Skills.
Give your AI a better way to work.
A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.
Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.
Category: Security
1,738 results · page 37 of 58
- View details
liveview-code-reviewSkillSecurity
Reviews Phoenix LiveView code for lifecycle patterns, assigns/streams usage, components, and security. Use when reviewing LiveView modules, .heex templates, or LiveComponents.
Ready to connect★ 81
- View details
remix-v2-meta-sessions-reviewSkillSecurity
Reviews Remix v2 code for v1-shape meta exports (BREAKING in v2), cookie security gaps (httpOnly, secure, secrets rotation), auth gates in wrong layer, and missing CSRF. Use when reviewing meta/SEO, session, auth, or form-mutation code in a Remix v2 codebase.
Ready to connect★ 81
- View details
review-planSkillSecurity
Review implementation plans for parallelization, TDD, types, libraries, and security before execution
Ready to connect★ 81
- View details
wish-ssh-code-reviewSkillSecurity
Reviews Wish SSH server code for proper middleware, session handling, and security patterns. Use when reviewing SSH server code using charmbracelet/wish.
Ready to connect★ 81
- View details
ctf-kitSkillSecurity
Use when the user is solving an authorized CTF / lab reverse-engineering challenge focused on Windows application authentication or license-check bypass. Guides triage → static analysis → dynamic experiment planning → bypass verification, with strong evidence discipline and VM safety boundaries. NOT
Ready to connect★ 79
- View details
iterative-converging-auditSkillSecurity
Run any "find all instances of X" sweep — a security audit, a safety audit, a code review, a research question, a compliance check — as an iterative loop that does NOT stop at one pass. Audit → fix → RE-audit → … until a clean pass returns zero NEW discoveries. Use whenever thoroughness matters and
Ready to connect★ 79
- View details
repo-scanSkillSecurity
Use when the user wants to evaluate a GitHub repository before installing, running, forking, or depending on it. Takes a GitHub repo URL, cleans tracking params, shallow-clones to /tmp, inspects dependency/supply-chain risk, static vulnerability patterns, issue-reported security problems, maintainer
Ready to connect★ 79
- View details
secret-setupSkillSecurity
Focused micro-skill for secret management setup. Explains options, guides through Bitwarden installation/login/unlock, configures backend. Exits when done.
Ready to connect★ 79
- View details
spec-convergeSkillSecurity
Iteratively review an instar-development spec with multi-angle internal reviewers (security, scalability, adversarial, integration, decision-completeness, lessons-aware) and real cross-model external reviewers routed through the agent's own installed CLIs (codex → GPT-tier, gemini → Gemini-tier; one
Ready to connect★ 79
- View details
specsfy-specialist-application-securitySkillSecurity
Model threats and review security of applications, APIs, authentication, authorization, data, dependencies, secrets, and infrastructure. Use for changes involving trust boundaries, identity, external input, sensitive data, or security review; also use for threat modeling before a feature with no
Ready to connect★ 79
- View details
specsfy-specialist-code-reviewSkillSecurity
Reviews diffs, branches, and PRs for contract compliance, correctness, security, architecture, tests, and operational risk, reporting findings by severity with location and evidence. Use when the user asks for a code review, a second opinion on a change, or a risk assessment of a diff; read-only exc
Ready to connect★ 79
- View details
access-control-policy-designSkillSecurity
USE THIS SKILL whenever any topic related to access control, authorization, permissions, or security policy arises in any form. Triggers include — but are not limited to: RBAC, ABAC, PBAC, ACL, DAC, ReBAC, Zanzibar, OPA, Cedar, Casbin, SpiceDB, OpenFGA, Permify, Oso, Cerbos, Permit.io; any mention o
Ready to connect★ 78
- View details
acl-securitySkillSecurity
Create and debug ServiceNow ACLs (record, field, REST, script-include). Covers role/condition/script patterns, which ACL names can apply to a table or field, field-level visibility, and impersonation testing for row- and field-level security.
Ready to connect★ 78
- View details
ai-governanceSkillSecurity
Design and operate an organization's AI governance system: define governance principles, operating models and decision rights, risk frameworks, lifecycle gates, and fairness, transparency, privacy, security, regulatory, and board-oversight controls. Use when standing up a governance program, tiering
Ready to connect★ 78
- View details
ai-scanner-garakSkillSecurity
AI model safety scanner built on NVIDIA garak for testing LLMs against 179 security probes across 35 vulnerability families
Ready to connect★ 78
- View details
anthropic-cybersecurity-skills-agent-librarySkillSecurity
Trending Claude Code skills
Ready to connect★ 78
- View details
autoteam-f-chatgpt-team-rotationSkillSecurity
AutoTeam-F is a ChatGPT Team account rotation and authentication sync tool with batch free account generation, OAuth management, and a Web dashboard.
Ready to connect★ 78
- View details
bluehammer-vulnerability-pocSkillSecurity
Skill for working with the BlueHammer vulnerability proof-of-concept repository, covering build, usage, and code patterns.
Ready to connect★ 78
- View details
cairn-ai-pentestSkillSecurity
AI-automated penetration testing and general problem-solving system that achieved unique AK (All Killed) in Tencent Cloud Hackathon intelligent penetration challenge
Ready to connect★ 78
- View details
codex-oauth-automation-extensionSkillSecurity
Chrome extension for automating OpenAI OAuth registration flows with captcha retrieval, CPA callback verification, and auto-recovery across multiple rounds
Ready to connect★ 78
- View details
- View details
copyfail-go-lpeSkillSecurity
Go implementation of CVE-2026-31431 (CopyFail), a Linux local privilege escalation exploit targeting the AF_ALG iov_iter kernel vulnerability affecting kernels v4.14–April 2026.
Ready to connect★ 78
- View details
crabtrap-llm-proxySkillSecurity
LLM-as-a-judge HTTP/HTTPS proxy that secures AI agents by intercepting and evaluating outbound requests against security policies before they reach external APIs.
Ready to connect★ 78
- View details
instance-securitySkillSecurity
Harden a ServiceNow instance — password complexity, session timeout, MFA enforcement, input sanitization for XSS/injection, security properties, syslog events, and security health checks.
Ready to connect★ 78
- View details
legal-strategySkillSecurity
Analyze legal and regulatory risk, IP, contracts, privacy, governance, and employment questions as structured issue-spotting for counsel. Do not use this methodology as legal advice or for technical security implementation, CRM, or delivery execution.
Ready to connect★ 78
- View details
lightfriend-add-integrationSkillSecurity
Step-by-step guide for adding new OAuth integrations to Lightfriend
Ready to connect★ 78
- View details
pier-cloudSkillSecurity
This skill should be used when the user needs to consume the Pier Cloud (Lighthouse) API for cloud cost management — including JWT authentication, listing contexts, workspaces, and FinOps data views. Trigger whenever there is a need to integrate, automate, or debug calls to the Pier Cloud platform v
Ready to connect★ 77
- View details
secure-software-engineeringSkillSecurity
Use when designing or implementing software securely: define security requirements, threat-model a feature, choose secure defaults, design authentication and authorization, handle untrusted data and secrets, evaluate dependencies, design multi-tenant trust boundaries, or review security-sensitive ch
Ready to connect★ 78
- View details
security-audit-methodologySkillSecurity
Plan authorized security reviews with threat modeling, architecture and dependency audits, and vulnerability classification. Use for scoped defensive security assessment. Do not use for offensive operations, unauthorized testing, or security control implementation.
Ready to connect★ 78
- View details
security-specialistSkillSecurity
Runs security audits on codebases — full scans, diff reviews, threat models, vulnerability triage, remediation guidance, and finding tracking. Activate when the user says "security scan", "audit this repo", "review this PR for security", "threat model", "triage vulnerabilities", "fix this vuln", or
Ready to connect★ 77
What is a skill?
A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.
52,524 of the 52,958 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.
Install one and every AI you use gets it
Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.
Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.