Skills.

Give your AI a better way to work.

A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.

Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.

Category: Security

1,738 results · page 13 of 58

  • sast-hunterSkillSecurity

    Focused PoC builder for SAST candidates. Receives a SPECIFIC candidate vulnerability that survived adversarial validation. Writes a PoC, compiles, runs with ASan, confirms or rejects. Use via /sast command.

    Ready to connect★ 908

    github.com/h-mmer/pentest-agents816 stars

    View details
  • sast-methodologySkillSecurity

    Bug bounty agent framework for Claude Code, Codex, Gemini, Cursor, Windsurf, Copilot, and OpenClaw — 48 agents, 26 commands, 19 CLI tools, 2 MCP servers, autonomous hunt loops, exploit chain builder.

    Ready to connect★ 908

    github.com/h-mmer/pentest-agents816 stars

    View details
  • statusSkillSecurity

    Show engagement dashboard with program info, scope, brain state, findings, agent activity, and cost estimate.

    Ready to connect★ 908

    github.com/h-mmer/pentest-agents816 stars

    View details
  • subdomain-takeoverSkillSecurity

    Subdomain Takeover specialist (H1 #145). Use for finding dangling DNS records pointing to unclaimed cloud resources, expired services, or deprovisioned infrastructure.

    Ready to connect★ 908

    github.com/h-mmer/pentest-agents816 stars

    View details
  • submitSkillSecurity

    Draft and submit a vulnerability report to the bug bounty platform. Reads scope.yaml for platform/program, uses brain + findings for content. Always drafts first for review.

    Ready to connect★ 908

    github.com/h-mmer/pentest-agents816 stars

    View details
  • surfaceSkillSecurity

    Show ranked attack surface for a target. Invokes recon-ranker agent. Usage: /surface target.com

    Ready to connect★ 908

    github.com/h-mmer/pentest-agents816 stars

    View details
  • syncSkillSecurity

    Sync program scope, policy, and hacktivity from a bug bounty platform. Usage: /sync hackerone tesla or /sync bugcrowd uber

    Ready to connect★ 908

    github.com/h-mmer/pentest-agents816 stars

    View details
  • triageSkillSecurity

    Batch-validate ALL findings through the 7-Question Gate. Kills weak findings in bulk. Usage: /triage

    Ready to connect★ 908

    github.com/h-mmer/pentest-agents816 stars

    View details
  • triage-validationSkillSecurity

    Bug bounty agent framework for Claude Code, Codex, Gemini, Cursor, Windsurf, Copilot, and OpenClaw — 48 agents, 26 commands, 19 CLI tools, 2 MCP servers, autonomous hunt loops, exploit chain builder.

    Ready to connect★ 908

    github.com/h-mmer/pentest-agents816 stars

    View details
  • validateSkillSecurity

    Validate a finding through the 7-Question Gate + 4 gates. Kills weak findings FAST. Usage: /validate <finding description>

    Ready to connect★ 908

    github.com/h-mmer/pentest-agents816 stars

    View details
  • validatorSkillSecurity

    Finding validator. Runs 7-Question Gate + 4-gate checklist. Kills weak/theoretical findings FAST before any report writing. Output: PASS, KILL, DOWNGRADE, or CHAIN REQUIRED.

    Ready to connect★ 908

    github.com/h-mmer/pentest-agents816 stars

    View details
  • vuln-classesSkillSecurity

    Bug bounty agent framework for Claude Code, Codex, Gemini, Cursor, Windsurf, Copilot, and OpenClaw — 48 agents, 26 commands, 19 CLI tools, 2 MCP servers, autonomous hunt loops, exploit chain builder.

    Ready to connect★ 908

    github.com/h-mmer/pentest-agents816 stars

    View details
  • vuln-scannerSkillSecurity

    Automated vulnerability scanning agent. Use for running nuclei templates, nikto scans, SSL/TLS analysis, header checks, and known CVE detection against targets. Provide target URL or list and scan profile: 'quick' for top vulns, 'standard' for common checks, 'thorough' for deep scanning.

    Ready to connect★ 908

    github.com/h-mmer/pentest-agents816 stars

    View details
  • web3-auditorSkillSecurity

    Smart contract and Web3/DeFi security auditor. Covers Solidity vulnerabilities, Foundry PoC building, and DeFi-specific attack patterns. Use for Immunefi, Code4rena, and other Web3 bug bounty programs.

    Ready to connect★ 908

    github.com/h-mmer/pentest-agents816 stars

    View details
  • xss-hunterSkillSecurity

    XSS specialist covering reflected (H1 #60), stored (H1 #61), and DOM (H1 #62). Dispatcher passes subtype — 'reflected', 'stored', or 'dom' — in the task; falls back to inference from target. Use for parameter reflection, persisted inputs (comments/profiles/uploads/filenames), or client-side source→s

    Ready to connect★ 908

    github.com/h-mmer/pentest-agents816 stars

    View details
  • nodejs-best-practicesSkillSecurity

    Node.js development principles and decision-making. Framework selection, async patterns, security, and architecture. Teaches thinking, not copying.

    Ready to connect★ 906

    github.com/legions-developer/invoicely902 stars

    View details
  • code-quality-analyzerSkillSecurity

    Triggered when the user submits code or requests a comprehensive code quality analysis. Automatically performs static analysis, code review, and quality scoring. Analysis covers coding standards, potential bugs, performance issues, and security vulnerabilities. Trigger phrases include "analyze code

    Ready to connect★ 892

    github.com/alibaba/skill-up892 stars

    View details
  • code-review-assistantSkillSecurity

    Triggered when the user submits code or requests a code review. Automatically analyzes code quality, identifies potential bugs, security vulnerabilities, and performance issues, and provides improvement suggestions. Trigger phrases include "take a look at this code", "review this", "is there a probl

    Ready to connect★ 892

    github.com/alibaba/skill-up892 stars

    View details
  • cmmcSkillSecurity

    Expert CMMC 2.0 (Cybersecurity Maturity Model Certification) advisor for US defense contractors and subcontractors in the Defense Industrial Base (DIB). Use this skill whenever a user asks about CMMC 2.0, CMMC Level 1, Level 2, or Level 3, DoD cybersecurity compliance, NIST SP 800-171, CUI (Controll

    Ready to connect★ 890

    github.com/sushegaad/claude-skills-governance-risk-and-compliance891 stars

    View details
  • eu-craSkillSecurity

    Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the EU. Use this skill for gap analysis, product classification (Default / Class I / Class II), conformit

    Ready to connect★ 890

    github.com/sushegaad/claude-skills-governance-risk-and-compliance891 stars

    View details
  • fedrampSkillSecurity

    Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026). Use this skill whenever a user asks about FedRAMP authorization, ATO (Authority to Operate), cloud security for federal government, NIST SP 800-53 controls, CSP compliance, or any of the core F

    Ready to connect★ 890

    github.com/sushegaad/claude-skills-governance-risk-and-compliance891 stars

    View details
  • nist-csfSkillSecurity

    Expert NIST Cybersecurity Framework (CSF) advisor covering CSF 2.0 and CSF 1.1. Use this skill whenever a user asks about NIST CSF, cybersecurity risk management, the six CSF functions (Govern, Identify, Protect, Detect, Respond, Recover), CSF profiles, implementation tiers, gap assessments, organiz

    Ready to connect★ 890

    github.com/sushegaad/claude-skills-governance-risk-and-compliance891 stars

    View details
  • nzismSkillSecurity

    Expert New Zealand Information Security Manual (NZISM) advisor for NZ government agencies and their supply chains. Use for NZISM control guidance, gap analysis, agency security obligations, classification framework (Unclassified through Top Secret), security risk management, system certification, an

    Ready to connect★ 890

    github.com/sushegaad/claude-skills-governance-risk-and-compliance891 stars

    View details
  • pci-complianceSkillSecurity

    Expert PCI DSS compliance advisor covering PCI DSS v4.0.1 (current) and v4.0. Use this skill whenever a user asks about PCI DSS, payment card security, cardholder data protection, CDE scoping, SAQ types (A, A-EP, B, B-IP, C, C-VT, P2PE, D), ROC, AOC, QSA assessments, ASV scans, merchant levels, serv

    Ready to connect★ 890

    github.com/sushegaad/claude-skills-governance-risk-and-compliance891 stars

    View details
  • saudi-arabia-grcSkillSecurity

    Saudi Arabia Governance, Risk & Compliance advisor — a compliance router that first determines WHICH Saudi regulations apply (NCA ECC-2:2024, Saudi PDPL, NCA Cloud Cybersecurity Controls, SAMA Cyber Security Framework, CST cloud framework, DCC/OTCC/TCC), then guides framework-specific compliance. Us

    Ready to connect★ 890

    github.com/sushegaad/claude-skills-governance-risk-and-compliance891 stars

    View details
  • soc2SkillSecurity

    Expert SOC 2 compliance assistant covering all five Trust Services Criteria (Security/CC, Availability/A, Confidentiality/C, Processing Integrity/PI, Privacy/P). Use this skill whenever a user mentions SOC 2, Trust Services Criteria, SOC 2 Type 1 or Type 2, audit readiness, compliance gaps, control

    Ready to connect★ 890

    github.com/sushegaad/claude-skills-governance-risk-and-compliance891 stars

    View details
  • swift-cspSkillSecurity

    Expert SWIFT Customer Security Programme (CSP) advisor covering the Customer Security Controls Framework (CSCF v2026). Use this skill whenever a user asks about SWIFT CSP, CSCF controls, SWIFT security attestation, KYC-SA portal, SWIFT architecture types (A1/A2/A3/A4/B), mandatory vs advisory contro

    Ready to connect★ 890

    github.com/sushegaad/claude-skills-governance-risk-and-compliance891 stars

    View details
  • tisaxSkillSecurity

    Expert TISAX (Trusted Information Security Assessment Exchange) advisor for the automotive supply chain — the ENX/VDA assessment regime that OEMs like VW, BMW, and Mercedes-Benz require from suppliers and service providers. Covers the VDA ISA 6 catalogue (current through 2026) and the ISA2027 transi

    Ready to connect★ 890

    github.com/sushegaad/claude-skills-governance-risk-and-compliance891 stars

    View details
  • tsa-complianceSkillSecurity

    Expert TSA cybersecurity compliance advisor for critical infrastructure owners and operators. Use this skill whenever a user asks about TSA Security Directives for pipelines, freight railroads, passenger rail, public transit, or bus operators; the TSA Cyber Risk Management Program (CRMP); Cybersecur

    Ready to connect★ 890

    github.com/sushegaad/claude-skills-governance-risk-and-compliance891 stars

    View details
  • create-webrolesSkillSecurity

    Creates and configures web roles for a Power Pages code site. Web roles control access and permissions for site users, including authenticated and anonymous roles. Use when the user wants to create, add, set up, or manage web roles for their site.

    Ready to connect★ 859

    github.com/microsoft/power-platform-skills867 stars

    View details

What is a skill?

A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.

52,524 of the 52,958 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.

Install one and every AI you use gets it

Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.

Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.

See how to connect your AI