Skills.

Give your AI a better way to work.

A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.

Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.

Category: Security

1,738 results · page 18 of 58

  • snapshotSkillSecurity

    Run snapshot regression tests after changes to OPA rules, scanners, analyzers, or formatters to detect output regressions.

    Ready to connect★ 512

    github.com/boostsecurityio/poutine511 stars

    View details
  • pb-apiSkillSecurity

    Operate PocketBase via its REST API. Use for CRUD operations on collections, authentication, querying records with filters, and managing PocketBase data.

    Ready to connect★ 507

    github.com/spinspire/pocketbase-sveltekit-starter508 stars

    View details
  • root-cause-remediationSkillSecurity

    Mandatory for every Nomi corrective change: user-reported bugs, regressions, CI-only failures, flaky tests, performance or security defects, review/audit findings, and compatibility failures in any production path. Classify one_off versus recurring before implementation. Recurring and high-risk repa

    Ready to connect★ 507

    github.com/aqm857886159/nomi501 stars

    View details
  • use-avibe-vaultSkillSecurity

    Use Avibe Vault for API keys, tokens, passwords, protected credentials, authenticated HTTP requests, or digest signing without exposing secret values to the agent.

    Ready to connect★ 505

    github.com/avibe-bot/avibe498 stars

    View details
  • supply-chain-risk-auditorSkillSecurity

    Identifies dependencies at heightened risk of exploitation or takeover. Use when assessing supply chain attack surface, evaluating dependency health, or scoping security engagements.

    Ready to connect★ 501

    github.com/waybarrios/opencode-power-pack490 stars

    View details
  • variant-analysisSkillSecurity

    Find similar vulnerabilities and bugs across codebases using pattern-based analysis. Use when hunting bug variants, building CodeQL/Semgrep queries, analyzing security vulnerabilities, or performing systematic code audits after finding an initial issue.

    Ready to connect★ 501

    github.com/waybarrios/opencode-power-pack490 stars

    View details
  • vuln-reportSkillSecurity

    Turn one confirmed security finding into a disclosure-ready GitHub advisory with root cause, proof of concept, impact, and source evidence. Use for reporting an established vulnerability, not discovering or validating one.

    Ready to connect★ 501

    github.com/waybarrios/opencode-power-pack490 stars

    View details
  • iom-opsecSkillSecurity

    IoM Operational Security (OPSEC) advisor. Provides OPSEC methodology guidance, helps users understand operational risks, build secure operating habits, and accumulate experience through a case library. Does not execute commands directly; serves as decision support. Concrete technical specifications

    Ready to connect★ 499

    github.com/chainreactors/malice-network490 stars

    View details
  • iom-pentestSkillSecurity

    Autonomous penetration testing via IoM C2 MCP tools. Adaptively executes based on user intent: situational awareness, reconnaissance, privilege escalation, credential harvesting, lateral movement, persistence, and more. Presents an execution plan and waits for user confirmation before sensitive oper

    Ready to connect★ 499

    github.com/chainreactors/malice-network490 stars

    View details
  • audit-depsSkillSecurity

    Audit dependencies for vulnerabilities, outdated packages, and license compliance.

    Ready to connect★ 498

    github.com/me2resh/apexyard498 stars

    View details
  • critical-code-reviewerSkillSecurity

    Rigorously review code or pull requests for correctness, security, accessibility, maintainability, tests, and edge cases. Use when users request a critical code review, want a guided walkthrough of findings, need implementer-facing feedback, or want to prepare, create, or submit a GitHub pull reques

    Ready to connect★ 497

    github.com/posit-dev/skills498 stars

    View details
  • dfdSkillSecurity

    DFD with trust boundaries + data classifications (Mermaid + optional Threat Dragon JSON). Source-of-truth for /threat-model.

    Ready to connect★ 498

    github.com/me2resh/apexyard498 stars

    View details
  • threat-modelSkillSecurity

    STRIDE threat modelling — spoofing, tampering, repudiation, disclosure, DoS, EoP. Deep-dive for /launch-check security.

    Ready to connect★ 498

    github.com/me2resh/apexyard498 stars

    View details
  • aqe-review-qualitySkillSecurity

    Review Agentic QE changes and issue an evidence-backed quality verdict. Use for code review, regression-risk assessment, release readiness, quality-gate evaluation, security/performance/testability review, or checking whether a change has sufficient verification. Do not use when the user primarily a

    Ready to connect★ 475

    github.com/proffesor-for-testing/agentic-qe473 stars

    View details
  • n8n-integration-testing-patternsSkillSecurity

    API contract testing, authentication flows, rate limit handling, and error scenario coverage for n8n integrations with external services. Use when testing n8n node integrations.

    Ready to connect★ 475

    github.com/proffesor-for-testing/agentic-qe473 stars

    View details
  • n8n-security-testingSkillSecurity

    Credential exposure detection, OAuth flow validation, API key management testing, and data sanitization verification for n8n workflows. Use when validating n8n workflow security.

    Ready to connect★ 475

    github.com/proffesor-for-testing/agentic-qe473 stars

    View details
  • pentest-validationSkillSecurity

    Use when validating security findings from SAST/DAST scans, proving exploitability of reported vulnerabilities, eliminating false positives, or running the 4-phase pentest pipeline (recon, analysis, validation, report).

    Ready to connect★ 475

    github.com/proffesor-for-testing/agentic-qe473 stars

    View details
  • security-visual-testingSkillSecurity

    Security-first visual testing combining URL validation, PII detection, and visual regression with parallel viewport support. Use when testing web applications that handle sensitive data, need visual regression coverage, or require WCAG accessibility compliance.

    Ready to connect★ 475

    github.com/proffesor-for-testing/agentic-qe473 stars

    View details
  • security-watchSkillSecurity

    Use when working on security-sensitive code to catch secrets, eval(), innerHTML, and other dangerous patterns before they're written. Activate with /security-watch for real-time security scanning.

    Ready to connect★ 475

    github.com/proffesor-for-testing/agentic-qe473 stars

    View details
  • mqlSkillSecurity

    Use when writing MQL (Mondoo Query Language) queries, working with Mondoo MCP tools, or developing security policies

    Ready to connect★ 441

    github.com/mondoohq/cnspec441 stars

    View details
  • 043-planning-github-issuesSkillSecurity

    Use when you need GitHub CLI (`gh`) installation/authentication guidance and an operator-only GitHub issue inventory workflow. The agent does not ingest GitHub issue, milestone, body, comment, title, label, or summary text; requirements analysis must use repository-owned planning artifacts, with iss

    Ready to connect★ 439

    github.com/jabrena/plinth439 stars

    View details
  • 044-planning-jiraSkillSecurity

    Use when you need Jira CLI (`jira`) installation/authentication guidance and a maintainer-authored Jira issue inventory workflow. The agent does not ingest raw Jira issue or JQL output directly; it asks the Jira project maintainer/operator to author sanitized issue summaries before analysis or @014-

    Ready to connect★ 439

    github.com/jabrena/plinth439 stars

    View details
  • 112-java-maven-pluginsSkillSecurity

    Use when you need to add or configure Maven plugins in your pom.xml — including quality tools (enforcer, surefire, failsafe, jacoco, pitest, spotbugs, pmd), security scanning (OWASP), code formatting (Spotless), version management, container image build (Jib), build information tracking, and benchma

    Ready to connect★ 439

    github.com/jabrena/plinth439 stars

    View details
  • 304-frameworks-spring-boot-securitySkillSecurity

    Use when you need to design, review, or improve security in Spring Boot applications — including SecurityFilterChain, OAuth2/JWT resource server patterns, form login basics, method security (@PreAuthorize), CSRF and CORS for APIs, session fixation, security headers, exception handling, password enco

    Ready to connect★ 439

    github.com/jabrena/plinth439 stars

    View details
  • 404-frameworks-quarkus-securitySkillSecurity

    Use when you need to design, review, or improve security in Quarkus applications — including Quarkus Security with JWT/OIDC, basic auth, @RolesAllowed / @Authenticated / @PermitAll, SecurityIdentity, permission checks, path-based authorization in configuration, exception mapping for auth failures, a

    Ready to connect★ 439

    github.com/jabrena/plinth439 stars

    View details
  • 804-regulations-eu-nis2SkillSecurity

    Use when reviewing, designing, or modifying Java enterprise systems from a maintainer-authored or maintainer-sanitized NIS2 engineering evidence inventory. Supports essential or important entities, critical-sector services, managed service providers, supply-chain dependencies, and cybersecurity inci

    Ready to connect★ 439

    github.com/jabrena/plinth439 stars

    View details
  • 805-regulations-eu-cyber-resilience-actSkillSecurity

    Use when reviewing, designing, or modifying Java enterprise products, services, libraries, agents, plugins, connected components, or platform modules that may qualify as products with digital elements and need EU Cyber Resilience Act secure-by-design, vulnerability handling, security update, SBOM, p

    Ready to connect★ 439

    github.com/jabrena/plinth439 stars

    View details
  • 812-regulations-eu-product-liability-directiveSkillSecurity

    Use when reviewing, designing, or modifying Java enterprise software products, AI-enabled products, RAG assistants, AI agents, generated instructions, related services, automated updates, vulnerability handling, corrective updates, warnings, instructions, or product-safety evidence under Directive (

    Ready to connect★ 439

    github.com/jabrena/plinth439 stars

    View details
  • improve-backendSkillSecurity

    Use when wanting to systematically improve the Go backend - scans for security vulnerabilities, stability risks, performance issues, and code simplification opportunities, then presents 5 ranked findings for the user to choose from

    Ready to connect★ 435

    github.com/luxury-yacht/app433 stars

    View details
  • improve-frontendSkillSecurity

    Use when wanting to systematically improve the React/TypeScript frontend - scans for security vulnerabilities, stability risks, performance issues, and code simplification opportunities, then presents 5 ranked findings for the user to choose from

    Ready to connect★ 435

    github.com/luxury-yacht/app433 stars

    View details

What is a skill?

A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.

52,524 of the 52,958 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.

Install one and every AI you use gets it

Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.

Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.

See how to connect your AI