Skills.
Give your AI a better way to work.
A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.
Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.
Category: Security
1,738 results · page 20 of 58
- View details
Vulnerability Scanning & AssessmentSkillSecurity
Dependency auditing, CVE detection, configuration security review, CVSS scoring, and prioritized vulnerability reporting
Ready to connect★ 409
- View details
Web Application Security TestingSkillSecurity
OWASP Top 10 testing, injection vulnerability detection, API security assessment, authentication testing, and web vulnerability reporting for authorized assessments
Ready to connect★ 409
- View details
ghost-exoSkillSecurity
The single interface for building, improving, and debugging exo workflows. Routes to one of three intents. BUILD takes a rough idea through interrogation, assessment, resource creation in dependency order, and one manual run, then hands off. IMPROVE runs the observe-and-iterate loop over recent runs
Ready to connect★ 405
- View details
ghost-reportSkillSecurity
Ghost Security — combined security report. Aggregates findings from all scan skills (scan-deps, scan-secrets, scan-code) into a single prioritized report focused on the highest risk, highest confidence issues. Use when the user requests a security overview, vulnerability summary, full security audit
Ready to connect★ 405
- View details
ghost-scan-depsSkillSecurity
Ghost Security - Software Composition Analysis (SCA) scanner. Scans dependency lockfiles for known vulnerabilities, identifies CVEs, and generates findings with severity levels and remediation guidance. Use when the user asks about dependency vulnerabilities, vulnerable packages, CVE checks, securit
Ready to connect★ 405
- View details
ghost-scan-secretsSkillSecurity
Ghost Security - Secrets and credentials scanner. Scans codebase for leaked API keys, tokens, passwords, and sensitive data. Detects hardcoded secrets and generates findings with severity and remediation guidance. Use when the user asks to check for leaked secrets, scan for credentials, find hardcod
Ready to connect★ 405
- View details
ghost-validateSkillSecurity
This skill should be used when the user asks to "validate a finding", "check if a vulnerability is real", "triage a security finding", "confirm a vulnerability", "determine if a finding is a true positive or false positive", or provides a security finding for review. It validates security vulnerabil
Ready to connect★ 405
- View details
convex-http-actionsSkillSecurity
External API integration and webhook handling including HTTP endpoint routing, request/response handling, authentication, CORS configuration, and webhook signature validation
Ready to connect★ 404
- View details
convex-security-auditSkillSecurity
Deep security review patterns for authorization logic, data access boundaries, action isolation, rate limiting, and protecting sensitive operations
Ready to connect★ 404
- View details
convex-security-checkSkillSecurity
Quick security audit checklist covering authentication, function exposure, argument validation, row-level access control, and environment variable handling
Ready to connect★ 404
- View details
create-threat-modelSkillSecurity
Analyze a codebase and produce a structured threat model at .turbo/threat-model.md covering assets, trust boundaries, attack surfaces with existing mitigations, attacker stories, and calibrated severity. Use when the user asks to \"create a threat model\", \"threat model\", \"threat model this codeb
Ready to connect★ 402
- View details
review-codeSkillSecurity
Review code for bugs, security vulnerabilities, API misuse, consistency issues, simplicity problems, or test coverage gaps by running internal reviews and a peer review in parallel and returning combined findings. Single-concern with a type argument, or full review with no argument. Use when the use
Ready to connect★ 402
- View details
review-dependenciesSkillSecurity
Detect package managers and CI action pins, then discover outdated or vulnerable dependencies. Returns structured findings without upgrading. Use when the user asks to \"review dependencies\", \"check for outdated packages\", \"check dependencies\", \"scan dependencies\", \"dependency review\", \"ch
Ready to connect★ 402
- View details
agentsop-multi-tenant-ragSkillSecurity
Security-first SOP for multi-tenant RAG systems. Activate when a calling agent is building, reviewing, or debugging any retrieval pipeline whose vector store is shared across more than one user, organisation, workspace, customer, or permission scope. Encodes the single non-negotiable rule — **filter
Ready to connect★ 398
- View details
auth-implementation-patternsSkillSecurity
Master authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable access control systems. Use when implementing auth systems, securing APIs, or debugging security issues.
Ready to connect★ 394
- View details
bitcoin-auth-diagnosticsSkillSecurity
Diagnose and troubleshoot bitcoin-auth token generation and verification issues. This skill should be used when users encounter authentication failures, signature verification errors, or integration problems with the bitcoin-auth library.
Ready to connect★ 394
- View details
blockchain-developerSkillSecurity
Expert blockchain developer specializing in smart contract development, DApp architecture, and DeFi protocols. Masters Solidity, Web3 integration, and blockchain security with focus on building secure, gas-efficient, and innovative decentralized applications.
Ready to connect★ 394
- View details
secure-authSkillSecurity
Secure authentication patterns (OWASP, NIST). Use for login, registration, password reset, sessions, JWT, OAuth, MFA, passkeys.
Ready to connect★ 391
- View details
supply-chain-hardeningSkillSecurity
Install-time cooldowns for npm/bun plus a sandboxed pre-install scan for bypasses. Use for supply-chain attacks or npm security.
Ready to connect★ 391
- View details
yao-codereview-hskillSkillSecurity
Provides professional code review services, checking code quality, security vulnerabilities, performance issues, and best practices. Supports multiple programming languages and frameworks.
Ready to connect★ 384
- View details
llm-testingSkillSecurity
Comprehensive LLM security testing prompts for bias detection, data leakage, alignment testing, and adversarial prompt resistance.
Ready to connect★ 383
- View details
security-passwordsSkillSecurity
Top password lists for authorized security testing: common passwords, darkweb leaks, worst passwords. Curated essentials (<10MB).
Ready to connect★ 383
- View details
security-usernamesSkillSecurity
Top username lists for enumeration: common usernames, default credentials, names. Curated essentials for authorized testing.
Ready to connect★ 383
- View details
security-webshellsSkillSecurity
Web shell samples for detection and analysis: PHP, ASP, ASPX, JSP, Python, Perl shells. Use for security research and detection system testing.
Ready to connect★ 383
- View details
asanaSkillSecurity
Asana API integration with managed OAuth. Access tasks, projects, workspaces, users, and manage webhooks. Use this skill when users want to manage work items, track projects, or integrate with Asana workflows. For other third party apps, use the api-gateway skill (https://clawhub.ai/byungkyu/api-gat
Ready to connect★ 382
- View details
audit-context-buildingSkillSecurity
Enables ultra-granular, line-by-line code analysis to build deep architectural context before vulnerability or bug finding.
Ready to connect★ 382
- View details
calendlySkillSecurity
Calendly API integration with managed OAuth. Access event types, scheduled events, invitees, availability, and manage webhooks. Use this skill when users want to view scheduling data, check availability, book meetings, or integrate with Calendly workflows. For other third party apps, use the api-gat
Ready to connect★ 382
- View details
clickupSkillSecurity
ClickUp API integration with managed OAuth. Access tasks, lists, folders, spaces, workspaces, users, and manage webhooks. Use this skill when users want to manage work items, track projects, or integrate with ClickUp workflows. For other third party apps, use the api-gateway skill (https://clawhub.a
Ready to connect★ 382
- View details
compliance-cert-plannerSkillSecurity
Plan and sequence security and privacy compliance certifications (SOC 2, ISO 27001, GDPR, HIPAA, PCI DSS, CASA, etc.). Use when the user needs to scope which frameworks apply, classify each one, identify shared controls, and produce a roadmap.
Ready to connect★ 382
- View details
google-meetSkillSecurity
Google Meet API integration with managed OAuth. Create meeting spaces, list conference records, and manage meeting participants. Use this skill when users want to interact with Google Meet. For other third party apps, use the api-gateway skill (https://clawhub.ai/byungkyu/api-gateway).
Ready to connect★ 382
What is a skill?
A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.
52,524 of the 52,958 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.
Install one and every AI you use gets it
Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.
Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.