallet-secret and no-transaction safety boundaries.

    Ready to connect

    github.com/agentskillexchange/skills40 stars

    View details
  • bump-transitiveSkillSecurity

    Surgically bump a vulnerable transitive dependency to its latest patch per major using pnpm.overrides, then clean up without leaving override traces in package.json.

    Ready to connect

    github.com/mendix/web-widgets40 stars

    View details
  • claude-pentest-skillsSkillSecurity

    Structured web application penetration testing with OWASP methodology, curated payload references, 6-gate validation, and professional report generation

    Ready to connect

    github.com/frendysanusi/claude-pentest-skills40 stars

    View details
  • plugin-architectureSkillSecurity

    Build pluggable authentication features using the plugin system with initialization, migrations, routes, and service registration.

    Ready to connect

    github.com/cliqrelay/cliqrelay39 stars

    View details
  • vigilante-issue-implementation-on-dotnetSkillSecurity

    Implement a GitHub issue end-to-end when Vigilante dispatches work for a .NET/C# repository with analyzer, test, and security guidance.

    Ready to connect

    github.com/aliengiraffe/vigilante40 stars

    View details
  • vigilante-issue-implementation-on-goSkillSecurity

    Implement a GitHub issue end-to-end when Vigilante dispatches work for a Go repository with idiomatic tooling and security guidance.

    Ready to connect

    github.com/aliengiraffe/vigilante40 stars

    View details
  • vigilante-issue-implementation-on-phpSkillSecurity

    Implement a GitHub issue end-to-end when Vigilante dispatches work for a PHP repository with Composer, static analysis, and security guidance.

    Ready to connect

    github.com/aliengiraffe/vigilante40 stars

    View details
  • vigilante-issue-implementation-on-pythonSkillSecurity

    Implement a GitHub issue end-to-end when Vigilante dispatches work for a Python repository with idiomatic tooling and security guidance.

    Ready to connect

    github.com/aliengiraffe/vigilante40 stars

    View details
  • vigilante-issue-implementation-on-rubySkillSecurity

    Implement a GitHub issue end-to-end when Vigilante dispatches work for a Ruby repository with Bundler, test, lint, and security guidance.

    Ready to connect

    github.com/aliengiraffe/vigilante40 stars

    View details
  • vigilante-issue-implementation-on-rustSkillSecurity

    Implement a GitHub issue end-to-end when Vigilante dispatches work for a Rust repository with Cargo, Clippy, fmt, and security guidance.

    Ready to connect

    github.com/aliengiraffe/vigilante40 stars

    View details
  • action1SkillSecurity

    Every Action1 endpoint, plus the fleet-wide patch and vulnerability views the org-siloed API cannot give you. Trigger phrases: `action1 patch posture`, `which endpoints are missing patches`, `triage action1 vulnerabilities`, `find stale action1 agents`, `action1 fleet view across organizations`, `us

    Ready to connect

    github.com/servosity/msp-skills39 stars

    View details
  • corkSkillSecurity

    Every Cork API operation as one CLI and MCP server, plus cross-client risk attribution, exploitability-first vulnerability triage, overdue-compliance detection, and stale-connector health checks that a stateless API mirror cannot answer in a single call. Trigger phrases: `which Cork clients got wors

    Ready to connect

    github.com/servosity/msp-skills39 stars

    View details
  • inbound-triageSkillSecurity

    Maintainer-only. Use when triaging inbound GitHub issues and pull requests on skyf0xx/hedgehog — "triage the issues", "check the PRs", "review inbound", "what's in the queue". Reads each item read-only, judges it for security and for whether it is real, then fixes and closes or comments and closes.

    Ready to connect

    github.com/skyf0xx/hedgehog39 stars

    View details
  • msp-skills-conciergeSkillSecurity

    Use when the user has msp-skills installed and wants help choosing or installing connectors - it reads the live catalog, learns their PSA/RMM/backup/security/billing stack, recommends the connectors that fit, and installs only the ones they approve. Trigger phrases: `recommend which connectors I sho

    Ready to connect

    github.com/servosity/msp-skills39 stars

    View details
  • ninjaoneSkillSecurity

    Every NinjaOne report, plus a local store that answers fleet-wide questions no single API call can: patch compliance, backup gaps, AV blast-radius, health, drift. Trigger phrases: `check patch compliance in ninjaone`, `which ninjaone devices have no backup`, `ninjaone av threat sweep`, `ninjaone fle

    Ready to connect

    github.com/servosity/msp-skills39 stars

    View details
  • proofpointSkillSecurity

    Every TAP Threat Insight endpoint, plus a local threat store that answers the cross-endpoint questions - who is both attacked and clicking, what touched this user - inside Proofpoint's punishing daily quotas. Trigger phrases: `pull proofpoint siem events`, `who are my VAPs`, `decode this urldefe

    Ready to connect

    github.com/servosity/msp-skills39 stars

    View details
  • storybook-pentestSkillSecurity

    Pentest Storybook components two ways. Whether they break under stress, and whether they actually do their job well. Test one story, a component group, or the whole Storybook, and write every finding into an OKF bundle with screenshots, severity, and a reproducible URL. The break pass probes extreme

    Ready to connect

    github.com/saschb2b/okf-studio34 stars

    View details
  • alpaca-browseros-authSkillSecurity

    Recover Alpaca paper API access from the authenticated BrowserOS Neo session, store credentials in macOS Keychain without exposing them, and verify broker truth through the trading repo. Use when Alpaca credentials are reported missing, broker inventory is unverified, system_state is stale, or a pap

    Ready to connect

    github.com/igorganapolsky/trading38 stars

    View details
  • cisco-security-cloud-setupSkillSecurity

    Use when configuring Cisco Security Cloud API inputs, product flows, indexes, or dashboards in Splunk.

    Ready to connect

    github.com/chambear2809/splunk-cisco-skills37 stars

    View details

What is a skill?

A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.

55,111 of the 55,543 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.

Install one and every AI you use gets it

Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.

Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.

See how to connect your AI