Security skills.
1,995 security skills, including brandkit, security-review and defi-amm-security, are listed on ahel today. Each one has a page of its own that says what it does and whether ahel can serve it in Claude, Claude Code, ChatGPT, Codex and Cursor.
Category: Security
1,995 results · page 57 of 67
- View details
scaffold-apiSkillSecurity
Generate a new authenticated Next.js API route following RDO project conventions
Ready to connect
- View details
security-auditing-code-reviewSkillSecurity
Use when auditing or code-reviewing an existing WordPress plugin or theme for security issues, triaging a vulnerability report, or hardening inherited code. Provides a systematic methodology — locate trust boundaries, inventory sensitive sinks, trace their controls and data flows, then triage confir
Ready to connect
- View details
security-headers-cspSkillSecurity
Use when adding HTTP response headers to a WordPress site or plugin: Content-Security-Policy (or Report-Only), X-Content-Type-Options, frame protection (X-Frame-Options or frame-ancestors), Referrer-Policy, Permissions-Policy, HSTS, Secure/HttpOnly/SameSite cookie flags, or CORS on REST responses. C
Ready to connect
- View details
settings-options-securitySkillSecurity
Use when building an options or settings page with the WordPress Settings API - register_setting, add_settings_field, settings_fields, an options.php form, or update_option / get_option on plugin data. Attaches a sanitize_callback to every setting, gates the page with manage_options, relies on Setti
Ready to connect
- View details
shortcode-block-securitySkillSecurity
Use when registering a shortcode with add_shortcode or a dynamic block with a render_callback, or processing shortcode / block attributes. Normalizes attributes with shortcode_atts, validates against allowlists, and escapes all rendered output for its context with esc_html, esc_attr, esc_url, or wp_
Ready to connect
- View details
tdmcp-quality-auditSkillSecurity
Run or maintain the full tdmcp repo quality-audit team: command sweeps, all package/Makefile/CI gates, security review, usability/flow review, refactor/test-gap analysis, coverage hardening, QA, and follow-up fix waves. Use whenever the user asks for a complete audit, improve repo/code quality, test
Ready to connect
- View details
woocommerce-securitySkillSecurity
Use when a plugin extends WooCommerce - reading or writing orders, customer data, or hooking checkout, REST, or the Store API. Sanitizes input with wc_clean, gates shop actions with WooCommerce capabilities like edit_shop_orders, minimizes stored payment data, and escapes customer PII on output. Pre
Ready to connect
- View details
wp-cli-securitySkillSecurity
Use when registering a WP-CLI command with WP_CLI::add_command or writing command logic. Validates and sanitizes positional and associative arguments, does not assume a logged-in user or capability context, avoids printing secrets, and confirms destructive operations. Prevents injection and unsafe a
Ready to connect
- View details
apple-firmware-inspectorSkillSecurity
Apple firmware: inspect and reverse-engineer IPSWs, kernelcaches, dyld shared caches, private headers, entitlements, Mach-O binaries, KEXTs, and security internals with `ipsw`.
Ready to connect
- View details
verificationSkillSecurity
Full agent verification suite. Runs security, patterns, quality, and language-specific checks. Use when asked to "verify agent", "verify my agent", "audit agent", or "full verification".
Ready to connect
- View details
verify-securitySkillSecurity
Verify code for security issues including hardcoded secrets, input validation, error exposure, and dependency vulnerabilities. Use when asked to "verify security", "check for secrets", or "scan for vulnerabilities".
Ready to connect
- View details
ci-cd-reliability-architectureSkillSecurity
Establishes idempotency, self-containment, immutable artifacts, self-healing, zero-downtime, and zero-knowledge security for CI/CD pipelines, including delivery-strategy choice, evidence-gated release, and production promotion. Use this skill when designing, auditing, or debugging any workflow, rele
Ready to connect
- View details
inbound-triageSkillSecurity
Maintainer-only. Use when triaging inbound GitHub issues and pull requests on skyf0xx/hedgehog — "triage the issues", "check the PRs", "review inbound", "what's in the queue". Reads each item read-only, judges it for security and for whether it is real, then fixes and closes or comments and closes.
Ready to connect
- View details
odoo-grill-meSkillSecurity
Odoo-specific grilling session that stress-tests addon plans, migrations, model/view/security designs, OWL frontend changes, and verification strategy. Use when the user wants to be grilled on an Odoo plan/design, asks to stress-test an addon architecture, or mentions grill me in an Odoo context.
Ready to connect
- View details
review-advancedSkillSecurity
Rigorous sequential-audit code review with a dedicated security block and cited pedagogical lessons. Customize for your project.
Ready to connect
- View details
review-fullstackSkillSecurity
Complete code review of a fullstack MR/PR with 8 sequential audits (Clean Architecture, DDD, React Best Practices, SOLID, Testing, Code Quality, Security, Performance). The audit set is the deduplicated union of review-front and review-back — no audit runs twice. An orchestrator runs each audit one
Ready to connect
- View details
storybook-pentestSkillSecurity
Pentest Storybook components two ways. Whether they break under stress, and whether they actually do their job well. Test one story, a component group, or the whole Storybook, and write every finding into an OKF bundle with screenshots, severity, and a reproducible URL. The break pass probes extreme
Ready to connect
- View details
wordpress-mcp-devSkillSecurity
Build and maintain modern WordPress plugins and MCP servers, including hybrid WordPress+MCP products. Use when implementing plugin architecture (PHP, REST API, Gutenberg/admin/page-builder integrations), MCP tooling (TypeScript/Python, stdio/HTTP transport), security hardening, licensing/updates, an
Ready to connect
- View details
wordpress-security-reviewSkillSecurity
Use when the user asks 'is my site secure', 'run a security audit', 'check for vulnerabilities', 'was my site hacked', or 'fix the vulnerable plugins'. Runs the Respira security audit, reads its indicators, coverage and known vulnerabilities honestly, never calls a partial scan clean, and fixes what
Ready to connect
- View details
wordpress-site-dnaSkillSecurity
Use when the user says 'analyze my wordpress site', 'what is running on my site', 'site dna', or 'what plugins are on my site'. Detects every page builder, audits active versus dead-weight plugins, maps content structure, finds orphaned shortcodes, and checks performance and security posture.
Ready to connect
- View details
analyzing-activist-investor-vulnerabilitiesSkillSecurity
Evaluates corporate vulnerability to shareholder activism with governance assessment, valuation gaps, and operational improvement opportunities. Use when assessing activist risk, identifying vulnerabilities, or preparing defensive analyses.
Ready to connect
- View details
analyzing-competitive-landscapesSkillSecurity
Maps competitive dynamics with market positioning, feature comparison, funding histories, and differentiation assessment. Use when analyzing startup competition, mapping market landscapes, or identifying competitive threats.
Ready to connect
- View details
analyzing-sovereign-credit-riskSkillSecurity
Evaluates sovereign creditworthiness with fiscal analysis, external vulnerability, political risk, and institutional quality assessment. Use when analyzing sovereign risk, assessing country credit, or evaluating government bond exposure.
Ready to connect
- View details
composeSkillSecurity
An operating system designed from the core up for agents and agentic security requirements. Built on seL4 microkernel with capability-based security and agent-native vibe-coding.
Ready to connect
- View details
composio-cliSkillSecurity
Help users operate the published Composio CLI to find the right tool, connect accounts, inspect schemas, execute tools, subscribe to trigger events with `composio listen`, script workflows with `composio run`, and call authenticated app APIs with `composio proxy`. Use when the user asks how to do so
Ready to connect
- View details
dopplerSkillSecurity
Doppler CLI workflows for secrets management in this workspace. Covers creating projects non-interactively (agent-friendly), renaming the default envs to development/preview/production, uploading secrets, type-safe env access in TypeScript apps, CI integration via GitHub Actions, and syncing secrets
Ready to connect
- View details
hermes-sessionSkillSecurity
An operating system designed from the core up for agents and agentic security requirements. Built on seL4 microkernel with capability-based security and agent-native vibe-coding.
Ready to connect
- View details
linux-guestSkillSecurity
An operating system designed from the core up for agents and agentic security requirements. Built on seL4 microkernel with capability-based security and agent-native vibe-coding.
Ready to connect
- View details
- View details
sddf-netSkillSecurity
An operating system designed from the core up for agents and agentic security requirements. Built on seL4 microkernel with capability-based security and agent-native vibe-coding.
Ready to connect
Looking for something else?
Security is one category of skills on ahel. Browse all skills, or open another category above.