Skills.
Give your AI a better way to work.
A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.
Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.
Category: Security
1,738 results · page 24 of 58
- View details
gpo-abuseSkillSecurity
Exploits Group Policy Objects for code execution, privilege escalation, and lateral movement in Active Directory. Covers GPO enumeration (GPOHound, BloodHound, PowerView), exploitation via immediate tasks, logon scripts, and registry modifications (SharpGPOAbuse, PowerGPOAbuse, pyGPOAbuse, GroupPoli
Ready to connect★ 271
- View details
idorSkillSecurity
Exploit Insecure Direct Object Reference (IDOR) and broken access control vulnerabilities during authorized penetration testing.
Ready to connect★ 271
- View details
infrastructure-enumerationSkillSecurity
Enumeration of infrastructure services: DNS, SMTP, SNMP, IPMI, NFS, TFTP, RPC/MSRPC, and HTTP/HTTPS surface detection. Checks zone transfers, open relays, default community strings, cipher zero, NFS exports, and web technology fingerprinting. Use after network-recon identifies infrastructure ports.
Ready to connect★ 271
- View details
jwt-attacksSkillSecurity
Exploit JWT (JSON Web Token) vulnerabilities during authorized penetration testing.
Ready to connect★ 271
- View details
kerberos-delegationSkillSecurity
Exploits Kerberos delegation misconfigurations for privilege escalation and lateral movement in Active Directory. Covers Unconstrained Delegation (TGT harvesting via coercion), Constrained Delegation (S4U2Self + S4U2Proxy with SPN swapping), and Resource-Based Constrained Delegation (RBCD via writab
Ready to connect★ 271
- View details
kerberos-roastingSkillSecurity
Extracts and cracks Kerberos service tickets (Kerberoasting) and AS-REP hashes (AS-REP Roasting) for offline password recovery.
Ready to connect★ 271
- View details
kerberos-ticket-forgingSkillSecurity
Forges Kerberos tickets for domain persistence and privilege escalation. Covers Golden Ticket (krbtgt hash → forged TGT), Silver Ticket (service hash → forged TGS), Diamond Ticket (decrypt/modify/re-encrypt legitimate TGT for stealth), Sapphire Ticket (U2U PAC swap), and Pass-the-Ticket injection.
Ready to connect★ 271
- View details
ldap-injectionSkillSecurity
Exploit LDAP injection vulnerabilities during authorized penetration testing.
Ready to connect★ 271
- View details
linux-cron-service-abuseSkillSecurity
Exploit cron jobs, systemd timers/services, D-Bus services, and Unix sockets for privilege escalation.
Ready to connect★ 271
- View details
linux-discoverySkillSecurity
Linux local privilege escalation enumeration and attack surface mapping.
Ready to connect★ 271
- View details
linux-kernel-exploitsSkillSecurity
Exploit Linux kernel vulnerabilities and escape restricted shells for privilege escalation.
Ready to connect★ 271
- View details
linux-sudo-suid-capabilitiesSkillSecurity
Exploit sudo misconfigurations, SUID/SGID binaries, and Linux capabilities for privilege escalation.
Ready to connect★ 271
- View details
network-reconSkillSecurity
Network reconnaissance, host discovery, port scanning, and OS fingerprinting. Produces a port/service map that the orchestrator uses to route to service-specific enumeration skills.
Ready to connect★ 271
- View details
nosql-injectionSkillSecurity
Guide NoSQL injection exploitation during authorized penetration testing.
Ready to connect★ 271
- View details
oauth-attacksSkillSecurity
Exploit OAuth 2.0 and OpenID Connect vulnerabilities during authorized penetration testing.
Ready to connect★ 271
- View details
pass-the-hashSkillSecurity
Authenticates to AD services using NTLM hashes, AES keys, or Kerberos tickets without cracking passwords. Covers Pass-the-Hash, Over-Pass-the-Hash, Pass-the-Key, and Pass-the-Ticket for lateral movement.
Ready to connect★ 271
- View details
password-reset-poisoningSkillSecurity
Exploit password reset vulnerabilities during authorized penetration testing.
Ready to connect★ 271
- View details
password-sprayingSkillSecurity
Performs password spraying against authentication services with lockout-safe techniques. Works against AD (SMB/Kerberos/LDAP), SSH, web login forms, OWA, and any service with username/password auth. Service-agnostic — the orchestrator passes target services and spray intensity tier.
Ready to connect★ 271
- View details
php-code-injectionSkillSecurity
Exploit PHP code evaluation injection via eval(), assert(), preg_replace /e, create_function(), call_user_func(), usort() callbacks, and runtime function creation (runkit, uopz). Distinct from OS command injection (shell operators) and SSTI (template engines) — this targets direct PHP code evaluatio
Ready to connect★ 271
- View details
pivoting-tunnelingSkillSecurity
Network pivoting, port forwarding, and tunneling through compromised hosts to reach internal networks.
Ready to connect★ 271
- View details
python-code-injectionSkillSecurity
Exploit Python eval(), exec(), and compile() injection in web applications. Distinct from OS command injection (shell operators) and SSTI (template engines) — this targets direct Python code evaluation of user input.
Ready to connect★ 271
- View details
red-run-ctfSkillSecurity
Multi-phase penetration test orchestrator. Handles recon, assessment surface mapping, vulnerability chaining, and routes to technique skills for execution. Invoke via /red-run-ctf slash command only.
Ready to connect★ 271
- View details
red-run-legacySkillSecurity
Legacy subagent-based orchestrator. Superseded by /red-run-ctf (agent teams). Use /red-run-legacy to invoke manually. Does not auto-trigger.
Ready to connect★ 271
- View details
remote-access-enumerationSkillSecurity
Enumeration of remote access services: FTP, SSH, RDP, VNC, and WinRM. Checks anonymous access, default credentials, version vulnerabilities, and authentication methods. Use after network-recon identifies remote access ports.
Ready to connect★ 271
- View details
request-smugglingSkillSecurity
Guide HTTP request smuggling exploitation during authorized penetration testing.
Ready to connect★ 271
- View details
retrospectiveSkillSecurity
Post-engagement lessons-learned retrospective. Reads the engagement directory, analyzes skill routing decisions, identifies knowledge gaps and missing skills, and produces an actionable improvement report.
Ready to connect★ 271
- View details
sccm-exploitationSkillSecurity
Enumerates and exploits Microsoft SCCM/MECM (System Center Configuration Manager / Microsoft Endpoint Configuration Manager) infrastructure for credential harvesting, lateral movement, and domain escalation. Covers SCCM enumeration (sccmhunter, SharpSCCM), Network Access Account (NAA) credential ext
Ready to connect★ 271
- View details
smb-exploitationSkillSecurity
Exploit remote SMB vulnerabilities for unauthenticated code execution on Windows hosts.
Ready to connect★ 271
- View details
source-code-reviewSkillSecurity
Security-focused source code review. Identifies hardcoded credentials, injection sinks, authentication weaknesses, and framework-specific vulnerabilities. Use when application source code is available for review.
Ready to connect★ 271
- View details
ssrfSkillSecurity
Guide server-side request forgery (SSRF) exploitation during authorized penetration testing.
Ready to connect★ 271
What is a skill?
A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.
52,524 of the 52,958 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.
Install one and every AI you use gets it
Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.
Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.