Skills.
Give your AI a better way to work.
A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.
Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.
Category: Security
1,738 results · page 39 of 58
- View details
audit-liquidation-dosSkillSecurity
Audits Solidity liquidation mechanisms for denial of service vulnerabilities including unbounded loops over positions causing out-of-gas reverts, data structure corruption preventing liquidation, front-running to block liquidation via nonce changes or self-liquidation, pending withdrawals forcing re
Ready to connect★ 73
- View details
china-piplSkillSecurity
Guides compliance with China''s Personal Information Protection Law (PIPL, effective 1 November 2021). Covers consent requirements, cross-border transfer mechanisms (CAC security assessment, standard contracts, certification), separate consent triggers, and critical information infrastructure obliga
Ready to connect★ 72
- View details
cyber-risk-modelingSkillSecurity
Quantify cyber risk using FAIR methodology with Monte Carlo simulation, assess control effectiveness against NIST CSF/CIS/ISO 27001 frameworks, evaluate risk appetite alignment, and analyze cyber insurance coverage adequacy. Covers threat landscape mapping, asset valuation, loss event frequency and
Ready to connect★ 73
- View details
Generate Risk Register Vulnerability AnalysisSkillSecurity
Analyzes and describes vulnerabilities for specific assets and threats within an insurance company risk register context. The output must be highly professional, eloquent, and grammatically impressive, utilizing labelled headings and subheadings.
Ready to connect★ 73
- View details
sdlc-code-reviewSkillSecurity
Language-agnostic workflow for code reviews and security audits using a Two-Axis (Standards vs Spec) approach against Clean Code/SOLID principles, generating formal refactoring plans.
Ready to connect★ 73
- View details
sweepSkillSecurity
Scan codebase for debug artifacts and code quality issues; optionally auto-fix safe patterns. Use when: before committing, during PR review, or periodic codebase cleanup. Not for: structural code improvement — use /refactor; security-specific scanning — use /scan. Keywords: sweep, debug cleanup, con
Ready to connect★ 73
- View details
tdd-code-reviewSkillSecurity
Language-agnostic workflow for code reviews and security audits using a Two-Axis (Standards vs Spec) approach against Clean Code/SOLID principles, generating formal refactoring plans.
Ready to connect★ 73
- View details
ubsSkillSecurity
Run Ultimate Bug Scanner (UBS) for code review. Use when reviewing code, checking for bugs, scanning for security issues, validating AI-generated code, or pre-commit quality checks.
Ready to connect★ 73
- View details
wechat-query-realname-infoSkillSecurity
Execution skill for retrieving WeChat real-name authentication information. By means of a court assistance letter or a lawyer with an investigation order, submit a request to Tenpay Payment Technology Co., Ltd. to obtain the real-name authentication information of a target WeChat account, acquiring
Ready to connect★ 72
- View details
agent-reachSkillSecurity
Load when a task needs read-only internet research or content retrieval through an already installed Agent Reach CLI; diagnose available backends first, never install, upgrade, authenticate, configure, or copy credentials on the user's behalf.
Ready to connect★ 72
- View details
dotnet-jwt-authenticationSkillSecurity
Configures JWT Bearer authentication for .NET APIs. Includes token generation, validation, refresh tokens, and user context extraction from claims.
Ready to connect★ 72
- View details
5g-6g-telecom-attack-advancedSkillSecurity
Advanced 5G/6G telecom attacks covering 5G Core (SBA) exploitation, IMSI catcher evolution (5G Stingray), SIP/Diameter protocol attacks, Open RAN vulnerabilities, network slicing abuse, and early 6G research vectors (THz comms, AI-native air interface).
Ready to connect★ 71
- View details
ad-cs-abuseSkillSecurity
Active Directory Certificate Services (AD CS) abuse — ESC1-ESC15 attack patterns, PKINIT, PetitPotam to AD CS to Domain Admin chains, CVE-2022-26923 (Certifried), Shadow Credentials, Golden Certificate, certificate template ACL abuse, NTLM relay to web enrollment.
Ready to connect★ 71
- View details
agentic-pentestSkillSecurity
LLM-driven autonomous penetration testing framework operations covering PentestGPT, HexStrike AI, Viper, PentestAgent, AI-Infra-Guard, AutoPWN, and custom agent harness patterns — including reasoning chain orchestration, tool delegation, context window management, output validation, multi-agent pent
Ready to connect★ 71
- View details
ai-agent-supply-chain-attackSkillSecurity
AI/ML supply chain attacks — model poisoning, Pickle RCE, Hugging Face / Ollama registry compromise, LangChain plugin backdoors, OpenClaw / ClawHub ecosystem threats. Distinguishes from ci-cd-supply-chain-attack by focusing on model weights, training data, and serialization formats. Anchored by the
Ready to connect★ 71
- View details
ai-fuzzingSkillSecurity
AI-assisted fuzzing for automated vulnerability discovery. Coverage-guided fuzzing engines, AI-driven seed generation, intelligent mutation strategies, and systematic crash triage.
Ready to connect★ 71
- View details
automotive-vehicle-securitySkillSecurity
CAN/CAN-FD bus analysis, UDS diagnostics, IVI pentest, OBD-II exploitation, key fob replay/relay attacks, GNSS spoofing, EV charging station (ISO 15118), and connected vehicle red team operations.
Ready to connect★ 71
- View details
binary-reverseSkillSecurity
Binary reverse engineering covers the complete chain from static analysis, dynamic debugging, to vulnerability discovery, exploit development, and malware analysis.
Ready to connect★ 71
- View details
blue-reconSkillSecurity
Audit existing security controls and detection coverage — find gaps against MITRE ATT&CK. Use when asked to "audit our detection coverage", "where are our security control gaps", or "check our MITRE coverage".
Ready to connect★ 71
- View details
chain-reconSkillSecurity
Audit existing dependency security — find unscanned packages, license violations, and SBOM gaps. Use when asked to "audit our dependencies", "do we have an SBOM", or "find license violations".
Ready to connect★ 71
- View details
chain-scanSkillSecurity
Design a dependency scanning program — CVE detection, license checks, and CI gates. Use when asked to "scan our dependencies", "set up CVE detection", or "add a dependency CI gate".
Ready to connect★ 71
- View details
ci-cd-supply-chain-attackSkillSecurity
CI/CD pipeline and software supply chain compromise covering Jenkins (script console, Jenkinsfile injection, shared library abuse, CVE-2024-23897 args4j), GitLab CI/CD (runner abuse, .gitlab-ci.yml injection, self-hosted runner takeover, CVE-2022-1162, OmniAuth CVE-2024-9653), GitHub Actions (self-h
Ready to connect★ 71
- View details
clerk-androidSkillSecurity
Implement Clerk authentication for native Android apps using Kotlin and
Ready to connect★ 71
- View details
clerk-expoSkillSecurity
Add Clerk authentication to Expo and React Native apps using @clerk/expo.
Ready to connect★ 71
- View details
clerk-swiftSkillSecurity
Implement Clerk authentication for native Swift and iOS apps using ClerkKit
Ready to connect★ 71
- View details
cloud-native-vuln-researchSkillSecurity
CVE research methodology, PoC reproduction, patch gap analysis, and exploit chain composition across container/k8s/cloud-native surfaces; SBOM-driven vuln management and nuclei template authoring.
Ready to connect★ 71
- View details
cms-framework-attackSkillSecurity
Targeted security assessment of Content Management Systems (WordPress, Joomla, Drupal) using specialized scanners and exploit techniques.
Ready to connect★ 71
- View details
codebase-onboardingSkillSecurity
Rapidly acquire a mental model of any unfamiliar codebase — from a 500-line script to a 100M+ line monorepo. This skill transforms raw code into structured intelligence: architecture maps, entry points, data flows, security surfaces, and onboarding confidence scores.
Ready to connect★ 71
- View details
concurrency-exploitationSkillSecurity
Concurrency exploitation covers race condition vulnerabilities including TOCTOU, signal handler races, thread synchronization bypasses, and timing attacks.
Ready to connect★ 71
- View details
config-hardenerSkillSecurity
Audit and harden your OpenClaw configuration. Checks AGENTS.md, gateway settings, sandbox config, and permission
Ready to connect★ 71
What is a skill?
A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.
52,524 of the 52,958 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.
Install one and every AI you use gets it
Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.
Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.