Skills.
Give your AI a better way to work.
A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.
Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.
Category: Security
1,738 results · page 22 of 58
- View details
react-patternsSkillSecurity
Provides comprehensive React 19 patterns for Server Components, Server Actions, useOptimistic, useActionState, useTransition, concurrent features, Suspense boundaries, and TypeScript integration. Generates executable code patterns, validates security for public endpoints, and optimizes performance w
Ready to connect★ 343
- View details
spring-boot-rest-api-standardsSkillSecurity
Provides REST API design standards and best practices for Spring Boot projects. Use when creating or reviewing REST endpoints, DTOs, error handling, pagination, security headers, HATEOAS and architecture patterns.
Ready to connect★ 343
- View details
unit-test-security-authorizationSkillSecurity
Provides patterns for unit testing Spring Security with `@PreAuthorize`, `@Secured`, `@RolesAllowed`. Validates role-based access control and authorization policies. Use when testing security configurations and access control logic.
Ready to connect★ 343
- View details
authentication-patternsSkillSecurity
Provides auth patterns for API keys, OAuth, and token management. Use when implementing or reviewing service authentication and credential handling.
Ready to connect★ 337
- View details
- View details
hook-authoringSkillSecurity
Guide creating Claude Code hooks with security-first design. Use for validation and enforcement.
Ready to connect★ 337
- View details
hooks-evalSkillSecurity
Evaluate hook security, performance, and SDK compliance. Use for audits.
Ready to connect★ 337
- View details
provider-setupSkillSecurity
Reports which delegation CLIs are installed and authenticated, installs missing ones, and stores the result. Use before delegating or when a provider errors.
Ready to connect★ 337
- View details
- View details
api-authenticationSkillSecurity
Implement secure API authentication with JWT, OAuth 2.0, API keys, and session management. Use when securing APIs, managing tokens, or implementing user authentication flows.
Ready to connect★ 336
- View details
api-security-hardeningSkillSecurity
Secure REST APIs with authentication, rate limiting, CORS, input validation, and security middleware. Use when building or hardening API endpoints against common attacks.
Ready to connect★ 336
- View details
code-review-analysisSkillSecurity
Perform comprehensive code reviews with best practices, security checks, and constructive feedback. Use when reviewing pull requests, analyzing code quality, checking for security vulnerabilities, or providing code improvement suggestions.
Ready to connect★ 336
- View details
competitor-analysisSkillSecurity
Analyze competitive landscape to identify strengths, weaknesses, opportunities, and threats. Inform product strategy and positioning based on market insights.
Ready to connect★ 336
- View details
configuration-managementSkillSecurity
Manage application configuration including environment variables, settings management, configuration hierarchies, secret management, feature flags, and 12-factor app principles. Use for config, environment setup, or settings management.
Ready to connect★ 336
- View details
supply-chainSkillSecurity
Use when auditing security and supply chain in any codebase — trust boundaries, credential handling, injection surfaces, update/release integrity, CI permissions, dependency pinning. Assess by default, harden on request; provenance or it didn't happen.
Ready to connect★ 335
- View details
disclosureSkillSecurity
Drive responsible disclosure of a proven finding to a CVE. Package the report, find the vendor contact, report privately, coordinate a timeline, request the CVE (vendor CNA / GitHub / MITRE), and publish an advisory. Closes the research loop. Triggers - "disclose", "request a cve", "report this to t
Ready to connect★ 322
- View details
ndaySkillSecurity
N-day / patch-diff workflow - given a CVE/advisory or a suspicious patch, diff pre- vs post-patch to locate the fixed bug, build a PoC for the unpatched version, and run variant analysis for a fresh bug. Triggers - "n-day", "patch diff", "diff the patch", "bindiff".
Ready to connect★ 322
- View details
pt-workflowSkillSecurity
Autonomous pentest campaign driver. Runs a scoped engagement end to end with no operator approvals - the deterministic driver (scripts/campaign.py) owns pass state, generates the killchain board from recon, and prints the exact next action (Skill + tool) every turn. Use when starting or resuming a p
Ready to connect★ 322
- View details
screenshotSkillSecurity
Capture web-page / PoC screenshots into the engagement evidence (targets/<eng>/poc/) and embed them in walkthrough.md. Live pages + authenticated/exploited states (post-login dashboard, the flag page, an SSTI/cmdi render). Runs chromium on the Kali tooling host (VPN path to targets); hands off to th
Ready to connect★ 322
- View details
audit-xcode-security-settingsSkillSecurity
Audit and enable security-oriented Xcode build settings. Progressively enables compiler warnings, static analyzer checkers, and Enhanced Security features. Use when: user wants to secure their Xcode project, audit security settings, enable hardening, review security posture of build configuration, s
Ready to connect★ 317
- View details
dependency-vuln-auditorSkillSecurity
Inventories project dependencies and runtimes across ecosystems and reports known CVEs, supply-chain risks and a prioritized upgrade plan. Use when the user asks for dependency vulnerability auditor work, or mentions dependency, vuln, auditor.
Ready to connect★ 308
- View details
osint-investigatorSkillSecurity
Plans and correlates open-source intelligence collection on domains, organizations and infrastructure for authorized investigations and threat intel. Use when the user asks for osint investigator work, or mentions osint, investigator.
Ready to connect★ 308
- View details
skilldSkillSecurity
Operate skilld CLI for Skill discovery, use, installation, inspection, updates, authentication, configuration, restoration, and removal.
Ready to connect★ 309
- View details
fix-dependenciesSkillSecurity
Fix all vulnerabilities on the current branch using npm audit. Local branch only — no ADO/GitHub queries.
Ready to connect★ 303
- View details
auth:keycloak-confidential-clientSkillSecurity
Create confidential OAuth2 clients in Keycloak for server-to-service authentication
Ready to connect★ 300
- View details
auth:mlflow-oidc-authSkillSecurity
Configure MLflow with mlflow-oidc-auth plugin for Keycloak OIDC authentication
Ready to connect★ 300
- View details
auth:otel-oauth2-exporterSkillSecurity
Configure OpenTelemetry Collector with OAuth2 authentication for trace export
Ready to connect★ 300
- View details
cveSkillSecurity
CVE awareness — scan dependencies and code for vulnerabilities, audit docs for CVE leaks, plan responsible disclosure, block public leaks
Ready to connect★ 300
- View details
cve:brainstormSkillSecurity
Plan responsible CVE disclosure, guide silent fixes, and BLOCK all public GitHub actions until CVE is properly handled
Ready to connect★ 300
- View details
cve:scanSkillSecurity
Scan dependencies and source code for CVEs — Trivy, LLM reasoning, WebSearch, code security review, and doc audit
Ready to connect★ 300
What is a skill?
A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.
52,524 of the 52,958 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.
Install one and every AI you use gets it
Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.
Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.