Skills.
Give your AI a better way to work.
A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.
Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.
Category: Security
1,738 results · page 32 of 58
- View details
security-automationSkillSecurity
安全自动化顶级专业技能:DevSecOps全流程集成、CI/CD安全管道、SAST/DAST/SCA/容器/IaC自动化扫描编排、安全工具链集成实战、攻防双视角自动化(红队打点/蓝队检测响应)、SOAR深度编排、Agentic AI安全自动化(LLM Agent编排扫描与响应)、大模型安全运营(AI告警降噪/剧本生成)、误报治理与质量保障、合规自动化(证据收集/报告)
Ready to connect★ 115
- View details
security-awareness-trainingSkillSecurity
安全意识培训深度专业技能(v3.0高级版):AI时代社工威胁升级、深度伪造语音/视频钓鱼、AI生成个性化钓鱼、Evilginx2全链路仿真演练、防御方角色化培训体系、Kirkpatrick四层量化效果评估、AI大模型结合(LLM生成教材/演练内容/数据分析/大模型使用安全规范)、新威胁面培训(提示注入/Deepfake识别/供应链/QR钓鱼)、红蓝对抗演练组织方法论,从"意识培训"升级为"行为安全工程"的完整攻防培训体系
Ready to connect★ 115
- View details
shiro-exploitationSkillSecurity
Apache Shiro安全框架深度利用专业技能v3.0:rememberMe Cookie AES-CBC/CBC-GCM双模式深挖、密钥爆破方法论升级(Padding Oracle深度解密原理/工具选型/并行加速)、Gadget链版本兼容矩阵、Shiro-550/721、认证绕过全系列(CVE-2020-1957至CVE-2026-56091)、Tomcat内存马/错链回显、Shiro+Fastjson/Log4j组合链、Spring Boot生态实战面、AI大模型辅助攻击载荷生成与配置审计、从指纹识别到RCE完整攻击链
Ready to connect★ 115
- View details
spring-exploitationSkillSecurity
Spring Framework漏洞深度利用专业技能:全年代CVE时间线(2016-2026)、Spring Boot Actuator深度利用与heapdump凭据链、SpEL注入全家族、Spring4Shell数据绑定RCE、Spring Security认证/授权绕过面、Spring内存马全谱系(Filter/Servlet/Interceptor/ControllerAdvice/WebFlux)、Spring Cloud组件漏洞、Spring AI/LLM集成框架攻击面、环境变量/配置注入、Log4Shell组合利用、AI大模型辅助攻防、WAF绕过与不出网利用
Ready to connect★ 115
- View details
type-jugglingSkillSecurity
PHP type juggling and weak comparison (`==`) bypass. Use when authentication, HMAC/signature checks, or token validation uses loose equality, numeric coercion, or hash comparisons without strict types — common in legacy PHP and CTF-style code paths.
Ready to connect★ 115
- View details
vulnerability-assessmentSkillSecurity
漏洞评估高级专业技能:CVSS 3.1/4.0评分体系深度与滥用案例、EPSS/KEV/VPT漏洞优先级技术融合、攻击面管理与扫描器深度配置(Nessus/OpenVAS/Nuclei自动化与误报治理)、漏洞验证与真实可利用性分析、供应链SBOM与云容器漏洞评估专项、AI大模型辅助漏洞研判与报告生成、从发现到闭环的漏洞全生命周期管理
Ready to connect★ 115
- View details
web-cache-deceptionSkillSecurity
Web cache deception and poisoning playbook. Use when CDN, reverse proxy, or application caching may serve sensitive authenticated content to other users due to path confusion or cache key manipulation.
Ready to connect★ 115
- View details
xpath-injection-testingSkillSecurity
XPath injection vulnerability testing. Use when user input reaches XPath/XQuery
Ready to connect★ 115
- View details
abi-to-mcp-guideSkillSecurity
Guide to UCAI (Universal Contract AI Interface) — the ABI-to-MCP server generator. Point it at any smart contract ABI and get a working MCP server. One command, any contract, Claude speaks it. Supports Uniswap, Aave, ERC20, NFTs, all EVM chains. Security scanner included.
Ready to connect★ 114
- View details
agenti-mcp-guideSkillSecurity
Guide to Agenti — a universal MCP server for AI agents to interact with 20+ blockchains. 380+ tools for DeFi, DEX aggregation, security scanning, cross-chain bridges, QR payments. x402 enabled for autonomous agent-to-agent payments. Works with Claude, ChatGPT, Cursor, and any MCP-compatible client.
Ready to connect★ 114
- View details
chainlink-oracle-guideSkillSecurity
How Chainlink oracle price feeds work — architecture, reading feeds on-chain, available pairs, the aggregator model, and oracle security. Covers how DeFi protocols (Aave, Sperax, Compound) rely on Chainlink for accurate pricing. Use when explaining oracles, price feeds, or DeFi infrastructure.
Ready to connect★ 114
- View details
cross-chain-bridge-guideSkillSecurity
Guide to cross-chain bridges — bridge architectures, trust assumptions, security risks, major bridges comparison, and bridging best practices. Covers Stargate, Across, Hop, Wormhole, and official L2 bridges. Use when helping users move assets between chains safely.
Ready to connect★ 114
- View details
restaking-explainedSkillSecurity
Guide to restaking and liquid restaking tokens (LRTs) — EigenLayer, restaking mechanics, operator selection, risk analysis, and the restaking ecosystem. Use when explaining restaking concepts, evaluating LRT protocols, or helping users understand EigenLayer and AVS security.
Ready to connect★ 114
- View details
yield-farming-analysisSkillSecurity
Analyze DeFi yield farming opportunities including APY breakdown, risk assessment, smart contract security, and impermanent loss estimation.
Ready to connect★ 114
- View details
bitquery-graphql-skillSkillSecurity
Use Bitquery GraphQL through UXC for onchain trades, transfers, token holder analysis, balances, and market structure queries across supported networks, with OAuth client_credentials authentication and query-first execution.
Ready to connect★ 113
- View details
linear-graphql-skillSkillSecurity
Operate Linear workspace issues, projects, and teams through Linear GraphQL API using UXC. Use when tasks require querying or creating issues, managing projects, or interacting with Linear workflow. Supports both Personal API Key and OAuth authentication.
Ready to connect★ 113
- View details
reality-check-modeSkillSecurity
Use for grounding or AI-loop escalation when the user treats ordinary artifacts, numbers, phrases, coincidences, symbols, model wording, or AI behavior as hidden, personal, threatening, mystical, or specially meaningful signals. Use only Grounding, What I can say, and Safer next step. Do not decode
Ready to connect★ 113
- View details
recon-playbookSkillSecurity
Build a hunting checklist / methodology for a vulnerability class or target tech stack, distilled from the local disclosed-report corpus. Use when the user asks "how do I hunt for X", "give me a methodology / checklist for X", "what should I test on a <tech> target", or wants a recon plan grounded i
Ready to connect★ 113
- View details
severitySkillSecurity
Estimate the severity of a vulnerability finding and produce a CVSS 3.1 vector + impact framing, calibrated against how similar findings were rated in the local disclosed-report corpus. Use when the user asks "how severe is this", "what CVSS score", "how should I rate this", or needs an impact state
Ready to connect★ 113
- View details
write-reportSkillSecurity
Write a disclosure-quality bug bounty report for a finding, matching the HackerOne report format used in this repo's corpus. Use when the user has a vulnerability and wants it written up — "write a report for this", "draft a HackerOne submission", "turn this finding into a report". Produces title, s
Ready to connect★ 113
- View details
apollo-serverSkillSecurity
Guide for building GraphQL servers with Apollo Server 5.x. Use this skill when: (1) setting up a new Apollo Server project, (2) writing resolvers or defining GraphQL schemas, (3) implementing authentication or authorization, (4) creating plugins or custom data sources, (5) troubleshooting Apollo Ser
Ready to connect★ 112
- View details
graphql-schemaSkillSecurity
Guide for designing GraphQL schemas following industry best practices. Use this skill when: (1) designing a new GraphQL schema or API, (2) reviewing existing schema for improvements, (3) deciding on type structures or nullability, (4) implementing pagination or error patterns, (5) ensuring security
Ready to connect★ 112
- View details
value-chain-mappingSkillSecurity
Map end-user needs to the full value chain, identify core value generators, and highlight vulnerabilities.
Ready to connect★ 112
- View details
neo4j-security-skillSkillSecurity
Programmatic security management in Neo4j — RBAC/ABAC, user lifecycle (CREATE/ALTER/DROP USER),
Ready to connect★ 110
- View details
flutter-networkingSkillSecurity
Implement, fix, debug, review, or refactor Flutter networking code for HTTP/REST APIs, WebSocket realtime flows, authentication and token refresh, request headers, timeouts, retries, JSON parsing, caching, background isolates, repositories, services, and adaptation to existing http, Dio, Retrofit, C
Ready to connect★ 108
- View details
approve-exemptSkillSecurity
Approve pending Harness STO security exemptions (waivers) at their current scope or elevate them to Project, Org, or Account scope. Users say "approve" for both in-scope approval and higher-scope elevation — do not require the word "promote". Supports approving one exemption or a mixed list where ea
Ready to connect★ 106
- View details
audit-reportSkillSecurity
Lets your agent generate a security audit report summarizing findings and issues.
Ready to connect★ 106
- View details
configure-dast-scanSkillSecurity
Add Dynamic Application Security Testing (DAST) steps to existing Harness pipelines using Harness STO scanners. Supports API DAST / Traceable (default), Burp Suite Enterprise, ZAP (OWASP), Nikto, and Nmap. Scans running application instances for vulnerabilities including API security issues, injecti
Ready to connect★ 106
- View details
configure-repo-scanSkillSecurity
Configure code scanning in Harness pipelines using STO security scanners. Helps identify where to inject SAST/SCA scanning steps into existing pipelines, recommends appropriate scanners, and configures them with proper connector references. Use when asked to add code scanning, configure security sca
Ready to connect★ 106
- View details
configure-secret-scanSkillSecurity
Add secret detection scanning steps to existing Harness pipelines using STO security scanners. Detects exposed credentials, API keys, tokens, and sensitive data in code repositories. Supports Harness Code (default, native, unified SAST/SCA/secret detection), Gitleaks (standalone secret scanner, open
Ready to connect★ 106
What is a skill?
A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.
52,524 of the 52,958 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.
Install one and every AI you use gets it
Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.
Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.