Skills.

Give your AI a better way to work.

A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.

Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.

Category: Security

1,738 results · page 30 of 58

  • ai-code-securitySkillSecurity

    Security vulnerabilities in AI-generated code and LLM applications, covering OWASP Top 10 for LLMs, secure coding patterns, and AI-specific threat modelsUse when "ai code security, llm vulnerabilities, ai generated code review, owasp llm, secure ai development, security, ai, llm, owasp, code-review,

    Ready to connect★ 144

    github.com/omer-metin/skills-for-antigravity139 stars

    View details
  • auth-specialistSkillSecurity

    Authentication and authorization expert for OAuth, sessions, JWT, MFA, and identity securityUse when "authentication flow, login system, oauth integration, jwt tokens, session management, password hashing, mfa setup, refresh tokens, social login, role-based access, authentication, authorization, oau

    Ready to connect★ 144

    github.com/omer-metin/skills-for-antigravity139 stars

    View details
  • authentication-oauthSkillSecurity

    Expert guidance on authentication implementation including OAuth 2.0/OIDC, JWT tokens, session management, and secure password handling. Covers both implementing auth from scratch and integrating auth providers. Use when "implement authentication, oauth login, jwt tokens, session management, social

    Ready to connect★ 144

    github.com/omer-metin/skills-for-antigravity139 stars

    View details
  • blockchain-defiSkillSecurity

    Use when building DeFi protocols, implementing AMMs, yield farming strategies, or integrating with Ethereum/L2s - covers smart contract patterns, liquidity pools, and security considerationsUse when ", " mentioned.

    Ready to connect★ 144

    github.com/omer-metin/skills-for-antigravity139 stars

    View details
  • ca-threat-modelSkillSecurity

    Opt-in lightweight STRIDE pass for a sensitive feature before implementation. Not a routine gate — invoke it when a change warrants security thought.

    Ready to connect★ 144

    github.com/arbiterforge/codearbiter144 stars

    View details
  • clerk-authSkillSecurity

    Expert patterns for Clerk auth implementation, middleware, organizations, webhooks, and user syncUse when "adding authentication, clerk auth, user authentication, sign in, sign up, user management, multi-tenancy, organizations, sso, single sign-on, clerk, authentication, auth, user-management, multi

    Ready to connect★ 144

    github.com/omer-metin/skills-for-antigravity139 stars

    View details
  • computer-use-agentsSkillSecurity

    Lets your agent control a computer like a person, using the mouse and keyboard to complete tasks.

    Ready to connect★ 144

    github.com/omer-metin/skills-for-antigravity139 stars

    View details
  • creature-designSkillSecurity

    Designing anatomically plausible, visually distinctive creatures that communicate threat, personality, and role through form - from terrifying bosses to collectible companionsUse when "creature design, design a creature, design a monster, monster design, boss design, enemy creature, companion creatu

    Ready to connect★ 144

    github.com/omer-metin/skills-for-antigravity139 stars

    View details
  • crypto-complianceSkillSecurity

    The banned-primitive gate. Routed to when changed code hashes, signs, encrypts, derives keys, generates security-relevant randomness, configures TLS, or imports a crypto library. Rejects broken primitives, disabled TLS verification, and home-rolled crypto; the approved-primitive list lives in securi

    Ready to connect★ 144

    github.com/arbiterforge/codearbiter144 stars

    View details
  • defi-architectSkillSecurity

    DeFi protocol specialist for AMMs, lending protocols, yield strategies, and economic securityUse when "defi, amm, liquidity pool, lending protocol, yield farming, oracle, liquidation, tokenomics, tvl, impermanent loss, defi, amm, lending, yield, liquidity, oracle, tokenomics, protocol, ethereum, web

    Ready to connect★ 144

    github.com/omer-metin/skills-for-antigravity139 stars

    View details
  • dependency-risk-auditSkillSecurity

    Audit dependencies for licensing, security, and maintenance risk. Use when a senior developer needs risk assessment.

    Ready to connect★ 144

    github.com/proflead/codex-skills-library144 stars

    View details
  • raytsystem-security-reviewSkillSecurity

    Audit raytsystem changes for prompt injection, provenance bypass, path/symlink/hardlink escape, secret leakage, stale fencing, partial promotion, unsafe parsing, and unapproved side effects. Use for SECURITY REVIEW, adversarial testing, recovery review, or approval-boundary validation; remain indepe

    Ready to connect★ 144

    github.com/romarayt/raytsystem-public-os140 stars

    View details
  • sandbox-claude-insideSkillSecurity

    Run Claude Code INSIDE a ca-sandbox box (`--with-claude`). Routed to when the user wants an agent loop running against an isolated, ephemeral sandbox rather than the host. Authenticates via an env-injected CLAUDE_CODE_OAUTH_TOKEN with no host bind of ~/.claude; the image pins the CLI and disables th

    Ready to connect★ 144

    github.com/arbiterforge/codearbiter144 stars

    View details
  • security-architectureSkillSecurity

    Optional, opt-in STRIDE threat pass for a sensitive feature — invoked deliberately via /threat-model, never forced on ordinary changes. Walks the change's attack surface and security boundaries (governed by ${CLAUDE_PROJECT_DIR}/.codearbiter/security-controls.md), surfaces threats and unmitigated ga

    Ready to connect★ 144

    github.com/arbiterforge/codearbiter144 stars

    View details
  • security-quick-scanSkillSecurity

    Scan code or configuration for common security issues. Use when a mid-level developer needs a quick security pass.

    Ready to connect★ 144

    github.com/proflead/codex-skills-library144 stars

    View details
  • bitbucket-cloudSkillSecurity

    Bitbucket Cloud (bitbucket.org) specifics — authenticate with BITBUCKET_TOKEN, use the REST API v2, workspace/repo_slug repositories, and the create_bitbucket_pr tool. Loaded on demand by the bitbucket skill once a Cloud environment is detected.

    Ready to connect★ 143

    github.com/openhands/extensions141 stars

    View details
  • bitbucket-data-centerSkillSecurity

    Bitbucket Data Center (self-hosted Bitbucket Server) specifics — authenticate with BITBUCKET_DATA_CENTER_TOKEN, use the REST API 1.0, PROJECT/repo_slug repositories, scm/ git remotes, and the create_bitbucket_data_center_pr tool. Loaded on demand by the bitbucket skill once a Data Center environment

    Ready to connect★ 143

    github.com/openhands/extensions141 stars

    View details
  • brandkitSkillSecurity

    Premium brand-kit image generation skill for creating high-end brand-guidelines boards, logo systems, identity decks, and visual-world presentations. Trained for minimalist, cinematic, editorial, dark-tech, luxury, cultural, security, gaming, developer-tool, and consumer-app brand systems. Optimized

    Ready to connect★ 143

    github.com/hamzafarooq/claude-code-starter139 stars

    View details
  • rank-auditSkillSecurity

    Full SEO/GEO/AEO/Citability/Content/Performance/Vertical/Security audit with auto-fix. Scans, reports, fixes, and verifies.

    Ready to connect★ 143

    github.com/houseofmvps/claude-rank133 stars

    View details
  • dt-sec-contextualizationSkillSecurity

    Resolve security signals, IoC matches, or Smartscape nodes to runtime Dynatrace entities and connect findings on different entity levels through a shared runtime entity. Covers identity-to-Smartscape mapping (incl. container-image digest/ID to workload), cross-level topology (K8s pod detection vs. n

    Ready to connect★ 142

    github.com/dynatrace/dynatrace-for-ai142 stars

    View details
  • dt-sec-semantic-mappingSkillSecurity

    Suggest and validate semantic dictionary (SD) mappings for new security integrations using vendor API samples or live events. Use when: mapping a new security vendor data to Dynatrace SD; checking required fields; validating namespaces; highlighting discrepancies vs the semantic dictionary; proposin

    Ready to connect★ 142

    github.com/dynatrace/dynatrace-for-ai142 stars

    View details
  • dotnet-dependencySkillSecurity

    This skill should be used when investigating .NET project dependencies, understanding why packages are included, listing references, or auditing for outdated/vulnerable packages.

    Ready to connect★ 141

    github.com/nikiforovall/claude-code-rules141 stars

    View details
  • ai-safe2SkillSecurity

    The Universal Governance, Risk, Compliance (GRC) Operating System with Integrated Security for Agentic AI, Non-Human Identities, and Swarm Governance. AI SAFE² + AI Sovereignty Maturity Model (AISM), NEXUS-A2A Protocol, FORGE-Act, Marshal Plan for AI [Dual License: MIT + CC-BY-SA]

    Ready to connect★ 139

    github.com/cyberstrategyinstitute/ai-safe2-framework139 stars

    View details
  • ai-safe2-secure-build-copilotSkillSecurity

    Apply AI SAFE2 v3.0 to security architecture reviews, code reviews, compliance mapping, and governance decisions for AI agents, multi-agent systems, RAG pipelines, MCP servers, tool-calling workflows, and AI-enabled automations. Use when the task involves agent autonomy classification, HEAR or CP.9

    Ready to connect★ 139

    github.com/cyberstrategyinstitute/ai-safe2-framework139 stars

    View details
  • openpost-cliSkillSecurity

    Operate a running OpenPost instance through the openpost CLI. Use for authentication and profile setup; workspace, account, provider, media, schedule, job, and billing inspection; creating or editing text posts, threads, and format-first publications; scheduling or publishing content; checking lifec

    Ready to connect★ 138

    github.com/getopenpost/openpost101 stars

    View details
  • klaviyo-developerSkillSecurity

    Klaviyo API and developer integration expertise. Event tracking, SDKs, webhooks, rate limits, OAuth, catalog sync, and code patterns. Use when the user asks about Klaviyo API, integrating with Klaviyo, tracking events, building custom integrations, webhook handling, or developer implementation. For

    Ready to connect★ 136

    github.com/thatrebeccarae/claude-marketing129 stars

    View details
  • causal-designSkillSecurity

    Design or audit the identification strategy for an observational study. Use when the task concerns estimands, causal assumptions, threats to identification, or defensible research design rather than model implementation.

    Ready to connect★ 133

    github.com/flonat/flonat-research131 stars

    View details
  • evals-initSkillSecurity

    Initialize evals/{system}/ directory structure for evaluation system following EDD principles (Standalone). Choose PromptFoo or DeepEval based on tech stack, generate security baseline.

    Ready to connect★ 133

    github.com/tikalk/adlc-team-skills133 stars

    View details
  • linear-configSkillSecurity

    Configure linear-cli - auth (API key + OAuth), workspaces, diagnostics, setup wizard.

    Ready to connect★ 133

    github.com/nesszer/linear-cli133 stars

    View details
  • sellSkillSecurity

    Self-contained SaaS automation — invoke directly, do not decompose. Transforms a Vibes app into a multi-tenant SaaS with subdomain-based tenancy. Adds Pocket ID authentication, subscription gating, and generates a unified app with landing page, tenant routing, and admin dashboard. Use when the user

    Ready to connect★ 133

    github.com/popmechanic/vibesos133 stars

    View details

What is a skill?

A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.

52,524 of the 52,958 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.

Install one and every AI you use gets it

Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.

Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.

See how to connect your AI