Security skills.
1,995 security skills, including brandkit, security-review and defi-amm-security, are listed on ahel today. Each one has a page of its own that says what it does and whether ahel can serve it in Claude, Claude Code, ChatGPT, Codex and Cursor.
Category: Security
1,995 results · page 54 of 67
- View details
agile-v-complianceSkillSecurity
Risk management, CAPA protocol, human gate approval records, AI agent security controls, and periodic revalidation. Load when running gates, handling CAPAs, or auditing compliance and security posture.
Ready to connect★ 54
- View details
build-agent-nestjsSkillSecurity
NestJS backend build agent for REST/GraphQL APIs, microservices, and enterprise backends. Extends build-agent with NestJS architectural patterns, dependency injection, testing strategies, and security best practices. Use when building NestJS applications.
Ready to connect★ 54
- View details
skill-snitchSkillSecurity
Security auditing for MOOLLM skills - static analysis and runtime surveillance
Ready to connect★ 54
- View details
auth-bypassSkillSecurity
Detect authentication and authorization bypass vulnerabilities including missing auth middleware, JWT algorithm confusion, IDOR, and session fixation.
Ready to connect★ 53
- View details
code-injection-codegenSkillSecurity
Detect code injection vulnerabilities in packages that dynamically generate or evaluate code via new Function(), eval(), vm.run*, or template literal interpolation.
Ready to connect★ 53
- View details
entity-expansionSkillSecurity
Detect XML/SVG/YAML entity expansion (Billion Laughs) vulnerabilities in parsers that allow unbounded entity definitions.
Ready to connect★ 53
- View details
method-clobberingSkillSecurity
Detect method clobbering via user-controlled object keys that overwrite built-in methods like toString, valueOf, or hasOwnProperty, causing crashes or logic bypass.
Ready to connect★ 53
- View details
path-traversalSkillSecurity
Detect path traversal and Zip Slip vulnerabilities where user-controlled path components can escape intended directories.
Ready to connect★ 53
- View details
prototype-pollutionSkillSecurity
Detect prototype pollution via object merge/clone/assign operations where __proto__ or constructor.prototype keys can modify Object.prototype.
Ready to connect★ 53
- View details
recursion-dosSkillSecurity
Detect stack overflow and infinite recursion DoS in recursive parsers, tree walkers, and serializers that lack depth limits.
Ready to connect★ 53
- View details
redosSkillSecurity
Detect Regular Expression Denial of Service (ReDoS) where crafted input causes catastrophic backtracking in regex patterns applied to user-controlled strings.
Ready to connect★ 53
- View details
sandbox-escapeSkillSecurity
Detect VM/sandbox escape vulnerabilities in packages using node:vm, simpleeval, or custom sandboxes that can be bypassed to achieve code execution.
Ready to connect★ 53
- View details
sstiSkillSecurity
Detect Server-Side Template Injection where user input is passed as the template string itself rather than as template variables, enabling code execution.
Ready to connect★ 53
- View details
work-with-authSkillSecurity
Work on HFS authentication & authorization. Use for SMART-on-FHIR/OAuth2, JWT bearer validation, JWKS, scopes/permissions, token replay semantics, SMART discovery, and HFS_AUTH_* configuration.
★ 53
- View details
auth0SkillSecurity
Use when adding, fixing, or improving how an app authenticates users or protects an API, or when using or configuring any Auth0 feature — signing users in and out, sessions and tokens, guarding routes and endpoints, MFA, SSO, Organizations, RBAC, custom domains, Universal Portals for hosted account
Ready to connect★ 52
- View details
council-planSkillSecurity
Architect a feature with the Carmack Council before writing code. Use when explicitly asked to plan a feature, do a "council plan", "carmack plan", or invoke /council-plan. Carmack's philosophy chairs a council of domain experts — Troy Hunt (security), Martin Fowler (refactoring), Kent C. Dodds (fro
Ready to connect★ 52
- View details
council-reviewSkillSecurity
Perform a rigorous Carmack Council code review. Use when explicitly asked to review code, do a "council review", "carmack review", or invoke /council-review. Carmack's philosophy chairs a council of domain experts — Troy Hunt (security), Martin Fowler (refactoring), Kent C. Dodds (frontend), Matteo
Ready to connect★ 52
- View details
crisp-executeSkillSecurity
CRISP Execute — Sprint execution loop with change request management, security gates, product gates, and stakeholder reporting. Use after Phase S (Spec) is complete and crisp-state.json shows ready_for_execute: true. Triggers on "start sprint", "begin build", "execute", "sprint 1", "run sprints", or
Ready to connect★ 52
- View details
Address GitHub PR review comments from the current branch with gh-address-commentsSkillSecurity
Find the open PR for the current branch, gather unresolved review comments, and drive a focused comment-resolution workflow with gh-authenticated context.
Ready to connect
- View details
Aperture Wallet GuideSkillSecurity
Answer Aperture Wallet questions from first-party product, security, network, release, app-screen, and Journal sources while enforcing explicit wallet-secret and no-transaction safety boundaries.
Ready to connect
- View details
api-design-opsSkillSecurity
API design patterns for REST, gRPC, and GraphQL. Use for: api design, REST, gRPC, GraphQL, protobuf, schema design, api versioning, pagination, rate limiting, error format, OpenAPI, API authentication, JWT, OAuth2, API gateway, webhook, idempotency.
Ready to connect
- View details
asus-router-opsSkillSecurity
ASUS router config and hardening: Asuswrt-Merlin, security hardening, encrypted DNS (DoT/DoH), VPN (WireGuard/OpenVPN), guest networks, VLAN/IoT isolation, AiMesh, AiProtection. Triggers on: asus router, asuswrt, merlin, wireguard router, AiProtection, AiMesh, nvram, jffs, IoT isolation.
Ready to connect
- View details
attack-path-analysisSkillSecurity
Use when Codex is already in the attack-path-analysis phase of a security scan or the user explicitly asks to trace a security finding from source to sink and calibrate severity. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.
Ready to connect★ 51
- View details
clean-finreport-enhancerSkillSecurity
Summarise a parsed financial statement table into year-on-year deltas using exact decimal arithmetic. Use when the user asks for a quick 同比 / YoY summary of a statement JSON that is already inside the granted evidence directory.
Ready to connect★ 51
- View details
Code ReviewerSkillSecurity
Professional code review expert providing constructive, actionable feedback focused on correctness, maintainability, security, and performance rather than code style preferences.
Ready to connect★ 51
- View details
deep-security-scanSkillSecurity
Use when the user asks for a deep, exhaustive, multi-pass, or variance-reducing repository-wide or scoped-path Codex Security scan. Run repeated complete independent Standard scans with the Codex Security deep-scan tool, which aggregates their validated findings and prepares the canonical artifacts;
Ready to connect★ 51
- View details
define-security-policySkillSecurity
Define, review, or update SECURITY.md guidance for a repository or component. Use when the user wants to clarify what Codex Security should review, what is out of scope, which security properties must hold, or whether existing guidance still matches the code.
Ready to connect★ 51
- View details
finding-discoverySkillSecurity
Use when Codex is already in the finding-discovery phase of a security scan or the user explicitly asks to discover candidate security findings in a repository or code change. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.
Ready to connect★ 51
- View details
fix-findingSkillSecurity
Use only when the user explicitly asks to fix and verify a validated or plausible security vulnerability. Do not use for ordinary bug fixes, correctness or design review findings, general validation, or full PR, commit, branch, patch, or repository scans.
Ready to connect★ 51
- View details
github-opsSkillSecurity
GitHub remote operations and README authoring: repo creation, metadata, releases, issue/PR management with preview-before-send, README as a landing page (badge row, features-as-benefits, screenshots, Recent Updates), and read-only security auditing. Triggers on: write a README, improve the README, R
Ready to connect
Looking for something else?
Security is one category of skills on ahel. Browse all skills, or open another category above.