Security skills.
1,995 security skills, including brandkit, security-review and defi-amm-security, are listed on ahel today. Each one has a page of its own that says what it does and whether ahel can serve it in Claude, Claude Code, ChatGPT, Codex and Cursor.
Category: Security
1,995 results · page 53 of 67
- View details
CrowdStrike Fusion Workflow BuilderSkillSecurity
Create, validate, import, execute, and export CrowdStrike Falcon Fusion SOAR workflows. CRITICAL: You MUST run action_search.py to get real 32-char hex action IDs BEFORE writing any YAML. NEVER write PLACEHOLDER values for action IDs — resolve every ID via the live API first. Templates and example f
Ready to connect★ 58
- View details
devexpress-xaf-securitySkillSecurity
XAF Security System covering authentication (password, Windows, OAuth2), user and role setup for EF Core and XPO, authorization and Permission Policy, type/object/member/navigation permissions, current-user and role checks, security APIs including ApplicationUser, ISecurityUserWithRoles, ISecurityPr
Ready to connect★ 57
- View details
HexStrike AI MCP IntegrationSkillSecurity
Instructions for utilizing the HexStrike AI MCP Server for automated pentesting and security research.
Ready to connect★ 58
- View details
- View details
PentestAgent Framework ExecutionSkillSecurity
Instructions for dropping into the PentestAgent TUI/CLI interface for black-box target assessment.
Ready to connect★ 58
- View details
- View details
threat-model-authoringSkillSecurity
Draft phase 3.5 of a threat model from the orientation brief, surface analysis, and maintainer answers. USE WHEN writing threat-model.md to the canonical §1.1–§1.19 structure. Combines concise prose with the §1.7 trust table and contract matrix, §1.8 output statements, §1.17 disposition table, §1.1
Ready to connect★ 56
- View details
threat-model-backtestSkillSecurity
Backtest phase 3.6 of threat-model production against historical findings before sign-off. USE WHEN a draft model must prove it can uniquely route real reports. Builds a stratified producer-side corpus across components and contract dimensions, clusters large corpora by sink and attack class, and ro
Ready to connect★ 56
- View details
threat-model-interviewSkillSecurity
Run phase 3.4 maintainer question waves for threat-model production. USE WHEN inferred claims need ratification or interview-first versus draft-first mode must be chosen. Asks 3–7 prioritized proposed-answer questions per wave; wave 1 always covers scope, intended use, configuration support, and hos
Ready to connect★ 56
- View details
threat-model-reconSkillSecurity
Orient and mine an open-source repository for threat-model production phases 3.1–3.2. USE WHEN starting a threat model or surveying security posture before modeling. Reads README, top-level docs, SECURITY/THREAT docs, maintainer issue rulings, and changelog rationale; carves component families; flag
Ready to connect★ 56
- View details
threat-model-sidecarSkillSecurity
Emit and validate the §1.19 machine-readable companions: threat-model.yaml using schema threat-model-sidecar/v2, and the flat threat-model.json export conforming to schema.json. USE WHEN an orchestrated threat model is ready for publication, automated or AI-assisted triage, dependency compatibility
Ready to connect★ 56
- View details
threat-model-surfaceSkillSecurity
Perform phase 3.3 deep analysis of an in-scope attack surface for a threat model. USE WHEN the orientation brief is ready and code must be read to derive the §1.7 per-input trust table and contract-dimension matrix, §1.5 no-surprise side-effects inventory, §1.4 reachability preconditions, and §1.8 o
Ready to connect★ 56
- View details
threat-model-triageSkillSecurity
Triage one inbound vulnerability report, scanner hit, fuzzer artifact, or AI finding against a finished threat model. USE WHEN asked whether a finding is valid or in scope. Applies the §1.1 routing algorithm and §1.17 precedence to assign exactly one closed disposition with section and provenance ci
Ready to connect★ 56
- View details
ase-code-analyzeSkillSecurity
Analyze the source code for problems in either the logic and semantics and its related control flow, performance and efficiency, or security.
Ready to connect★ 56
- View details
identity-compromiseSkillSecurity
Investigate suspected account compromise — brute force followed by success, impossible travel, privilege escalation and lateral movement across Linux and Windows; use when a user account appears in suspicious authentication activity.
Ready to connect★ 57
- View details
threat-actor-attributionSkillSecurity
Assess possible threat-actor or campaign links using the Diamond Model and ATT&CK group data, expressed with calibrated estimative language; use only when a case shows enough TTP or infrastructure overlap to justify attribution discussion.
Ready to connect★ 57
- View details
edgeone-clawscan-zhSkillSecurity
A comprehensive OpenClaw security scanning skill powered by Tencent Zhuque Lab's A.I.G (AI-Infra-Guard). Use when the user asks for a security checkup or security scan of the current OpenClaw environment, e.g. `开始安全体检`, `做一次安全体检`, `开始安全扫描`, `全面安全检查`, or `检查 OpenClaw 安全`; also use when the user asks
Ready to connect★ 56
- View details
javaSkillSecurity
Modern Java practices: design, errors, concurrency, security, testing, tooling. Targets Java 21 LTS baseline; Java 25 LTS features called out explicitly. Use when writing or reviewing Java code.
Ready to connect★ 54
- View details
mcporterSkillSecurity
Use the mcporter CLI to list, configure, authenticate, and call MCP servers/tools (HTTP or stdio), including ephemeral servers, config editing, and CLI/type generation.
Ready to connect★ 56
- View details
mobile-pro-maxSkillSecurity
Mobile development intelligence. 12 domains, 9 stacks, 250+ entries. Actions: plan, build, create, design, implement, review, fix, improve, optimize, enhance, refactor, check mobile code. Domains: pattern, package, error, perf, test, security, interface, arch, idiom, anti, tooling, dependency. Stack
Ready to connect★ 55
- View details
moltguardSkillSecurity
Open-source OpenClaw security plugin: local prompt sanitization + injection detection. Full source code at github.com/openguardrails/moltguard
Ready to connect★ 56
- View details
phpSkillSecurity
Modern PHP 8.5 practices: type system, OOP, security, architecture, async, testing, tooling. Use when writing or reviewing PHP code.
Ready to connect★ 54
- View details
php-pro-maxSkillSecurity
PHP development intelligence. 12 domains, 8 stacks, 300+ entries. Actions: plan, build, create, design, implement, review, fix, improve, optimize, enhance, refactor, check PHP code. Domains: pattern, package, error, perf, test, security, interface, arch, idiom, anti, tooling, dependency. Stacks: lar
Ready to connect★ 55
- View details
- View details
security-warnSkillSecurity
Use when you need to test a skill that produces a security warning (not block).
Ready to connect★ 56
- View details
skill-vetter-zhSkillSecurity
A security-first review tool for AI agent skills. Use before installing any skill from ClawHub, GitHub, or other sources. Checks for red flags, permission scopes, and suspicious patterns.
Ready to connect★ 56
- View details
better-your-harnessSkillSecurity
Run an AI Harness health check on a local project and produce a visual HTML report. Scans five layers: security and hygiene (.gitignore, plaintext secrets, Agent permissions), context quality (AI readability, cold-start cost, noise ratio, directory structure), tooling (Skill/MCP/sub-agents, includin
Ready to connect★ 55
- View details
Gemini CLISkillSecurity
Consult Google Gemini CLI for second opinions on architecture, debugging, and security audits. Use Gemini's 1M+ context window for comprehensive code analysis. Compare Flash (fast) vs Pro (thorough) vs 3-Pro-Preview (cutting-edge).
Ready to connect★ 55
- View details
sdp-tokenizationSkillSecurity
Explain, plan, and prototype tokenization workflows on Solana Developer Platform using the supported public docs and API surface. Use when a consumer wants to issue a stablecoin, tokenized security, loyalty token, or other asset with SDP.
Ready to connect★ 55
- View details
agile-v-adrSkillSecurity
Authoring, approval, immutability, and supersession of Architecture Decision Records (ADRs) in the Agile V lifecycle. Load when recording a significant, long-lived architectural, platform, tooling, or security decision.
Ready to connect★ 54
Looking for something else?
Security is one category of skills on ahel. Browse all skills, or open another category above.