Skills.

Give your AI a better way to work.

A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.

Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.

Filter by category

55,286 results · page 178 of 1,843

  • red-team-toolsSkillSecurity

    This skill should be used when the user asks to "follow red team methodology", "perform bug bounty hunting", "automate reconnaissance", "hunt for XSS vulnerabilities", "enumerate subdomains", or needs security researcher techniques and tool configurations from top bug bounty hunters.

    Ready to connect★ 5k

    github.com/zebbern/claude-code-guide5k stars

    View details
  • regression-modelerSkillFiles & storage

    Run regression analysis (OLS or logistic) on uploaded CSV/Excel data, generating coefficients, R², p-values, VIF, and plain-language interpretation. Triggered by requests for regression modeling, fitting data, testing significance, checking multicollinearity, or keywords like OLS, logit, coefficient

    Ready to connect★ 5k

    github.com/zebbern/claude-code-guide5k stars

    View details
  • regulatory-audit-generatorSkillAI & models

    Builds compliance checklists for business scenarios involving GDPR, PIPL, or advertising/data laws. Outputs a structured checklist with check items, legal basis, risk levels, and actionable recommendations. Triggered by requests like \"run a compliance check,\" \"GDPR/PIPL compliance,\" \"pre-launch

    Ready to connect★ 5k

    github.com/zebbern/claude-code-guide5k stars

    View details
  • repo-auditSkillFiles & storage

    Deep analysis of Git history: identify frequently changed hotspot files, analyze code ownership by contributor, and scan for leaked secrets. Triggered when users ask about Git analysis, code hotspots, who owns what code, secret scanning, security audits of commit history, or optimizing code review a

    Ready to connect★ 5k

    github.com/zebbern/claude-code-guide5k stars

    View details
  • route-to-openapiSkillDocs & knowledge

    Generates RESTful API documentation (OpenAPI 3.0 / Swagger spec) by scanning route definitions in code for Flask, FastAPI, Express, Gin, and other frameworks. Trigger when users ask about API documentation, OpenAPI, Swagger, endpoint docs, generating docs from code, or extracting endpoints.

    Ready to connect★ 5k

    github.com/zebbern/claude-code-guide5k stars

    View details
  • scanning-toolsSkillSecurity

    This skill should be used when the user asks to "perform vulnerability scanning", "scan networks for open ports", "assess web application security", "scan wireless networks", "detect malware", "check cloud security", or "evaluate system compliance". It provides comprehensive guidance on security sca

    Ready to connect★ 5k

    github.com/zebbern/claude-code-guide5k stars

    View details
  • scholarly-writing-refinerSkillAI & models

    Polishes academic English paragraph by paragraph, reviewing grammar, word choice, voice, coherence, and sentence structure. Outputs revision suggestions alongside polished text. Triggered by phrases like 'polish this paragraph,' 'check the grammar,' 'rewrite in academic English,' or keywords like ma

    Ready to connect★ 5k

    github.com/zebbern/claude-code-guide5k stars

    View details
  • secure-code-reviewSkillDatabases & data

    Systematically reviews code for SQL injection, XSS, SSRF, broken access control, cryptographic failures, and other common OWASP Top 10 vulnerabilities, providing vulnerable code examples and ready-to-use remediation guidance. Trigger this skill when users ask for a security review, vulnerability sca

    Ready to connect★ 5k

    github.com/zebbern/claude-code-guide5k stars

    View details
  • shodan-reconnaissanceSkillSearch

    This skill should be used when the user asks to "search for exposed devices on the internet," "perform Shodan reconnaissance," "find vulnerable services using Shodan," "scan IP ranges with Shodan," or "discover IoT devices and open ports." It provides comprehensive guidance for using Shodan's search

    Ready to connect★ 5k

    github.com/zebbern/claude-code-guide5k stars

    View details
  • smtp-penetration-testingSkillCommunication

    This skill should be used when the user asks to "perform SMTP penetration testing", "enumerate email users", "test for open mail relays", "grab SMTP banners", "brute force email credentials", or "assess mail server security". It provides comprehensive techniques for testing SMTP server security.

    Ready to connect★ 5k

    github.com/zebbern/claude-code-guide5k stars

    View details
  • sql-injection-testingSkillDatabases & data

    This skill should be used when the user asks to "test for SQL injection vulnerabilities", "perform SQLi attacks", "bypass authentication using SQL injection", "extract database information through injection", "detect SQL injection flaws", or "exploit database query vulnerabilities". It provides comp

    Ready to connect★ 5k

    github.com/zebbern/claude-code-guide5k stars

    View details
  • sql-insightSkillDatabases & data

    Translate natural language to SQL, optimize query performance, and interpret EXPLAIN plans for SQLite and PostgreSQL. Triggered when users ask to convert questions into SQL, improve slow queries, tune indexes, analyze execution plans, or mention keywords like NL2SQL, query tuning, or full table scan

    Ready to connect★ 5k

    github.com/zebbern/claude-code-guide5k stars

    View details
  • sqlmap-database-pentestingSkillDatabases & data

    This skill should be used when the user asks to "automate SQL injection testing," "enumerate database structure," "extract database credentials using sqlmap," "dump tables and columns from a vulnerable database," or "perform automated database penetration testing." It provides comprehensive guidance

    Ready to connect★ 5k

    github.com/zebbern/claude-code-guide5k stars

    View details
  • test-driven-devSkillAI & models

    Test-driven development with red-green-refactor loop. Use when user wants to build features or fix bugs using TDD, mentions "red-green-refactor", wants integration tests, or asks for test-first development.

    Ready to connect★ 5k

    github.com/zebbern/claude-code-guide5k stars

    View details
  • test-suite-architectSkillMonitoring & ops

    This skill should be used when establishing comprehensive QA testing processes for any software project. Use when creating test strategies, writing test cases following Google Testing Standards, executing test plans, tracking bugs with P0-P4 classification, calculating quality metrics, or generating

    Ready to connect★ 5k

    github.com/zebbern/claude-code-guide5k stars

    View details
  • three-best-practicesSkillMedia

    Three.js performance optimization and best practices guidelines. Use when writing, reviewing, or optimizing Three.js code. Triggers on tasks involving 3D scenes, WebGL/WebGPU rendering, geometries, materials, textures, lighting, shaders, or TSL.

    Ready to connect★ 5k

    github.com/zebbern/claude-code-guide5k stars

    View details
  • timeline-builderSkillAI & models

    Generate beautiful interactive timeline HTML pages from JSON data, with vertical, horizontal, or dual-side layouts, collapsible details, and custom colors. Ideal for project milestones, company histories, or resumes. Triggered when a user mentions 'timeline', 'history of events', 'project milestones

    Ready to connect★ 5k

    github.com/zebbern/claude-code-guide5k stars

    View details
  • top-web-vulnerabilitiesSkillSecurity

    This skill should be used when the user asks to "identify web application vulnerabilities", "explain common security flaws", "understand vulnerability categories", "learn about injection attacks", "review access control weaknesses", "analyze API security issues", "assess security misconfigurations",

    Ready to connect★ 5k

    github.com/zebbern/claude-code-guide5k stars

    View details
  • tos-clause-scannerSkillAI & models

    Audit Terms of Service, user agreements, and privacy policies for consumer risks, producing a structured report that flags unfair clauses, data traps, and liability issues. Trigger when a user asks to review, audit, or analyze a ToS, privacy policy, or user agreement, or mentions specific concerns l

    Ready to connect★ 5k

    github.com/zebbern/claude-code-guide5k stars

    View details
  • vc-industry-researchSkillDocs & knowledge

    Generate professional primary market / venture capital industry research reports, including sector deep-dives, investment memos, and market analysis. Produces detailed PDF reports covering TMT, consumer, healthcare, and industrials. Triggered by requests to analyze an industry, create a market repor

    Ready to connect★ 5k

    github.com/zebbern/claude-code-guide5k stars

    View details
  • windows-privilege-escalationSkillAI & models

    This skill should be used when the user asks to "escalate privileges on Windows," "find Windows privesc vectors," "enumerate Windows for privilege escalation," "exploit Windows misconfigurations," or "perform post-exploitation privilege escalation." It provides comprehensive guidance for discovering

    Ready to connect★ 5k

    github.com/zebbern/claude-code-guide5k stars

    View details
  • wireshark-analysisSkillFiles & storage

    This skill should be used when the user asks to "analyze network traffic with Wireshark", "capture packets for troubleshooting", "filter PCAP files", "follow TCP/UDP streams", "detect network anomalies", "investigate suspicious traffic", or "perform protocol analysis". It provides comprehensive tech

    Ready to connect★ 5k

    github.com/zebbern/claude-code-guide5k stars

    View details
  • wordpress-penetration-testingSkillSecurity

    This skill should be used when the user asks to "pentest WordPress sites", "scan WordPress for vulnerabilities", "enumerate WordPress users, themes, or plugins", "exploit WordPress vulnerabilities", or "use WPScan". It provides comprehensive WordPress security assessment methodologies.

    Ready to connect★ 5k

    github.com/zebbern/claude-code-guide5k stars

    View details
  • apk-redteam-pipelineSkillAI & models

    End-to-end Android APK red-team pipeline — automated APK acquisition (Play Store + apkpure + apkmirror fallback), jadx decompilation, secret/URL/JWT/Firebase grep, pinned-cert extraction, exported-component enumeration, Frida runtime instrumentation templates, intent-injection probes. Built from an

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • bug-bountySkillSecurity

    Complete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning (disclosed reports, tech stack research, mind maps, threat modeling), vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi,

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • bugcrowd-reportingSkillSearch

    Bugcrowd-specific reporting tactics complementing report-writing: VRT category search-and-fallback strategy when no exact match exists, manual severity override when VRT defaults underrate impact, severity-request paragraph as first body section, OOS-clause rebuttal templates (rate limiting on auth-

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • cloud-iam-deepSkillCloud & infra

    Cloud IAM red-team attack chain across AWS, Azure, GCP — focused on EXTERNAL exploitation paths and post-credential-discovery privilege analysis. Covers IAM enumeration (aws iam, az role, gcloud iam), STS/AssumeRole chaining, Azure Managed Identity abuse (via SSRF/leak), GCP service account JSON abu

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • enterprise-vpn-attackSkillSecurity

    External SSL VPN / remote-access appliance attack matrix — Cisco ASA/AnyConnect, Fortinet FortiGate/FortiOS, Citrix NetScaler/ADC, Palo Alto GlobalProtect, Pulse Secure / Ivanti Connect Secure, SonicWall, F5 Big-IP. Covers version fingerprinting, CVE matrix (2018-2026), AAA backend identification, d

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • evidence-hygieneSkillCommunication

    Evidence-capture and PoC-redaction discipline for bug-bounty submissions: cookie redaction protocol (which fields to mask, Preview annotation / Burp panel hiding / DevTools workflow), PII black-bar discipline (what to mask in other-user data — names, emails, phones, faces — vs what is safe to leave

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-api-misconfigSkillSecurity

    Hunt API security misconfiguration — mass assignment, prototype pollution, HTTP verb tampering. Mass assignment: send {is_admin:true, role:admin, verified:true} on profile/account/reset endpoints — server blindly applies. JWT signature/crypto forging (alg:none, key confusion, kid/jku) is owned by hu

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details

What is a skill?

A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.

54,855 of the 55,286 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.

Install one and every AI you use gets it

Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.

Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.

See how to connect your AI