Skills.
Give your AI a better way to work.
A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.
Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.
Category: Security
1,738 results · page 19 of 58
- View details
account-authenticationSkillSecurity
Use when applying for Xiaohongshu account verification (blue check), understanding verification types and benefits, preparing verification application materials, or increasing account credibility and trust
Ready to connect★ 434
- View details
account-safetySkillSecurity
Use when needing to protect account from hacking, unauthorized access, suspension, or other security threats on Xiaohongshu
Ready to connect★ 434
- View details
account-securitySkillSecurity
Use when protecting Xiaohongshu account from unauthorized access, preventing account theft, recovering compromised accounts, or implementing security measures to safeguard account and follower base
Ready to connect★ 434
- View details
winui-code-reviewSkillSecurity
Code quality review for WinUI 3 apps — MVVM compliance, x:Bind correctness, accessibility, theming, security, and performance. Use before committing to catch issues that the compiler and UI tests won't find.
Ready to connect★ 433
- View details
1password-credential-lookupSkillSecurity
This skill should be used when agents need to log into websites, retrieve passwords, or access credentials. CRITICAL - always use find_credential with the website URL, never guess item names.
Ready to connect★ 422
- View details
cve-source-checkSkillSecurity
Audit CVE/vulnerability source coverage for a technology stack. Maps each component (container, library, base image, runtime) to authoritative CVE feeds, flags gaps, and produces audit-ready reports. Generic: works for any service or stack.
Ready to connect★ 419
- View details
memstack-automation-api-integrationSkillSecurity
Use this skill when the user says 'API integration', 'connect APIs', 'sync data', 'data mapping', 'rate limiting', or needs system-to-system connectors with authentication, rate limit handling, and error recovery. Generates API integration code with authentication (OAuth, API key, JWT), request/resp
Ready to connect★ 419
- View details
memstack-development-code-reviewerSkillSecurity
Use this skill when the user says 'review code', 'code review', 'check my code', 'audit this', 'review PR', 'review changes', 'what's wrong with this', or is requesting a structured review of code quality, security, performance, or maintainability. Do NOT use for refactoring plans or test generation
Ready to connect★ 419
- View details
memstack-development-performance-auditSkillSecurity
Use this skill when the user says 'performance audit', 'why is it slow', 'optimize performance', 'page speed', 'Core Web Vitals', 'lighthouse', 'load time', or needs to diagnose and fix frontend or backend performance issues. Do NOT use for code reviews or security audits.
Ready to connect★ 419
- View details
memstack-security-api-auditSkillSecurity
Use this skill when the user says 'audit API', 'check API security', 'API routes security', 'endpoint audit', 'check my routes', or needs to verify API route protection. Reviews API endpoints for authentication, authorization, and input validation gaps. Do NOT use for frontend security headers or de
Ready to connect★ 419
- View details
memstack-security-csp-headersSkillSecurity
Use this skill when the user says 'CSP', 'Content-Security-Policy', 'security headers', 'HSTS', 'X-Frame-Options', 'clickjacking', 'unsafe-inline', 'unsafe-eval', or needs to audit, generate, or fix HTTP security headers for a web application. Do NOT use for API route audits or dependency scanning.
Ready to connect★ 419
- View details
memstack-security-dependency-auditSkillSecurity
Use this skill when the user says 'dependency audit', 'npm audit', 'pip audit', 'cargo audit', 'security vulnerabilities', 'outdated packages', 'supply chain', or needs to scan project dependencies for vulnerabilities, abandoned packages, and upgrade risks. Do NOT use for application-level security
Ready to connect★ 419
- View details
memstack-security-owasp-top10SkillSecurity
Use this skill when the user says 'OWASP audit', 'OWASP top 10', 'security audit', 'vulnerability assessment', 'full security check', or needs a comprehensive web application security review against OWASP Top 10 categories. Do NOT use for dependency audits or secret scanning alone.
Ready to connect★ 419
- View details
memstack-security-secrets-scannerSkillSecurity
Use this skill when the user says 'scan for secrets', 'check for leaked keys', 'secrets scanner', 'hardcoded credentials', 'API key leak', or needs to detect exposed secrets in source code. Do NOT use for dependency vulnerabilities or RLS auditing.
Ready to connect★ 419
- View details
parallel-code-reviewSkillSecurity
Parallel 3-reviewer code review: Security, Business-Logic, Architecture.
Ready to connect★ 419
- View details
security-threat-modelSkillSecurity
Security threat model: scan toolkit for attack surface, supply-chain risks.
Ready to connect★ 419
- View details
AI & LLM SecuritySkillSecurity
LLM and AI application security testing — prompt injection, jailbreak resistance, OWASP LLM Top 10 (2025), RAG and agent/tool-use security, model supply chain, and AI red teaming for authorized assessments
Ready to connect★ 409
- View details
Cryptographic Analysis & AssessmentSkillSecurity
SSL/TLS auditing, cipher suite analysis, hash algorithm identification, encryption implementation review, and cryptographic weakness detection in code
Ready to connect★ 409
- View details
Exploit Development & Payload EngineeringSkillSecurity
Proof-of-concept development, payload crafting, shellcode analysis, and exploitation technique research for authorized security testing
Ready to connect★ 409
- View details
GRC & ComplianceSkillSecurity
Governance, risk, and compliance — risk assessment and scoring, control mapping across NIST CSF 2.0 / ISO 27001:2022 / SOC 2 / CIS Controls v8, gap analysis, audit evidence preparation, and security policy generation
Ready to connect★ 409
- View details
Malware Analysis & SandboxingSkillSecurity
Static and dynamic malware analysis, YARA rule generation, sandbox configuration, behavioral profiling, and malware family classification
Ready to connect★ 409
- View details
Network Security & Traffic AnalysisSkillSecurity
Network traffic analysis, PCAP parsing, IDS/IPS rule creation, firewall configuration auditing, and network anomaly detection
Ready to connect★ 409
- View details
OT / ICS / SCADA SecuritySkillSecurity
Operational Technology and industrial control system security — Purdue model segmentation, industrial protocol analysis (Modbus, DNP3, S7, EtherNet/IP), PLC/HMI exposure, IEC 62443 alignment, and MITRE ATT&CK for ICS, for authorized and safety-conscious assessments
Ready to connect★ 409
- View details
Purple Team & Adversary EmulationSkillSecurity
Collaborative purple-team operations — threat-informed adversary emulation planning (ATT&CK, CTID, Atomic Red Team, CALDERA), the detect-tune-validate loop, detection coverage measurement (DeTT&CT/Navigator), safe execution and deconfliction, and MTTD/coverage reporting
Ready to connect★ 409
- View details
Reconnaissance & OSINT AutomationSkillSecurity
Passive and active reconnaissance, subdomain enumeration, DNS analysis, technology fingerprinting, and OSINT data correlation for authorized security assessments
Ready to connect★ 409
- View details
Red Team Operations & Engagement PlanningSkillSecurity
Authorized red team engagement planning, C2 architecture design, attack methodology, lateral movement strategy, OPSEC, and professional reporting
Ready to connect★ 409
- View details
Reverse Engineering & Binary AnalysisSkillSecurity
Binary analysis, assembly interpretation, disassembly, decompilation, firmware RE, and protocol reverse engineering
Ready to connect★ 409
- View details
Supply Chain SecuritySkillSecurity
Software supply chain security — SBOM generation and analysis, dependency confusion and typosquatting detection, malicious package indicators, CI/CD pipeline hardening, and artifact provenance/signing (SLSA, Sigstore)
Ready to connect★ 409
- View details
Threat Hunting & IOC AnalysisSkillSecurity
IOC extraction, threat intelligence correlation, MITRE ATT&CK mapping, hunt hypothesis generation, and detection rule creation
Ready to connect★ 409
- View details
Threat Intelligence & CTISkillSecurity
Cyber threat intelligence production — the intelligence cycle, IOC extraction/normalization/enrichment, STIX/TAXII and MISP, structured analytic models (Diamond, Kill Chain, ATT&CK), source scoring, actor/campaign tracking, and finished intelligence reporting
Ready to connect★ 409
What is a skill?
A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.
52,524 of the 52,958 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.
Install one and every AI you use gets it
Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.
Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.