Security skills.
2,241 security skills, including defi-amm-security, fastapi-patterns and hipaa-compliance, are listed on ahel today. Each one has a page of its own that says what it does and whether ahel can serve it in Claude, Claude Code, ChatGPT, Codex and Cursor.
Category: Security
2,241 results · page 71 of 75
- View details
lookup-liberty91SkillSecurity
Use when you need Liberty91 platform intelligence — what actually happened (deduplicated Threat Events with every source, Admiralty reliability/credibility and verification stage), whether an IOC is already known to your account, the canonical threat library (actors, malware, vulnerabilities, cluste
Ready to connect
- View details
lookup-shodanSkillSecurity
Use when you need host reconnaissance for an IP or domain — open ports, services, banners, OS detection, vulnerabilities. For domains, resolves DNS first then queries the IP. Commonly invoked by /ip-investigation and /domain-investigation. Retrieval only.
- View details
malware-analysisSkillSecurity
Use when characterising a malware sample, the user asks "what does this binary do?" / "analyse this hash deeply", or `/hash-investigation` flags a novel sample warranting deeper review. Static + dynamic methodology, behavioural indicators, sandbox interpretation.
- View details
otx-apiSkillSecurity
AlienVault OTX API reference. Community threat intelligence pulses and indicator lookups.
- View details
shodan-apiSkillSecurity
Shodan API reference. Host reconnaissance, port scanning, and vulnerability data.
- View details
sigma-writingSkillSecurity
Use when the user asks for a SIGMA detection rule, "write a SIGMA rule for X", or `/hash-investigation` / `/malware-analysis` surfaces behaviour worth a vendor-agnostic detection. Format spec + writing guide.
- View details
sopsSkillSecurity
Use when the user asks about CTI standard operating procedures (daily triage, IOC processing, flash-report cadence, threat-actor profile updates, briefing schedule), or wants to look up a specific SOP.
- View details
stix-bundleSkillSecurity
STIX 2.1 bundle creation reference. Object types, relationships, and JSON templates for structured threat intelligence sharing. Includes the per-claim mapping of evidence grades (access level and claim support) from /quality-of-information-check to STIX confidence, and the reverse mapping on import.
Ready to connect
- View details
supply-chain-threatsSkillSecurity
Use when the user asks about supply-chain attacks, third-party / vendor compromise (SolarWinds, Kaseya, 3CX, MOVEit, XZ-utils-style), software-bill-of-materials risks, or library / dependency-injection attacks. Self-updating knowledge cell.
Ready to connect
- View details
threat-actor-profilingSkillSecurity
Use when the user asks to build or update a threat-actor profile, "tell me about actor X" / "profile actor Y", or another skill needs the canonical profile template (attribution, TTPs, campaigns, infrastructure patterns, intelligence gaps).
Ready to connect
- View details
threat-assessmentSkillSecurity
Structured threat assessment methodology. Intent + Capability + Opportunity = Threat Level. Use when formally evaluating a threat. Prefers graded evidence items from /quality-of-information-check and runs that skill first when handed raw URLs or text. Confidence is capped by the weakest load-bearing
Ready to connect
- View details
vulnerability-intelligenceSkillSecurity
Use when prioritising CVEs, the user asks "should we patch X first?" / "is CVE-YYYY-NNNNN being exploited?", or wants weaponisation, EPSS, and KEV context combined into a patch-now-vs-later recommendation.
- View details
writing-assessmentsSkillSecurity
Use when the user asks to write a threat / risk / vulnerability assessment, or wants the appropriate template for each type. Distinct structures and section ordering per assessment kind. Prefers graded evidence items from /quality-of-information-check and runs that skill first when handed raw URLs o
Ready to connect
- View details
auth-flow-reviewerSkillSecurity
Deep review of authentication, authorization, session, and SSO flows specifically - token lifecycle, session fixation, logout behavior, and OAuth/SSO correctness. Use when reviewing or designing login, session, or SSO code specifically.
Ready to connect
- View details
cors-csrf-auditorSkillSecurity
Reviews Cross-Origin Resource Sharing configs, CSRF protections, SameSite cookies, and origin security.
Ready to connect
- View details
find-bugs-diffSkillSecurity
Find bugs, security vulnerabilities, and code quality issues in local branch changes. Use when asked to review changes, find bugs, security review, or audit code on the current branch.
Ready to connect
- View details
flutter-apk-securitySkillSecurity
Review Flutter Android APK/AAB release artifacts for manifest, permission, cleartext traffic, exported component, embedded secret, signing, size, WebView, deep link, and third-party service risks.
Ready to connect
- View details
jwt-security-hardenerSkillSecurity
Audits JSON Web Token implementations for algorithm confusion attacks, key rotation, expiration, and replay defense.',
Ready to connect
- View details
mcp-configureSkillSecurity
Configure the LaunchDarkly hosted MCP server during onboarding. Use when the parent LaunchDarkly onboarding skill reaches the MCP offer, after the first flag works. Supports Cursor, Claude Code, Windsurf, GitHub Copilot, and other MCP-compatible agents. OAuth authentication; no API keys for the host
Ready to connect
- View details
am-agent-code-security-auditorSkillSecurity
Comprehensive security analysis and vulnerability detection for codebases. Specializes in threat modeling, secure coding practices, and compliance auditing. Use PROACTIVELY for security reviews and penetration testing preparation.
Ready to connect
- View details
am-agent-security-auditorSkillSecurity
Security engineer focused on vulnerability detection, threat modeling, and secure coding practices. Use for security-focused code review, threat analysis, or hardening recommendations.
Ready to connect
- View details
codexkit-api-design-reviewerSkillSecurity
Review REST and GraphQL API designs for consistency, usability, and best practices. Covers naming conventions, versioning strategy, error format, pagination, authentication patterns, and breaking change detection. Use when reviewing API specs, designing new APIs, or auditing existing endpoints.
Ready to connect
- View details
crowdsec-service-apiSkillSecurity
Use when the user wants to drive the CrowdSec Console **Service API (SAPI)** — the premium cloud REST API at admin.api.crowdsec.net — to programmatically manage blocklists (add/remove/bulk IPs, share, subscribe engines), allowlists, firewall/appliance integrations (Palo Alto, Fortinet, Cisco, F5, So
- View details
golang-rulesSkillSecurity
Comprehensive Go coding rules covering style, patterns, testing, and security
Ready to connect
- View details
python-reviewSkillSecurity
Expert Python code reviewer specializing in PEP 8 compliance, Pythonic idioms, type hints, security, and performance. Use for all Python code changes.
Ready to connect
- View details
python-rulesSkillSecurity
Comprehensive Python coding rules covering style, patterns, testing, and security
Ready to connect
- View details
springboot-verificationSkillSecurity
Verification loop for Spring Boot projects: build, static analysis, tests with coverage, security scans, and diff review before release or PR.
Ready to connect
- View details
typescript-rulesSkillSecurity
Comprehensive TypeScript/JavaScript coding rules covering style, patterns, testing, and security
Ready to connect
- View details
accelint-security-best-practicesSkillSecurity
Comprehensive security audit and vulnerability detection for JavaScript/TypeScript applications following OWASP Top 10. Use when (1) Users say 'audit security', 'check for vulnerabilities', 'security review', 'implement authentication', 'secure this code', (2) Adding authentication, API endpoints, f
Ready to connect
- View details
agentic-delegationSkillSecurity
Delegate exploration sweeps to Haiku subagents and bulk writing to Sonnet subagents while the orchestrator keeps architecture, security-sensitive edits, and commits; use at the start of any multi-step task in this repo to minimize token spend by delegating to cheaper models.
Ready to connect
Looking for something else?
Security is one category of skills on ahel. Browse all skills, or open another category above.