Skills.
Give your AI a better way to work.
A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.
Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.
Category: Security
1,738 results · page 40 of 58
- View details
cps-attackSkillSecurity
Cyber-Physical Systems (CPS) attacks — PLCs (Siemens S7, Rockwell ControlLogix, Schneider Modicon, Mitsubishi MELSEC), ICS protocols (Modbus, DNP3, Profinet, EtherNet/IP, IEC 61850, OPC UA), HMIs, SCADA historians, OT-to-IT pivot, SIS bypass. Distinct from scada-ics-security (broader ICS overview) —
Ready to connect★ 71
- View details
credential-scannerSkillSecurity
Scan your project for exposed credentials, API keys, and secrets before running OpenClaw skills. Prevents accidental
Ready to connect★ 71
- View details
exploit-developmentSkillSecurity
Exploit development covers the full chain from vulnerability discovery through crash analysis to working exploit code, spanning buffer overflows, ROP chains, format string bugs, and shellcode injection across x86 and ARM architectures.
Ready to connect★ 71
- View details
gitops-securitySkillSecurity
Attacks against GitOps control planes (Argo CD, FluxCD, Jenkins X, Tekton, Fleet, Rancher) — repo impersonation, manifest tampering, RBAC bypass, sync-wave abuse, secret management compromise (Sealed Secrets / SOPS / External Secrets / Vault), cluster privilege escalation via Application/CRDs, and p
Ready to connect★ 71
- View details
hardware-securitySkillSecurity
Lets your agent guide hardware security research like finding UART/JTAG debug pads and analyzing firmware offline.
Ready to connect★ 71
- View details
hypervisor-introspectionSkillSecurity
Hypervisor introspection (VMI) and virtualization escape attacks — VMware ESXi, Hyper-V, KVM/QEMU, Xen, Proxmox, VirtualBox, LibVMI, DRAKVUF, VENOM CVE-2015-3456, hardware-assisted VT-x/EPT/AMD-V
Ready to connect★ 71
- View details
insecure-designSkillSecurity
Insecure Design (OWASP A06:2025) focuses on security flaws in system architecture and design phases, rather than code implementation-level bugs.
Ready to connect★ 71
- View details
macos-securitySkillSecurity
macOS red team and security assessment — SIP/TCC bypass, Endpoint Security framework, Apple Silicon/T2/M-series attacks, Mach-O analysis, Keychain extraction, MDM bypass, LaunchAgents/Daemons persistence, and macOS-native malware analysis.
Ready to connect★ 71
- View details
malware-analysis-advancedSkillSecurity
Advanced malware analysis covering unpacking (UPX, VMProtect, Themida, Enigma, custom packers), sandbox-evasion detection (anti-VM, anti-debug, anti-analysis), rootkit analysis (user-mode, kernel-mode, bootkits, UEFI), YARA rule authoring and optimization, and IDA Pro / Ghidra / Binary Ninja workflo
Ready to connect★ 71
- View details
mcp-server-patternsSkillSecurity
Building and security-testing MCP (Model Context Protocol) servers for Kali Linux security tools.
Ready to connect★ 71
- View details
mobile-securitySkillSecurity
Mobile security covers the complete attack/defense chain of Android/iOS application security testing, APK/IPA reverse engineering, runtime manipulation, certificate pinning bypass, and mobile data protection.
Ready to connect★ 71
- View details
network-pentestSkillSecurity
Network penetration testing covering the full attack chain from reconnaissance, port scanning, and service fingerprinting through vulnerability assessment, exploitation, traffic sniffing, and MITM attacks.
Ready to connect★ 71
- View details
open-banking-attackSkillSecurity
Open Banking / PSD2 / Open Finance attacks — FAPI (Financial-grade API), OpenID Connect for Financial APIs, OAuth2 PKCE, Strong Customer Authentication (SCA) bypass, AIS/PIS/CBPII API abuse, payment redirection, consent manipulation. Covers UK Open Banking, US FDX, Brazil Open Finance, India Account
Ready to connect★ 71
- View details
output-sanitizerSkillSecurity
Sanitize OpenClaw agent output before display. Strips leaked credentials, PII, internal paths, and sensitive
Ready to connect★ 71
- View details
pam-privilege-attackSkillSecurity
Privileged Access Management (PAM) vendor abuse — CyberArk PVWA/PSM/EPV/AIM/CFE, BeyondTrust PRA/Password Safe/Identity Security Insights, Delinea Secret Server/Privilege Manager, One Identity Safeguard, ManageEngine Password Manager Pro, WALLIX Bastion, Devolutions Server, Xton Core. Covers PVWA au
Ready to connect★ 71
- View details
patch-to-poc-pipelineSkillSecurity
The end-to-end patch-diff vulnerability reproduction workflow — patch analysis (read diff, identify protective pattern, hypothesize bug class), source or binary-only code path walking (Ghidra + BinDiff), PoC generation (manual craft OR AFL++/libFuzzer harness with ASan/UBSan), CyberGym-style differe
Ready to connect★ 71
- View details
payment-securitySkillSecurity
Payment systems security — PCI-DSS compliance testing, payment API security (Stripe/Adyen/PayPal), EMV chip/PIN, 3-D Secure, mobile wallets (Apple Pay/Google Pay), and fraud system assessment.
Ready to connect★ 71
- View details
pentest-reportingSkillSecurity
Initialize Dradis for collaborative report authoring and Faraday for vulnerability correlation before testing begins.
Ready to connect★ 71
- View details
permission-auditorSkillSecurity
Analyze OpenClaw skill permissions and explain exactly what each permission allows. Identifies over-privileged
Ready to connect★ 71
- View details
prompt-guardSkillSecurity
Detect and neutralize prompt injection attacks in OpenClaw skill content, user inputs, and external data sources.
Ready to connect★ 71
- View details
protocol-state-exploitationSkillSecurity
Protocol state exploitation targets vulnerabilities in network protocol state machines including SSH/TLS/HTTP2/DNS, covering illegal state transitions, stateful fuzzing, and protocol-level race conditions.
Ready to connect★ 71
- View details
satellite-leo-securitySkillSecurity
Satellite and LEO communication security — Starlink, Kuiper, OneWeb, Iridium, Inmarsat, Viasat KA-SAT, HughesNet, DVB-S/S2, VSAT (iDirect/Hughes), GNSS receiver attacks, AcidRain wiper (Viasat 2022)
Ready to connect★ 71
- View details
scada-ics-securitySkillSecurity
SCADA/ICS security assessment covering industrial control system protocols including Modbus TCP, S7comm (Siemens), DNP3, EtherNet/IP (CIP), OPC UA, BACnet, and GOOSE.
Ready to connect★ 71
- View details
security-bounty-hunterSkillSecurity
Hunt for exploitable, bounty-worthy security issues in target systems. Focuses on remotely reachable vulnerabilities that qualify for real reports and responsible disclosure, not broad best-practices reviews or theoretical findings.
Ready to connect★ 71
- View details
setup-auditorSkillSecurity
'Audit your OpenClaw environment for credential leaks, unsafe defaults, and missing sandbox configuration. Wizard-style:
Ready to connect★ 71
- View details
skill-auditorSkillSecurity
Comprehensive security auditor for OpenClaw skills. Checks for typosquatting, dangerous permissions, prompt injection,
Ready to connect★ 71
- View details
social-engineeringSkillSecurity
Social engineering is the art of exploiting human psychological weaknesses rather than technical vulnerabilities to execute attacks. Attack vectors encompass Phishing, Pretexting, Baiting, Tailgating, Vishing, and other techniques.
Ready to connect★ 71
- View details
terminal-opsSkillSecurity
Evidence-first execution workflow for running security commands, inspecting system state, debugging tool failures, and making verified changes. This skill enforces a disciplined approach: inspect before acting, keep changes narrow, and report exact execution state.
Ready to connect★ 71
- View details
threat-intel-platform-attackSkillSecurity
Attacking threat intelligence platforms (MISP, OpenCTI, Anomali ThreatStream, ThreatQuotient, ThreatConnect, IBM Threat Intel, Palo Alto AutoFocus, Mandiant Advantage). Covers platform CVEs (MISP CVE-2022-29527, OpenCTI vulnerabilities), API abuse, sharing-group trust abuse, false-positive IOC injec
Ready to connect★ 71
- View details
tool-masterySkillSecurity
Verification and assessment of practical proficiency with Kali Linux security tools. Covers tool classification, proficiency levels, verification methods, and combination strategies across the 518-tool Kali arsenal.
Ready to connect★ 71
What is a skill?
A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.
52,524 of the 52,958 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.
Install one and every AI you use gets it
Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.
Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.