Skills.
Give your AI a better way to work.
A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.
Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.
Category: Security
1,738 results · page 28 of 58
- View details
coercion-ntlm-relaySkillSecurity
Authentication coercion (PetitPotam MS-EFSR, PrinterBug MS-RPRN, DFSCoerce MS-DFSNM) chained into NTLM relay (impacket ntlmrelayx) toward LDAP, AD CS web enrollment (ESC8), or SMB. Use when SMB signing is not enforced or LDAP channel binding is missing, and you want to force a privileged machine acc
Ready to connect★ 193
- View details
kerberos-attacksSkillSecurity
Kerberos-based Active Directory attacks driven by hand with standard tooling (Kerberoasting, AS-REP roasting, and delegation abuse: unconstrained, constrained/S4U, RBCD). Use when the target has SPN-bearing service accounts, accounts without pre-authentication, or delegation configured on computer/u
Ready to connect★ 193
- View details
mcp_nangoSkillSecurity
Reach 200+ third-party apps through the Nango MCP. Use when the user wants to act on an app that has no dedicated Manor MCP but is available via Nango — discover the provider, confirm a connection exists, then call its API through the authenticated proxy.
Ready to connect★ 171
- View details
code-forgeSkillSecurity
Generate implementation code from an approved design blueprint or verbal requirements. Composes context anchoring, architecture, clean code, DDD, security, and test quality into an inside-out implementation workflow. Use when moving from design to code, implementing approved contracts, or when the u
Ready to connect★ 190
- View details
codex-code-reviewSkillSecurity
Code review using Codex MCP. Use when: PR review, code audit, second opinion on changes. Not for: doc review (use doc-review), security audit (use security-review). Output: severity-grouped findings + merge gate.
Ready to connect★ 188
- View details
codex-securitySkillSecurity
OWASP Top 10 security review using Codex MCP. Supports review loop with context preservation.
Ready to connect★ 188
- View details
- View details
dev-security-auditSkillSecurity
Comprehensive developer workstation security audit — scans for exposed credentials, compromised application data, persistence mechanisms, and supply chain attack indicators. Use this skill whenever the user suspects their machine may be compromised, wants to check for exposed secrets, asks about sup
Ready to connect★ 188
- View details
project-auditSkillSecurity
Project health audit with deterministic scoring. Use when: evaluating project quality, onboarding to new codebase, periodic health checks. Not for: runtime performance analysis, security-specific audits (use /codex-security). Output: 5-dimension score + actionable findings.
Ready to connect★ 188
- View details
command-executionSkillSecurity
Execute security scanning commands on remote worker agents. Use when you need to run CLI tools like nmap, subfinder, httpx, nuclei, or any shell command on worker nodes.
Ready to connect★ 187
- View details
shopify-admin-staff-account-auditSkillSecurity
Read-only: reviews staff accounts for stale logins, inactive status, and overpermissioned roles to surface security and access hygiene issues.
Ready to connect★ 187
- View details
vulnerability-analysisSkillSecurity
Perform deep analysis of CVEs and security vulnerabilities including CVSS scoring, affected versions, exploit maturity, and remediation steps. Use when the user needs detailed vulnerability intelligence.
Ready to connect★ 187
- View details
tech-reviewSkillSecurity
Reviews technical blog posts, tutorials, and technical manuscripts for technical accuracy, primary sources, current API behavior, code, reproducibility, security, accessibility, and compatibility. Use when asked to verify technical claims, code samples, supported versions, specifications, or accurac
Ready to connect★ 186
- View details
prd-v03-moat-definitionSkillSecurity
Assess competitor defensibility and define our own moat strategy during PRD v0.3 Commercial Model. Triggers on requests to analyze competitor moats, define our defensibility, assess switching costs, identify vulnerabilities, find wedge opportunities, or when user asks "what's our moat?", "how defens
Ready to connect★ 182
- View details
spring-boot-skillSkillSecurity
Build Spring Boot 4.x applications following the best practices. Use this skill: * When developing Spring Boot applications using Spring MVC, Spring Data JPA, Spring Modulith, Spring Security * To create recommended Spring Boot package structure * To implement REST APIs, entities/repositories, servi
Ready to connect★ 181
- View details
dependency-scanningSkillSecurity
Scan project dependencies for known vulnerabilities, generate software bills of materials, and enforce license compliance across the software supply chain. Use when the user requests dependency scanning or provides relevant inputs for this workflow.
Ready to connect★ 179
- View details
prompt-injection-defenseSkillSecurity
Threat-model and harden AI agents, RAG systems, assistants, and tool-using workflows against direct, indirect, stored, cross-agent, and multimodal prompt injection. Use when reviewing an agent architecture, isolating untrusted content, constraining tools and egress, protecting secrets, adding inject
Ready to connect★ 179
- View details
static-application-security-testingSkillSecurity
Analyze source code for security vulnerabilities using static analysis tools, custom rules, and CI-integrated scanning pipelines. Use when the user requests static application security testing or provides relevant inputs for this workflow.
Ready to connect★ 179
- View details
threat-modelingSkillSecurity
Conduct structured threat modeling for software systems using established methodologies to identify, prioritize, and mitigate security threats before they are exploited. Use when the user requests threat modeling or provides relevant inputs for this workflow.
Ready to connect★ 179
- View details
frappe-core-apiSkillSecurity
Use when building ERPNext/Frappe API integrations (v14/v15/v16) including REST API, RPC API, authentication, webhooks, and rate limiting. Covers external API calls, endpoint design, token/OAuth2/session authentication. Keywords: API integration, REST endpoint, webhook, token authentication,, how to
Ready to connect★ 178
- View details
frappe-core-permissionsSkillSecurity
Use when implementing the Frappe/ERPNext permission system. Covers roles, user permissions, perm levels, data masking, and permission hooks for v14/v15/v16. Prevents common access control mistakes and security issues. Keywords: permissions, roles, user permissions, perm levels, data masking,, restri
Ready to connect★ 178
- View details
frappe-errors-apiSkillSecurity
Use when debugging or handling API errors in Frappe/ERPNext v14/v15/v16. Prevents silent failures and wrong HTTP status codes in REST endpoints. Covers 401 Unauthorized (wrong token format, expired OAuth), 403 Forbidden (missing @whitelist, allow_guest needed), 404 Not Found (wrong endpoint URL), 41
Ready to connect★ 178
- View details
frappe-impl-integrationsSkillSecurity
Use when implementing OAuth providers, Connected Apps, Webhooks, Payment Gateways, or Data Import/Export in Frappe. Prevents authentication failures from wrong OAuth flow, missed webhook deliveries, and data corruption during bulk imports. Covers OAuth2 provider/client, Connected App DocType, Webhoo
Ready to connect★ 178
- View details
angular-routingSkillSecurity
Implement routing in Angular v20+ applications with lazy loading, functional guards, resolvers, and route parameters. Use for navigation setup, protected routes, route-based data loading, and nested routing. Triggers on route configuration, adding authentication guards, implementing lazy loading, or
Ready to connect★ 175
- View details
databricks-coreSkillSecurity
Databricks CLI operations and the parent/entry-point skill for all Databricks work: authentication, profile selection, data exploration, bundles, and Genie natural-language data Q&A. Load this first for any Databricks task (CLI, auth, profiles, exploring catalogs/tables), then load the matching prod
Ready to connect★ 175
- View details
fastapi-itechmeatSkillSecurity
FastAPI Python framework. Covers REST APIs, validation, dependencies, security. Use when building Python web APIs with FastAPI, configuring Pydantic models, implementing dependency injection, or setting up OAuth2/JWT authentication. Keywords: FastAPI, Pydantic, async, OAuth2, JWT, REST API.
Ready to connect★ 175
- View details
fastapi-martinholovskySkillSecurity
REST API and WebSocket development with FastAPI emphasizing security, performance, and async patterns
Ready to connect★ 175
- View details
trace-mcp-pre-commitSkillSecurity
Run trace-mcp security, quality-gate, and antipattern checks before committing or opening a PR. Activate when the agent is about to create a commit or pull request in a project indexed by trace-mcp.
Ready to connect★ 175
- View details
benignSkillSecurity
Offline security scanner for AI-agent repos, skills, plugins, and MCP servers.
Ready to connect★ 173
- View details
What is a skill?
A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.
52,524 of the 52,958 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.
Install one and every AI you use gets it
Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.
Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.