Skills.
Give your AI a better way to work.
A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.
Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.
Category: Security
1,738 results · page 31 of 58
- View details
weakness-scannerSkillSecurity
Identify recurring weak arguments, unsupported assumptions, and vulnerable inference patterns across a literature corpus. Use when stress-testing a body of work rather than reviewing one manuscript. For one paper's argument, use the appropriate paper-review workflow.
Ready to connect★ 133
- View details
blinkSkillSecurity
Read Blink camera and video-doorbell state, list motion clips, and prepare guarded home-security control requests without exposing Blink credentials.
Ready to connect★ 132
- View details
agent-authenticationSkillSecurity
Agent skill for authentication - invoke with $agent-authentication
Ready to connect★ 129
- View details
agent-security-managerSkillSecurity
Agent skill for security-manager - invoke with $agent-security-manager
Ready to connect★ 129
- View details
agent-v3-security-architectSkillSecurity
Agent skill for v3-security-architect - invoke with $agent-v3-security-architect
Ready to connect★ 129
- View details
vulnhunterSkillSecurity
Security vulnerability detection and variant analysis skill. Use when hunting for dangerous APIs, footgun patterns, error-prone configurations, and vulnerability variants across codebases. Combines sharp edges detection with variant hunting methodology.
Ready to connect★ 128
- View details
zz-code-reconSkillSecurity
Deep architectural context building for security audits. Use when conducting security reviews, building codebase understanding, mapping trust boundaries, or preparing for vulnerability analysis. Inspired by Trail of Bits methodology.
Ready to connect★ 128
- View details
argentos-security-auditSkillSecurity
Security audit procedures for ArgentOS marketplace packages. Use when scanning packages, reviewing submissions, auditing for prompt injection, checking VirusTotal results, approving marketplace submissions, or when anyone mentions "security scan", "VT scan", "prompt injection", "audit package", "rev
Ready to connect★ 126
- View details
community-github-authSkillSecurity
Set up GitHub authentication for the agent using git (universally
Ready to connect★ 126
- View details
community-requesting-code-reviewSkillSecurity
Pre-commit verification pipeline — static security scan,
Ready to connect★ 126
- View details
evalSkillSecurity
Evaluates code output across 4 axes (functionality/quality/originality/security) and produces a score. Spawns an Evaluator agent to run an independent evaluation. Triggers on: eval, 평가, 품질 점수, 코드 평가, quality score. NOT for: 코드 작성, 구현, 리뷰.
Ready to connect★ 125
- View details
api-designSkillSecurity
Backend API design specialist. Use when building REST/GraphQL APIs, designing endpoints, data models, or backend architecture. Covers RESTful principles, HTTP semantics, error handling, versioning, and OWASP-aligned security.
Ready to connect★ 124
- View details
accountable-engineeringSkillSecurity
Guides disciplined AI-assisted engineering that avoids cognitive surrender and keeps humans accountable. Use for non-trivial implementation, architecture, security, or operational tasks.
Ready to connect★ 120
- View details
backend-fastapi-pythonSkillSecurity
Use this skill for any Python backend work in this project: building FastAPI endpoints, writing service functions, defining Pydantic/SQLModel schemas, running Alembic migrations, or debugging 422 errors. Essential for authentication and authorization patterns — setting up get_current_user, is_superu
Ready to connect★ 120
- View details
emby-integrationSkillSecurity
Emby API, authentication flow, rating scale, streaming, scrobbling, and video playback. Use when working on Emby integration, library browsing, playback reporting, or video casting.
Ready to connect★ 120
- View details
jellyfin-integrationSkillSecurity
Jellyfin API, authentication flow, rating scale, streaming, scrobbling, and video playback. Use when working on Jellyfin integration, library browsing, playback reporting, or video casting.
Ready to connect★ 120
- View details
plex-integrationSkillSecurity
Plex API endpoints, authentication, filtering, music radio, and video content. Use when working on Plex integration, library browsing, track queries, radio features, or video playback.
Ready to connect★ 120
- View details
subsonic-integrationSkillSecurity
Subsonic/Navidrome API, authentication, music folder selection, streaming, and scrobbling. Use when working on Subsonic/Navidrome integration, library browsing, music folder filtering, or playback reporting.
Ready to connect★ 120
- View details
sailSkillSecurity
Apply the SAIL (Secure AI Lifecycle) V2 framework by Pillar Security to secure AI applications and agents. Use this skill whenever the user asks about AI or agent security — assessing an AI system or agent architecture for risks, building an AI security roadmap or maturity assessment, writing or rev
Ready to connect★ 119
- View details
janitor-securitySkillSecurity
Heuristic security scan of installed skills — prompt-injection phrases, hidden unicode instructions, credential-store access, network-pipe-to-shell and payload-smuggling patterns. Use when the user asks 'are my skills safe', wants to scan skills for prompt injection or malware patterns, or before tr
Ready to connect★ 117
- View details
api-fuzzingSkillSecurity
API fuzzing for bug bounty. Use when the user asks to test API security,
Ready to connect★ 115
- View details
burp-mcp-vuln-checkSkillSecurity
Automate low-impact web vulnerability verification through Burp MCP. Use when Codex is asked to check, reproduce, triage, or write evidence for vulnerabilities using Burp Suite proxy history, Repeater, Collaborator/OOB payloads, HTTP replay, parameter mutation, response diffing, or scanner issues. A
Ready to connect★ 115
- View details
fastjson-exploitationSkillSecurity
Fastjson/Fastjson2反序列化漏洞深度利用专业技能:版本探测、AutoType全版本绕过、JNDI/BCEL/TemplatesImpl/c3p0利用链、1.2.83 Gadget-free RCE(CVE-2026-16723)、Fastjson2 FNV-1a哈希碰撞绕过(QVD-2026-45876)、不出网利用、WAF绕过、从探测到RCE完整攻击链
Ready to connect★ 115
- View details
jwt-oauth-token-attacksSkillSecurity
JWT and OAuth token attack playbook. Use when validating token trust, signing algorithms, key handling, claim abuse, bearer flows, and OAuth account-binding weaknesses.
Ready to connect★ 115
- View details
ldap-injection-testingSkillSecurity
LDAP injection vulnerability testing. Use when user input may reach LDAP
Ready to connect★ 115
- View details
log4shell-exploitationSkillSecurity
Log4Shell(CVE-2021-44228)及 Log4j2 全漏洞家族深度利用专业技能:JNDI Lookup 全链路原理与利用、全变体家族(44228/45046/45105/44832/4104)、现代 JDK 高版本绕过矩阵(8u191/17/21+)、Lookup 扩展攻击面(env/sys/ctx/k8s 信息泄露)、WAF 绕过全技术、不出网利用、供应链场景、Log4Shell→RCE→内网渗透完整链、带内/带外检测方法论、AI 大模型辅助攻防
Ready to connect★ 115
- View details
mobile-app-security-testingSkillSecurity
移动应用安全深度测试专业技能(v3.0):移动端深层攻击链(App→API→后端→云)、Android/iOS深度逆向与动态调试、Frida全面对抗与加固脱壳、iOS越狱检测绕过/ObjC Runtime/LLDB调试/证书固定绕过、跨平台框架漏洞(Flutter/React Native/uni-app/小程序)、移动端存储密钥(Keystore/Keychain/硬编码)、WebView与深链/IPC攻击面、移动端AI应用攻击面(端侧LLM/Agent提示注入/隐私数据)、AI大模型辅助逆向与API调用链分析、供应链SDK投毒与云凭据、模拟器/root/越狱检测绕过,从信息收集到漏洞利用完
Ready to connect★ 115
- View details
oauth-oidc-misconfigurationSkillSecurity
OAuth and OIDC misconfiguration testing playbook. Use when reviewing redirect URI handling, state and nonce validation, PKCE, token audience, callback binding, identity-provider trust flaws, and account takeover via OAuth flow manipulation.
Ready to connect★ 115
- View details
pentest-blackboardSkillSecurity
CyberStrikeAI 跨会话项目状态:Fact 图、漏洞记录、关系边与多代理落库边界。 Use when managing project facts, evidence state, or context recovery.
Ready to connect★ 115
- View details
pushbackSkillSecurity
Use when reviewing a spec, PRD, requirements doc, or design plan before implementation begins — especially when the doc feels too big, bundles unrelated features, may contradict the current codebase, or seems vague, infeasible, or thin on security and error handling. Not for cross-checking a spec ag
Ready to connect★ 112
What is a skill?
A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.
52,524 of the 52,958 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.
Install one and every AI you use gets it
Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.
Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.