Skills.
Give your AI a better way to work.
A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.
Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.
Category: Security
1,738 results · page 33 of 58
- View details
exempt-vulnSkillSecurity
Create Harness STO security exemptions (waivers) for vulnerabilities found by SAST, SCA, DAST, secret, container, or IaC scanners. Works from both entry points in the Harness UI: the Vulnerabilities tab of a specific pipeline execution (Target, Pipeline, or Project scope) and the All Issues page (Pr
Ready to connect★ 106
- View details
manage-supply-chainSkillSecurity
Manage Harness Software Supply Chain Assurance (SSCA) via MCP. Configure automated SBOM generation with CycloneDX or SPDX formats, set up artifact signing and attestation with Cosign, define supply chain security policies using OPA, and track SLSA provenance levels. Use when asked to generate SBOMs,
Ready to connect★ 106
- View details
pm-checkupSkillSecurity
On-demand five-dimension project checkup (security, function, completeness, quality, docs) with P0/P1/P2. No cron.
Ready to connect★ 106
- View details
security-reportSkillSecurity
Generate security compliance reports using Harness SCS and STO via MCP. Analyze vulnerabilities, SBOMs, and manage exemptions. Use when user says "security report", "vulnerabilities", "SBOM", "security scan", "compliance check", or asks about application security.
Ready to connect★ 106
- View details
cometchat-android-v5-productionSkillSecurity
Production readiness for CometChat Android — server-side token auth, user management CRUD, ProGuard rules, and security checklist.
Ready to connect★ 105
- View details
cometchat-flutter-v5-productionSkillSecurity
Use when preparing a CometChat Flutter UIKit v5 app for production. Covers auth tokens, ProGuard, environment config, security hardening.
Ready to connect★ 105
- View details
cometchat-productionSkillSecurity
Production readiness for CometChat — server-side token auth, user management CRUD, environment hardening, and security checklist. Replaces dev-mode authKey with server-side tokens.
Ready to connect★ 105
- View details
design-production-ai-systemSkillSecurity
Design a production AI-enabled system after its workflow, value, and intelligence choices are approved. Use for architecture, domain and state modeling, model behavior, context, tools, human review, security boundaries, delivery planning, or a complete design packet.
Ready to connect★ 105
- View details
review-ai-production-readinessSkillSecurity
Review a specific AI-system release for production readiness. Use for architecture review, launch gate, customer security review, audit evidence, autonomy expansion, canary approval, rollback decision, or a prioritized gap assessment against this guide's controls.
Ready to connect★ 105
- View details
secure-ai-action-boundarySkillSecurity
Secure model-visible reads and real-world actions at trusted software boundaries. Use for tool or MCP contracts, identity and tenant scoping, capability provenance, credentials and egress, approval, idempotency, readback, action authorization, or negative security tests.
Ready to connect★ 105
- View details
API CatalogSkillSecurity
Reference guide for connecting popular APIs to Home Assistant via Node-RED, YAML, or custom integrations. Covers authentication, endpoints, and complete working examples for: energy APIs (Tibber, Nordpool), weather (SMHI, OpenWeatherMap, yr.no), transport (SL, Trafikverket, Resrobot), smart home clo
Ready to connect★ 104
- View details
clerkSkillSecurity
Clerk authentication router. Use when user asks about Clerk CLI operations, adding authentication, setting up Clerk, custom sign-in flows, Swift or native iOS auth, native Android auth, Next.js patterns, React patterns, Vue patterns, Nuxt patterns, Astro patterns, TanStack Start patterns, Expo patte
Ready to connect★ 101
- View details
system-administratorSkillSecurity
Manage and troubleshoot computer systems with security-first practices. Trigger on phrases like "system administration", "system admin", "linux admin", "server management", "troubleshoot system".
Ready to connect★ 99
- View details
repo-maintenanceSkillSecurity
Full repository maintenance pipeline that orchestrates all project agents in sequence - code review, accessibility, bundle size, security, API stability, test coverage, ecosystem, and release preparation. Acts as a quality gate before publishing or merging major changes. Use when: maintenance, healt
Ready to connect★ 99
- View details
application-securitySkillSecurity
OWASP Top 10 with code examples, SAST/DAST tools, dependency scanning, CSP headers, and input validation patterns. Use when hardening applications, reviewing security posture, or implementing defensive coding practices.
Ready to connect★ 97
- View details
blockchain-web3SkillSecurity
Solidity smart contracts, Web3 development, DeFi protocols, NFTs, EVM chains, Hardhat/Foundry tooling, and blockchain security. Use when writing smart contracts, building dApps, auditing contract security, or integrating Web3 wallets.
Ready to connect★ 97
- View details
core-workflowSkillSecurity
Detailed development workflow patterns, checklists, and standards. Auto-loads for complex tasks, planning, debugging, testing, or when explicit patterns are needed. Contains session protocols, git conventions, security checklists, testing strategy, and communication standards.
Ready to connect★ 97
- View details
generic-code-reviewerSkillSecurity
Review code for bugs, security vulnerabilities, performance issues, accessibility gaps, and CLAUDE.md workflow compliance. Supports any tech stack - HTML/CSS/JS, React, TypeScript, Node.js, Python, NestJS, Next.js, and more. Use when completing features, before commits, or reviewing pull requests.
Ready to connect★ 97
- View details
generic-fullstack-code-reviewerSkillSecurity
Review full-stack code for bugs, security vulnerabilities, performance issues, accessibility gaps, and CLAUDE.md compliance. Enforces TypeScript strict mode, input validation, GPU-accelerated animations, and design system consistency. Use when completing features, before commits, or reviewing pull r
Ready to connect★ 97
- View details
generic-react-code-reviewerSkillSecurity
Review React/TypeScript code for bugs, security vulnerabilities, performance issues, accessibility gaps, and CLAUDE.md workflow compliance. Enforces TypeScript strict mode, GPU-accelerated animations, WCAG AA accessibility, bundle size limits, and surgical simplicity. Use when completing features, b
Ready to connect★ 97
- View details
generic-static-code-reviewerSkillSecurity
Review static site code for bugs, security issues, performance problems, accessibility gaps, and CLAUDE.md compliance. Enforces pure HTML/CSS/JS standards, minimal page weight, mobile-first design. Use when completing features, before commits, or reviewing changes.
Ready to connect★ 97
- View details
tauri-desktopSkillSecurity
Tauri 2.0 project setup, Rust backend + web frontend, plugin system, IPC commands, security model, auto-update, and mobile support. Use when building lightweight cross-platform desktop or mobile apps with Tauri.
Ready to connect★ 97
- View details
test-specialistSkillSecurity
This skill should be used when writing test cases, fixing bugs, analyzing code for potential issues, or improving test coverage for JavaScript/TypeScript applications. Use this for unit tests, integration tests, end-to-end tests, debugging runtime errors, logic bugs, performance issues, security vul
Ready to connect★ 97
- View details
API Fuzzing for Bug BountySkillSecurity
This skill should be used when the user asks to "test API security", "fuzz APIs", "find IDOR vulnerabilities", "test REST API", "test GraphQL", "API penetration testing", "bug bounty API testing", or needs guidance on API security assessment techniques.
Ready to connect★ 96
- View details
attack-tree-constructionSkillSecurity
Build comprehensive attack trees to visualize threat paths. Use when mapping attack scenarios, identifying defense gaps, or communicating security risks to stakeholders.
Ready to connect★ 96
- View details
backend-security-coderSkillSecurity
Lets your agent review and write backend code with secure input validation, authentication, and API security practices.
Ready to connect★ 96
- View details
Broken Authentication TestingSkillSecurity
This skill should be used when the user asks to "test for broken authentication vulnerabilities", "assess session management security", "perform credential stuffing tests", "evaluate password policies", "test for session fixation", or "identify authentication bypass flaws". It provides comprehensive
Ready to connect★ 96
- View details
Burp Suite Web Application TestingSkillSecurity
This skill should be used when the user asks to "intercept HTTP traffic", "modify web requests", "use Burp Suite for testing", "perform web vulnerability scanning", "test with Burp Repeater", "analyze HTTP history", or "configure proxy for web testing". It provides comprehensive guidance for using B
Ready to connect★ 96
- View details
cicd-automation-workflow-automateSkillSecurity
Lets your agent design and set up automated CI/CD pipelines and GitHub Actions workflows.
Ready to connect★ 96
- View details
code-review-checklistSkillSecurity
Comprehensive checklist for conducting thorough code reviews covering functionality, security, performance, and maintainability
Ready to connect★ 96
What is a skill?
A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.
52,524 of the 52,958 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.
Install one and every AI you use gets it
Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.
Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.