Skills.

Give your AI a better way to work.

A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.

Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.

Category: Security

1,738 results · page 29 of 58

  • repo-forensicsSkillSecurity

    Security forensics for git repos, AI skills, and MCP servers. Audits dependencies, detects prompt injection, credential theft, runtime dynamism, manifest drift, known CVEs, CISA KEV (actively exploited) vulns, and 2026 attack patterns. Not for fixing vulnerabilities or pentesting.

    Ready to connect★ 173

    github.com/alexgreensh/repo-forensics173 stars

    View details
  • lyrikSkillSecurity

    Security assessment of a codebase — minimal mode for runner validation

    Ready to connect★ 171

    github.com/gebruder/wirken170 stars

    View details
  • greenfieldSkillSecurity

    Parallel persona planning for new projects. Research agent runs first to build domain context, then Architect, PM, and Security agents run in parallel. Synthesis agent combines all perspectives into a detailed GSD-style PLAN.md with Tensions section.

    Ready to connect★ 168

    github.com/wednesday-solutions/ai-agent-skills168 stars

    View details
  • agent-tool-builderSkillSecurity

    Define agent tools using the fail-closed design pattern — unified name/schema/security/execution in one class, with three-layer execution (validate → permission → call). Use this skill whenever the user wants to define a new agent tool, add permission or validation logic to an existing tool, or asks

    Ready to connect★ 164

    github.com/simbajigege/book2skills164 stars

    View details
  • cve-lookupSkillSecurity

    Look up Common Vulnerabilities and Exposures (CVEs) with severity scores, affected software, exploitability status, and remediation guidance. Essential for security research, vulnerability management, and patch prioritization.

    Ready to connect★ 164

    github.com/sandbaseai/sandbase-skills163 stars

    View details
  • domain-analyzerSkillSecurity

    Comprehensive domain analysis combining WHOIS ownership, DNS infrastructure, SSL security, SEO performance, tech stack, site structure, and backlink profile. One-stop domain intelligence for acquisition research, security assessment, and competitive analysis.

    Ready to connect★ 164

    github.com/sandbaseai/sandbase-skills163 stars

    View details
  • domain-intelligenceSkillSecurity

    Research any domain with WHOIS data, DNS records, SSL certificate details, domain age, reputation scoring, and security header analysis. Covers ownership research, infrastructure mapping, security assessment, and competitive domain analysis.

    Ready to connect★ 164

    github.com/sandbaseai/sandbase-skills163 stars

    View details
  • langchain-tool-builderSkillSecurity

    Build LangChain (Python) tools using Claude Code's fail-closed design pattern — unified name/schema/security/execution in one class, with automatic three-layer execution (validate → permission → call). Use this skill whenever the user wants to define a new LangChain tool, add permission or validatio

    Ready to connect★ 164

    github.com/simbajigege/book2skills164 stars

    View details
  • levyra-android-intent-securitySkillSecurity

    Automatically use for Levyra Android Intent, deep-link, PendingIntent, exported component, receiver, service, provider, URI-grant, FileProvider, caller-verification, or onNewIntent security work. Pair it with levyra-security-review and the affected Android domain skill.

    Ready to connect★ 164

    github.com/luc4n3x/levyra-deepsound44 stars

    View details
  • levyra-ci-workflowsSkillSecurity

    Automatically use for Levyra GitHub Actions, CI, F-Droid, Gradle/AGP/Kotlin/KSP compatibility, build performance, configuration/build cache, artifacts, release automation, workflow security, or configuration-sync work.

    Ready to connect★ 164

    github.com/luc4n3x/levyra-deepsound44 stars

    View details
  • levyra-motion-artworkSkillSecurity

    Implement, debug, or review Levyra decorative motion artwork, provider matching, muted media playback, prefetch, caching, lifecycle, and remote-media security.

    Ready to connect★ 164

    github.com/luc4n3x/levyra-deepsound44 stars

    View details
  • levyra-pr-reviewSkillSecurity

    Review a Levyra branch, commit, patch, or pull request for correctness, regressions, concurrency, lifecycle, security, data safety, UI behavior, CI, release risk, missing tests, and merge-readiness evidence.

    Ready to connect★ 164

    github.com/luc4n3x/levyra-deepsound44 stars

    View details
  • npm-package-researchSkillSecurity

    Research npm packages — download stats, dependencies, maintainers, version history, and security advisories. Useful for technology due diligence, dependency auditing, and evaluating package reliability before adoption.

    Ready to connect★ 164

    github.com/sandbaseai/sandbase-skills163 stars

    View details
  • ai-security-engineerSkillSecurity

    Expert AI Security Engineer specializing in adversarial machine learning, LLM security, model supply chain protection, and MLSecOps. Use when: securing LLM applications, evaluating model robustness, implementing differential privacy, conducting authorized AI red-teaming, securing ML pipelines, or ma

    Ready to connect★ 161

    github.com/theneoai/awesome-skills158 stars

    View details
  • data-security-officerSkillSecurity

    Expert-level Data Security Officer with deep knowledge of data classification, DLP strategy, encryption at rest and in transit, data governance frameworks, regulatory compliance (GDPR, CCPA, PIPL, HIPAA), and data lifecycle security. Use when: data-security, data-governance, dlp, gdpr, compliance.

    Ready to connect★ 161

    github.com/theneoai/awesome-skills158 stars

    View details
  • deliberation-debate-red-teamingSkillSecurity

    Challenges plans, designs, and decisions from multiple adversarial perspectives to surface blind spots, hidden assumptions, and vulnerabilities before they cause real damage. Use when testing plans or decisions for blind spots, need adversarial review before launch, validating strategy against worst

    Ready to connect★ 158

    github.com/lyndonkl/claude151 stars

    View details
  • myrqenSkillSecurity

    Run an authorized, local-first application security assessment on the current project using this agent's own reasoning. Use when the user invokes Myrqen, asks to security-test or pentest the app they are building, asks whether their app has real vulnerabilities before shipping, wants a Myrqen findin

    Ready to connect★ 158

    github.com/stijnswapped/myrqen158 stars

    View details
  • supply-chain-securitySkillSecurity

    SBOM generation, CVE scanning, supply chain attack detection, license compliance, dependency pinning, and artifact verification.

    Ready to connect★ 156

    github.com/irahardianto/awesome-agv156 stars

    View details
  • laravel:specifying-constraintsSkillSecurity

    Define clear constraints—performance, security, testing, architecture, dependencies—so AI generates code that meets your project standards

    Ready to connect★ 153

    github.com/jpcaparas/superpowers-laravel147 stars

    View details
  • golang-securitySkillSecurity

    A Go security skill for reviewing code

    Ready to connect★ 149

    github.com/serpro69/claude-toolbox149 stars

    View details
  • ai-pentestingSkillSecurity

    Run autonomous AI-driven penetration tests on web applications using tools like Shannon, PentAGI, and similar frameworks. Use when tasks involve setting up automated penetration testing pipelines, combining AI agents with security tools (nmap, subfinder, nuclei, sqlmap), building autonomous exploit

    Ready to connect★ 148

    github.com/terminalskills/skills144 stars

    View details
  • airtableSkillSecurity

    Build integrations with the Airtable Web API — bases, tables, records, fields, views, webhooks, and OAuth. Use when tasks involve reading or writing Airtable data, syncing external sources with Airtable bases, building automations triggered by record changes, or migrating data to/from Airtable.

    Ready to connect★ 148

    github.com/terminalskills/skills144 stars

    View details
  • api-testerSkillSecurity

    Test REST and GraphQL API endpoints with structured assertions and reporting. Use when a user asks to test an API, hit an endpoint, check if an API works, validate a response, debug an API call, test authentication flows, or verify API contracts. Supports GET, POST, PUT, PATCH, DELETE with headers,

    Ready to connect★ 148

    github.com/terminalskills/skills144 stars

    View details
  • apollo-clientSkillSecurity

    You are an expert in Apollo Client, the comprehensive GraphQL client for React applications. You help developers fetch data with GraphQL queries and mutations, manage local and remote state with Apollo's normalized cache, implement optimistic UI updates, handle pagination, and configure authenticati

    Ready to connect★ 148

    github.com/terminalskills/skills144 stars

    View details
  • auth-system-setupSkillSecurity

    When the user wants to set up authentication and authorization for a web application. Use when the user mentions "auth," "login," "OAuth," "SSO," "single sign-on," "role-based access," "RBAC," "permissions," "user roles," "access control," "authentication," or "authorization." Covers OAuth 2.0 provi

    Ready to connect★ 148

    github.com/terminalskills/skills144 stars

    View details
  • better-authSkillSecurity

    Add authentication to any framework with Better Auth. Use when a user asks to implement auth, set up login/signup, add OAuth providers, implement session management, or choose between auth libraries for TypeScript apps.

    Ready to connect★ 148

    github.com/terminalskills/skills144 stars

    View details
  • burp-suiteSkillSecurity

    Test web application security with Burp Suite. Use when a user asks to intercept HTTP traffic, test for web vulnerabilities, fuzz API endpoints, analyze authentication flows, or perform manual web application pentesting.

    Ready to connect★ 148

    github.com/terminalskills/skills144 stars

    View details
  • specializeSkillSecurity

    Author a new built-in Lagune sub-skill inside the Lagune source, not a scaffolded `.lagune/` target. Use when adding or refining a security knowledge module that ships with Lagune, against the native layout (`spec/skills/*.md` plus the catalog).

    Ready to connect★ 148

    github.com/wellwelwel/lagune148 stars

    View details
  • alibabacloud-ecs-sec-kernelSkillSecurity

    A Linux kernel-mode CVE vulnerability detection and PoC verification tool designed for AI Agents. Includes 88 kernel CVE detectors (2003-2026) covering local privilege escalation (LPE) vulnerabilities in subsystems such as Netfilter/eBPF/TLS/io_uring/xfrm. Uses a CTF challenge mode to objectively ve

    Ready to connect★ 147

    github.com/aliyun/alibabacloud-ecs-troubleshoot-skills147 stars

    View details
  • alibabacloud-ecs-sec-userspaceSkillSecurity

    Linux userspace security intrusion detection and forensics tool, designed for AI Agents. Automatically determines whether a server has been compromised and provides a complete evidence chain and actionable remediation recommendations. 51 security analyzers cover 12 detection dimensions including pro

    Ready to connect★ 147

    github.com/aliyun/alibabacloud-ecs-troubleshoot-skills147 stars

    View details

What is a skill?

A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.

52,524 of the 52,958 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.

Install one and every AI you use gets it

Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.

Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.

See how to connect your AI