Skills.
Give your AI a better way to work.
A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.
Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.
Category: Security
1,738 results · page 23 of 58
- View details
orchestrateSkillSecurity
Enhance any repository with CI, tests, skills, and security through phased PRs - self-replicating
Ready to connect★ 300
- View details
orchestrate:ciSkillSecurity
Add comprehensive CI workflows to a target repo - lint, test, build, security scanning, dependabot, scorecard, action pinning
Ready to connect★ 300
- View details
orchestrate:scanSkillSecurity
Scan and assess a target repository - tech stack, CI maturity, security posture, test coverage, supply chain health
Ready to connect★ 300
- View details
orchestrate:securitySkillSecurity
Add security governance to a target repo - CODEOWNERS, SECURITY.md, CONTRIBUTING.md, LICENSE, .gitignore audit
Ready to connect★ 300
- View details
php-developmentSkillSecurity
Expert guidance for PHP 8+ development, prioritizing code quality (SOLID, PSR standards), security practices, and testing requirements
Ready to connect★ 295
- View details
code-review-proSkillSecurity
Comprehensive code review covering security vulnerabilities, performance bottlenecks, best practices, and refactoring opportunities. Use when user requests code review, security audit, or performance analysis.
Ready to connect★ 291
- View details
git-pr-reviewerSkillSecurity
Review pull requests for code quality, security issues, and best practices. Use when reviewing PRs, checking code changes, or analyzing diffs before merge.
Ready to connect★ 291
- View details
overnight-repo-auditorSkillSecurity
Uses Managed Agents' 14.5-hour runtime to audit an entire codebase overnight. Security, performance, accessibility, dependency issues. You wake up to a full report.
Ready to connect★ 291
- View details
aiscanSkillSecurity
Use this skill for AIScan's attack surface management and penetration-testing capabilities, including scanner pseudo-commands, supporting security tools, vulnerability verification, evidence handling, and assessment reporting.
Ready to connect★ 287
- View details
agentic-actions-auditorSkillSecurity
Audits GitHub Actions workflows for security vulnerabilities in AI agent integrations including Claude Code Action, Gemini CLI, OpenAI Codex, and GitHub AI Inference. Detects attack vectors where attacker-controlled input reaches. AI agents running in CI/CD pipelines.
Ready to connect★ 282
- View details
api-security-testingSkillSecurity
API security testing workflow for REST and GraphQL APIs covering authentication, authorization, rate limiting, input validation, and security best practices.
Ready to connect★ 282
- View details
auth-securitySkillSecurity
OAuth 2.1 + JWT authentication security best practices. Use when implementing auth, API authorization, token management. Follows RFC 9700 (2025).
Ready to connect★ 278
- View details
codebase-auditSkillSecurity
Comprehensive codebase audit — adaptive parallel deep analysis (frontend/backend contracts, data integrity, exception handling/security, architecture/tech debt, configuration/caching), structured findings + adversarial verification + baseline comparison, producing a unified severity-sorted report an
Ready to connect★ 278
- View details
codex-agentSkillSecurity
Use when you want a second-opinion review via Codex CLI, cross-verification after another agent implements changes, debugging help, or alternative implementation proposals. Requires Codex CLI to be installed and authenticated.
Ready to connect★ 278
- View details
basecamp-doctorSkillSecurity
Diagnose Basecamp CLI, authentication, and agent-plugin health.
Ready to connect★ 272
- View details
<skill-name>SkillSecurity
<What this skill does in 2-3 sentences. Focus on technique scope and when to use it. No trigger phrases, negative conditions, or OPSEC details here.>
Ready to connect★ 271
- View details
2fa-bypassSkillSecurity
Bypass two-factor authentication (2FA/MFA) during authorized penetration testing.
Ready to connect★ 271
- View details
acl-abuseSkillSecurity
Exploits misconfigured Active Directory ACLs for privilege escalation. Covers GenericAll, GenericWrite, WriteDACL, WriteOwner, ForceChangePassword, targeted Kerberoasting via SPN manipulation, shadow credentials (msDS-KeyCredentialLink → PKINIT), and AdminSDHolder persistence.
Ready to connect★ 271
- View details
ad-discoverySkillSecurity
Enumerates Active Directory domains and maps attack surface for penetration testing.
Ready to connect★ 271
- View details
adcs-access-and-relaySkillSecurity
Exploits ADCS through ACL abuse on templates/CA objects and NTLM relay to enrollment endpoints. Covers ESC4 (template ACL → modify to ESC1), ESC5 (PKI object ACLs), ESC7 (ManageCA/ManageCertificates abuse), ESC8 (NTLM relay to HTTP enrollment), ESC11 (NTLM relay to ICPR RPC).
Ready to connect★ 271
- View details
adcs-persistenceSkillSecurity
Establishes persistence and exploits weak certificate mapping in AD CS. Covers ESC9 (no security extension), ESC10 (weak certificate mapping), ESC12-15 (YubiHSM, issuance policy, altSecIdentities, application policies), Golden Certificate (forge with stolen CA key), certificate theft (DPAPI/CAPI/CNG
Ready to connect★ 271
- View details
adcs-template-abuseSkillSecurity
Exploits misconfigured AD CS certificate templates to impersonate any domain user via SAN manipulation or enrollment agent abuse. Covers ESC1 (enrollee supplies subject), ESC2 (any-purpose/no EKU), ESC3 (enrollment agent), ESC6 (EDITF_ATTRIBUTESUBJECTALTNAME2 CA flag).
Ready to connect★ 271
- View details
auth-coercion-relaySkillSecurity
Forces remote systems to authenticate back to attacker-controlled listeners and relays captured authentication to escalate privileges or move laterally. Covers authentication coercion (PetitPotam, PrinterBug, DFSCoerce, ShadowCoerce, CheeseOunce), NTLM relay (ntlmrelayx to LDAP/SMB/AD CS/MSSQL), Ker
Ready to connect★ 271
- View details
av-edr-evasionSkillSecurity
Bypass antivirus and EDR detection for payload delivery during exploitation. Covers custom payload compilation (mingw C, Go), AMSI bypass, shellcode alternatives, and ETW patching. Route here when an agent reports a payload was quarantined, blocked, or detected by endpoint protection.
Ready to connect★ 271
- View details
command-injectionSkillSecurity
Guide OS command injection exploitation during authorized penetration testing.
Ready to connect★ 271
- View details
cors-misconfigurationSkillSecurity
Exploit CORS (Cross-Origin Resource Sharing) misconfigurations during authorized penetration testing.
Ready to connect★ 271
- View details
csrfSkillSecurity
Exploit Cross-Site Request Forgery (CSRF) vulnerabilities during authorized penetration testing.
Ready to connect★ 271
- View details
deserialization-dotnetSkillSecurity
Exploit .NET deserialization vulnerabilities during authorized penetration testing.
Ready to connect★ 271
- View details
deserialization-javaSkillSecurity
Exploit Java deserialization vulnerabilities during authorized penetration testing.
Ready to connect★ 271
- View details
deserialization-phpSkillSecurity
Exploit PHP deserialization vulnerabilities during authorized penetration testing.
Ready to connect★ 271
What is a skill?
A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.
52,524 of the 52,958 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.
Install one and every AI you use gets it
Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.
Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.