Skills.

Give your AI a better way to work.

A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.

Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.

Category: Security

1,738 results · page 23 of 58

  • orchestrateSkillSecurity

    Enhance any repository with CI, tests, skills, and security through phased PRs - self-replicating

    Ready to connect★ 300

    github.com/rossoctl/rossoctl298 stars

    View details
  • orchestrate:ciSkillSecurity

    Add comprehensive CI workflows to a target repo - lint, test, build, security scanning, dependabot, scorecard, action pinning

    Ready to connect★ 300

    github.com/rossoctl/rossoctl298 stars

    View details
  • orchestrate:scanSkillSecurity

    Scan and assess a target repository - tech stack, CI maturity, security posture, test coverage, supply chain health

    Ready to connect★ 300

    github.com/rossoctl/rossoctl298 stars

    View details
  • orchestrate:securitySkillSecurity

    Add security governance to a target repo - CODEOWNERS, SECURITY.md, CONTRIBUTING.md, LICENSE, .gitignore audit

    Ready to connect★ 300

    github.com/rossoctl/rossoctl298 stars

    View details
  • php-developmentSkillSecurity

    Expert guidance for PHP 8+ development, prioritizing code quality (SOLID, PSR standards), security practices, and testing requirements

    Ready to connect★ 295

    github.com/cecilapp/cecil295 stars

    View details
  • code-review-proSkillSecurity

    Comprehensive code review covering security vulnerabilities, performance bottlenecks, best practices, and refactoring opportunities. Use when user requests code review, security audit, or performance analysis.

    Ready to connect★ 291

    github.com/onewave-ai/claude-skills291 stars

    View details
  • git-pr-reviewerSkillSecurity

    Review pull requests for code quality, security issues, and best practices. Use when reviewing PRs, checking code changes, or analyzing diffs before merge.

    Ready to connect★ 291

    github.com/onewave-ai/claude-skills291 stars

    View details
  • overnight-repo-auditorSkillSecurity

    Uses Managed Agents' 14.5-hour runtime to audit an entire codebase overnight. Security, performance, accessibility, dependency issues. You wake up to a full report.

    Ready to connect★ 291

    github.com/onewave-ai/claude-skills291 stars

    View details
  • aiscanSkillSecurity

    Use this skill for AIScan's attack surface management and penetration-testing capabilities, including scanner pseudo-commands, supporting security tools, vulnerability verification, evidence handling, and assessment reporting.

    Ready to connect★ 287

    github.com/chainreactors/aiscan274 stars

    View details
  • agentic-actions-auditorSkillSecurity

    Audits GitHub Actions workflows for security vulnerabilities in AI agent integrations including Claude Code Action, Gemini CLI, OpenAI Codex, and GitHub AI Inference. Detects attack vectors where attacker-controlled input reaches. AI agents running in CI/CD pipelines.

    Ready to connect★ 282

    github.com/lingxling/awesome-skills-cn282 stars

    View details
  • api-security-testingSkillSecurity

    API security testing workflow for REST and GraphQL APIs covering authentication, authorization, rate limiting, input validation, and security best practices.

    Ready to connect★ 282

    github.com/lingxling/awesome-skills-cn282 stars

    View details
  • auth-securitySkillSecurity

    OAuth 2.1 + JWT authentication security best practices. Use when implementing auth, API authorization, token management. Follows RFC 9700 (2025).

    Ready to connect★ 278

    github.com/majiayu000/spellbook278 stars

    View details
  • codebase-auditSkillSecurity

    Comprehensive codebase audit — adaptive parallel deep analysis (frontend/backend contracts, data integrity, exception handling/security, architecture/tech debt, configuration/caching), structured findings + adversarial verification + baseline comparison, producing a unified severity-sorted report an

    Ready to connect★ 278

    github.com/majiayu000/spellbook278 stars

    View details
  • codex-agentSkillSecurity

    Use when you want a second-opinion review via Codex CLI, cross-verification after another agent implements changes, debugging help, or alternative implementation proposals. Requires Codex CLI to be installed and authenticated.

    Ready to connect★ 278

    github.com/majiayu000/spellbook278 stars

    View details
  • basecamp-doctorSkillSecurity

    Diagnose Basecamp CLI, authentication, and agent-plugin health.

    Ready to connect★ 272

    github.com/basecamp/basecamp-cli272 stars

    View details
  • <skill-name>SkillSecurity

    <What this skill does in 2-3 sentences. Focus on technique scope and when to use it. No trigger phrases, negative conditions, or OPSEC details here.>

    Ready to connect★ 271

    github.com/blacklanternsecurity/red-run266 stars

    View details
  • 2fa-bypassSkillSecurity

    Bypass two-factor authentication (2FA/MFA) during authorized penetration testing.

    Ready to connect★ 271

    github.com/blacklanternsecurity/red-run266 stars

    View details
  • acl-abuseSkillSecurity

    Exploits misconfigured Active Directory ACLs for privilege escalation. Covers GenericAll, GenericWrite, WriteDACL, WriteOwner, ForceChangePassword, targeted Kerberoasting via SPN manipulation, shadow credentials (msDS-KeyCredentialLink → PKINIT), and AdminSDHolder persistence.

    Ready to connect★ 271

    github.com/blacklanternsecurity/red-run266 stars

    View details
  • ad-discoverySkillSecurity

    Enumerates Active Directory domains and maps attack surface for penetration testing.

    Ready to connect★ 271

    github.com/blacklanternsecurity/red-run266 stars

    View details
  • adcs-access-and-relaySkillSecurity

    Exploits ADCS through ACL abuse on templates/CA objects and NTLM relay to enrollment endpoints. Covers ESC4 (template ACL → modify to ESC1), ESC5 (PKI object ACLs), ESC7 (ManageCA/ManageCertificates abuse), ESC8 (NTLM relay to HTTP enrollment), ESC11 (NTLM relay to ICPR RPC).

    Ready to connect★ 271

    github.com/blacklanternsecurity/red-run266 stars

    View details
  • adcs-persistenceSkillSecurity

    Establishes persistence and exploits weak certificate mapping in AD CS. Covers ESC9 (no security extension), ESC10 (weak certificate mapping), ESC12-15 (YubiHSM, issuance policy, altSecIdentities, application policies), Golden Certificate (forge with stolen CA key), certificate theft (DPAPI/CAPI/CNG

    Ready to connect★ 271

    github.com/blacklanternsecurity/red-run266 stars

    View details
  • adcs-template-abuseSkillSecurity

    Exploits misconfigured AD CS certificate templates to impersonate any domain user via SAN manipulation or enrollment agent abuse. Covers ESC1 (enrollee supplies subject), ESC2 (any-purpose/no EKU), ESC3 (enrollment agent), ESC6 (EDITF_ATTRIBUTESUBJECTALTNAME2 CA flag).

    Ready to connect★ 271

    github.com/blacklanternsecurity/red-run266 stars

    View details
  • auth-coercion-relaySkillSecurity

    Forces remote systems to authenticate back to attacker-controlled listeners and relays captured authentication to escalate privileges or move laterally. Covers authentication coercion (PetitPotam, PrinterBug, DFSCoerce, ShadowCoerce, CheeseOunce), NTLM relay (ntlmrelayx to LDAP/SMB/AD CS/MSSQL), Ker

    Ready to connect★ 271

    github.com/blacklanternsecurity/red-run266 stars

    View details
  • av-edr-evasionSkillSecurity

    Bypass antivirus and EDR detection for payload delivery during exploitation. Covers custom payload compilation (mingw C, Go), AMSI bypass, shellcode alternatives, and ETW patching. Route here when an agent reports a payload was quarantined, blocked, or detected by endpoint protection.

    Ready to connect★ 271

    github.com/blacklanternsecurity/red-run266 stars

    View details
  • command-injectionSkillSecurity

    Guide OS command injection exploitation during authorized penetration testing.

    Ready to connect★ 271

    github.com/blacklanternsecurity/red-run266 stars

    View details
  • cors-misconfigurationSkillSecurity

    Exploit CORS (Cross-Origin Resource Sharing) misconfigurations during authorized penetration testing.

    Ready to connect★ 271

    github.com/blacklanternsecurity/red-run266 stars

    View details
  • csrfSkillSecurity

    Exploit Cross-Site Request Forgery (CSRF) vulnerabilities during authorized penetration testing.

    Ready to connect★ 271

    github.com/blacklanternsecurity/red-run266 stars

    View details
  • deserialization-dotnetSkillSecurity

    Exploit .NET deserialization vulnerabilities during authorized penetration testing.

    Ready to connect★ 271

    github.com/blacklanternsecurity/red-run266 stars

    View details
  • deserialization-javaSkillSecurity

    Exploit Java deserialization vulnerabilities during authorized penetration testing.

    Ready to connect★ 271

    github.com/blacklanternsecurity/red-run266 stars

    View details
  • deserialization-phpSkillSecurity

    Exploit PHP deserialization vulnerabilities during authorized penetration testing.

    Ready to connect★ 271

    github.com/blacklanternsecurity/red-run266 stars

    View details

What is a skill?

A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.

52,524 of the 52,958 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.

Install one and every AI you use gets it

Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.

Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.

See how to connect your AI