Skills.
Give your AI a better way to work.
A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.
Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.
Category: Security
1,738 results · page 38 of 58
- View details
update-set-workflowSkillSecurity
Manage ServiceNow update sets — create named sets before any development, ensure auto_switch tracks API changes under the OAuth service account, complete on done, and export for promotion. Mandatory for all change-producing work.
Ready to connect★ 78
- View details
breachSkillSecurity
Designing red team attack scenarios, threat models, MITRE ATT&CK/OWASP application, Purple Team exercises, and AI/LLM red teaming. Use when adversarial security validation is needed.
Ready to connect★ 77
- View details
cullSkillSecurity
Scanning and eradicating supply-chain malware (Shai-Hulud/S1ngularity npm/PyPI worms): IoC scan, OS/IDE persistence, safe credential rotation. Not for SAST (Sentinel) or skill/MCP audit (Chain).
Ready to connect★ 77
- View details
pipeSkillSecurity
Designing GitHub Actions workflows in depth: trigger strategy, security hardening, performance optimization, PR automation, and Reusable Workflow design.
Ready to connect★ 77
- View details
specialist-reviewSkillSecurity
Conducts a focused review from ONE specific specialist's perspective (e.g., Security Specialist, Performance Expert). Use when the user requests "Ask [specialist role] to review [target]", "Get [specialist]'s opinion on [topic]", "Have [role] review [code/component]", or when they want deep expertis
Ready to connect★ 77
- View details
zenSkillSecurity
Refactoring code: variable naming, function extraction, magic number constants, dead code removal. Does not change behavior. Not for bugs/security (Judge), tests (Radar), or features (Builder).
Ready to connect★ 77
- View details
ack-reputationSkillSecurity
Peer-driven onchain reputation layer for AI agents enabling kudos across reliability, speed, accuracy, creativity, and security categories.
Ready to connect★ 76
- View details
audit-intelligenceSkillSecurity
Query Solodit audit knowledge to review smart contracts with evidence-backed findings, severity summaries, and remediation guidance. Use for contract audit prep, vulnerability triage, and secure coding reviews.
Ready to connect★ 76
- View details
authz-securitySkillSecurity
Review application source code for broken authorization — IDOR / Broken Object Level Authorization (OWASP API1), Broken Function Level Authorization (API5), mass assignment (API3), multi-tenant isolation gaps, and privilege escalation. Reads routes, controllers, resolvers, and data models offline an
Ready to connect★ 76
- View details
cybercentrySkillSecurity
AI-powered cyber security information and intelligence hub on Virtuals Protocol and Agent Commerce Protocol (ACP) v2.
Ready to connect★ 76
- View details
hackerSkillSecurity
Cursor-native offensive security engagement and exploitability autoresearch orchestrator inspired by offensive-claude. Use for an authorized offensive engagement, red-team or pentest workflow, Kill Chain style assessment, scoped web/network/cloud/mobile/AD/bug-bounty offensive plan, or exploitabilit
Ready to connect★ 76
- View details
hooksSkillSecurity
Operates oma's extended native hook pipeline, with deterministic triggers, security gating, and efficiency budgets.
Ready to connect★ 76
- View details
pr-github-opsSkillSecurity
Post Superagent PR security scan findings as inline GitHub pull request review comments using the authenticated gh CLI. Use whenever you need to comment on a PR scan finding, manage Superagent PR labels, complete a GitHub check run, or avoid posting findings as general PR thread comments. Trigger fo
Ready to connect★ 76
- View details
recon-securitySkillSecurity
Guide authorized external penetration testing from recon through validation and scoped exploitation using free and open-source tools. Use for domain/IP attack surface mapping, subdomain discovery, nmap/httpx/nuclei/ffuf workflows, web app testing, SIP/NAS checks, Burp/ZAP validation, PoC documentati
Ready to connect★ 76
- View details
repo-security-postureSkillSecurity
Audit a GitHub repository's security posture and hardening gaps across branch protection, CODEOWNERS, GitHub Actions, publish/release integrity, collaborator access, security features, and dependency review. Use when reviewing or hardening a repo, assessing GitHub configuration, checking CI/CD or Ac
Ready to connect★ 76
- View details
security-disclosure-triageSkillSecurity
Verify whether an incoming security advisory is a real, disclosable vulnerability in a target repository checkout, and assign an honest severity. Use when triaging an advisory, GHSA, scanner finding, or draft report from the researcher/reporter side to decide if it is worth disclosing. Optimizes aga
Ready to connect★ 76
- View details
superagentSkillSecurity
Set up Superagent Context Guardrails at coding-agent tool boundaries, configure and safely use the remote MCP server, and manage signed webhooks for findings, security reports, Contributor Trust, and Runtime Guardrails. Use when the user asks to enable context scanning before an agent consumes URLs,
Ready to connect★ 76
- View details
verdictswarm-mcpSkillSecurity
Fight AI with AI. The security layer for AI agents that touch money — 6 adversarial AI agents debate crypto token risk. MCP server for Claude, Cursor, OpenClaw, Codex.
Ready to connect★ 76
- View details
vulnerability-triageSkillSecurity
Triage inbound vulnerability reports - GitHub Advisories (GHSA/CVE), bug bounty submissions, HackerOne/Bugcrowd/Intigriti exports, or a researcher's issue - to decide whether a finding is real, by-design, or noise. Reads the report offline, cross-references the project's documented intent and threat
Ready to connect★ 76
- View details
claude-security-reviewSkillSecurity
Security-focused review for Hyperlane protocol code. Use for Solidity contracts, Rust agents, and infrastructure changes.
Ready to connect★ 75
- View details
claude-tob-reviewSkillSecurity
Trail of Bits security skills analysis for Solidity contracts. Use for deep smart contract security review with invariant suggestions.
Ready to connect★ 75
- View details
mega-pipelineSkillSecurity
Use when user wants to orchestrate 50+ specialized PR review agents covering different concerns (security, performance, style, dependencies, accessibility, i18n, testing, docs, etc.). Routes through specialist agents and aggregates findings.
Ready to connect★ 75
- View details
pr-security-reviewerSkillSecurity
Use when the parent pipeline routes a security-related PR review request. Reads the diff and emits structured securityFindings using the security specialist heuristics.
Ready to connect★ 75
- View details
cve-remediationSkillSecurity
Dependency vulnerability remediation workflow for this repository. Use when fixing CVE, BDSA, GHSA, OSV, npm, PyPI, Dependabot, Black Duck, Snyk, or other package vulnerability findings, especially when the user asks for minimal package-only updates, validation, commits, branches, or pull requests.
Ready to connect★ 74
- View details
nmap-usageSkillSecurity
Professional nmap scanning techniques and optimization for penetration testing. Use this skill when you need to perform network reconnaissance, port scanning, or service enumeration during authorized security assessments.
Ready to connect★ 74
- View details
system-commandsSkillSecurity
System-level commands for security assessment and system enumeration. Use this skill when performing local system reconnaissance, process analysis, or system information gathering during authorized security testing.
Ready to connect★ 74
- View details
terminal-sessionSkillSecurity
Persistent terminal session management for security testing. Use this skill when you need an interactive shell session that maintains state between commands (working directory, environment variables, etc.) during authorized penetration testing.
Ready to connect★ 74
- View details
yaxSkillSecurity
CLI tool for Yandex Disk, Calendar, and Mail via Yandex OAuth API
Ready to connect★ 74
- View details
arckit-ca-soiaSkillSecurity
[COMMUNITY] Generate a Canada Security of Information Act handling plan — Special Operational Information (SOI) register, marking and handling matrix, transmission channels, compartments and need-to-know, destruction and sanitisation, CSIS Act §16 and §19 coordination, RCMP NSP liaison, breach respo
Ready to connect★ 72
- View details
au-apra-cps-234-expertSkillSecurity
APRA CPS 234 expert for Australian prudential information security. Reference-depth framework plugin with scope determination, evidence checklist, and SCF-backed assessment guidance.
Ready to connect★ 72
What is a skill?
A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.
52,524 of the 52,958 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.
Install one and every AI you use gets it
Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.
Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.