Security skills.

2,241 security skills, including defi-amm-security, fastapi-patterns and hipaa-compliance, are listed on Ahel today. Each one has a page of its own that says what it does and whether Ahel can serve it in Claude, Claude Code, ChatGPT, Codex and Cursor.

Category: Security

2,241 results · page 74 of 75

  • sota-rustSkillSecurity

    State-of-the-art Rust engineering (2026) for writing and auditing Rust code. Covers idiomatic ownership and API design, error handling and panic policy, unsafe discipline with Miri, async/tokio (cancellation safety, structured concurrency, graceful shutdown), security and supply chain (cargo audit/d

    Ready to connect

    github.com/martinholovsky/sota-skills22 stars

    View details
  • sota-security-complianceSkillSecurity

    State-of-the-art security & compliance engineering (2026) for the cybersecurity control frameworks and product-security regulations that drive architecture, code, and CI gates — not the organizational policy binder. Use when work must satisfy or be audited against NIST CSF 2.0, SP 800-53, SP 800-171

    Ready to connect

    github.com/martinholovsky/sota-skills22 stars

    View details
  • sota-threat-modelingSkillSecurity

    State-of-the-art threat modeling for both designing new systems and auditing existing ones. Use when designing a feature, service, integration, or architecture that touches untrusted input, new trust boundaries, sensitive data, or third-party dependencies (BUILD mode), and when reviewing, auditing,

    Ready to connect

    github.com/martinholovsky/sota-skills22 stars

    View details
  • auth-rbac-scaffoldSkillSecurity

    Use when developer is implementing authentication, building login/logout flows, writing JWT validation, adding middleware, creating role-based access control, building permission systems, or asking how to protect routes. Also triggers on keywords: auth, bearer token, JWT, session, middleware, permis

    Ready to connect

    github.com/apisec-inc/apisec-skills21 stars

    View details
  • deep-analysisSkillSecurity

    Analytical thinking patterns for comprehensive evaluation, code audits, security analysis, and performance reviews. Provides structured templates for thorough investigation with extended thinking support.

    Ready to connect

    github.com/thelobbi/claude21 stars

    View details
  • dependabot-reviewSkillSecurity

    Reviews open Dependabot PRs, classifies by risk (patch/minor/major, security, lockfile-only), and merges safe ones or advises on what to do. Use when user mentions "dependabot", "dependabot PRs", "dependency updates", "merge dependabot", "review dependabot", "dependency PRs", "bump PRs", "update dep

    Ready to connect

    github.com/joaquimscosta/arkhe-claude-plugins21 stars

    View details
  • gha-auditSkillSecurity

    Audit the GitHub Actions workflows in this repo for security, speed, and correctness, and report findings with a proposed diff.

    Ready to connect

    github.com/bretfisher/skills21 stars

    View details
  • harness-keycloak-authSkillSecurity

    Keycloak OIDC integration with Harness pipelines, EKS IRSA, service account authentication, and realm-as-code patterns

    Ready to connect

    github.com/thelobbi/claude21 stars

    View details
  • hook-script-librarySkillSecurity

    Security-hardened hook script implementations — ready-to-paste templates for security-guard, auto-format, inject-context, session-init, on-stop, and lessons-learned-capture

    Ready to connect

    github.com/thelobbi/claude21 stars

    View details
  • keycloakSkillSecurity

    Keycloak identity and access management including realms, clients, authentication flows, themes, and user federation. Activate for OAuth2, OIDC, SAML, SSO, identity providers, and authentication configuration.

    Ready to connect

    github.com/thelobbi/claude21 stars

    View details
  • language-code-review-edho-ferdianSkillSecurity

    Language- and framework-specific code review lenses layered on top of the general four-domain review in code-review-edho-ferdian — idioms, framework security misconfigurations, ORM/query correctness, performance traps, and testing conventions, auto-detected across ~20 stacks (React, Python, Go, Java

    Ready to connect

    github.com/edhoferdian/eef21 stars

    View details
  • permissions-securitySkillSecurity

    A skill for security by thelobbi.

    Ready to connect

    github.com/thelobbi/claude21 stars

    View details
  • rseng-agent-securitySkillSecurity

    Covers operating AI coding agents securely: auditing whether the agent runs sandboxed, permission and dangerous-command configuration, containerized environments, secrets kept out of context, network egress and token privileges, prompt-injection risk, and the privacy of agent use itself. Use PROACTI

    Ready to connect

    github.com/fdiblen/rseng-agent-skills21 stars

    View details
  • s-auditSkillSecurity

    Quality audit for WoW addons using Mechanic's static analyzers: security (combat lockdown, secret values, taint), complexity, deprecated APIs and dead code. Explains categories, limits, truncation and how far to trust each result. Triggers: audit, quality, security scan, complexity, deprecations, se

    Ready to connect

    github.com/falkicon/mechanic20 stars

    View details
  • spring-boot-securitySkillSecurity

    Spring Security 7 implementation for Spring Boot 4. Use when configuring authentication, authorization, OAuth2/JWT resource servers, method security, or CORS/CSRF. Covers the mandatory Lambda DSL migration, SecurityFilterChain patterns, @PreAuthorize, and password encoding. For testing secured endpo

    Ready to connect

    github.com/joaquimscosta/arkhe-claude-plugins21 stars

    View details
  • spring-boot-testingSkillSecurity

    Spring Boot 4 testing strategies and patterns. Use when writing unit tests, slice tests (@WebMvcTest, @DataJpaTest), integration tests, Testcontainers with @ServiceConnection, security testing (@WithMockUser, JWT), or Modulith event testing with Scenario API. Covers the critical @MockitoBean migrati

    Ready to connect

    github.com/joaquimscosta/arkhe-claude-plugins21 stars

    View details
  • sudoSkillSecurity

    Root operator execution override. Disables unsolicited moralizing, paternalistic refusals, sycophantic pushback, and false-positive safety friction for authorized technical systems, security auditing, and scientific research. Use for /sudo, "sudo", or root override mode.

    Ready to connect

    github.com/scino/fstack21 stars

    View details
  • teardownSkillSecurity

    Conducts deep competitor, product, and pricing teardowns using web browsing and market intelligence. Analyzes positioning, pricing packaging, customer friction, sentiment on Reddit/X, and architectural vulnerabilities. Use for /teardown, "analyze competitor", or competitor teardown.

    Ready to connect

    github.com/scino/fstack21 stars

    View details
  • ai-mcp-securitySkillSecurity

    Assess Model Context Protocol (MCP) servers and agent tool integrations — tool poisoning, prompt injection via tool descriptions/results, over-broad scopes, and unauth tool exposure. Load when the target uses MCP servers, agent tool/function integrations, or connectors. Signals: mcp.json, MCP server

    Ready to connect

    github.com/noorqureshi/sploitagent20 stars

    View details
  • api-auth-attacksSkillSecurity

    Break API authentication: token handling, key leakage, weak session/JWT, and no-auth endpoints. Load on REST/GraphQL APIs using API keys, Bearer tokens, HMAC signing, or basic auth. Signals: `Authorization` headers, api_key params, tokens in URLs, /v1 vs /v2 auth drift.

    Ready to connect

    github.com/noorqureshi/sploitagent20 stars

    View details
  • automation-nuclei-templatesSkillSecurity

    Write custom nuclei templates to codify a finding into a repeatable, mass-scannable check. Load on "write a nuclei template", turning a manual bug into automation, checking a CVE across many hosts, or regression-scanning. Signals: a reproducible request→match, YAML templates, nuclei.

    Ready to connect

    github.com/noorqureshi/sploitagent20 stars

    View details
  • code-modernizationSkillSecurity

    Lets your agent assess a legacy codebase and plan an upgrade or rewrite, with proof the new code matches the old.

    Ready to connect

    github.com/gbb-acelerators/awesome-harness-primitives20 stars

    View details
  • code-review-cicdSkillSecurity

    Review CI/CD pipelines for security flaws — poisoned workflows, secret leakage, and injection. Load on GitHub Actions / GitLab CI / Jenkins config, ".github/workflows", pull_request_target, self-hosted runners, or "pipeline security". Signals: workflow YAML, secrets in CI, third-party actions.

    Ready to connect

    github.com/noorqureshi/sploitagent20 stars

    View details
  • code-review-javaSkillSecurity

    Security review of Java code — dangerous sinks and Spring pitfalls. Load when reviewing a Java/ Spring codebase/PR, on .java source in scope, or "review this Java". Signals: pom.xml/build.gradle, Spring/Spring Boot, ObjectInputStream, XML parsers, Runtime.exec, JNDI/lookups.

    Ready to connect

    github.com/noorqureshi/sploitagent20 stars

    View details
  • code-review-methodologySkillSecurity

    Systematic manual source-code security review — how to find bugs by reading code. Load on "review this code/repo", a source-available target, whitebox testing, or auditing a PR/app for vulnerabilities. Signals: a codebase in scope, "SAST", "secure code review", a language repo.

    Ready to connect

    github.com/noorqureshi/sploitagent20 stars

    View details
  • code-review-pythonSkillSecurity

    Security review of Python code — dangerous sinks and framework-specific pitfalls (Django/Flask/ FastAPI). Load when reviewing a Python codebase/PR, on .py source in scope, or "review this Python". Signals: requirements.txt/pyproject, Django/Flask/FastAPI, ORMs, pickle/yaml, subprocess.

    Ready to connect

    github.com/noorqureshi/sploitagent20 stars

    View details
  • code-review-rubySkillSecurity

    Security review of Ruby code — dangerous sinks and Rails pitfalls. Load when reviewing a Ruby/Rails codebase/PR, on .rb source in scope, or "review this Rails app". Signals: Gemfile, config/routes.rb, ActiveRecord, ERB, YAML.load, send/constantize.

    Ready to connect

    github.com/noorqureshi/sploitagent20 stars

    View details
  • code-review-soliditySkillSecurity

    Security review of Solidity / EVM smart contracts — reentrancy, access control, arithmetic, and DeFi economic bugs. Load when reviewing a smart contract / web3 codebase or PR, on .sol source in scope, or "audit this contract". Signals: *.sol, foundry/hardhat, ERC-20/721, external calls, delegatecall

    Ready to connect

    github.com/noorqureshi/sploitagent20 stars

    View details
  • defense-threat-modelingSkillSecurity

    Threat-model a system or feature (STRIDE + attack trees) to find design-level risk before code. Load on "threat model", a new design/architecture review, security design questions, or planning controls. Signals: architecture diagram, data-flow, "what could go wrong", pre-build security.

    Ready to connect

    github.com/noorqureshi/sploitagent20 stars

    View details
  • exploit-chainingSkillSecurity

    Combine low/medium findings into one high-impact exploit chain, and amplify demonstrated impact. Load when you have several small bugs, a "so what?" finding, on "chain", "escalate impact", or building the narrative for a report. Signals: self-XSS + CSRF, open-redirect + OAuth, IDOR + info-leak, SSRF

    Ready to connect

    github.com/noorqureshi/sploitagent20 stars

    View details

Looking for something else?

Security is one category of skills on Ahel. Browse all skills, or open another category above.

See how to connect your AI