Skills.

Give your AI a better way to work.

A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.

Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.

Filter by category

55,286 results · page 179 of 1,843

  • hunt-aspnetSkillAI & models

    Hunt ASP.NET-specific surface — ViewState deserialization (signed-only vs encrypted), machineKey recovery, dual-parser MAC-bypass anti-pattern, request-validator bypass, trace.axd/elmah.axd disclosure, load-balanced ViewState cross-node failures, SafeControl enumeration via reflection, customErrors

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-atoSkillCommunication

    Hunt account takeover taxonomy — 9 distinct paths to ATO, plus chains. Paths: (1) password reset flaws (host-header injection redirects token, predictable/numeric token, Referer leak, no-expiry/reuse), (2) email change without re-auth, (3) OAuth account-link CSRF, (4) MFA bypass (per hunt-mfa-bypass

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-auth-bypassSkillSecurity

    Hunting skill for auth bypass vulnerabilities. Built from 12 public bug bounty reports across SAML XSW / parser-differential (GitHub Enterprise CVE-2025-25291/25292), SAML signature stripping (Uber, Rocket.Chat, samlify CVE-2025-47949), SAML domain enforcement bypass via control characters (HackerOn

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-brute-forceSkillCommunication

    Hunt Missing/Weak Rate Limiting — login brute force, OTP/2FA brute force (10^6 keyspace), password-reset-token brute, credential stuffing, username/email enumeration via error-string / status-code / timing differences, weak password policy, missing CAPTCHA (CAPTCHA token replay / single-use / concur

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-business-logicSkillSecurity

    Hunting skill for business logic vulnerabilities. Built from 12 public bug bounty reports. Covers coupon-race-stacking (Instacart, Stripe, Reverb), negative-quantity-in-cart price tampering (Upserve, Eternal/Zomato), decimal/fraction price-field overflow (Shipt), client-side checkout amount trust on

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-cache-poisonSkillCloud & infra

    Hunting skill for cache poison vulnerabilities. Built from 10 public bug bounty reports including X-Forwarded-Host poisoning, X-HTTP-Method-Override / GCS cache, reflected→stored XSS via cache, classic Omer-Gil Web Cache Deception, Cloudflare Cache Deception Armor bypass, session-token cache decepti

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-captcha-bypassSkillAI & models

    Hunt CAPTCHA Bypass — 6 distinct patterns: (1) CAPTCHA field simply omitted from the request (server-side validation absent), (2) CAPTCHA token replayed from a solved challenge (no single-use enforcement), (3) CAPTCHA response accepted on a different endpoint than it was solved on (no binding to act

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-cicdSkillFiles & storage

    Hunt CI/CD pipeline vulnerabilities — GitHub Actions workflow injection (pull_request_target Pwnrequest + ${{ }}-into-shell), self-hosted runner poisoning, OIDC trust-policy abuse, Jenkins script-console RCE and CVE-2024-23897 file read, GitLab CI runner-token registration, Terraform state file leak

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-clickjackingSkillSecurity

    Hunt Clickjacking — missing X-Frame-Options / CSP frame-ancestors lets an attacker embed the target page in an invisible iframe and trick victims into clicking buttons they cannot see (UI redressing). Targets: login flows, money transfers, account settings, OAuth confirmation pages. Confirm by fetch

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-cloud-misconfigSkillFiles & storage

    Hunt cloud / infrastructure misconfigurations. AWS: public S3 buckets (s3:GetObject anonymous), permissive bucket policies (PutObjectAcl public-write), exposed CloudFront origin, public Lambda function URL, public RDS snapshot, IAM credentials in JS bundles, AWS metadata accessible via SSRF. GCP: pu

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-corsSkillCommunication

    Hunt CORS Misconfiguration — origin-reflection with credentials, null-origin trust, subdomain-regex bypass (unanchored vs unescaped-dot vs prefix-only), pre-flight (OPTIONS) gating bypass, postMessage origin checks. High only when an attacker-controlled origin can perform a CREDENTIALED cross-origin

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-csrfSkillSecurity

    Hunting skill for csrf vulnerabilities. Built from 15 public bug bounty reports including modern variants — SameSite=Lax sibling-subdomain bypass (Argo CD CVE-2024-22424), GraphQL mutations-via-GET (GitLab $3,370), framework-wide CSRF middleware disabled (Stripe Dashboard $5,000), path-traversal CSR

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-deserializationSkillAI & models

    Hunt Insecure Deserialization — Java gadget chains (ysoserial), PHP object injection (phpggc), Python pickle RCE, .NET BinaryFormatter, Ruby Marshal.load, JNDI/Log4Shell. RCE via deserialization is almost always Critical. Use when target runs Java, PHP serialization, Python pickle, .NET, or Ruby on

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-dispatchSkillAI & models

    Skill-set loader for /hunt orchestrator. Fingerprints the target, picks the right platform attack skills, and loads the Red Team or WAPT skill set. Use when /hunt has just received a mode answer (redteam or wapt + blackbox|greybox) and needs to load the appropriate skills and print the taxonomy. Not

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-domSkillCommunication

    Hunt client-side DOM vulnerabilities — DOM Clobbering (overwrite JS globals via HTML injection), PostMessage hijacking (missing origin check), Service Worker abuse (intercept requests from same-origin script), CSS Injection/Exfiltration (attribute selectors → token char-by-char via OOB), client-side

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-exceptional-conditionsSkillFiles & storage

    Hunt mishandling of exceptional conditions — feed an endpoint malformed/unexpected input (wrong type, broken JSON, oversized field, null byte) and make it fail OPEN or leak internals: a verbose stack-trace / framework error page that discloses ORM internals, server file paths, library versions, or a

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-fintech-graphqlSkillSecurity

    Hunt fintech-specific GraphQL vulnerabilities: money-movement mutations (transfers, redemptions, withdrawals, card top-ups), ledger/balance/portfolio query IDOR, decimal-precision and rounding abuse, idempotency-key bypass enabling double-spend, KYC/PII field-level authorization gaps, and admin-over

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-forgot-passwordSkillCommunication

    Hunt Forgot Password / Account Recovery Authentication Flaws — 5 distinct patterns: (1) username enumeration via different responses for valid vs invalid email, (2) reset token exposed directly in the API response body, (3) reset token not invalidated after use (replay), (4) password reset link work

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-graphqlSkillSecurity

    Hunting skill for graphql vulnerabilities. Built from 12 public bug bounty reports across IDOR via node() / GID, mutation IDOR including AI/LLM features, cross-tenant IDOR, SSRF via argument, batching-DoS, query-cost-bypass, SQLi via argument, broken-object-level-authz, auth-bypass via unscoped muta

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-grpcSkillFiles & storage

    Hunt gRPC vulnerabilities — server reflection enabled (enumerate all services/methods), missing authentication / metadata-stripping on internal endpoints, plaintext gRPC over HTTP/2, internal endpoint disclosure, proto file leakage, gRPC-Web/grpc-gateway transcoding injection, and HTTP/2 Rapid Reset

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-host-headerSkillSecurity

    Hunt Host Header Injection — password reset poisoning → ATO, web cache poisoning via unkeyed Host/X-Forwarded-Host, routing-based SSRF (Host picks upstream → cloud metadata/internal services), path-override SSRF/ACL-bypass (X-Original-URL/X-Rewrite-URL), OAuth redirect_uri/issuer poisoning, and abso

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-html-injectionSkillSecurity

    Hunt HTML Injection — user-supplied input is rendered as raw HTML in the response without sanitisation, allowing an attacker to inject arbitrary HTML tags (but not necessarily JavaScript). Lower severity than XSS but enables phishing, UI manipulation, and credential harvesting via injected forms. Us

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-http-smugglingSkillAI & models

    Hunt HTTP request smuggling (CL.TE, TE.CL, H2.CL, H2.TE). Cause: front-end proxy and back-end server disagree on where one request ends and the next begins (Content-Length vs Transfer-Encoding header parsing inconsistency). CL.TE: front-end uses CL, back uses TE → smuggle by sending TE: chunked but

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-idorSkillSecurity

    Hunting skill for idor vulnerabilities. Built from 26 public bug bounty reports. Use when hunting idor on any target.

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-jwt-cryptoSkillSecurity

    Hunt JWT cryptographic failures — alg:none signature-stripping and RS256→HS256 key-confusion that let an attacker forge a token for any identity (e.g. an admin) without knowing a secret. Use when the app authenticates with a JSON Web Token (an `eyJ...` Bearer token in the Authorization header, a coo

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-k8sSkillCloud & infra

    Hunt Kubernetes & Docker — API anonymous access, kubelet 10250 exec (SPDY/WebSocket, NOT plain POST) and the simpler /run primitive, etcd 2379 unauth, dashboard skip-login, RBAC misconfig, secret/SA-token abuse, docker.sock host escape, runc/container-escape (Leaky Vessels CVE-2024-21626), API-serve

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-laravelSkillSecurity

    Hunt Laravel specific vulnerabilities — Debug mode leakage (APP_DEBUG=true exposes full stack trace + env vars), Laravel Telescope/Horizon dashboard unauthorized access, Ignition RCE (CVE-2021-3129), Signed URL manipulation, Queue Worker abuse, mass assignment via Eloquent, deserialization via cooki

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-ldapSkillSearch

    Hunt LDAP Injection and XPath Injection — authentication bypass, blind char-by-char attribute exfiltration, AD user/group enumeration, XML-store XPath bypass. Covers the LDAP special-character set (* ( ) \\ NUL /), search-filter-context vs DN-injection, parenthesis-balancing, AND/OR filter logic, an

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-lfiSkillFiles & storage

    Hunt Local File Inclusion (LFI), Remote File Inclusion (RFI), and Path Traversal — /etc/passwd read, log poisoning → RCE, PHP filter-chain RCE (no upload needed), php:// / data:// / zip:// / phar:// wrappers, RFI via allow_url_include, directory traversal read/write/delete. Covers OOB/blind LFI conf

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-llm-aiSkillWeb & browsing

    Hunt LLM/AI feature bugs — prompt injection, indirect injection, exfiltration via tool-use/markdown, ASCII smuggling, agentic AI security (OWASP Agentic Apps 2026, ASI01-ASI10). Patterns: direct injection ('ignore previous instructions'), indirect injection via documents/web pages/email the model re

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details

What is a skill?

A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.

54,855 of the 55,286 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.

Install one and every AI you use gets it

Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.

Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.

See how to connect your AI