Skills.

Give your AI a better way to work.

A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.

Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.

Category: Security

1,738 results · page 21 of 58

  • google-playSkillSecurity

    Google Play Developer API (Android Publisher) integration with managed OAuth. Manage apps, subscriptions, in-app purchases, and reviews. Use this skill when users want to interact with Google Play Console programmatically. For other third party apps, use the api-gateway skill (https://clawhub.ai/byu

    Ready to connect★ 382

    github.com/craftos-dev/craftbot376 stars

    View details
  • google-workspace-adminSkillSecurity

    Google Workspace Admin SDK integration with managed OAuth. Manage users, groups, organizational units, and domain settings. Use this skill when users want to administer Google Workspace. For other third party apps, use the api-gateway skill (https://clawhub.ai/byungkyu/api-gateway).

    Ready to connect★ 382

    github.com/craftos-dev/craftbot376 stars

    View details
  • pipedriveSkillSecurity

    Pipedrive API integration with managed OAuth. Manage deals, persons, organizations, activities, and pipelines. Use this skill when users want to interact with Pipedrive CRM. For other third party apps, use the api-gateway skill (https://clawhub.ai/byungkyu/api-gateway).

    Ready to connect★ 382

    github.com/craftos-dev/craftbot376 stars

    View details
  • salesforceSkillSecurity

    Salesforce CRM API integration with managed OAuth. Query records with SOQL, manage sObjects (Contacts, Accounts, Leads, Opportunities), and perform batch operations. Use this skill when users want to interact with Salesforce data. For other third party apps, use the api-gateway skill (https://clawhu

    Ready to connect★ 382

    github.com/craftos-dev/craftbot376 stars

    View details
  • shannonSkillSecurity

    Autonomous AI pentester for web apps and APIs. Run white-box security assessments with Shannon — analyzes source code, identifies attack vectors, and executes real exploits to prove vulnerabilities. Triggered by 'shannon', 'pentest', 'security audit', 'vuln scan'.

    Ready to connect★ 382

    github.com/craftos-dev/craftbot376 stars

    View details
  • sharp-edgesSkillSecurity

    Lets your agent check code or designs for sharp edges like unfinished parts or risky spots.

    Ready to connect★ 382

    github.com/craftos-dev/craftbot376 stars

    View details
  • stripeSkillSecurity

    Stripe API integration with managed OAuth. Manage customers, subscriptions, invoices, products, prices, and payments. Use this skill when users want to process payments, manage billing, or handle subscriptions with Stripe. For other third party apps, use the api-gateway skill (https://clawhub.ai/byu

    Ready to connect★ 382

    github.com/craftos-dev/craftbot376 stars

    View details
  • e2eSkillSecurity

    Run end-to-end tests of SmokedMeat against the Whooli goat repos. Use when testing TUI changes, verifying exploit flows, debugging UI state, or validating Kitchen/Counter integration.

    Ready to connect★ 378

    github.com/boostsecurityio/smokedmeat376 stars

    View details
  • sonarqubeSkillSecurity

    Operate SonarQube-enabled repositories through the SonarQube CLI (`sonar`): verify authentication, discover project keys, inspect project metadata, issues, measures, and quality gates, analyze changed code, scan secrets and dependency risks, call authenticated APIs, trigger remediation, configure in

    Ready to connect★ 371

    github.com/dougtrajano/pydantic-ai-skills371 stars

    View details
  • composio-integrationsSkillSecurity

    Use Composio-connected SaaS tools safely. Generate OAuth connect links in chat when the user's account is not connected.

    Ready to connect★ 364

    github.com/ahmadrosid/nakama286 stars

    View details
  • lean-pr-reviewSkillSecurity

    Review a GitHub PR for unnecessary complexity. For PRs authored by someone else, post short human-sounding inline review comments via gh. For PRs authored by the authenticated gh user ("me"), apply the cuts on the PR branch and push — do not post review comments. Use when the user asks for a lean PR

    Ready to connect★ 364

    github.com/ahmadrosid/nakama286 stars

    View details
  • advanced-redteamSkillSecurity

    Offensive security toolkit for Claude Code covering red team, exploit dev, AD attacks, EDR bypass, mobile pentest

    Ready to connect★ 358

    github.com/hypnguyen1209/offensive-claude362 stars

    View details
  • coding-masterySkillSecurity

    Use when writing security tooling, exploits, scanners, or C2 in Python/C/Go/Rust/ASM — systems & network programming, automation, cryptography implementation

    Ready to connect★ 358

    github.com/hypnguyen1209/offensive-claude362 stars

    View details
  • engagement-flowSkillSecurity

    Use when starting, planning, or running a multi-phase pentest or red-team engagement — to sequence the Cyber Kill Chain phases with quality gates instead of jumping straight to exploitation

    Ready to connect★ 358

    github.com/hypnguyen1209/offensive-claude362 stars

    View details
  • finding-disciplineSkillSecurity

    Use when about to record, claim, rate the severity of, or report any security finding — before marking anything [CONFIRMED] or writing it into the report

    Ready to connect★ 358

    github.com/hypnguyen1209/offensive-claude362 stars

    View details
  • initial-accessSkillSecurity

    Use when gaining initial access to a target — phishing, payload delivery, HTML smuggling, ISO/IMG/MOTW bypass, supply-chain, credential stuffing, exposed-service exploitation

    Ready to connect★ 358

    github.com/hypnguyen1209/offensive-claude362 stars

    View details
  • keylogger-archSkillSecurity

    Offensive security toolkit for Claude Code covering red team, exploit dev, AD attacks, EDR bypass, mobile pentest

    Ready to connect★ 358

    github.com/hypnguyen1209/offensive-claude362 stars

    View details
  • network-attackSkillSecurity

    Use when attacking a network or moving laterally — L2/L3 poisoning (LLMNR/mDNS, ARP/DHCP, mitm6), coercion + NTLM relay (CVE-2025-33073), TUN pivoting (Ligolo-ng/Chisel), MitM, network-service RCE (CVE-2024-38077), WPA2/WPA3 wireless

    Ready to connect★ 358

    github.com/hypnguyen1209/offensive-claude362 stars

    View details
  • privesc-linuxSkillSecurity

    Use when escalating privileges on a Linux host — SUID/SGID & GTFOBins, sudo LPE (CVE-2025-32462/32463), capabilities & LD_PRELOAD, kernel LPE (CVE-2024-1086, Dirty Pipe, GameOver(lay)), service misconfig (PwnKit, Looney Tunables), container/namespace escape

    Ready to connect★ 358

    github.com/hypnguyen1209/offensive-claude362 stars

    View details
  • privesc-windowsSkillSecurity

    Use when escalating privileges on a Windows host — SeImpersonate Potato chains (GodPotato/PrintNotifyPotato), service & DLL hijacking, UAC bypass (fodhelper/ICMLuaUtil), kernel EoP + BYOVD (CVE-2025-29824), token-rights abuse, LSASS/SAM/DPAPI credential harvesting

    Ready to connect★ 358

    github.com/hypnguyen1209/offensive-claude362 stars

    View details
  • threat-huntingSkillSecurity

    Use when hunting threats or engineering detections — ATT&CK Detection-Strategies, Sigma + correlation with Detection-as-Code CI, Windows endpoint hunting (Sysmon/ETW/LSASS/LOLBins), network C2 hunting (JA4+, beaconing, DNS tunneling), cloud-identity hunting, Atomic Red Team purple-team validation

    Ready to connect★ 358

    github.com/hypnguyen1209/offensive-claude362 stars

    View details
  • threat-model-disciplineSkillSecurity

    Use when starting an engagement, before exploitation, or whenever the attack surface changes — build/validate the threat model and detect drift (new unreviewed surface) before advancing

    Ready to connect★ 358

    github.com/hypnguyen1209/offensive-claude362 stars

    View details
  • using-offensive-claudeSkillSecurity

    Use when starting any offensive-security engagement or task — establishes how to find and invoke the right skill before any action (including clarifying questions, recon, exploitation, or reporting)

    Ready to connect★ 358

    github.com/hypnguyen1209/offensive-claude362 stars

    View details
  • web-pentestSkillSecurity

    Use when pentesting a web application or API — injection, XSS/CSP, SSRF/cloud-metadata, HTTP desync & cache poisoning, SSTI/prototype-pollution/deserialization, JWT/OAuth/GraphQL/IDOR, business logic & single-packet race

    Ready to connect★ 358

    github.com/hypnguyen1209/offensive-claude362 stars

    View details
  • windows-boundariesSkillSecurity

    Use when crossing a Windows security boundary or escaping a sandbox — kernel/user crossing (win32k/dxgkrnl UAF CVE-2025-24983), BYOVD kernel R/W, UAC/COM elevation, AppContainer/LPAC & Chromium-Mojo sandbox escape (CVE-2025-2783), PPL bypass, RPC/ALPC & named-pipe impersonation

    Ready to connect★ 358

    github.com/hypnguyen1209/offensive-claude362 stars

    View details
  • owasp-securitySkillSecurity

    Use when reviewing code for security vulnerabilities, implementing authentication/authorization, handling user input, or discussing web application security. Covers OWASP Top 10:2025, ASVS 5.0, LLM Top 10 (2025), and Agentic AI security (2026).

    Ready to connect★ 358

    github.com/agamm/claude-code-owasp361 stars

    View details
  • robotics-securitySkillSecurity

    Security hardening and best practices for robotic systems, covering SROS2 DDS security, network segmentation, secrets management, secure boot, and the physical-cyber safety intersection. Use this skill when securing ROS2 communications, configuring DDS encryption and access control, hardening robot

    Ready to connect★ 358

    github.com/arpitg1304/robotics-agent-skills358 stars

    View details
  • V3 Security OverhaulSkillSecurity

    Complete security architecture overhaul for claude-flow v3. Addresses critical CVEs (CVE-1, CVE-2, CVE-3) and implements secure-by-default patterns. Use for security-first v3 implementation.

    Ready to connect★ 355

    github.com/spencermarx/open-code-review357 stars

    View details
  • V3 Swarm CoordinationSkillSecurity

    15-agent hierarchical mesh coordination for v3 implementation. Orchestrates parallel execution across security, core, and integration domains following 10 ADRs with 14-week timeline.

    Ready to connect★ 355

    github.com/spencermarx/open-code-review357 stars

    View details
  • nextjs-authenticationSkillSecurity

    Provides authentication implementation patterns for Next.js 15+ App Router using Auth.js 5 (NextAuth.js). Use when setting up authentication flows, implementing protected routes, managing sessions in Server Components and Server Actions, configuring OAuth providers, implementing role-based access co

    Ready to connect★ 343

    github.com/giuseppe-trisciuoglio/developer-kit345 stars

    View details

What is a skill?

A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.

52,524 of the 52,958 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.

Install one and every AI you use gets it

Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.

Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.

See how to connect your AI