Security skills.

2,241 security skills, including defi-amm-security, fastapi-patterns and hipaa-compliance, are listed on ahel today. Each one has a page of its own that says what it does and whether ahel can serve it in Claude, Claude Code, ChatGPT, Codex and Cursor.

Category: Security

2,241 results · page 62 of 75

  • threat-modelerSkillSecurity

    STRIDE threat modeling and privacy impact assessment to generate security/privacy requirements. Use before requirement-architect to shift security left.

    Ready to connect★ 54

    github.com/agile-v/agile_v_skills54 stars

    View details
  • api-design-opsSkillSecurity

    API design patterns for REST, gRPC, and GraphQL. Use for: api design, REST, gRPC, GraphQL, protobuf, schema design, api versioning, pagination, rate limiting, error format, OpenAPI, API authentication, JWT, OAuth2, API gateway, webhook, idempotency.

    Ready to connect★ 53

    github.com/0xdarkmatter/claude-mods53 stars

    View details
  • asus-router-opsSkillSecurity

    ASUS router config and hardening: Asuswrt-Merlin, security hardening, encrypted DNS (DoT/DoH), VPN (WireGuard/OpenVPN), guest networks, VLAN/IoT isolation, AiMesh, AiProtection. Triggers on: asus router, asuswrt, merlin, wireguard router, AiProtection, AiMesh, nvram, jffs, IoT isolation.

    Ready to connect★ 53

    github.com/0xdarkmatter/claude-mods53 stars

    View details
  • auth-bypassSkillSecurity

    Detect authentication and authorization bypass vulnerabilities including missing auth middleware, JWT algorithm confusion, IDOR, and session fixation.

    Ready to connect★ 53

    github.com/byamb4/find-cve-agent50 stars

    View details
  • code-injection-codegenSkillSecurity

    Detect code injection vulnerabilities in packages that dynamically generate or evaluate code via new Function(), eval(), vm.run*, or template literal interpolation.

    Ready to connect★ 53

    github.com/byamb4/find-cve-agent50 stars

    View details
  • corkSkillSecurity

    Every Cork API operation as one CLI and MCP server, plus cross-client risk attribution, exploitability-first vulnerability triage, overdue-compliance detection, and stale-connector health checks that a stateless API mirror cannot answer in a single call. Trigger phrases: `which Cork clients got wors

    ★ 53

    github.com/servosity/msp-skills53 stars

    Reviewed instructions are unavailable in ahel. This skill cannot be added until its reviewed copy is available.

    View details
  • entity-expansionSkillSecurity

    Detect XML/SVG/YAML entity expansion (Billion Laughs) vulnerabilities in parsers that allow unbounded entity definitions.

    Ready to connect★ 53

    github.com/byamb4/find-cve-agent50 stars

    View details
  • github-opsSkillSecurity

    GitHub remote operations and README authoring: repo creation, metadata, releases, issue/PR management with preview-before-send, README as a landing page (badge row, features-as-benefits, screenshots, Recent Updates), and read-only security auditing. Triggers on: write a README, improve the README, R

    Ready to connect★ 53

    github.com/0xdarkmatter/claude-mods53 stars

    View details
  • laravel-opsSkillSecurity

    Laravel framework patterns, Eloquent ORM, authentication, queues, and testing. Use for: laravel, eloquent, artisan, blade, php, sanctum, livewire, inertia, pest, phpunit, forge, vapor, queue, middleware, migration, factory, seeder.

    Ready to connect★ 53

    github.com/0xdarkmatter/claude-mods53 stars

    View details
  • method-clobberingSkillSecurity

    Detect method clobbering via user-controlled object keys that overwrite built-in methods like toString, valueOf, or hasOwnProperty, causing crashes or logic bypass.

    Ready to connect★ 53

    github.com/byamb4/find-cve-agent50 stars

    View details
  • msp-skills-conciergeSkillSecurity

    Use when the user has msp-skills installed and wants help choosing or installing connectors - it reads the live catalog, learns their PSA/RMM/backup/security/billing stack, recommends the connectors that fit, and installs only the ones they approve. Trigger phrases: `recommend which connectors I sho

    ★ 53

    github.com/servosity/msp-skills53 stars

    Reviewed instructions are unavailable in ahel. This skill cannot be added until its reviewed copy is available.

    View details
  • ninjaoneSkillSecurity

    Every NinjaOne report, plus a local store that answers fleet-wide questions no single API call can: patch compliance, backup gaps, AV blast-radius, health, drift. Trigger phrases: `check patch compliance in ninjaone`, `which ninjaone devices have no backup`, `ninjaone av threat sweep`, `ninjaone fle

    ★ 53

    github.com/servosity/msp-skills53 stars

    Reviewed instructions are unavailable in ahel. This skill cannot be added until its reviewed copy is available.

    View details
  • path-traversalSkillSecurity

    Detect path traversal and Zip Slip vulnerabilities where user-controlled path components can escape intended directories.

    Ready to connect★ 53

    github.com/byamb4/find-cve-agent50 stars

    View details
  • proofpointSkillSecurity

    Every TAP Threat Insight endpoint, plus a local threat store that answers the cross-endpoint questions - who is both attacked and clicking, what touched this user - inside Proofpoint's punishing daily quotas. Trigger phrases: `pull proofpoint siem events`, `who are my VAPs`, `decode this urldefe

    ★ 53

    github.com/servosity/msp-skills53 stars

    Reviewed instructions are unavailable in ahel. This skill cannot be added until its reviewed copy is available.

    View details
  • prototype-pollutionSkillSecurity

    Detect prototype pollution via object merge/clone/assign operations where __proto__ or constructor.prototype keys can modify Object.prototype.

    Ready to connect★ 53

    github.com/byamb4/find-cve-agent50 stars

    View details
  • recursion-dosSkillSecurity

    Detect stack overflow and infinite recursion DoS in recursive parsers, tree walkers, and serializers that lack depth limits.

    Ready to connect★ 53

    github.com/byamb4/find-cve-agent50 stars

    View details
  • redosSkillSecurity

    Detect Regular Expression Denial of Service (ReDoS) where crafted input causes catastrophic backtracking in regex patterns applied to user-controlled strings.

    Ready to connect★ 53

    github.com/byamb4/find-cve-agent50 stars

    View details
  • sandbox-escapeSkillSecurity

    Detect VM/sandbox escape vulnerabilities in packages using node:vm, simpleeval, or custom sandboxes that can be bypassed to achieve code execution.

    Ready to connect★ 53

    github.com/byamb4/find-cve-agent50 stars

    View details
  • sstiSkillSecurity

    Detect Server-Side Template Injection where user input is passed as the template string itself rather than as template variables, enabling code execution.

    Ready to connect★ 53

    github.com/byamb4/find-cve-agent50 stars

    View details
  • supply-chain-defenseSkillSecurity

    Behavioural-first defense against poisoned npm/PyPI/Composer/Cargo packages, malicious editor extensions and config-as-code repo poisoning, in the publish-to-advisory window CVE tools miss. Use when adding or bumping a dependency, when an advisory names a package you may run, when auditing CI OIDC t

    Ready to connect★ 53

    github.com/0xdarkmatter/claude-mods53 stars

    View details
  • techdebtSkillSecurity

    Technical debt detection and remediation. Run at session end to find duplicated code, dead imports, security issues, and complexity hotspots. Triggers: 'find tech debt', 'scan for issues', 'check code quality', 'wrap up session', 'ready to commit', 'before merge', 'code review prep'. Always uses par

    Ready to connect★ 53

    github.com/0xdarkmatter/claude-mods53 stars

    View details
  • work-with-authSkillSecurity

    Work on HFS authentication & authorization. Use for SMART-on-FHIR/OAuth2, JWT bearer validation, JWKS, scopes/permissions, token replay semantics, SMART discovery, and HFS_AUTH_* configuration.

    ★ 53

    github.com/heliossoftware/hfs51 stars

    Reviewed instructions are unavailable in ahel. This skill cannot be added until its reviewed copy is available.

    View details
  • auth0SkillSecurity

    Use when adding, fixing, or improving how an app authenticates users or protects an API, or when using or configuring any Auth0 feature — signing users in and out, sessions and tokens, guarding routes and endpoints, MFA, passwordless passkey login (WebAuthn), SSO, Organizations, RBAC, custom domains

    Ready to connect★ 52

    github.com/auth0/agent-skills52 stars

    View details
  • Code ReviewerSkillSecurity

    Professional code review expert providing constructive, actionable feedback focused on correctness, maintainability, security, and performance rather than code style preferences.

    Ready to connect★ 52

    github.com/kongfangxun/sofagent48 stars

    View details
  • council-planSkillSecurity

    Architect a feature with the Carmack Council before writing code. Use when explicitly asked to plan a feature, do a "council plan", "carmack plan", or invoke /council-plan. Carmack's philosophy chairs a council of domain experts — Troy Hunt (security), Martin Fowler (refactoring), Kent C. Dodds (fro

    Ready to connect★ 52

    github.com/samjhudson01/carmack-council52 stars

    View details
  • council-reviewSkillSecurity

    Perform a rigorous Carmack Council code review. Use when explicitly asked to review code, do a "council review", "carmack review", or invoke /council-review. Carmack's philosophy chairs a council of domain experts — Troy Hunt (security), Martin Fowler (refactoring), Kent C. Dodds (frontend), Matteo

    Ready to connect★ 52

    github.com/samjhudson01/carmack-council52 stars

    View details
  • crisp-executeSkillSecurity

    CRISP Execute — Sprint execution loop with change request management, security gates, product gates, and stakeholder reporting. Use after Phase S (Spec) is complete and crisp-state.json shows ready_for_execute: true. Triggers on "start sprint", "begin build", "execute", "sprint 1", "run sprints", or

    Ready to connect★ 52

    github.com/radekamirko/c.r.i.s.p52 stars

    View details
  • Address GitHub PR review comments from the current branch with gh-address-commentsSkillSecurity

    Find the open PR for the current branch, gather unresolved review comments, and drive a focused comment-resolution workflow with gh-authenticated context.

    Ready to connect★ 51

    github.com/agentskillexchange/skills51 stars

    View details
  • Aperture Wallet GuideSkillSecurity

    Answer Aperture Wallet questions from first-party product, security, network, release, app-screen, and Journal sources while enforcing explicit wallet-secret and no-transaction safety boundaries.

    Ready to connect★ 51

    github.com/agentskillexchange/skills51 stars

    View details
  • attack-path-analysisSkillSecurity

    Use when Codex is already in the attack-path-analysis phase of a security scan or the user explicitly asks to trace a security finding from source to sink and calibrate severity. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.

    Ready to connect★ 51

    github.com/bex-co/bex-security45 stars

    View details

Looking for something else?

Security is one category of skills on ahel. Browse all skills, or open another category above.

See how to connect your AI