Security skills.
2,241 security skills, including defi-amm-security, fastapi-patterns and hipaa-compliance, are listed on Ahel today. Each one has a page of its own that says what it does and whether Ahel can serve it in Claude, Claude Code, ChatGPT, Codex and Cursor.
Category: Security
2,241 results · page 74 of 75
- View details
sota-rustSkillSecurity
State-of-the-art Rust engineering (2026) for writing and auditing Rust code. Covers idiomatic ownership and API design, error handling and panic policy, unsafe discipline with Miri, async/tokio (cancellation safety, structured concurrency, graceful shutdown), security and supply chain (cargo audit/d
Ready to connect
- View details
sota-security-complianceSkillSecurity
State-of-the-art security & compliance engineering (2026) for the cybersecurity control frameworks and product-security regulations that drive architecture, code, and CI gates — not the organizational policy binder. Use when work must satisfy or be audited against NIST CSF 2.0, SP 800-53, SP 800-171
Ready to connect
- View details
sota-threat-modelingSkillSecurity
State-of-the-art threat modeling for both designing new systems and auditing existing ones. Use when designing a feature, service, integration, or architecture that touches untrusted input, new trust boundaries, sensitive data, or third-party dependencies (BUILD mode), and when reviewing, auditing,
Ready to connect
- View details
auth-rbac-scaffoldSkillSecurity
Use when developer is implementing authentication, building login/logout flows, writing JWT validation, adding middleware, creating role-based access control, building permission systems, or asking how to protect routes. Also triggers on keywords: auth, bearer token, JWT, session, middleware, permis
Ready to connect
- View details
deep-analysisSkillSecurity
Analytical thinking patterns for comprehensive evaluation, code audits, security analysis, and performance reviews. Provides structured templates for thorough investigation with extended thinking support.
Ready to connect
- View details
dependabot-reviewSkillSecurity
Reviews open Dependabot PRs, classifies by risk (patch/minor/major, security, lockfile-only), and merges safe ones or advises on what to do. Use when user mentions "dependabot", "dependabot PRs", "dependency updates", "merge dependabot", "review dependabot", "dependency PRs", "bump PRs", "update dep
Ready to connect
- View details
gha-auditSkillSecurity
Audit the GitHub Actions workflows in this repo for security, speed, and correctness, and report findings with a proposed diff.
Ready to connect
- View details
harness-keycloak-authSkillSecurity
Keycloak OIDC integration with Harness pipelines, EKS IRSA, service account authentication, and realm-as-code patterns
Ready to connect
- View details
hook-script-librarySkillSecurity
Security-hardened hook script implementations — ready-to-paste templates for security-guard, auto-format, inject-context, session-init, on-stop, and lessons-learned-capture
Ready to connect
- View details
keycloakSkillSecurity
Keycloak identity and access management including realms, clients, authentication flows, themes, and user federation. Activate for OAuth2, OIDC, SAML, SSO, identity providers, and authentication configuration.
Ready to connect
- View details
language-code-review-edho-ferdianSkillSecurity
Language- and framework-specific code review lenses layered on top of the general four-domain review in code-review-edho-ferdian — idioms, framework security misconfigurations, ORM/query correctness, performance traps, and testing conventions, auto-detected across ~20 stacks (React, Python, Go, Java
Ready to connect
- View details
- View details
rseng-agent-securitySkillSecurity
Covers operating AI coding agents securely: auditing whether the agent runs sandboxed, permission and dangerous-command configuration, containerized environments, secrets kept out of context, network egress and token privileges, prompt-injection risk, and the privacy of agent use itself. Use PROACTI
Ready to connect
- View details
s-auditSkillSecurity
Quality audit for WoW addons using Mechanic's static analyzers: security (combat lockdown, secret values, taint), complexity, deprecated APIs and dead code. Explains categories, limits, truncation and how far to trust each result. Triggers: audit, quality, security scan, complexity, deprecations, se
Ready to connect
- View details
spring-boot-securitySkillSecurity
Spring Security 7 implementation for Spring Boot 4. Use when configuring authentication, authorization, OAuth2/JWT resource servers, method security, or CORS/CSRF. Covers the mandatory Lambda DSL migration, SecurityFilterChain patterns, @PreAuthorize, and password encoding. For testing secured endpo
Ready to connect
- View details
spring-boot-testingSkillSecurity
Spring Boot 4 testing strategies and patterns. Use when writing unit tests, slice tests (@WebMvcTest, @DataJpaTest), integration tests, Testcontainers with @ServiceConnection, security testing (@WithMockUser, JWT), or Modulith event testing with Scenario API. Covers the critical @MockitoBean migrati
Ready to connect
- View details
sudoSkillSecurity
Root operator execution override. Disables unsolicited moralizing, paternalistic refusals, sycophantic pushback, and false-positive safety friction for authorized technical systems, security auditing, and scientific research. Use for /sudo, "sudo", or root override mode.
Ready to connect
- View details
teardownSkillSecurity
Conducts deep competitor, product, and pricing teardowns using web browsing and market intelligence. Analyzes positioning, pricing packaging, customer friction, sentiment on Reddit/X, and architectural vulnerabilities. Use for /teardown, "analyze competitor", or competitor teardown.
Ready to connect
- View details
ai-mcp-securitySkillSecurity
Assess Model Context Protocol (MCP) servers and agent tool integrations — tool poisoning, prompt injection via tool descriptions/results, over-broad scopes, and unauth tool exposure. Load when the target uses MCP servers, agent tool/function integrations, or connectors. Signals: mcp.json, MCP server
Ready to connect
- View details
api-auth-attacksSkillSecurity
Break API authentication: token handling, key leakage, weak session/JWT, and no-auth endpoints. Load on REST/GraphQL APIs using API keys, Bearer tokens, HMAC signing, or basic auth. Signals: `Authorization` headers, api_key params, tokens in URLs, /v1 vs /v2 auth drift.
Ready to connect
- View details
automation-nuclei-templatesSkillSecurity
Write custom nuclei templates to codify a finding into a repeatable, mass-scannable check. Load on "write a nuclei template", turning a manual bug into automation, checking a CVE across many hosts, or regression-scanning. Signals: a reproducible request→match, YAML templates, nuclei.
Ready to connect
- View details
code-modernizationSkillSecurity
Lets your agent assess a legacy codebase and plan an upgrade or rewrite, with proof the new code matches the old.
Ready to connect
- View details
code-review-cicdSkillSecurity
Review CI/CD pipelines for security flaws — poisoned workflows, secret leakage, and injection. Load on GitHub Actions / GitLab CI / Jenkins config, ".github/workflows", pull_request_target, self-hosted runners, or "pipeline security". Signals: workflow YAML, secrets in CI, third-party actions.
Ready to connect
- View details
code-review-javaSkillSecurity
Security review of Java code — dangerous sinks and Spring pitfalls. Load when reviewing a Java/ Spring codebase/PR, on .java source in scope, or "review this Java". Signals: pom.xml/build.gradle, Spring/Spring Boot, ObjectInputStream, XML parsers, Runtime.exec, JNDI/lookups.
Ready to connect
- View details
code-review-methodologySkillSecurity
Systematic manual source-code security review — how to find bugs by reading code. Load on "review this code/repo", a source-available target, whitebox testing, or auditing a PR/app for vulnerabilities. Signals: a codebase in scope, "SAST", "secure code review", a language repo.
Ready to connect
- View details
code-review-pythonSkillSecurity
Security review of Python code — dangerous sinks and framework-specific pitfalls (Django/Flask/ FastAPI). Load when reviewing a Python codebase/PR, on .py source in scope, or "review this Python". Signals: requirements.txt/pyproject, Django/Flask/FastAPI, ORMs, pickle/yaml, subprocess.
Ready to connect
- View details
code-review-rubySkillSecurity
Security review of Ruby code — dangerous sinks and Rails pitfalls. Load when reviewing a Ruby/Rails codebase/PR, on .rb source in scope, or "review this Rails app". Signals: Gemfile, config/routes.rb, ActiveRecord, ERB, YAML.load, send/constantize.
Ready to connect
- View details
code-review-soliditySkillSecurity
Security review of Solidity / EVM smart contracts — reentrancy, access control, arithmetic, and DeFi economic bugs. Load when reviewing a smart contract / web3 codebase or PR, on .sol source in scope, or "audit this contract". Signals: *.sol, foundry/hardhat, ERC-20/721, external calls, delegatecall
Ready to connect
- View details
defense-threat-modelingSkillSecurity
Threat-model a system or feature (STRIDE + attack trees) to find design-level risk before code. Load on "threat model", a new design/architecture review, security design questions, or planning controls. Signals: architecture diagram, data-flow, "what could go wrong", pre-build security.
Ready to connect
- View details
exploit-chainingSkillSecurity
Combine low/medium findings into one high-impact exploit chain, and amplify demonstrated impact. Load when you have several small bugs, a "so what?" finding, on "chain", "escalate impact", or building the narrative for a report. Signals: self-XSS + CSRF, open-redirect + OAuth, IDOR + info-leak, SSRF
Ready to connect
Looking for something else?
Security is one category of skills on Ahel. Browse all skills, or open another category above.