Skills.
Give your AI a better way to work.
A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.
Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.
Filter by category
55,286 results · page 181 of 1,843
- View details
recon-scope-triageSkillAI & models
Triage ASM/recon output for ownership before testing — separate the target's real assets from namespace-collision noise. Automated recon keyword-matches on the brand name, so for any target whose name is a common/dictionary word, the output is dominated by assets belonging to UNRELATED same-named co
Ready to connect★ 5k
- View details
redteam-mindsetSkillAI & models
Red-team operator discipline — the mindset corrections that separate offensive testing from defensive WAPT. Built from authorized red-team work where conservative defaults caused multiple findings to be missed and one to be incorrectly retracted. Use at the START of any red-team engagement and again
Ready to connect★ 5k
- View details
redteam-report-templateSkillAI & models
Client-facing red-team deliverable format — codifies the Subject / Observations / Description / Impact / Recommendation / PoC structure used for external red-team engagements (not bug-bounty platform reports). Different audience, different tone, different cadence. Built from an authorized engagement
Ready to connect★ 5k
- View details
report-writingSkillAI & models
Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi — report templates, human tone guidelines, impact-first writing, CVSS 3.1 scoring, title formula, impact statement formula, severity decision guide, downgrade counters, pre-submit checklist. Validation gates and the submittability/always-r
Ready to connect★ 5k
- View details
security-arsenalSkillSecurity
Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, and conditionally-valid-with-chain table. Use when you need specific payloads for XSS/SSRF/SQLi/XXE/NoSQLi/command injection/SSTI/IDOR/path-traversal/HTTP smuggling/WebSocket/MFA bypass, or bypass techniques. Su
Ready to connect★ 5k
- View details
supply-chain-attack-reconSkillSecurity
External recon for software supply-chain attack surface — package-namespace squatting candidates, dependency-confusion vulnerabilities, GitHub Actions injection openings, container image registry exposure, SBOM mining, internal-package-name leakage, and CI/CD configuration exposure. Reconnaissance a
Ready to connect★ 5k
- View details
triage-validationSkillAI & models
Finding validation before writing any report — 7-Question Gate (all 7 questions), 4 pre-submission gates, always-rejected list, conditionally valid with chain table, CVSS 3.1 quick reference, severity decision guide, report title formula, 60-second pre-submit checklist. Use BEFORE writing any report
Ready to connect★ 5k
- View details
vmware-vcenter-attackSkillFiles & storage
VMware vSphere / vCenter Server external attack matrix — version fingerprinting, the high-impact CVE chain (CVE-2021-21972 vRealize unauth file upload, CVE-2021-21985 vSAN plugin RCE, CVE-2022-22954 Workspace ONE SSTI, CVE-2023-20887 Aria RCE, CVE-2024-37085 ESXi AD bypass, CVE-2023-34048 vCenter DC
Ready to connect★ 5k
- View details
web2-reconSkillWeb & browsing
Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis (LinkFinder, SecretFinder), continuous monitoring (new subdomain alerts, JS change detection, GitHub comm
Ready to connect★ 5k
- View details
web3-auditSkillSecurity
Smart contract security audit — 10 DeFi bug classes (accounting desync, access control, incomplete path, off-by-one, oracle, ERC4626, reentrancy, flash loan, signature replay, proxy), pre-dive kill signals (TVL < $500K etc), Foundry PoC template, grep patterns for each class, and real Immunefi paid
Ready to connect★ 5k
- View details
address-pr-commentsSkillDev tools
Triage and address GitHub PR review feedback for fallow, then implement the agreed fixes. Use when the user wants to inspect PR comments, requested changes, or unresolved review threads and act on them.
Ready to connect★ 5k
- View details
binary-loopSkillDev tools
Iteratively reduce Fallow binary size using cargo-bloat and release-build measurements while preserving features, performance, and compatibility.
Ready to connect★ 5k
- View details
browser-smoke-reviewSkillWeb & browsing
Use browser automation to review docs pages, preview URLs, rendered output, or web-facing fallow surfaces. Use when the user wants a screenshot-based review, browser smoke test, docs site check, or preview deployment inspection.
Ready to connect★ 5k
- View details
ci-formats-reviewSkillDocs & knowledge
Review SARIF, CodeClimate, compact, markdown, badge, and other CI-facing output formats for correctness and integrator expectations. Use when changes affect machine-consumed report formats or CI presentation layers.
Ready to connect★ 5k
- View details
cli-output-reviewSkillDev tools
Review fallow's human-readable CLI output for scanability, information hierarchy, empty states, and terminal compatibility. Use when changes affect human output, command UX, or text formatting in the CLI.
Ready to connect★ 5k
- View details
conformance-loopSkillDev tools
Iteratively improve Fallow analysis accuracy by comparing it with competing tools and verified source truth across a stable real-world corpus.
Ready to connect★ 5k
- View details
coverage-loopSkillDev tools
Iteratively improve Fallow Rust test coverage with cargo-llvm-cov, prioritizing meaningful untested behavior and preserving runtime correctness.
Ready to connect★ 5k
- View details
debug-false-positiveSkillDev tools
Diagnose and fix a Fallow false positive or false negative through extraction, resolution, graph, analysis, reporting, and real-consumer verification.
Ready to connect★ 5k
- View details
fallowSkillSecurity
Codebase intelligence for TypeScript and JavaScript. Static analysis reports changed-code risk, cleanup opportunities, duplication, circular dependencies, complexity hotspots, architecture boundaries, design-system drift, feature flags, and opt-in security candidates. Optional local similar-code dis
Ready to connect★ 5k
- View details
fix-gh-actionsSkillDev tools
Investigate and fix failing GitHub Actions checks for this repo or its PRs. Use when the user asks to debug CI failures, broken workflows, failed release jobs, or failing GitHub checks.
Ready to connect★ 5k
- View details
github-action-reviewSkillDev tools
Review fallow's GitHub Action, shell scripts, jq filters, annotations, review comments, and workflow integration. Use when changes touch action/, action.yml, GitHub review formatting, or CI shell/jq behavior.
Ready to connect★ 5k
- View details
gitlab-ci-reviewSkillDev tools
Review fallow's GitLab CI integration, scripts, jq filters, MR comments, and report formatting. Use when changes touch ci/ or GitLab-specific output behavior.
Ready to connect★ 5k
- View details
json-output-reviewSkillDev tools
Review machine-readable JSON output changes for schema stability, determinism, and downstream usability. Use when changes affect JSON output, result fields, ordering, snapshots, or integration contracts.
Ready to connect★ 5k
- View details
lsp-reviewSkillDev tools
Review fallow's LSP server behavior, diagnostics, code actions, code lens, and protocol-facing UX. Use when changes touch crates/lsp or LSP-visible behavior.
Ready to connect★ 5k
- View details
mcp-reviewSkillAI & models
Review fallow's MCP server for tool contract clarity, output stability, and agent usability. Use when changes touch crates/mcp or AI-agent integration surfaces.
Ready to connect★ 5k
- View details
open-draft-prSkillDev tools
Prepare local changes for review with an intentional commit, push, and ready PR for fallow. Use when the user wants to publish work, open a PR, or turn local changes into a reviewable branch.
Ready to connect★ 5k
- View details
panel-review-loopSkillDev tools
Iteratively review and improve a Fallow user-facing surface across representative real-world projects until the panel has no blocking concerns.
Ready to connect★ 5k
- View details
perf-loopSkillDev tools
Iteratively optimize Fallow performance with stable benchmarks, before-and-after evidence, and correctness gates.
Ready to connect★ 5k
- View details
sig-auditSkillDev tools
Measure Fallow maintainability using the repository's SIG system properties and update the evidence-backed audit report.
Ready to connect★ 5k
- View details
sig-audit-loopSkillDev tools
Iteratively improve Fallow maintainability using measured SIG audit deltas, retaining only changes that improve the targeted property without regressions.
Ready to connect★ 5k
What is a skill?
A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.
54,855 of the 55,286 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.
Install one and every AI you use gets it
Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.
Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.