Security skills.

2,241 security skills, including defi-amm-security, fastapi-patterns and hipaa-compliance, are listed on Ahel today. Each one has a page of its own that says what it does and whether Ahel can serve it in Claude, Claude Code, ChatGPT, Codex and Cursor.

Category: Security

2,241 results · page 75 of 75

  • exploit-poc-developmentSkillSecurity

    Turn a known/1-day vulnerability or a raw bug into a working, reliable PoC for an authorized target. Load when a CVE/advisory needs weaponizing, a public PoC needs adapting, or "write an exploit/PoC". Signals: a versioned service with a known CVE, a crash/primitive to develop, searchsploit hits.

    Ready to connect

    github.com/noorqureshi/sploitagent20 stars

    View details
  • mobile-deeplink-abuseSkillSecurity

    Abuse deep links / custom URL schemes / intents for redirect, token theft, and reaching internal screens. Load on custom schemes (myapp://), App Links/Universal Links, exported activities, or "open in app". Signals: intent-filters in the manifest, WebView loading deep-link params, OAuth redirect via

    Ready to connect

    github.com/noorqureshi/sploitagent20 stars

    View details
  • move-auditorSkillSecurity

    Audits Move contracts (Sui & Aptos) for security bugs.

    Ready to connect

    github.com/pantheraudits/move-auditor20 stars

    View details
  • network-appliance-attacksSkillSecurity

    Offensively test perimeter appliances and VPN crypto — IKE/IPsec aggressive mode, transform/DH enumeration, safe firmware/version inference for FortiGate / PAN-OS / Cisco ASA / Citrix feeding CVE applicability, TLS-version posture, and NTLM Type-2 info leaks. Load when an edge firewall, VPN, or load

    Ready to connect

    github.com/noorqureshi/sploitagent20 stars

    View details
  • network-ntlm-relaySkillSecurity

    Coerce and relay NTLM authentication for lateral movement and privilege escalation (relay to SMB, LDAP, ADCS). Load in an AD network with a foothold, on "NTLM relay", "responder", "coerce", no/absent SMB signing, or PetitPotam/PrinterBug. Signals: LLMNR/NBT-NS traffic, SMB signing off, MS-RPRN/EFSRP

    Ready to connect

    github.com/noorqureshi/sploitagent20 stars

    View details
  • reporting-pentest-reportSkillSecurity

    Structure a professional penetration-test report (engagement deliverable, not a single bug). Load at the end of a pentest, on "write the pentest report", "executive summary", "deliverable", or compiling findings for a client. Signals: engagement wrap-up, multiple findings, client report.

    Ready to connect

    github.com/noorqureshi/sploitagent20 stars

    View details
  • reporting-triage-validationSkillSecurity

    Validate a finding BEFORE you write it up — kill false positives, confirm real impact, check scope, and deduplicate. Load after a candidate bug and before reporting-bug-bounty-writeup or reporting-pentest-report. Signals: "I think I found", "is this reportable", a scanner hit, a reflected value, a 5

    Ready to connect

    github.com/noorqureshi/sploitagent20 stars

    View details
  • reverse-eng-binary-triageSkillSecurity

    Triage a native binary you can run or read — find the vulnerable logic, the dangerous sinks, and the input path — with static + dynamic analysis. Load when handed an ELF/PE/Mach-O, a thick client, a standalone or obfuscated binary, or a service whose source you don't have. Signals: a compiled execut

    Ready to connect

    github.com/noorqureshi/sploitagent20 stars

    View details
  • self-evolverSkillSecurity

    Collects, merges, and processes real failure signals and user correction signals from creator.skill. Ordinary signals first enter observation; patches are generated once signals accumulate to a threshold or a severe event occurs (security, privacy, data corruption, incorrect publishing). Every patch

    Ready to connect

    github.com/arctan303/creator.skill20 stars

    View details
  • social-eng-methodologySkillSecurity

    Plan and run an AUTHORIZED social-engineering assessment safely — the load-first guardrails for any human-factor test. Load before any phishing, vishing, pretext, or physical work. Signals: "social engineering", "phishing assessment", "test our employees", "security awareness", a human-factor object

    Ready to connect

    github.com/noorqureshi/sploitagent20 stars

    View details
  • social-eng-physicalSkillSecurity

    Run an authorized physical social-engineering assessment — tailgating, pretext entry, badge/RFID cloning checks, and media-drop tests — to measure physical and human access controls safely. Load after social-eng-methodology when the objective is on-site. Signals: "physical pentest", "test our buildi

    Ready to connect

    github.com/noorqureshi/sploitagent20 stars

    View details
  • social-eng-vishing-pretextSkillSecurity

    Run authorized voice-phishing (vishing) and pretext-based scenarios that test whether staff and help desks follow verification procedures — safely and by consent. Load after social-eng-methodology when the objective is phone/live-interaction based (help-desk password reset, MFA-reset abuse, pretext

    Ready to connect

    github.com/noorqureshi/sploitagent20 stars

    View details
  • sunnydata-securitySkillSecurity

    Comprehensive security review — OWASP Top 10 classification, implementation checklists, and language-specific best practices. Use when implementing auth, handling user input, creating API endpoints, working with secrets, or doing security assessments.

    Ready to connect

    github.com/zenobia000/claude-godzilla-z20 stars

    View details
  • tradecraft-scope-roeSkillSecurity

    Establish and enforce the authorization envelope before any testing — the scope rule that governs everything. Load FIRST on every engagement, on "start", a new target, a program handle, or any ambiguity about what is allowed. Signals: a domain/IP to test, a bug-bounty program handle, a pentest state

    Ready to connect

    github.com/noorqureshi/sploitagent20 stars

    View details
  • web-auth-jwtSkillSecurity

    Attack JWT/session authentication. Load when auth uses a JWT (three base64url parts, header.payload.signature), Authorization: Bearer, or you see alg/kid/jku fields. Signals: eyJ... tokens, "alg":"none"/"HS256"/"RS256", kid header, JWKS endpoints, role/admin claims.

    Ready to connect

    github.com/noorqureshi/sploitagent20 stars

    View details
  • web-clickjackingSkillSecurity

    Clickjacking / UI redress — frame a target so a victim's clicks hit hidden actions. Load when a page allows framing (no X-Frame-Options / frame-ancestors), on state-changing one-click actions, or "clickjacking". Signals: missing framebusting headers, sensitive buttons, OAuth consent, account setting

    Ready to connect

    github.com/noorqureshi/sploitagent20 stars

    View details
  • web-csp-bypassSkillSecurity

    Get script to run despite a Content-Security-Policy — the step after finding an injection that CSP is blocking. Load when you have HTML/JS injection but the payload won't execute, on "CSP is blocking my XSS", or when auditing a CSP for weakness. Signals: a Content-Security-Policy header, a blocked-s

    Ready to connect

    github.com/noorqureshi/sploitagent20 stars

    View details
  • web-oauthSkillSecurity

    Attack OAuth 2.0 / OIDC / SSO flows for account takeover. Load on "Login with Google/GitHub", /authorize, /callback, redirect_uri, state, code/token params, SAML/OIDC SSO. Signals: OAuth endpoints, redirect_uri handling, missing state, implicit flow, pre-account-linking.

    Ready to connect

    github.com/noorqureshi/sploitagent20 stars

    View details
  • web-open-redirectSkillSecurity

    Open redirect — abuse a redirect param to send users to attacker sites, and chain it (OAuth token theft, SSRF filter bypass, phishing). Load on params like redirect=, next=, url=, return=, callback=, dest=, or a 30x Location built from input. Signals: `?returnUrl=`, login redirects, OAuth `redirect_

    Ready to connect

    github.com/noorqureshi/sploitagent20 stars

    View details
  • web-samlSkillSecurity

    Attack SAML SSO — signature exclusion/wrapping (XSW), unsigned assertions, and comment/XXE tricks to forge authentication. Load on SAML SSO (SAMLResponse, ACS URL, IdP/SP), enterprise login, or "SAML". Signals: SAMLResponse base64 in POST, /saml/acs, <saml:Assertion>, Shibboleth/ADFS/Okta SSO.

    Ready to connect

    github.com/noorqureshi/sploitagent20 stars

    View details
  • anthropic-cybersecurity-skillsSkillSecurity

    Use 754 structured cybersecurity skills mapped to MITRE ATT&CK, NIST CSF, ATLAS, D3FEND, and NIST AI RMF for AI-driven security operations

    Ready to connect

    github.com/aradotso/security-skills11 stars

    View details

Looking for something else?

Security is one category of skills on Ahel. Browse all skills, or open another category above.

See how to connect your AI