Skills.

Give your AI a better way to work.

A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.

Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.

Category: Security

1,738 results · page 10 of 58

  • moai-ref-llm-securitySkillSecurity

    AI/LLM defensive security reference: prompt-injection defense, OWASP LLM Top 10 defensive mapping, MCP and agentic tool-call hardening, training-data poisoning detection, model-output validation and guardrails, MITRE ATLAS defensive correlation, and NIST AI RMF governance. Agent-extending skill that

    Ready to connect★ 1k

    github.com/modu-ai/moai-adk1k stars

    View details
  • moai-ref-supply-chainSkillSecurity

    Software supply-chain defensive security reference: SBOM generation and verification (SPDX / CycloneDX), dependency-confusion defense, malicious-package triage playbook, SLSA provenance levels, Sigstore / cosign signing and verification, package-registry hardening, typosquatting defense, and transit

    Ready to connect★ 1k

    github.com/modu-ai/moai-adk1k stars

    View details
  • pr-workflowSkillSecurity

    General guidelines for Commits, formatting, CI, dependencies, security

    Ready to connect★ 1k

    github.com/glommer/pgmicro1k stars

    View details
  • react-adminSkillSecurity

    This skill should be used when building, modifying, or debugging a react-admin application — including creating resources, lists, forms, data fetching, authentication, relationships between entities, custom pages, or any CRUD admin interface built with react-admin.

    Ready to connect★ 1k

    github.com/awesome-technologies/synapse-admin1k stars

    View details
  • synology-apiSkillSecurity

    Synology Download Station Web API reference covering API discovery, authentication, request format, common errors, and Download Station task operations.

    Ready to connect★ 1k

    github.com/tympanix/electorrent1k stars

    View details
  • setupSkillSecurity

    This skill should be used when the user asks "how to setup GitHub CLI", "configure gh", "gh auth not working", "GitHub CLI connection failed", "gh CLI error", or needs help with GitHub authentication.

    Ready to connect★ 1k

    github.com/fcakyon/claude-codex-settings1k stars

    View details
  • auth-providersSkillSecurity

    Reference for OrangeHRM's pluggable authentication system — `AuthProviderChain` (DI-registered as `Services::AUTH_PROVIDER_CHAIN`, holds an ordered list of `AbstractAuthProvider` implementations and dispatches `authenticate()` to the highest-priority one that accepts), `AbstractAuthProvider` (`authe

    Ready to connect★ 1k

    github.com/orangehrm/orangehrm1k stars

    View details
  • authorizationSkillSecurity

    Reference for OrangeHRM's authorization model — how REST endpoints and Vue/page controllers are gated by authentication, role-based screen/data-group permissions, and the marker interface that opts controllers out for pre-login routes. Use whenever the user is adding a new REST endpoint or page, mak

    Ready to connect★ 1k

    github.com/orangehrm/orangehrm1k stars

    View details
  • agentlas-security-scanSkillSecurity

    Use when an agent folder must pass the Agentlas Cloud 2-stage security scan (static rules + BYOK LLM judgment) before private sync or public publish, or when asked to run/interpret `hephaestus security scan`.

    Ready to connect★ 1k

    github.com/agentlas-ai/agentlas-os1k stars

    View details
  • api-conventionsSkillSecurity

    API design patterns and conventions for this project. Covers RESTful URL naming, response format standards, error handling, and authentication requirements. Use when writing or reviewing API endpoints, designing new APIs, or making decisions about request/response formats.

    Ready to connect★ 1k

    github.com/huangjia2019/claude-code-engineering1k stars

    View details
  • code-reviewingSkillSecurity

    Review code for quality, security, and best practices. Use when the user asks for code review, wants feedback on their code, mentions reviewing changes, or asks about code quality.

    Ready to connect★ 1k

    github.com/huangjia2019/claude-code-engineering1k stars

    View details
  • aejpol-robustnessSkillSecurity

    Use when an AEJ: Economic Policy manuscript's headline policy estimate needs to be shown stable and credible against specification, sample, inference, and identification threats. Organizes the robustness program by threat-to-the-policy-conclusion; it does not design the primary identification or wri

    Ready to connect★ 1k

    github.com/brycewang-stanford/awesome-journal-skills1k stars

    View details
  • ase-writing-styleSkillSecurity

    Use when shaping the prose and structure of an ASE (IEEE/ACM Automated Software Engineering) research paper, covering the automation-first first-page arc, stating the automated task precisely, keeping the tool runnable and the model-swap test in mind, threats-as-argument, and the 10+2 page disciplin

    Ready to connect★ 1k

    github.com/brycewang-stanford/awesome-journal-skills1k stars

    View details
  • ccs-artifact-evaluationSkillSecurity

    Use when packaging ACM CCS artifacts for the artifact-evaluation committee and the ACM badges — Artifacts Available, Artifacts Evaluated Functional, Artifacts Evaluated Reusable, and Results Reproduced — covering what security evaluators inspect, how to make attacks and defenses turnkey, and how to

    Ready to connect★ 1k

    github.com/brycewang-stanford/awesome-journal-skills1k stars

    View details
  • ccs-author-responseSkillSecurity

    Use when drafting an ACM CCS rebuttal during the HotCRP author-response window, covering threat-model defenses, adaptive-attack objections, ethics and disclosure questions, anonymity constraints, adversarial reviewer pushback patterns, and decision-focused replies aimed at the meta-reviewer.

    Ready to connect★ 1k

    github.com/brycewang-stanford/awesome-journal-skills1k stars

    View details
  • ccs-experimentsSkillSecurity

    Use when designing or auditing ACM CCS experiments, attack demonstrations, adaptive-attack defense evaluations, security measurements, baselines, overhead and cost reporting, ablations, and claim-to-evidence fit, with emphasis on evidence that survives an adversarial program committee rather than le

    Ready to connect★ 1k

    github.com/brycewang-stanford/awesome-journal-skills1k stars

    View details
  • ccs-related-workSkillSecurity

    Use when positioning an ACM CCS submission against the security big-four and specialist literature, including arXiv preprints, prior CCS/S&P/USENIX/NDSS papers, concurrent disclosures, CVE and advisory records, and the attack-and-defense lineage that a SIGSAC program committee expects to see credite

    Ready to connect★ 1k

    github.com/brycewang-stanford/awesome-journal-skills1k stars

    View details
  • ccs-supplementarySkillSecurity

    Use when preparing ACM CCS appendices and supplementary material, including the ethics considerations appendix, protocol transcripts, formal proofs, measurement tables, and anonymized supporting material under the 12-page body limit, anonymity, and reviewer-discretion constraints for a security pape

    Ready to connect★ 1k

    github.com/brycewang-stanford/awesome-journal-skills1k stars

    View details
  • ccs-topic-selectionSkillSecurity

    Use when deciding whether a security project fits ACM CCS versus IEEE S&P, USENIX Security, NDSS, PETS, or a crypto/theory venue, identifying the security contribution type, and sharpening the threat model and attacker capability before writing begins.

    Ready to connect★ 1k

    github.com/brycewang-stanford/awesome-journal-skills1k stars

    View details
  • ccs-writing-styleSkillSecurity

    Use when revising an ACM CCS paper for a precise threat model, calibrated attack/defense claims, 12-page ACM sigconf compression, double-blind wording, adaptive-evaluation honesty, and the security house style that survives an adversarial SIGSAC program committee.

    Ready to connect★ 1k

    github.com/brycewang-stanford/awesome-journal-skills1k stars

    View details
  • auth-webSkillSecurity

    Use when adding CloudBase Web authentication after providers have been checked with auth-tool / queryAppAuth.

    Ready to connect★ 1k

    github.com/tencentcloudbase/cloudbase-ai-toolkit1k stars

    View details
  • auth-web-cloudbaseSkillSecurity

    CloudBase Web Authentication Quick Guide for frontend integration after auth-tool has already been checked. Provides concise and practical Web authentication solutions with multiple login methods and complete user management.

    Ready to connect★ 1k

    github.com/tencentcloudbase/cloudbase-ai-toolkit1k stars

    View details
  • auth-wechat-miniprogramSkillSecurity

    CloudBase WeChat Mini Program native authentication guide. This skill should be used when users need mini program identity handling, OPENID/UNIONID access, or `wx.cloud` auth behavior in projects where login is native and automatic.

    Ready to connect★ 1k

    github.com/tencentcloudbase/cloudbase-ai-toolkit1k stars

    View details
  • cloudbase-wechat-integrationSkillSecurity

    CloudBase WeChat integration guide for Mini Program WeChat Pay, Official Account JSAPI Pay, Native QR-code Pay, Official Account OAuth, openid handling, payment callbacks, and CloudBase Integration Center generated functions. This skill should be used when users ask to add, debug, or extend WeChat p

    Ready to connect★ 1k

    github.com/tencentcloudbase/cloudbase-ai-toolkit1k stars

    View details
  • cryptotokenkitSkillSecurity

    Access security tokens and smart cards using CryptoTokenKit. Use when building TKTokenDriver or TKSmartCardTokenDriver extensions, communicating with smart cards via TKSmartCard/TKSmartCardSlotManager, using iOS 26+ NFC smart-card sessions, registering smart cards, querying token-backed keychain ite

    Ready to connect★ 1k

    github.com/dpearson2699/swift-ios-skills1k stars

    View details
  • gamekitSkillSecurity

    Integrate Game Center features using GameKit. Use when authenticating GKLocalPlayer, checking player restrictions, submitting leaderboard scores, reporting achievements, implementing real-time or turn-based matchmaking, handling GKMatch data, showing the Game Center dashboard or access point, adding

    Ready to connect★ 1k

    github.com/dpearson2699/swift-ios-skills1k stars

    View details
  • crowi-spec-reviewSkillSecurity

    Use when you want to adversarially validate a spec before handing it to implementation. Especially for correctness-critical specs (data integrity / concurrency / auth / security / data-loss risk), or when told "Is this spec OK? Check it thoroughly." Verifies, from multiple independent perspectives,

    Ready to connect★ 1k

    github.com/crowi/crowi1k stars

    View details
  • autoresearchSkillSecurity

    Autonomous Goal-directed Iteration. Apply Karpathy's autoresearch principles to ANY task. Loops autonomously — modify, verify, keep/discard, repeat. 9 subcommands: plan, debug, fix, security, ship, scenario, predict, learn.

    Ready to connect★ 1k

    github.com/openlair/dr-claw1k stars

    View details
  • code-review-expertSkillSecurity

    Expert code review of current git changes with a senior engineer lens. Detects SOLID violations, security risks, and proposes actionable improvements.

    Ready to connect★ 1k

    github.com/dtsola/xiaoyaosearch1k stars

    View details
  • ar-security-triage-externalSkillSecurity

    Reformat, evaluate against the Arweave threat model, and post an assessment on an externally reported security-tracker issue. Use only when the user explicitly invokes this skill with an issue URL.

    Ready to connect★ 1k

    github.com/arweaveteam/arweave1k stars

    View details

What is a skill?

A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.

52,524 of the 52,958 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.

Install one and every AI you use gets it

Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.

Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.

See how to connect your AI