Security skills.
2,241 security skills, including defi-amm-security, fastapi-patterns and hipaa-compliance, are listed on Ahel today. Each one has a page of its own that says what it does and whether Ahel can serve it in Claude, Claude Code, ChatGPT, Codex and Cursor.
Category: Security
2,241 results · page 73 of 75
- View details
br-auth-middlewareSkillSecurity
Configure Better Route 1.1 authentication with JWT, custom bearer tokens, WordPress Application Passwords, or cookie nonces. Use when protecting routes, mapping verified claims to WordPress users, enforcing scopes, consuming the shared AuthContext identity, restoring native users after nested dispat
Ready to connect
- View details
br-error-contractSkillSecurity
Produce and consume better-route 1.1 structured errors. Use for ApiException, Response, ErrorNormalizer, ResponseNormalizer, WP_Error conversion, OAuth RFC 6749 error_format, status/code/details/headers, Retry-After, validation_failed, idempotency/rate/optimistic-lock/Woo errors, leak prevention, or
Ready to connect
- View details
br-hmac-signatureSkillSecurity
Configure Better Route 1.1 HMAC authentication for webhooks and server-to-server REST requests. Use when signing request timestamps, methods, paths, raw bodies, optional query strings, rotating key IDs, or consuming the shared HMAC AuthContext identity.
Ready to connect
- View details
br-jwks-jwt-authSkillSecurity
Configure Better Route 1.1 RS256 or ES256 JWT verification from a local or HTTPS JWKS. Use when integrating OIDC/OAuth bearer tokens, selecting keys by kid, validating issuer/audience/lifetime, or operating JWKS caching and refresh behavior safely.
Ready to connect
- View details
br-owned-resource-guardsSkillSecurity
Add Better Route 1.1 ownership authorization to raw routes and Resource DSL endpoints. Use when authenticated users may access only their own records, orders, profiles, memberships, tokens, or subscriptions.
Ready to connect
- View details
br-resource-policySkillSecurity
Configure better-route 1.1 Resource action and field authorization. Use for ResourcePolicy::publicReadPrivateWrite, adminOnly, capabilities, callbacks, Resource::policy, permissionCallback, per-action rules, wildcard rules, fieldPolicy, public Resource OpenAPI security, ownership policies, or review
Ready to connect
- View details
colyseus-authoritative-multiplayerSkillSecurity
Use when planning, implementing, or QA-reviewing MMOOMM realtime multiplayer with Colyseus rooms, server-authoritative simulation, room authentication, Schema state, fixed tick processing, client interpolation or reconciliation, reconnection, or MVP scaling. Applies to `@universo-react/colyseus-serv
Ready to connect
- View details
deserialization-securitySkillSecurity
Block unsafe deserialization and unsafe XML parsing in Java, Python, .NET, PHP, and Ruby: gadget chains, unrestricted type resolution, external entity expansion, and safer formats. Use when parsing or deserializing data from an untrusted source, wiring cookies, sessions, queues, or RPC payloads, or
Ready to connect
- View details
dynamic-verificationSkillSecurity
Confirm or refute a vulnerability candidate against a live target with a deterministic probe, respecting authorization and scope. Use when a SAST or LLM review flags a possible injection or SSRF, when triaging a finding before filing a bug or shipping a fix, or when a verification result turns out w
Ready to connect
- View details
erc8128SkillSecurity
Sign and verify HTTP requests with Ethereum wallets using ERC-8128. Use when building authenticated APIs that need wallet-based auth, making signed requests to ERC-8128 endpoints, implementing request verification in servers, or working with agent-to-server authentication. Covers both the @slicekit/
Ready to connect
- View details
fec-code-reviewSkillSecurity
Use when the user asks for general frontend code review, PR review, merge-readiness assessment, architecture maintainability, type-safety, rendering/state risks, style consistency, testability gaps, or a cross-cutting review summary. Delegate deep security, accessibility, E2E, or performance investi
Ready to connect
- View details
fec-dependency-upgradeSkillSecurity
Use when planning, implementing, or reviewing frontend dependency upgrades, package migrations, lockfile changes, major framework version bumps, CVE remediation, peer dependency conflicts, ESM/CJS shifts, build-tool compatibility, or CI verification matrices; Chinese triggers include dependency upgr
Ready to connect
- View details
fec-testing-strategySkillSecurity
Use when planning or reviewing a frontend testing strategy, selecting the right test layer by risk, mapping coverage across static checks, unit tests, component tests, integration tests, E2E, Storybook/visual regression, a11y, security, performance, or CI gates. Do not use to write individual compon
Ready to connect
- View details
fortify-change-reviewSkillSecurity
Lightweight, AI-powered security review of code CHANGES (a diff, PR, or in-session edits) using the agent's own analysis — no Fortify scan engine or platform needed. Use when the user asks to "run a Fortify security review" / "Fortify change review", or when adding/modifying code touching authentica
Ready to connect
- View details
fortify-dependency-upgradeSkillSecurity
Perform dependency upgrade impact assessment, code fixes, and migration work. Use to remediate Fortify SCA / open source / software composition analysis findings — vulnerable third-party dependencies, CVEs/GHSAs, components flagged by FoD or SSC — by upgrading to a safe version and fixing any result
Ready to connect
- View details
fortify-exploitability-analysisSkillSecurity
Triage whether a known CVE/GHSA vulnerability is actually exploitable in this project. Use when the user wants a reachability verdict on a specific advisory — is the project really affected, or is the advisory noise? Analysis only; for fixes, hand off to fortify-dependency-upgrade.
Ready to connect
- View details
graphql-securitySkillSecurity
Bound and control a GraphQL endpoint: operation cost budgets, cost-based rate limiting, pre-registered operations, alias and batch abuse on authentication paths, introspection, cache keying, and untyped scalar inputs. Use when generating schemas, resolvers, or server config, wiring limits or persist
Ready to connect
- View details
llm-app-securitySkillSecurity
Securing a feature that calls an LLM: prompt injection as an unsolved input problem, bounding what model output is allowed to reach, tool authorization against the human rather than the model, approval gates on consequential actions, RAG context provenance, system-prompt leakage, and cost limits. Us
Ready to connect
- View details
lw-site-manager-overviewSkillSecurity
Operate and integrate with LW Site Manager 1.5.x through its WordPress Abilities REST surface or built-in MCP server. Covers the site-manager/* catalog, Application Password authentication, MCP enablement and domain lock, skill discovery, capability and object-level authorization, error contracts, a
Ready to connect
- View details
ml-securitySkillSecurity
The model and data artifacts: checkpoint formats that execute code on load, provenance for a model you did not train, training-data poisoning and the ingestion controls that bound it, PII that survives into weights, and notebooks that commit their own output. Use when loading a model from disk, a Hu
Ready to connect
- View details
ml4t-agent-governanceSkillSecurity
Security and governance controls for autonomous financial agents. Use when agents can call tools, read untrusted content, or affect research or trading decisions.
Ready to connect
- View details
product-auditSkillSecurity
Audit the whole product across code, quality, process, docs, roadmap, and tooling; it owns the repo-wide bug hunt, security research, and broken-version investigation (scoped and budgeted per dimension, as distinct from `review-change`'s change-scoped review). Persist one severity-ranked, F-numbered
Ready to connect
- View details
protocol-securitySkillSecurity
Transport security where the client establishes trust: TLS version floor, certificate chain and hostname verification, the trust store, connecting by IP, mTLS and workload identity as authentication, gRPC channel credentials, and SMTP STARTTLS. Use when generating HTTP, gRPC, or SMTP clients and ser
Ready to connect
- View details
review-securitySkillSecurity
Internal security review pass of the agentic-workflow review pack — composed in-turn by review-change and product-audit; not a menu entry. Checks secrets, input validation, injection, authn/authz, PII exposure, and dependency risk on the changed surface. Findings only; never edits code.
Ready to connect
- View details
saas-securitySkillSecurity
Wiring your application to a third-party SaaS platform: verifying an inbound webhook against the vendor's own scheme rather than a generalized one, why a valid signature identifies the sender and not the user in the payload, replay windows, one credential per integration and per environment, least-p
Ready to connect
- View details
security-regression-testsSkillSecurity
Turning a confirmed and fixed finding into a permanent guard: proving the test fails without the fix, asserting the effect and not only the status code, seeding the two principals an authorization test needs, making a timing or out-of-band proof deterministic enough for CI, and keeping the test in a
Ready to connect
- View details
sota-api-designSkillSecurity
State-of-the-art API design and audit guidance (2026) covering REST/HTTP, GraphQL, gRPC, WebSockets/SSE/realtime, webhooks, versioning/evolution, and API security/operations. Use when designing or building any API surface (endpoints, schemas, protos, realtime channels, webhook senders/receivers) AND
Ready to connect
- View details
sota-devsecopsSkillSecurity
State-of-the-art DevSecOps and software supply chain security (2026). Applies when building or auditing CI/CD pipelines, GitHub Actions workflows, supply chain controls, SBOM generation, SAST/secret-scanning gates, dependency management, container builds, container/artifact registries, IaC (Terrafor
Ready to connect
- View details
sota-javascript-typescriptSkillSecurity
State-of-the-art JavaScript and TypeScript engineering (2026) for both writing and auditing code. Covers strict TypeScript configuration and type design, language idioms and pitfalls, async patterns, Node.js backends, JS/TS-specific security (XSS, prototype pollution, supply chain, injection), front
Ready to connect
- View details
sota-pythonSkillSecurity
State-of-the-art Python engineering for both writing new Python and auditing existing Python code. Covers uv-based tooling and project setup, strict typing, idioms and pitfalls, asyncio structured concurrency, security (injection, deserialization, supply chain), performance, and FastAPI/Django/pytes
Ready to connect
Looking for something else?
Security is one category of skills on Ahel. Browse all skills, or open another category above.