Skills.

Give your AI a better way to work.

A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.

Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.

Category: Security

1,738 results · page 39 of 58

  • audit-liquidation-dosSkillSecurity

    Audits Solidity liquidation mechanisms for denial of service vulnerabilities including unbounded loops over positions causing out-of-gas reverts, data structure corruption preventing liquidation, front-running to block liquidation via nonce changes or self-liquidation, pending withdrawals forcing re

    Ready to connect★ 73

    github.com/fdu-ins/insurance-skills71 stars

    View details
  • china-piplSkillSecurity

    Guides compliance with China''s Personal Information Protection Law (PIPL, effective 1 November 2021). Covers consent requirements, cross-border transfer mechanisms (CAC security assessment, standard contracts, certification), separate consent triggers, and critical information infrastructure obliga

    Ready to connect★ 72

    github.com/thomasmoreai/legal-skills-open73 stars

    View details
  • cyber-risk-modelingSkillSecurity

    Quantify cyber risk using FAIR methodology with Monte Carlo simulation, assess control effectiveness against NIST CSF/CIS/ISO 27001 frameworks, evaluate risk appetite alignment, and analyze cyber insurance coverage adequacy. Covers threat landscape mapping, asset valuation, loss event frequency and

    Ready to connect★ 73

    github.com/fdu-ins/insurance-skills71 stars

    View details
  • Generate Risk Register Vulnerability AnalysisSkillSecurity

    Analyzes and describes vulnerabilities for specific assets and threats within an insurance company risk register context. The output must be highly professional, eloquent, and grammatically impressive, utilizing labelled headings and subheadings.

    Ready to connect★ 73

    github.com/fdu-ins/insurance-skills71 stars

    View details
  • sdlc-code-reviewSkillSecurity

    Language-agnostic workflow for code reviews and security audits using a Two-Axis (Standards vs Spec) approach against Clean Code/SOLID principles, generating formal refactoring plans.

    Ready to connect★ 73

    github.com/gulajavaministudio/awesome-copilot-id73 stars

    View details
  • sweepSkillSecurity

    Scan codebase for debug artifacts and code quality issues; optionally auto-fix safe patterns. Use when: before committing, during PR review, or periodic codebase cleanup. Not for: structural code improvement — use /refactor; security-specific scanning — use /scan. Keywords: sweep, debug cleanup, con

    Ready to connect★ 73

    github.com/asiaostrich/universal-dev-standards72 stars

    View details
  • tdd-code-reviewSkillSecurity

    Language-agnostic workflow for code reviews and security audits using a Two-Axis (Standards vs Spec) approach against Clean Code/SOLID principles, generating formal refactoring plans.

    Ready to connect★ 73

    github.com/gulajavaministudio/awesome-copilot-id73 stars

    View details
  • ubsSkillSecurity

    Run Ultimate Bug Scanner (UBS) for code review. Use when reviewing code, checking for bugs, scanning for security issues, validating AI-generated code, or pre-commit quality checks.

    Ready to connect★ 73

    github.com/dicklesworthstone/agent_flywheel_clawdbot_skills_and_integrations73 stars

    View details
  • wechat-query-realname-infoSkillSecurity

    Execution skill for retrieving WeChat real-name authentication information. By means of a court assistance letter or a lawyer with an investigation order, submit a request to Tenpay Payment Technology Co., Ltd. to obtain the real-name authentication information of a target WeChat account, acquiring

    Ready to connect★ 72

    github.com/thomasmoreai/legal-skills-open73 stars

    View details
  • agent-reachSkillSecurity

    Load when a task needs read-only internet research or content retrieval through an already installed Agent Reach CLI; diagnose available backends first, never install, upgrade, authenticate, configure, or copy credentials on the user's behalf.

    Ready to connect★ 72

    github.com/jasonxzwen/harness-hub72 stars

    View details
  • dotnet-jwt-authenticationSkillSecurity

    Configures JWT Bearer authentication for .NET APIs. Includes token generation, validation, refresh tokens, and user context extraction from claims.

    Ready to connect★ 72

    github.com/ronnythedev/dotnet-clean-architecture-skills72 stars

    View details
  • 5g-6g-telecom-attack-advancedSkillSecurity

    Advanced 5G/6G telecom attacks covering 5G Core (SBA) exploitation, IMSI catcher evolution (5G Stingray), SIP/Diameter protocol attacks, Open RAN vulnerabilities, network slicing abuse, and early 6G research vectors (THz comms, AI-native air interface).

    Ready to connect★ 71

    github.com/brucesongs/kali-claw67 stars

    View details
  • ad-cs-abuseSkillSecurity

    Active Directory Certificate Services (AD CS) abuse — ESC1-ESC15 attack patterns, PKINIT, PetitPotam to AD CS to Domain Admin chains, CVE-2022-26923 (Certifried), Shadow Credentials, Golden Certificate, certificate template ACL abuse, NTLM relay to web enrollment.

    Ready to connect★ 71

    github.com/brucesongs/kali-claw67 stars

    View details
  • agentic-pentestSkillSecurity

    LLM-driven autonomous penetration testing framework operations covering PentestGPT, HexStrike AI, Viper, PentestAgent, AI-Infra-Guard, AutoPWN, and custom agent harness patterns — including reasoning chain orchestration, tool delegation, context window management, output validation, multi-agent pent

    Ready to connect★ 71

    github.com/brucesongs/kali-claw67 stars

    View details
  • ai-agent-supply-chain-attackSkillSecurity

    AI/ML supply chain attacks — model poisoning, Pickle RCE, Hugging Face / Ollama registry compromise, LangChain plugin backdoors, OpenClaw / ClawHub ecosystem threats. Distinguishes from ci-cd-supply-chain-attack by focusing on model weights, training data, and serialization formats. Anchored by the

    Ready to connect★ 71

    github.com/brucesongs/kali-claw67 stars

    View details
  • ai-fuzzingSkillSecurity

    AI-assisted fuzzing for automated vulnerability discovery. Coverage-guided fuzzing engines, AI-driven seed generation, intelligent mutation strategies, and systematic crash triage.

    Ready to connect★ 71

    github.com/brucesongs/kali-claw67 stars

    View details
  • automotive-vehicle-securitySkillSecurity

    CAN/CAN-FD bus analysis, UDS diagnostics, IVI pentest, OBD-II exploitation, key fob replay/relay attacks, GNSS spoofing, EV charging station (ISO 15118), and connected vehicle red team operations.

    Ready to connect★ 71

    github.com/brucesongs/kali-claw67 stars

    View details
  • binary-reverseSkillSecurity

    Binary reverse engineering covers the complete chain from static analysis, dynamic debugging, to vulnerability discovery, exploit development, and malware analysis.

    Ready to connect★ 71

    github.com/brucesongs/kali-claw67 stars

    View details
  • blue-reconSkillSecurity

    Audit existing security controls and detection coverage — find gaps against MITRE ATT&CK. Use when asked to "audit our detection coverage", "where are our security control gaps", or "check our MITRE coverage".

    Ready to connect★ 71

    github.com/tonone-ai/tonone71 stars

    View details
  • chain-reconSkillSecurity

    Audit existing dependency security — find unscanned packages, license violations, and SBOM gaps. Use when asked to "audit our dependencies", "do we have an SBOM", or "find license violations".

    Ready to connect★ 71

    github.com/tonone-ai/tonone71 stars

    View details
  • chain-scanSkillSecurity

    Design a dependency scanning program — CVE detection, license checks, and CI gates. Use when asked to "scan our dependencies", "set up CVE detection", or "add a dependency CI gate".

    Ready to connect★ 71

    github.com/tonone-ai/tonone71 stars

    View details
  • ci-cd-supply-chain-attackSkillSecurity

    CI/CD pipeline and software supply chain compromise covering Jenkins (script console, Jenkinsfile injection, shared library abuse, CVE-2024-23897 args4j), GitLab CI/CD (runner abuse, .gitlab-ci.yml injection, self-hosted runner takeover, CVE-2022-1162, OmniAuth CVE-2024-9653), GitHub Actions (self-h

    Ready to connect★ 71

    github.com/brucesongs/kali-claw67 stars

    View details
  • clerk-androidSkillSecurity

    Implement Clerk authentication for native Android apps using Kotlin and

    Ready to connect★ 71

    github.com/clerk/skills70 stars

    View details
  • clerk-expoSkillSecurity

    Add Clerk authentication to Expo and React Native apps using @clerk/expo.

    Ready to connect★ 71

    github.com/clerk/skills70 stars

    View details
  • clerk-swiftSkillSecurity

    Implement Clerk authentication for native Swift and iOS apps using ClerkKit

    Ready to connect★ 71

    github.com/clerk/skills70 stars

    View details
  • cloud-native-vuln-researchSkillSecurity

    CVE research methodology, PoC reproduction, patch gap analysis, and exploit chain composition across container/k8s/cloud-native surfaces; SBOM-driven vuln management and nuclei template authoring.

    Ready to connect★ 71

    github.com/brucesongs/kali-claw67 stars

    View details
  • cms-framework-attackSkillSecurity

    Targeted security assessment of Content Management Systems (WordPress, Joomla, Drupal) using specialized scanners and exploit techniques.

    Ready to connect★ 71

    github.com/brucesongs/kali-claw67 stars

    View details
  • codebase-onboardingSkillSecurity

    Rapidly acquire a mental model of any unfamiliar codebase — from a 500-line script to a 100M+ line monorepo. This skill transforms raw code into structured intelligence: architecture maps, entry points, data flows, security surfaces, and onboarding confidence scores.

    Ready to connect★ 71

    github.com/brucesongs/kali-claw67 stars

    View details
  • concurrency-exploitationSkillSecurity

    Concurrency exploitation covers race condition vulnerabilities including TOCTOU, signal handler races, thread synchronization bypasses, and timing attacks.

    Ready to connect★ 71

    github.com/brucesongs/kali-claw67 stars

    View details
  • config-hardenerSkillSecurity

    Audit and harden your OpenClaw configuration. Checks AGENTS.md, gateway settings, sandbox config, and permission

    Ready to connect★ 71

    github.com/useai-pro/openclaw-skills-security71 stars

    View details

What is a skill?

A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.

52,524 of the 52,958 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.

Install one and every AI you use gets it

Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.

Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.

See how to connect your AI