Security skills.
1,995 security skills, including brandkit, security-review and defi-amm-security, are listed on ahel today. Each one has a page of its own that says what it does and whether ahel can serve it in Claude, Claude Code, ChatGPT, Codex and Cursor.
Category: Security
1,995 results · page 56 of 67
- View details
Blackpoint Vulnerability ManagementSkillSecurity
Blackpoint Cyber (CompassOne) exposure data across four lenses: host vulnerability findings and the filters that matter (CVE, severity, patch and exploit availability), scan history, dark-web credential and data leaks, and internet-facing external exposures — plus how to combine them into a prioriti
Ready to connect
- View details
boring-google-signup-setupSkillSecurity
Teach a boring-ui child app how to enable Google signup with @hachej/boring-core. Use when the user asks for Google auth, Google OAuth, social signup, or how to turn on Google sign-in/sign-up in a child app.
Ready to connect
- View details
cipp-groupsSkillSecurity
Tenant-scoped Entra/M365 group enumeration and creation in CIPP, the four group types (Security, Microsoft 365, Distribution, Mail-Enabled Security) and when to pick each, and the boundary where CIPP's group surface ends and Graph/M365 takes over.
Ready to connect
- View details
cipp-securitySkillSecurity
Read-only access to a tenant's Conditional Access policy graph and named locations through CIPP: policy state semantics, the findings that matter in a CA review, portfolio drift detection, and why CA writes are absent from the MCP surface.
Ready to connect
- View details
Cyber Insurance QuestionnairesSkillSecurity
Drafting tool-verified answers to cyber-insurance renewal, new-business, and underwriter security questionnaires: the standard recurring question set (MFA everywhere including privileged accounts, EDR coverage ratio, tested and immutable backups, documented and tested IR plan, security awareness tra
Ready to connect
- View details
Human Risk ScoringSkillSecurity
Explainable per-user and per-org human risk scoring from training-completion status, phishing-simulation failure history, and optional real-world click/attack-targeting signal: the weighted factor table, three-tier bucketing, per-org rollup as a distribution rather than a blended number, and gracefu
Ready to connect
- View details
KnowBe4 PhishingSkillSecurity
KnowBe4 phishing simulations: campaign creation and lifecycle, security test management, recipient interaction tracking (sent, opened, clicked, reported), phish-prone percentage calculation, template selection, landing pages, and click tracking.
Ready to connect
- View details
Proofpoint PeopleSkillSecurity
Proofpoint People-Centric Security fundamentals: Very Attacked People (VAP) reports, attack index scoring, click susceptibility, top clickers, and user risk categorization for targeting security controls and training.
Ready to connect
- View details
Proofpoint Threat IntelligenceSkillSecurity
Proofpoint Threat Intelligence fundamentals: campaign tracking, threat families and actors, indicators of compromise (IOCs), and how campaign/IOC data enriches individual TAP threat events.
Ready to connect
- View details
shellSkillSecurity
Shell and session operations after an attack module already established command execution, a raw shell, webshell channel, container/runner shell, or remote session. This module does not own exploitation and should not pull SSH/WinRM/RDP authentication or vulnerability-to-shell chains out of Web/AD/C
Ready to connect
- View details
standard-security-authSkillSecurity
Security & Authentication Specialist - Expert in JWT, cookie-based auth, MFA, and generic security patterns
Ready to connect
- View details
Training Completion TrackingSkillSecurity
Security-awareness training completion across whatever training/awareness platform is connected: assignment-overdue versus cadence-overdue detection, per-campaign and per-org completion-rate calculation, ranking clients that have fallen behind a contracted cadence, and the unmeasured-versus-0% disti
Ready to connect
- View details
WYRE MCP Gateway TroubleshootingSkillSecurity
WYRE MCP Gateway diagnostics: missing vendor tools, OAuth failures, "Failed to update tool access" errors, expired credentials, and the request flow through mcp-remote to gateway to vendor container to external API.
Ready to connect
- View details
gha-security-reviewSkillSecurity
Use when reviewing GitHub Actions workflows for exploitable vulnerabilities — finds pwn-request patterns, expression injection, credential escalation, config poisoning, and supply chain risks, and reports only HIGH and MEDIUM confidence findings with concrete attack paths.
Ready to connect
- View details
mandu-securitySkillSecurity
Security best practices for Mandu applications. Use when implementing authentication, authorization, input validation, or protecting against common vulnerabilities. Triggers on guard, auth, CSRF, XSS, or security tasks.
Ready to connect
- View details
pr-security-reviewSkillSecurity
Use when reviewing a pull request for security issues — automatically analyzes the diff for vulnerabilities, hardcoded secrets, injection risks, and broken access control before merging
Ready to connect
- View details
ajax-securitySkillSecurity
Use when registering or handling WordPress AJAX over admin-ajax.php - wp_ajax_{action} / wp_ajax_nopriv_{action} hooks, JavaScript that posts to admin_url('admin-ajax.php'), or wp.apiFetch / fetch calls to custom actions. Verifies the nonce with check_ajax_referer, gates the action with current_user
Ready to connect
- View details
capability-permission-checksSkillSecurity
Use when adding admin pages, menu items, AJAX/REST handlers, action links, or any code that performs a privileged operation in WordPress. Gates actions with current_user_can() using the correct capability (not roles), including per-object checks like edit_post, and pairs the check with a nonce. Prev
Ready to connect
- View details
claude-pentest-skillsSkillSecurity
Structured web application penetration testing with OWASP methodology, curated payload references, 6-gate validation, and professional report generation
Ready to connect
- View details
cron-background-job-securitySkillSecurity
Use when scheduling WordPress cron events with wp_schedule_event / wp_schedule_single_event or writing the callback that runs on a cron hook. Treats cron callbacks as running without a logged-in user, re-checks authorization against stored context rather than current_user_can, keeps secrets out of c
Ready to connect
- View details
dependency-supply-chain-securitySkillSecurity
Use when a plugin or theme bundles a third-party PHP or JavaScript library, enqueues an asset from a CDN, fetches or executes code at runtime, manages dependencies with Composer, or prepares the distributable zip. Covers core-handle-first enqueuing, dependency vetting with composer audit, lockfile p
Ready to connect
- View details
gutenberg-block-editor-securitySkillSecurity
Use when building dynamic blocks or block-editor features - a render_callback, server-side rendered blocks via ServerSideRender, REST-backed block data, or register_rest_field for the editor. Sanitizes block attributes per type, escapes server render output, sets a real permission_callback on editor
Ready to connect
- View details
harms-checkSkillSecurity
Use when building anything USER-FACING (or with persuasion/retention/cancellation/consent/pricing flows, or that touches vulnerable people) to surface design-level harm the security/privacy/compliance gates miss: dark/deceptive patterns and foreseeable misuse. Assumes the product works as designed a
Ready to connect
- View details
http-api-ssrf-preventionSkillSecurity
Use when a plugin or theme makes outbound HTTP requests with the WordPress HTTP API - wp_remote_get, wp_remote_post, wp_remote_request - especially when any part of the URL comes from user input, options, or webhooks. Uses wp_safe_remote_* with wp_http_validate_url, allowlists hosts, blocks internal
Ready to connect
- View details
multisite-securitySkillSecurity
Use when writing code that runs on a WordPress multisite network - switch_to_blog, network admin pages, get_sites, or capabilities that differ between site and network scope. Uses manage_network / manage_network_options and is_super_admin correctly, restores context with restore_current_blog, isolat
Ready to connect
- View details
nonces-csrf-protectionSkillSecurity
Use when handling any form submission, AJAX request, admin-post action, settings page, link that triggers an action, or any other user-initiated request in a WordPress plugin or theme. Generates nonces with wp_nonce_field / wp_create_nonce and verifies them with check_admin_referer, check_ajax_refer
Ready to connect
- View details
object-injection-deserializationSkillSecurity
Use when code calls unserialize, maybe_unserialize, or stores serialized PHP in options, meta, or transients from untrusted input. Avoids unserialize on attacker-controlled data, prefers json_encode / json_decode, and when unserialize is unavoidable passes ['allowed_classes' => false]. Prevents PHP
Ready to connect
- View details
oma-imageSkillSecurity
Multi-vendor AI image generation with authentication-aware parallel dispatch. Routes to Codex (gpt-image-2 via ChatGPT OAuth), Antigravity (gemini-2.5-flash-image aka nano-banana via `agy` CLI + Gemini Code Assist), and Pollinations (flux/zimage, free with signup). Use for image generation, image cr
Ready to connect
- View details
output-escapingSkillSecurity
Use when echoing or printing any dynamic value in WordPress PHP or templates — into HTML, attributes, URLs, inline JavaScript, or textareas. Escapes at the point of output with esc_html, esc_attr, esc_url, esc_js, esc_textarea, or wp_kses_post, including the i18n variants (esc_html__, esc_attr_e). P
Ready to connect
- View details
rest-api-securitySkillSecurity
Use when registering WordPress REST API routes with register_rest_route or building custom endpoints. Sets a real permission_callback (never __return_true for writes), defines args with sanitize_callback and validate_callback, enforces capabilities and per-object checks, and escapes any HTML in resp
Ready to connect
Looking for something else?
Security is one category of skills on ahel. Browse all skills, or open another category above.