Skills.

Give your AI a better way to work.

A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.

Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.

Category: Security

1,738 results · page 20 of 58

  • Vulnerability Scanning & AssessmentSkillSecurity

    Dependency auditing, CVE detection, configuration security review, CVSS scoring, and prioritized vulnerability reporting

    Ready to connect★ 409

    github.com/masriyan/claude-code-cybersecurity-skill411 stars

    View details
  • Web Application Security TestingSkillSecurity

    OWASP Top 10 testing, injection vulnerability detection, API security assessment, authentication testing, and web vulnerability reporting for authorized assessments

    Ready to connect★ 409

    github.com/masriyan/claude-code-cybersecurity-skill411 stars

    View details
  • ghost-exoSkillSecurity

    The single interface for building, improving, and debugging exo workflows. Routes to one of three intents. BUILD takes a rough idea through interrogation, assessment, resource creation in dependency order, and one manual run, then hands off. IMPROVE runs the observe-and-iterate loop over recent runs

    Ready to connect★ 405

    github.com/ghostsecurity/skills405 stars

    View details
  • ghost-reportSkillSecurity

    Ghost Security — combined security report. Aggregates findings from all scan skills (scan-deps, scan-secrets, scan-code) into a single prioritized report focused on the highest risk, highest confidence issues. Use when the user requests a security overview, vulnerability summary, full security audit

    Ready to connect★ 405

    github.com/ghostsecurity/skills405 stars

    View details
  • ghost-scan-depsSkillSecurity

    Ghost Security - Software Composition Analysis (SCA) scanner. Scans dependency lockfiles for known vulnerabilities, identifies CVEs, and generates findings with severity levels and remediation guidance. Use when the user asks about dependency vulnerabilities, vulnerable packages, CVE checks, securit

    Ready to connect★ 405

    github.com/ghostsecurity/skills405 stars

    View details
  • ghost-scan-secretsSkillSecurity

    Ghost Security - Secrets and credentials scanner. Scans codebase for leaked API keys, tokens, passwords, and sensitive data. Detects hardcoded secrets and generates findings with severity and remediation guidance. Use when the user asks to check for leaked secrets, scan for credentials, find hardcod

    Ready to connect★ 405

    github.com/ghostsecurity/skills405 stars

    View details
  • ghost-validateSkillSecurity

    This skill should be used when the user asks to "validate a finding", "check if a vulnerability is real", "triage a security finding", "confirm a vulnerability", "determine if a finding is a true positive or false positive", or provides a security finding for review. It validates security vulnerabil

    Ready to connect★ 405

    github.com/ghostsecurity/skills405 stars

    View details
  • convex-http-actionsSkillSecurity

    External API integration and webhook handling including HTTP endpoint routing, request/response handling, authentication, CORS configuration, and webhook signature validation

    Ready to connect★ 404

    github.com/waynesutton/convexskills404 stars

    View details
  • convex-security-auditSkillSecurity

    Deep security review patterns for authorization logic, data access boundaries, action isolation, rate limiting, and protecting sensitive operations

    Ready to connect★ 404

    github.com/waynesutton/convexskills404 stars

    View details
  • convex-security-checkSkillSecurity

    Quick security audit checklist covering authentication, function exposure, argument validation, row-level access control, and environment variable handling

    Ready to connect★ 404

    github.com/waynesutton/convexskills404 stars

    View details
  • create-threat-modelSkillSecurity

    Analyze a codebase and produce a structured threat model at .turbo/threat-model.md covering assets, trust boundaries, attack surfaces with existing mitigations, attacker stories, and calibrated severity. Use when the user asks to \"create a threat model\", \"threat model\", \"threat model this codeb

    Ready to connect★ 402

    github.com/tobihagemann/turbo402 stars

    View details
  • review-codeSkillSecurity

    Review code for bugs, security vulnerabilities, API misuse, consistency issues, simplicity problems, or test coverage gaps by running internal reviews and a peer review in parallel and returning combined findings. Single-concern with a type argument, or full review with no argument. Use when the use

    Ready to connect★ 402

    github.com/tobihagemann/turbo402 stars

    View details
  • review-dependenciesSkillSecurity

    Detect package managers and CI action pins, then discover outdated or vulnerable dependencies. Returns structured findings without upgrading. Use when the user asks to \"review dependencies\", \"check for outdated packages\", \"check dependencies\", \"scan dependencies\", \"dependency review\", \"ch

    Ready to connect★ 402

    github.com/tobihagemann/turbo402 stars

    View details
  • agentsop-multi-tenant-ragSkillSecurity

    Security-first SOP for multi-tenant RAG systems. Activate when a calling agent is building, reviewing, or debugging any retrieval pipeline whose vector store is shared across more than one user, organisation, workspace, customer, or permission scope. Encodes the single non-negotiable rule — **filter

    Ready to connect★ 398

    github.com/agentsope/skillalchemy398 stars

    View details
  • auth-implementation-patternsSkillSecurity

    Master authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable access control systems. Use when implementing auth systems, securing APIs, or debugging security issues.

    Ready to connect★ 394

    github.com/microck/ordinary-claude-skills395 stars

    View details
  • bitcoin-auth-diagnosticsSkillSecurity

    Diagnose and troubleshoot bitcoin-auth token generation and verification issues. This skill should be used when users encounter authentication failures, signature verification errors, or integration problems with the bitcoin-auth library.

    Ready to connect★ 394

    github.com/microck/ordinary-claude-skills395 stars

    View details
  • blockchain-developerSkillSecurity

    Expert blockchain developer specializing in smart contract development, DApp architecture, and DeFi protocols. Masters Solidity, Web3 integration, and blockchain security with focus on building secure, gas-efficient, and innovative decentralized applications.

    Ready to connect★ 394

    github.com/microck/ordinary-claude-skills395 stars

    View details
  • secure-authSkillSecurity

    Secure authentication patterns (OWASP, NIST). Use for login, registration, password reset, sessions, JWT, OAuth, MFA, passkeys.

    Ready to connect★ 391

    github.com/jamditis/claude-skills-journalism391 stars

    View details
  • supply-chain-hardeningSkillSecurity

    Install-time cooldowns for npm/bun plus a sandboxed pre-install scan for bypasses. Use for supply-chain attacks or npm security.

    Ready to connect★ 391

    github.com/jamditis/claude-skills-journalism391 stars

    View details
  • yao-codereview-hskillSkillSecurity

    Provides professional code review services, checking code quality, security vulnerabilities, performance issues, and best practices. Supports multiple programming languages and frameworks.

    Ready to connect★ 384

    github.com/bruc3van/agent-skills-guard384 stars

    View details
  • llm-testingSkillSecurity

    Comprehensive LLM security testing prompts for bias detection, data leakage, alignment testing, and adversarial prompt resistance.

    Ready to connect★ 383

    github.com/eyadkelleh/awesome-skills-security383 stars

    View details
  • security-passwordsSkillSecurity

    Top password lists for authorized security testing: common passwords, darkweb leaks, worst passwords. Curated essentials (<10MB).

    Ready to connect★ 383

    github.com/eyadkelleh/awesome-skills-security383 stars

    View details
  • security-usernamesSkillSecurity

    Top username lists for enumeration: common usernames, default credentials, names. Curated essentials for authorized testing.

    Ready to connect★ 383

    github.com/eyadkelleh/awesome-skills-security383 stars

    View details
  • security-webshellsSkillSecurity

    Web shell samples for detection and analysis: PHP, ASP, ASPX, JSP, Python, Perl shells. Use for security research and detection system testing.

    Ready to connect★ 383

    github.com/eyadkelleh/awesome-skills-security383 stars

    View details
  • asanaSkillSecurity

    Asana API integration with managed OAuth. Access tasks, projects, workspaces, users, and manage webhooks. Use this skill when users want to manage work items, track projects, or integrate with Asana workflows. For other third party apps, use the api-gateway skill (https://clawhub.ai/byungkyu/api-gat

    Ready to connect★ 382

    github.com/craftos-dev/craftbot376 stars

    View details
  • audit-context-buildingSkillSecurity

    Enables ultra-granular, line-by-line code analysis to build deep architectural context before vulnerability or bug finding.

    Ready to connect★ 382

    github.com/craftos-dev/craftbot376 stars

    View details
  • calendlySkillSecurity

    Calendly API integration with managed OAuth. Access event types, scheduled events, invitees, availability, and manage webhooks. Use this skill when users want to view scheduling data, check availability, book meetings, or integrate with Calendly workflows. For other third party apps, use the api-gat

    Ready to connect★ 382

    github.com/craftos-dev/craftbot376 stars

    View details
  • clickupSkillSecurity

    ClickUp API integration with managed OAuth. Access tasks, lists, folders, spaces, workspaces, users, and manage webhooks. Use this skill when users want to manage work items, track projects, or integrate with ClickUp workflows. For other third party apps, use the api-gateway skill (https://clawhub.a

    Ready to connect★ 382

    github.com/craftos-dev/craftbot376 stars

    View details
  • compliance-cert-plannerSkillSecurity

    Plan and sequence security and privacy compliance certifications (SOC 2, ISO 27001, GDPR, HIPAA, PCI DSS, CASA, etc.). Use when the user needs to scope which frameworks apply, classify each one, identify shared controls, and produce a roadmap.

    Ready to connect★ 382

    github.com/craftos-dev/craftbot376 stars

    View details
  • google-meetSkillSecurity

    Google Meet API integration with managed OAuth. Create meeting spaces, list conference records, and manage meeting participants. Use this skill when users want to interact with Google Meet. For other third party apps, use the api-gateway skill (https://clawhub.ai/byungkyu/api-gateway).

    Ready to connect★ 382

    github.com/craftos-dev/craftbot376 stars

    View details

What is a skill?

A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.

52,524 of the 52,958 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.

Install one and every AI you use gets it

Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.

Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.

See how to connect your AI