Skills.

Give your AI a better way to work.

A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.

Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.

Category: Security

1,738 results · page 33 of 58

  • exempt-vulnSkillSecurity

    Create Harness STO security exemptions (waivers) for vulnerabilities found by SAST, SCA, DAST, secret, container, or IaC scanners. Works from both entry points in the Harness UI: the Vulnerabilities tab of a specific pipeline execution (Target, Pipeline, or Project scope) and the All Issues page (Pr

    Ready to connect★ 106

    github.com/harness/harness-skills106 stars

    View details
  • manage-supply-chainSkillSecurity

    Manage Harness Software Supply Chain Assurance (SSCA) via MCP. Configure automated SBOM generation with CycloneDX or SPDX formats, set up artifact signing and attestation with Cosign, define supply chain security policies using OPA, and track SLSA provenance levels. Use when asked to generate SBOMs,

    Ready to connect★ 106

    github.com/harness/harness-skills106 stars

    View details
  • pm-checkupSkillSecurity

    On-demand five-dimension project checkup (security, function, completeness, quality, docs) with P0/P1/P2. No cron.

    Ready to connect★ 106

    github.com/wei63w/pm-manager106 stars

    View details
  • security-reportSkillSecurity

    Generate security compliance reports using Harness SCS and STO via MCP. Analyze vulnerabilities, SBOMs, and manage exemptions. Use when user says "security report", "vulnerabilities", "SBOM", "security scan", "compliance check", or asks about application security.

    Ready to connect★ 106

    github.com/harness/harness-skills106 stars

    View details
  • cometchat-android-v5-productionSkillSecurity

    Production readiness for CometChat Android — server-side token auth, user management CRUD, ProGuard rules, and security checklist.

    Ready to connect★ 105

    github.com/cometchat/cometchat-skills105 stars

    View details
  • cometchat-flutter-v5-productionSkillSecurity

    Use when preparing a CometChat Flutter UIKit v5 app for production. Covers auth tokens, ProGuard, environment config, security hardening.

    Ready to connect★ 105

    github.com/cometchat/cometchat-skills105 stars

    View details
  • cometchat-productionSkillSecurity

    Production readiness for CometChat — server-side token auth, user management CRUD, environment hardening, and security checklist. Replaces dev-mode authKey with server-side tokens.

    Ready to connect★ 105

    github.com/cometchat/cometchat-skills105 stars

    View details
  • design-production-ai-systemSkillSecurity

    Design a production AI-enabled system after its workflow, value, and intelligence choices are approved. Use for architecture, domain and state modeling, model behavior, context, tools, human review, security boundaries, delivery planning, or a complete design packet.

    Ready to connect★ 105

    github.com/davidahmann/applied-ai-field-guide70 stars

    View details
  • review-ai-production-readinessSkillSecurity

    Review a specific AI-system release for production readiness. Use for architecture review, launch gate, customer security review, audit evidence, autonomy expansion, canary approval, rollback decision, or a prioritized gap assessment against this guide's controls.

    Ready to connect★ 105

    github.com/davidahmann/applied-ai-field-guide70 stars

    View details
  • secure-ai-action-boundarySkillSecurity

    Secure model-visible reads and real-world actions at trusted software boundaries. Use for tool or MCP contracts, identity and tenant scoping, capability provenance, credentials and egress, approval, idempotency, readback, action authorization, or negative security tests.

    Ready to connect★ 105

    github.com/davidahmann/applied-ai-field-guide70 stars

    View details
  • API CatalogSkillSecurity

    Reference guide for connecting popular APIs to Home Assistant via Node-RED, YAML, or custom integrations. Covers authentication, endpoints, and complete working examples for: energy APIs (Tibber, Nordpool), weather (SMHI, OpenWeatherMap, yr.no), transport (SL, Trafikverket, Resrobot), smart home clo

    Ready to connect★ 104

    github.com/tonylofgren/aurora-smart-home104 stars

    View details
  • clerkSkillSecurity

    Clerk authentication router. Use when user asks about Clerk CLI operations, adding authentication, setting up Clerk, custom sign-in flows, Swift or native iOS auth, native Android auth, Next.js patterns, React patterns, Vue patterns, Nuxt patterns, Astro patterns, TanStack Start patterns, Expo patte

    Ready to connect★ 101

    github.com/vvedantb/eva101 stars

    View details
  • system-administratorSkillSecurity

    Manage and troubleshoot computer systems with security-first practices. Trigger on phrases like "system administration", "system admin", "linux admin", "server management", "troubleshoot system".

    Ready to connect★ 99

    github.com/captainflasmr/ollama-buddy100 stars

    View details
  • repo-maintenanceSkillSecurity

    Full repository maintenance pipeline that orchestrates all project agents in sequence - code review, accessibility, bundle size, security, API stability, test coverage, ecosystem, and release preparation. Acts as a quality gate before publishing or merging major changes. Use when: maintenance, healt

    Ready to connect★ 99

    github.com/pglejzer/timepicker-ui97 stars

    View details
  • application-securitySkillSecurity

    OWASP Top 10 with code examples, SAST/DAST tools, dependency scanning, CSP headers, and input validation patterns. Use when hardening applications, reviewing security posture, or implementing defensive coding practices.

    Ready to connect★ 97

    github.com/travisjneuman/.claude95 stars

    View details
  • blockchain-web3SkillSecurity

    Solidity smart contracts, Web3 development, DeFi protocols, NFTs, EVM chains, Hardhat/Foundry tooling, and blockchain security. Use when writing smart contracts, building dApps, auditing contract security, or integrating Web3 wallets.

    Ready to connect★ 97

    github.com/travisjneuman/.claude95 stars

    View details
  • core-workflowSkillSecurity

    Detailed development workflow patterns, checklists, and standards. Auto-loads for complex tasks, planning, debugging, testing, or when explicit patterns are needed. Contains session protocols, git conventions, security checklists, testing strategy, and communication standards.

    Ready to connect★ 97

    github.com/travisjneuman/.claude95 stars

    View details
  • generic-code-reviewerSkillSecurity

    Review code for bugs, security vulnerabilities, performance issues, accessibility gaps, and CLAUDE.md workflow compliance. Supports any tech stack - HTML/CSS/JS, React, TypeScript, Node.js, Python, NestJS, Next.js, and more. Use when completing features, before commits, or reviewing pull requests.

    Ready to connect★ 97

    github.com/travisjneuman/.claude95 stars

    View details
  • generic-fullstack-code-reviewerSkillSecurity

    Review full-stack code for bugs, security vulnerabilities, performance issues, accessibility gaps, and CLAUDE.md compliance. Enforces TypeScript strict mode, input validation, GPU-accelerated animations, and design system consistency. Use when completing features, before commits, or reviewing pull r

    Ready to connect★ 97

    github.com/travisjneuman/.claude95 stars

    View details
  • generic-react-code-reviewerSkillSecurity

    Review React/TypeScript code for bugs, security vulnerabilities, performance issues, accessibility gaps, and CLAUDE.md workflow compliance. Enforces TypeScript strict mode, GPU-accelerated animations, WCAG AA accessibility, bundle size limits, and surgical simplicity. Use when completing features, b

    Ready to connect★ 97

    github.com/travisjneuman/.claude95 stars

    View details
  • generic-static-code-reviewerSkillSecurity

    Review static site code for bugs, security issues, performance problems, accessibility gaps, and CLAUDE.md compliance. Enforces pure HTML/CSS/JS standards, minimal page weight, mobile-first design. Use when completing features, before commits, or reviewing changes.

    Ready to connect★ 97

    github.com/travisjneuman/.claude95 stars

    View details
  • tauri-desktopSkillSecurity

    Tauri 2.0 project setup, Rust backend + web frontend, plugin system, IPC commands, security model, auto-update, and mobile support. Use when building lightweight cross-platform desktop or mobile apps with Tauri.

    Ready to connect★ 97

    github.com/travisjneuman/.claude95 stars

    View details
  • test-specialistSkillSecurity

    This skill should be used when writing test cases, fixing bugs, analyzing code for potential issues, or improving test coverage for JavaScript/TypeScript applications. Use this for unit tests, integration tests, end-to-end tests, debugging runtime errors, logic bugs, performance issues, security vul

    Ready to connect★ 97

    github.com/travisjneuman/.claude95 stars

    View details
  • API Fuzzing for Bug BountySkillSecurity

    This skill should be used when the user asks to "test API security", "fuzz APIs", "find IDOR vulnerabilities", "test REST API", "test GraphQL", "API penetration testing", "bug bounty API testing", or needs guidance on API security assessment techniques.

    Ready to connect★ 96

    github.com/agent-skills-hub/agent-skills-hub92 stars

    View details
  • attack-tree-constructionSkillSecurity

    Build comprehensive attack trees to visualize threat paths. Use when mapping attack scenarios, identifying defense gaps, or communicating security risks to stakeholders.

    Ready to connect★ 96

    github.com/agent-skills-hub/agent-skills-hub92 stars

    View details
  • backend-security-coderSkillSecurity

    Lets your agent review and write backend code with secure input validation, authentication, and API security practices.

    Ready to connect★ 96

    github.com/agent-skills-hub/agent-skills-hub92 stars

    View details
  • Broken Authentication TestingSkillSecurity

    This skill should be used when the user asks to "test for broken authentication vulnerabilities", "assess session management security", "perform credential stuffing tests", "evaluate password policies", "test for session fixation", or "identify authentication bypass flaws". It provides comprehensive

    Ready to connect★ 96

    github.com/agent-skills-hub/agent-skills-hub92 stars

    View details
  • Burp Suite Web Application TestingSkillSecurity

    This skill should be used when the user asks to "intercept HTTP traffic", "modify web requests", "use Burp Suite for testing", "perform web vulnerability scanning", "test with Burp Repeater", "analyze HTTP history", or "configure proxy for web testing". It provides comprehensive guidance for using B

    Ready to connect★ 96

    github.com/agent-skills-hub/agent-skills-hub92 stars

    View details
  • cicd-automation-workflow-automateSkillSecurity

    Lets your agent design and set up automated CI/CD pipelines and GitHub Actions workflows.

    Ready to connect★ 96

    github.com/agent-skills-hub/agent-skills-hub92 stars

    View details
  • code-review-checklistSkillSecurity

    Comprehensive checklist for conducting thorough code reviews covering functionality, security, performance, and maintainability

    Ready to connect★ 96

    github.com/agent-skills-hub/agent-skills-hub92 stars

    View details

What is a skill?

A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.

52,524 of the 52,958 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.

Install one and every AI you use gets it

Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.

Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.

See how to connect your AI