Skills.

Give your AI a better way to work.

A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.

Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.

Filter by category

55,286 results · page 180 of 1,843

  • hunt-mfa-bypassSkillCommunication

    Hunt MFA / 2FA bypass — 7 distinct patterns. (1) MFA not enforced on sensitive endpoints (password change, email change accept without MFA challenge), (2) MFA-step skip via direct navigation to post-login URL, (3) MFA-token replay (same code accepted twice), (4) brute-force the 6-digit OTP without r

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-miscSkillSecurity

    Hunting skill for misc vulnerabilities. Built from 225 public bug bounty reports. Use when hunting misc on any target.

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-nextjsSkillSecurity

    Hunt Next.js specific vulnerabilities — Server Actions arbitrary function execution, Middleware auth bypass via static asset paths, ISR cache poisoning, Image Optimization SSRF (/_next/image), RSC payload leakage, getServerSideProps injection, source map exposure, debug endpoint leakage. Use when ta

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-nodejsSkillFiles & storage

    Hunt Node.js specific vulnerabilities — Prototype Pollution → RCE chains (lodash/merge/assign), Express trust proxy misconfiguration, child_process/eval injection, template engine SSTI (EJS/Pug/Handlebars), path traversal in file servers, require() injection, environment variable exfil via /proc/sel

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-nosqliSkillDatabases & data

    Hunt NoSQL Injection — MongoDB operator injection ($where, $regex, $gt, $ne), CouchDB, Redis command injection, auth bypass via NoSQLi, data dump. Use when target uses MongoDB/Mongoose, CouchDB, Redis, or shows NoSQL error messages.

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-ntlm-infoSkillAI & models

    Hunt NTLM/Negotiate information disclosure on internet-reachable IIS/SharePoint/Exchange. Anonymous NTLM Type-2 challenge capture leaks NetBIOS domain, internal DNS forest, computer name, AD timestamp via AV_PAIRS structure. Default Windows-installer hostnames (WIN-XXXXXXXXXXX pattern) signal lazy p

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-oauthSkillSecurity

    Hunting skill for oauth vulnerabilities. Built from 19 public bug bounty reports. Use when hunting oauth on any target.

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-open-redirectSkillSecurity

    Hunt Open Redirect — all types including low-impact, chained to OAuth token theft → ATO, phishing chains. URL parameter manipulation, JavaScript redirect, meta refresh, header injection. Use when hunting redirect bugs or building ATO chains.

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-race-conditionSkillSecurity

    Hunting skill for race condition vulnerabilities. Built from 12 public bug bounty reports including modern HTTP/2 single-packet attack cases (James Kettle DEF CON 2023 "Smashing the State Machine"; RyotaK / Flatt Security 10,000-request first-sequence-sync expansion 2024). Covers coupon double-redem

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-rag-vectorSkillDatabases & data

    Hunt vector-store / embedding-layer weaknesses in RAG pipelines (OWASP LLM08 Vector and Embedding Weaknesses) — persistent corpus poisoning that survives across sessions and users (distinct from one-shot indirect prompt injection, which is owned by hunt-llm-ai), cross-tenant vector-database IDOR (un

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-rceSkillSecurity

    Hunting skill for rce vulnerabilities. Built from 67 public bug bounty reports. Use when hunting rce on any target.

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-samlSkillAI & models

    Hunt SAML / SSO attacks. Patterns: XML Signature Wrapping (XSW) — modify Assertion while keeping Signature valid by relocating signed element, comment injection in NameID (admin@target.com<!--evil-->@attacker.com → some parsers see admin@target.com), signature stripping (remove Signature element ent

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-sessionSkillCommunication

    Hunt Session Management vulnerabilities — session fixation (no regeneration on login), insufficient invalidation on logout / password-change / email-change, predictable or low-entropy session IDs, JWT-as-session with no exp/revocation, refresh-token rotation/reuse-detection gaps, OAuth/SSO session l

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-sharepointSkillSecurity

    Hunt Microsoft SharePoint Server (2013/2016/2019/Subscription Edition) on-prem farms — anonymous endpoint enumeration, version disclosure, legacy SOAP login bypass (Authentication.asmx), ToolShell precondition chain (CVE-2025-53770), SafeControl reflection enumeration via Picker.aspx, NTLM Type-2 AD

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-source-leakSkillFiles & storage

    Hunt source code and build artifact leakage — JavaScript source maps (.js.map) reconstructing TypeScript/ES6 source, Swagger/OpenAPI JSON endpoint discovery, .env/.git exposure, webpack chunks with hardcoded secrets, robots.txt/security.txt recon, build-info files, asset-manifest.json API route disc

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-spa-apiSkillWeb & browsing

    Discover a single-page-app's hidden backend API from its public JS bundle, then test that API for broken access control / missing authentication. One of the highest-yield web plays in modern recon — SPAs ship their entire backend route map to the browser, and the API behind them is frequently missin

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-springbootSkillSecurity

    Hunt Spring Boot specific vulnerabilities — Actuator endpoints (heapdump, env, loggers, mappings, shutdown), Spring Expression Language (SpEL) injection → RCE, H2 console RCE, Jolokia JMX exposure, Spring4Shell (CVE-2022-22965), Spring Cloud Function SPEL (CVE-2022-22963), heap dump credential extra

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-sqliSkillDatabases & data

    Hunting skill for sqli vulnerabilities. Built from 12 public bug bounty reports including modern NoSQL injection (Rocket.Chat CVE-2021-22911 MongoDB $regex, Mongoose ORM CVE-2024-53900 $where bypass), modern ORM raw-fragment SQLi (Django CVE-2024-42005, Sequelize GHSA-wrh9-cjv3-2hpw), second-order S

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-ssrfSkillDatabases & data

    Hunting skill for ssrf vulnerabilities. Built from 15 public bug bounty reports including AWS metadata SSRF (HackerOne $25k Analytics PDF, Shopify Exchange $25k, Capital One 106M-record breach, Dropbox/HelloSign $4,913), GCP metadata SSRF (Snapchat $4k), Azure IMDS SSRF (Azure DevOps $15k chain, Cha

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-sstiSkillAI & models

    Hunt server-side template injection (SSTI) across Jinja2 (Flask/Django), Twig (Symfony), Freemarker (Java), ERB (Rails), Spring, Velocity, Mako, Thymeleaf, Smarty. Detection probes use double-curly and dollar-curly math expressions evaluated server-side. Once an engine is fingerprinted, escalate to

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-subdomainSkillCommunication

    Hunting skill for subdomain takeover vulnerabilities. Includes modern provider fingerprints — Microsoft Azure DevOps `cloudapp.azure.com` regional-pool re-issue (1-click OAuth ATO via wildcard `reply_to`, Binary Security), Zendesk help-desk takeover → email interception → password reset chain (0xpri

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-tls-networkSkillCommunication

    Hunt TLS/SSL and DNS misconfigurations — missing HSTS (downgrade attack), weak cipher suites, expired/invalid certificates, mTLS bypass, missing SPF/DKIM/DMARC (email spoofing), DNS Zone Transfer (AXFR), dangling CNAME subdomain takeover, CAA records. Most of these are Info/Low on their own — this s

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-websocketSkillCommunication

    Hunt WebSocket vulnerabilities — Cross-Site WebSocket Hijacking (CSWSH), missing/weak Origin validation on the WS handshake, no per-message authentication, message tampering, socket.io namespace/room authorization bypass, and handshake-layer Upgrade smuggling. Use when target has WebSocket endpoints

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • hunt-xxeSkillDocs & knowledge

    Hunting skill for xxe vulnerabilities. Built from 10 public bug bounty reports including SVG-upload XXE, Office-doc (PPTX/DOCX) XXE, SOAP XXE, SAML AssertionConsumer XXE, blind OOB XXE via DTD callback, parameter-entity XXE, XXE-to-LFI, XXE-to-SSRF, and XXE-to-RCE chains (Adobe Commerce CosmicSting

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • ios-redteam-pipelineSkillSecurity

    End-to-end iOS red-team pipeline — IPA acquisition (App Store extraction, TestFlight, enterprise/ad-hoc sideload), class-dump/Hopper/Ghidra static analysis, Info.plist + entitlements + Keychain secret extraction, App Transport Security (ATS) misconfig + certificate-pinning bypass (frida-ios-dump, ob

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • m365-entra-attackSkillWeb & browsing

    Microsoft 365 / Entra ID red-team attack chain — current 2026 reality. AADSTS code reference, user enumeration vectors (with hardening status), Smart Lockout math, Conditional Access bypass options, ROPC + SAML SSO browser flow, Burp/Playwright templates. Built from authorized red-team work where RO

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • meme-coin-auditSkillSecurity

    Meme coin and token security audit — rug pull detection (honeypot, hidden mint, fee manipulation, LP lock bypass), Solana SPL token analysis (freeze authority, mint authority, metadata mutability), Token-2022 extension risks (transfer hooks, permanent delegate), DEX liquidity pool attacks (sandwich

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • mid-engagement-ir-detectionSkillSecurity

    Methodology for detecting client SOC patches, attacker activity, and security-state changes that occur DURING a red-team engagement — and converting those observations into deliverable findings. Built from authorized red-team work where the client patched a confirmed SQLi within 30 minutes of detect

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • okta-attackSkillCommunication

    Okta-as-IdP red-team attack chain — tenant discovery, user enumeration (multiple vectors), authentication flow analysis (factors enumeration, push-notification fatigue, SMS bypass), password spray with lockout discipline, Okta-specific phishing primitives (kits, FastPass abuse, OIDC redirect_uri tam

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details
  • osint-methodologySkillAI & models

    Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments. Covers the 5-stage recon pipeline (seed discovery, asset expansion, enrichment, exposure analysis, reporting), asset-graph discipline with 29 asset types, severity rubric (CRITICAL/HIGH/MEDIUM

    Ready to connect★ 5k

    github.com/elementalsouls/claude-bughunter5k stars

    View details

What is a skill?

A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.

54,855 of the 55,286 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.

Install one and every AI you use gets it

Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.

Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.

See how to connect your AI