Security skills.

2,241 security skills, including defi-amm-security, fastapi-patterns and hipaa-compliance, are listed on Ahel today. Each one has a page of its own that says what it does and whether Ahel can serve it in Claude, Claude Code, ChatGPT, Codex and Cursor.

Category: Security

2,241 results · page 73 of 75

  • br-auth-middlewareSkillSecurity

    Configure Better Route 1.1 authentication with JWT, custom bearer tokens, WordPress Application Passwords, or cookie nonces. Use when protecting routes, mapping verified claims to WordPress users, enforcing scopes, consuming the shared AuthContext identity, restoring native users after nested dispat

    Ready to connect

    github.com/lonsdale201/wp-agent-skills22 stars

    View details
  • br-error-contractSkillSecurity

    Produce and consume better-route 1.1 structured errors. Use for ApiException, Response, ErrorNormalizer, ResponseNormalizer, WP_Error conversion, OAuth RFC 6749 error_format, status/code/details/headers, Retry-After, validation_failed, idempotency/rate/optimistic-lock/Woo errors, leak prevention, or

    Ready to connect

    github.com/lonsdale201/wp-agent-skills22 stars

    View details
  • br-hmac-signatureSkillSecurity

    Configure Better Route 1.1 HMAC authentication for webhooks and server-to-server REST requests. Use when signing request timestamps, methods, paths, raw bodies, optional query strings, rotating key IDs, or consuming the shared HMAC AuthContext identity.

    Ready to connect

    github.com/lonsdale201/wp-agent-skills22 stars

    View details
  • br-jwks-jwt-authSkillSecurity

    Configure Better Route 1.1 RS256 or ES256 JWT verification from a local or HTTPS JWKS. Use when integrating OIDC/OAuth bearer tokens, selecting keys by kid, validating issuer/audience/lifetime, or operating JWKS caching and refresh behavior safely.

    Ready to connect

    github.com/lonsdale201/wp-agent-skills22 stars

    View details
  • br-owned-resource-guardsSkillSecurity

    Add Better Route 1.1 ownership authorization to raw routes and Resource DSL endpoints. Use when authenticated users may access only their own records, orders, profiles, memberships, tokens, or subscriptions.

    Ready to connect

    github.com/lonsdale201/wp-agent-skills22 stars

    View details
  • br-resource-policySkillSecurity

    Configure better-route 1.1 Resource action and field authorization. Use for ResourcePolicy::publicReadPrivateWrite, adminOnly, capabilities, callbacks, Resource::policy, permissionCallback, per-action rules, wildcard rules, fieldPolicy, public Resource OpenAPI security, ownership policies, or review

    Ready to connect

    github.com/lonsdale201/wp-agent-skills22 stars

    View details
  • colyseus-authoritative-multiplayerSkillSecurity

    Use when planning, implementing, or QA-reviewing MMOOMM realtime multiplayer with Colyseus rooms, server-authoritative simulation, room authentication, Schema state, fixed tick processing, client interpolation or reconciliation, reconnection, or MVP scaling. Applies to `@universo-react/colyseus-serv

    Ready to connect

    github.com/teknokomo/universo-platformo-react22 stars

    View details
  • deserialization-securitySkillSecurity

    Block unsafe deserialization and unsafe XML parsing in Java, Python, .NET, PHP, and Ruby: gadget chains, unrestricted type resolution, external entity expansion, and safer formats. Use when parsing or deserializing data from an untrusted source, wiring cookies, sessions, queues, or RPC payloads, or

    Ready to connect

    github.com/shieldnet-360/secure-vibe22 stars

    View details
  • dynamic-verificationSkillSecurity

    Confirm or refute a vulnerability candidate against a live target with a deterministic probe, respecting authorization and scope. Use when a SAST or LLM review flags a possible injection or SSRF, when triaging a finding before filing a bug or shipping a fix, or when a verification result turns out w

    Ready to connect

    github.com/shieldnet-360/secure-vibe22 stars

    View details
  • erc8128SkillSecurity

    Sign and verify HTTP requests with Ethereum wallets using ERC-8128. Use when building authenticated APIs that need wallet-based auth, making signed requests to ERC-8128 endpoints, implementing request verification in servers, or working with agent-to-server authentication. Covers both the @slicekit/

    Ready to connect

    github.com/slice-so/erc812822 stars

    View details
  • fec-code-reviewSkillSecurity

    Use when the user asks for general frontend code review, PR review, merge-readiness assessment, architecture maintainability, type-safety, rendering/state risks, style consistency, testability gaps, or a cross-cutting review summary. Delegate deep security, accessibility, E2E, or performance investi

    Ready to connect

    github.com/bovinphang/frontend-craft22 stars

    View details
  • fec-dependency-upgradeSkillSecurity

    Use when planning, implementing, or reviewing frontend dependency upgrades, package migrations, lockfile changes, major framework version bumps, CVE remediation, peer dependency conflicts, ESM/CJS shifts, build-tool compatibility, or CI verification matrices; Chinese triggers include dependency upgr

    Ready to connect

    github.com/bovinphang/frontend-craft22 stars

    View details
  • fec-testing-strategySkillSecurity

    Use when planning or reviewing a frontend testing strategy, selecting the right test layer by risk, mapping coverage across static checks, unit tests, component tests, integration tests, E2E, Storybook/visual regression, a11y, security, performance, or CI gates. Do not use to write individual compon

    Ready to connect

    github.com/bovinphang/frontend-craft22 stars

    View details
  • fortify-change-reviewSkillSecurity

    Lightweight, AI-powered security review of code CHANGES (a diff, PR, or in-session edits) using the agent's own analysis — no Fortify scan engine or platform needed. Use when the user asks to "run a Fortify security review" / "Fortify change review", or when adding/modifying code touching authentica

    Ready to connect

    github.com/fortify/skills22 stars

    View details
  • fortify-dependency-upgradeSkillSecurity

    Perform dependency upgrade impact assessment, code fixes, and migration work. Use to remediate Fortify SCA / open source / software composition analysis findings — vulnerable third-party dependencies, CVEs/GHSAs, components flagged by FoD or SSC — by upgrading to a safe version and fixing any result

    Ready to connect

    github.com/fortify/skills22 stars

    View details
  • fortify-exploitability-analysisSkillSecurity

    Triage whether a known CVE/GHSA vulnerability is actually exploitable in this project. Use when the user wants a reachability verdict on a specific advisory — is the project really affected, or is the advisory noise? Analysis only; for fixes, hand off to fortify-dependency-upgrade.

    Ready to connect

    github.com/fortify/skills22 stars

    View details
  • graphql-securitySkillSecurity

    Bound and control a GraphQL endpoint: operation cost budgets, cost-based rate limiting, pre-registered operations, alias and batch abuse on authentication paths, introspection, cache keying, and untyped scalar inputs. Use when generating schemas, resolvers, or server config, wiring limits or persist

    Ready to connect

    github.com/shieldnet-360/secure-vibe22 stars

    View details
  • llm-app-securitySkillSecurity

    Securing a feature that calls an LLM: prompt injection as an unsolved input problem, bounding what model output is allowed to reach, tool authorization against the human rather than the model, approval gates on consequential actions, RAG context provenance, system-prompt leakage, and cost limits. Us

    Ready to connect

    github.com/shieldnet-360/secure-vibe22 stars

    View details
  • lw-site-manager-overviewSkillSecurity

    Operate and integrate with LW Site Manager 1.5.x through its WordPress Abilities REST surface or built-in MCP server. Covers the site-manager/* catalog, Application Password authentication, MCP enablement and domain lock, skill discovery, capability and object-level authorization, error contracts, a

    Ready to connect

    github.com/lonsdale201/wp-agent-skills22 stars

    View details
  • ml-securitySkillSecurity

    The model and data artifacts: checkpoint formats that execute code on load, provenance for a model you did not train, training-data poisoning and the ingestion controls that bound it, PII that survives into weights, and notebooks that commit their own output. Use when loading a model from disk, a Hu

    Ready to connect

    github.com/shieldnet-360/secure-vibe22 stars

    View details
  • ml4t-agent-governanceSkillSecurity

    Security and governance controls for autonomous financial agents. Use when agents can call tools, read untrusted content, or affect research or trading decisions.

    Ready to connect

    github.com/ml4t/skills22 stars

    View details
  • product-auditSkillSecurity

    Audit the whole product across code, quality, process, docs, roadmap, and tooling; it owns the repo-wide bug hunt, security research, and broken-version investigation (scoped and budgeted per dimension, as distinct from `review-change`'s change-scoped review). Persist one severity-ranked, F-numbered

    Ready to connect

    github.com/gtrabanco/agentic-workflow22 stars

    View details
  • protocol-securitySkillSecurity

    Transport security where the client establishes trust: TLS version floor, certificate chain and hostname verification, the trust store, connecting by IP, mTLS and workload identity as authentication, gRPC channel credentials, and SMTP STARTTLS. Use when generating HTTP, gRPC, or SMTP clients and ser

    Ready to connect

    github.com/shieldnet-360/secure-vibe22 stars

    View details
  • review-securitySkillSecurity

    Internal security review pass of the agentic-workflow review pack — composed in-turn by review-change and product-audit; not a menu entry. Checks secrets, input validation, injection, authn/authz, PII exposure, and dependency risk on the changed surface. Findings only; never edits code.

    Ready to connect

    github.com/gtrabanco/agentic-workflow22 stars

    View details
  • saas-securitySkillSecurity

    Wiring your application to a third-party SaaS platform: verifying an inbound webhook against the vendor's own scheme rather than a generalized one, why a valid signature identifies the sender and not the user in the payload, replay windows, one credential per integration and per environment, least-p

    Ready to connect

    github.com/shieldnet-360/secure-vibe22 stars

    View details
  • security-regression-testsSkillSecurity

    Turning a confirmed and fixed finding into a permanent guard: proving the test fails without the fix, asserting the effect and not only the status code, seeding the two principals an authorization test needs, making a timing or out-of-band proof deterministic enough for CI, and keeping the test in a

    Ready to connect

    github.com/shieldnet-360/secure-vibe22 stars

    View details
  • sota-api-designSkillSecurity

    State-of-the-art API design and audit guidance (2026) covering REST/HTTP, GraphQL, gRPC, WebSockets/SSE/realtime, webhooks, versioning/evolution, and API security/operations. Use when designing or building any API surface (endpoints, schemas, protos, realtime channels, webhook senders/receivers) AND

    Ready to connect

    github.com/martinholovsky/sota-skills22 stars

    View details
  • sota-devsecopsSkillSecurity

    State-of-the-art DevSecOps and software supply chain security (2026). Applies when building or auditing CI/CD pipelines, GitHub Actions workflows, supply chain controls, SBOM generation, SAST/secret-scanning gates, dependency management, container builds, container/artifact registries, IaC (Terrafor

    Ready to connect

    github.com/martinholovsky/sota-skills22 stars

    View details
  • sota-javascript-typescriptSkillSecurity

    State-of-the-art JavaScript and TypeScript engineering (2026) for both writing and auditing code. Covers strict TypeScript configuration and type design, language idioms and pitfalls, async patterns, Node.js backends, JS/TS-specific security (XSS, prototype pollution, supply chain, injection), front

    Ready to connect

    github.com/martinholovsky/sota-skills22 stars

    View details
  • sota-pythonSkillSecurity

    State-of-the-art Python engineering for both writing new Python and auditing existing Python code. Covers uv-based tooling and project setup, strict typing, idioms and pitfalls, asyncio structured concurrency, security (injection, deserialization, supply chain), performance, and FastAPI/Django/pytes

    Ready to connect

    github.com/martinholovsky/sota-skills22 stars

    View details

Looking for something else?

Security is one category of skills on Ahel. Browse all skills, or open another category above.

See how to connect your AI