Skills.

Give your AI a better way to work.

A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.

Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.

Category: Security

1,738 results · page 19 of 58

  • account-authenticationSkillSecurity

    Use when applying for Xiaohongshu account verification (blue check), understanding verification types and benefits, preparing verification application materials, or increasing account credibility and trust

    Ready to connect★ 434

    github.com/vivy-yi/xiaohongshu-skills418 stars

    View details
  • account-safetySkillSecurity

    Use when needing to protect account from hacking, unauthorized access, suspension, or other security threats on Xiaohongshu

    Ready to connect★ 434

    github.com/vivy-yi/xiaohongshu-skills418 stars

    View details
  • account-securitySkillSecurity

    Use when protecting Xiaohongshu account from unauthorized access, preventing account theft, recovering compromised accounts, or implementing security measures to safeguard account and follower base

    Ready to connect★ 434

    github.com/vivy-yi/xiaohongshu-skills418 stars

    View details
  • winui-code-reviewSkillSecurity

    Code quality review for WinUI 3 apps — MVVM compliance, x:Bind correctness, accessibility, theming, security, and performance. Use before committing to catch issues that the compiler and UI tests won't find.

    Ready to connect★ 433

    github.com/microsoft/win-dev-skills433 stars

    View details
  • 1password-credential-lookupSkillSecurity

    This skill should be used when agents need to log into websites, retrieve passwords, or access credentials. CRITICAL - always use find_credential with the website URL, never guess item names.

    Ready to connect★ 422

    github.com/aiskillstore/marketplace260 stars

    View details
  • cve-source-checkSkillSecurity

    Audit CVE/vulnerability source coverage for a technology stack. Maps each component (container, library, base image, runtime) to authoritative CVE feeds, flags gaps, and produces audit-ready reports. Generic: works for any service or stack.

    Ready to connect★ 419

    github.com/notque/vexjoy-agent419 stars

    View details
  • memstack-automation-api-integrationSkillSecurity

    Use this skill when the user says 'API integration', 'connect APIs', 'sync data', 'data mapping', 'rate limiting', or needs system-to-system connectors with authentication, rate limit handling, and error recovery. Generates API integration code with authentication (OAuth, API key, JWT), request/resp

    Ready to connect★ 419

    github.com/cwinvestments/memstack419 stars

    View details
  • memstack-development-code-reviewerSkillSecurity

    Use this skill when the user says 'review code', 'code review', 'check my code', 'audit this', 'review PR', 'review changes', 'what's wrong with this', or is requesting a structured review of code quality, security, performance, or maintainability. Do NOT use for refactoring plans or test generation

    Ready to connect★ 419

    github.com/cwinvestments/memstack419 stars

    View details
  • memstack-development-performance-auditSkillSecurity

    Use this skill when the user says 'performance audit', 'why is it slow', 'optimize performance', 'page speed', 'Core Web Vitals', 'lighthouse', 'load time', or needs to diagnose and fix frontend or backend performance issues. Do NOT use for code reviews or security audits.

    Ready to connect★ 419

    github.com/cwinvestments/memstack419 stars

    View details
  • memstack-security-api-auditSkillSecurity

    Use this skill when the user says 'audit API', 'check API security', 'API routes security', 'endpoint audit', 'check my routes', or needs to verify API route protection. Reviews API endpoints for authentication, authorization, and input validation gaps. Do NOT use for frontend security headers or de

    Ready to connect★ 419

    github.com/cwinvestments/memstack419 stars

    View details
  • memstack-security-csp-headersSkillSecurity

    Use this skill when the user says 'CSP', 'Content-Security-Policy', 'security headers', 'HSTS', 'X-Frame-Options', 'clickjacking', 'unsafe-inline', 'unsafe-eval', or needs to audit, generate, or fix HTTP security headers for a web application. Do NOT use for API route audits or dependency scanning.

    Ready to connect★ 419

    github.com/cwinvestments/memstack419 stars

    View details
  • memstack-security-dependency-auditSkillSecurity

    Use this skill when the user says 'dependency audit', 'npm audit', 'pip audit', 'cargo audit', 'security vulnerabilities', 'outdated packages', 'supply chain', or needs to scan project dependencies for vulnerabilities, abandoned packages, and upgrade risks. Do NOT use for application-level security

    Ready to connect★ 419

    github.com/cwinvestments/memstack419 stars

    View details
  • memstack-security-owasp-top10SkillSecurity

    Use this skill when the user says 'OWASP audit', 'OWASP top 10', 'security audit', 'vulnerability assessment', 'full security check', or needs a comprehensive web application security review against OWASP Top 10 categories. Do NOT use for dependency audits or secret scanning alone.

    Ready to connect★ 419

    github.com/cwinvestments/memstack419 stars

    View details
  • memstack-security-secrets-scannerSkillSecurity

    Use this skill when the user says 'scan for secrets', 'check for leaked keys', 'secrets scanner', 'hardcoded credentials', 'API key leak', or needs to detect exposed secrets in source code. Do NOT use for dependency vulnerabilities or RLS auditing.

    Ready to connect★ 419

    github.com/cwinvestments/memstack419 stars

    View details
  • parallel-code-reviewSkillSecurity

    Parallel 3-reviewer code review: Security, Business-Logic, Architecture.

    Ready to connect★ 419

    github.com/notque/vexjoy-agent419 stars

    View details
  • security-threat-modelSkillSecurity

    Security threat model: scan toolkit for attack surface, supply-chain risks.

    Ready to connect★ 419

    github.com/notque/vexjoy-agent419 stars

    View details
  • AI & LLM SecuritySkillSecurity

    LLM and AI application security testing — prompt injection, jailbreak resistance, OWASP LLM Top 10 (2025), RAG and agent/tool-use security, model supply chain, and AI red teaming for authorized assessments

    Ready to connect★ 409

    github.com/masriyan/claude-code-cybersecurity-skill411 stars

    View details
  • Cryptographic Analysis & AssessmentSkillSecurity

    SSL/TLS auditing, cipher suite analysis, hash algorithm identification, encryption implementation review, and cryptographic weakness detection in code

    Ready to connect★ 409

    github.com/masriyan/claude-code-cybersecurity-skill411 stars

    View details
  • Exploit Development & Payload EngineeringSkillSecurity

    Proof-of-concept development, payload crafting, shellcode analysis, and exploitation technique research for authorized security testing

    Ready to connect★ 409

    github.com/masriyan/claude-code-cybersecurity-skill411 stars

    View details
  • GRC & ComplianceSkillSecurity

    Governance, risk, and compliance — risk assessment and scoring, control mapping across NIST CSF 2.0 / ISO 27001:2022 / SOC 2 / CIS Controls v8, gap analysis, audit evidence preparation, and security policy generation

    Ready to connect★ 409

    github.com/masriyan/claude-code-cybersecurity-skill411 stars

    View details
  • Malware Analysis & SandboxingSkillSecurity

    Static and dynamic malware analysis, YARA rule generation, sandbox configuration, behavioral profiling, and malware family classification

    Ready to connect★ 409

    github.com/masriyan/claude-code-cybersecurity-skill411 stars

    View details
  • Network Security & Traffic AnalysisSkillSecurity

    Network traffic analysis, PCAP parsing, IDS/IPS rule creation, firewall configuration auditing, and network anomaly detection

    Ready to connect★ 409

    github.com/masriyan/claude-code-cybersecurity-skill411 stars

    View details
  • OT / ICS / SCADA SecuritySkillSecurity

    Operational Technology and industrial control system security — Purdue model segmentation, industrial protocol analysis (Modbus, DNP3, S7, EtherNet/IP), PLC/HMI exposure, IEC 62443 alignment, and MITRE ATT&CK for ICS, for authorized and safety-conscious assessments

    Ready to connect★ 409

    github.com/masriyan/claude-code-cybersecurity-skill411 stars

    View details
  • Purple Team & Adversary EmulationSkillSecurity

    Collaborative purple-team operations — threat-informed adversary emulation planning (ATT&CK, CTID, Atomic Red Team, CALDERA), the detect-tune-validate loop, detection coverage measurement (DeTT&CT/Navigator), safe execution and deconfliction, and MTTD/coverage reporting

    Ready to connect★ 409

    github.com/masriyan/claude-code-cybersecurity-skill411 stars

    View details
  • Reconnaissance & OSINT AutomationSkillSecurity

    Passive and active reconnaissance, subdomain enumeration, DNS analysis, technology fingerprinting, and OSINT data correlation for authorized security assessments

    Ready to connect★ 409

    github.com/masriyan/claude-code-cybersecurity-skill411 stars

    View details
  • Red Team Operations & Engagement PlanningSkillSecurity

    Authorized red team engagement planning, C2 architecture design, attack methodology, lateral movement strategy, OPSEC, and professional reporting

    Ready to connect★ 409

    github.com/masriyan/claude-code-cybersecurity-skill411 stars

    View details
  • Reverse Engineering & Binary AnalysisSkillSecurity

    Binary analysis, assembly interpretation, disassembly, decompilation, firmware RE, and protocol reverse engineering

    Ready to connect★ 409

    github.com/masriyan/claude-code-cybersecurity-skill411 stars

    View details
  • Supply Chain SecuritySkillSecurity

    Software supply chain security — SBOM generation and analysis, dependency confusion and typosquatting detection, malicious package indicators, CI/CD pipeline hardening, and artifact provenance/signing (SLSA, Sigstore)

    Ready to connect★ 409

    github.com/masriyan/claude-code-cybersecurity-skill411 stars

    View details
  • Threat Hunting & IOC AnalysisSkillSecurity

    IOC extraction, threat intelligence correlation, MITRE ATT&CK mapping, hunt hypothesis generation, and detection rule creation

    Ready to connect★ 409

    github.com/masriyan/claude-code-cybersecurity-skill411 stars

    View details
  • Threat Intelligence & CTISkillSecurity

    Cyber threat intelligence production — the intelligence cycle, IOC extraction/normalization/enrichment, STIX/TAXII and MISP, structured analytic models (Diamond, Kill Chain, ATT&CK), source scoring, actor/campaign tracking, and finished intelligence reporting

    Ready to connect★ 409

    github.com/masriyan/claude-code-cybersecurity-skill411 stars

    View details

What is a skill?

A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.

52,524 of the 52,958 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.

Install one and every AI you use gets it

Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.

Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.

See how to connect your AI