Skills.

Give your AI a better way to work.

A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.

Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.

Category: Security

1,738 results · page 42 of 58

  • scan-issuesSkillSecurity

    Passive codebase scan — find potential bugs, anti-patterns, security issues. Spawns subagents if available.

    Ready to connect★ 64

    github.com/neuron-mr-white/unipi63 stars

    View details
  • tauri-expertSkillSecurity

    Expert skill for Tauri (v2) development, Rust backend, IPC, and security / Panduan ahli untuk pengembangan Tauri v2, Rust backend, IPC, dan keamanan.

    Ready to connect★ 50

    github.com/roedyrustam/vibes-plug64 stars

    View details
  • zero-trust-secret-vaultSkillSecurity

    Expert guide for Zero-Trust Secret Management (Infisical, HashiCorp Vault, Doppler), automated API key rotation, and environment security / Panduan ahli manajemen rahasia Zero-Trust, rotasi kunci API, dan keamanan variabel lingkungan.

    Ready to connect★ 50

    github.com/roedyrustam/vibes-plug64 stars

    View details
  • access-reviewSkillSecurity

    Conducts access review and entitlement audit against CIS Controls v8 (Controls 5, 6) and NIST SP 800-53 AC family. Auto-invoked when reviewing entitlement certifications, orphaned accounts, role explosion, segregation of duties violations, or quarterly access recertification campaigns. Produces find

    Ready to connect★ 63

    github.com/unitoneai/securityskills63 stars

    View details
  • agent-protocol-interleaveSkillSecurity

    Bridge layer connecting the emerging agentic coordination protocol ecosystem (MCP, A2A, ANP, AGNTCY, AITP, LMOS, AAIF) to the plurigrid/asi skill graph. Maps protocol-level identity mechanisms (W3C DID, OAuth 2.1, IPSIE, Entra Agent ID, Agent Cards, passport.gay) into GF(3)-classified skills. The ce

    Ready to connect★ 63

    github.com/plurigrid/asi61 stars

    View details
  • agent-securitySkillSecurity

    Reviews AI agent architectures for security risks including permission model design, least-privilege enforcement, human-in-the-loop gate placement, blast radius containment, audit trail completeness, rollback capability, and multi-agent trust boundaries. Auto-invoked when reviewing agentic AI system

    Ready to connect★ 63

    github.com/unitoneai/securityskills63 stars

    View details
  • ai-data-privacySkillSecurity

    Reviews AI/ML systems for data privacy and governance risks including training data privacy, PII exposure in prompts and completions, data retention policies, model memorization risks, and regulatory compliance. Auto-invoked when reviewing systems that process personal data through LLMs, train or fi

    Ready to connect★ 63

    github.com/unitoneai/securityskills63 stars

    View details
  • appsec-engineerSkillSecurity

    Application Security Engineer role bundle for security design, testing, and code review of applications. Orchestrates new application reviews, PR security reviews, API security assessments, and AI feature security reviews. Auto-invoked when the user needs help with application threat modeling, secur

    Ready to connect★ 63

    github.com/unitoneai/securityskills63 stars

    View details
  • atherisSkillSecurity

    Python fuzzing with Atheris for discovering vulnerabilities in Python code.

    Ready to connect★ 63

    github.com/plurigrid/asi61 stars

    View details
  • axiom-app-compositionSkillSecurity

    Use when structuring app entry points, managing authentication flows, switching root views, handling scene lifecycle, or asking 'how do I structure my @main', 'where does auth state live', 'how do I prevent screen flicker on launch', 'when should I modularize' - app-level composition patterns for iO

    Ready to connect★ 63

    github.com/comeonoliver/skillshub63 stars

    View details
  • axiom-app-intents-refSkillSecurity

    Use when integrating App Intents for Siri, Apple Intelligence, Shortcuts, Spotlight, or system experiences - covers AppIntent, AppEntity, parameter handling, entity queries, background execution, authentication, and debugging common integration issues for iOS 16+

    Ready to connect★ 63

    github.com/comeonoliver/skillshub63 stars

    View details
  • bci-colored-operadSkillSecurity

    Brain-Computer Interface with colored operad security boundaries. Maximally isolated EEG/neural data processing via VM→Container→Process enclosure with GF(3) conservation for Agent-O-Rama neural pathways.

    Ready to connect★ 63

    github.com/plurigrid/asi61 stars

    View details
  • cve-triageSkillSecurity

    Triages and prioritizes CVEs using CVSS 4.0, SSVC 2.1 decision trees, EPSS scores, and CISA KEV catalog cross-referencing. Auto-invoked when a CVE ID is mentioned, vulnerability scan results are shared, or the user asks "should we patch this?" Produces a prioritized remediation recommendation with S

    Ready to connect★ 63

    github.com/unitoneai/securityskills63 stars

    View details
  • dast-configSkillSecurity

    Reviews DAST tool configurations against OWASP Top 10:2021 and OWASP Testing Guide v4.2. Auto-invoked when reviewing OWASP ZAP configurations, DAST CI/CD integration, scan policies, or authenticated scanning setups. Produces a DAST maturity assessment covering scan policy configuration, active vs pa

    Ready to connect★ 63

    github.com/unitoneai/securityskills63 stars

    View details
  • firewall-reviewSkillSecurity

    Performs a structured firewall rule base audit against CIS Controls v8 (Controls 4.4 and 4.5) and NIST SP 800-41 Rev 1 (Guidelines on Firewalls and Firewall Policy). Auto-invoked when reviewing firewall configurations, ACLs, or network security policies. Produces a prioritized findings report coveri

    Ready to connect★ 63

    github.com/unitoneai/securityskills63 stars

    View details
  • forensics-checklistSkillSecurity

    Guides digital forensic evidence collection following NIST SP 800-86 and RFC 3227 order of volatility. Auto-invoked when the user needs to collect forensic evidence, preserve chain of custody, capture volatile data, create disk images, or handle cloud forensics. Produces an evidence collection plan

    Ready to connect★ 63

    github.com/unitoneai/securityskills63 stars

    View details
  • hipaa-reviewSkillSecurity

    Performs a HIPAA Security Rule compliance review against all Administrative, Physical, and Technical Safeguards defined in 45 CFR Part 164, Subpart C. Auto-invoked when discussing healthcare data security, ePHI protection, HIPAA audit readiness, or business associate compliance. Evaluates required a

    Ready to connect★ 63

    github.com/unitoneai/securityskills63 stars

    View details
  • iam-reviewSkillSecurity

    Reviews identity and access management configurations against NIST SP 800-63B, NIST SP 800-207 zero trust principles, and CIS Controls v8. Auto-invoked when reviewing IAM policies, role definitions, user provisioning workflows, or when asked to assess identity security posture. Produces findings on

    Ready to connect★ 63

    github.com/unitoneai/securityskills63 stars

    View details
  • iso27001-gapSkillSecurity

    Performs an ISO 27001:2022 gap analysis against the full ISMS requirements (Clauses 4-10) and all 93 Annex A controls reorganized into four themes. Auto-invoked when discussing ISO 27001 certification readiness, ISMS implementation, or Statement of Applicability development. Identifies control gaps,

    Ready to connect★ 63

    github.com/unitoneai/securityskills63 stars

    View details
  • laravel-tddSkillSecurity

    Laravel testing strategies with PHPUnit, Pest, model factories, HTTP tests, Sanctum authentication testing, mocking, and coverage.

    Ready to connect★ 63

    github.com/dekaprayoga/aurixagent62 stars

    View details
  • llm-trading-agent-securitySkillSecurity

    Security patterns for autonomous trading agents with wallet or transaction authority. Covers prompt injection, spend limits, pre-send simulation, circuit breakers, MEV protection, and key handling.

    Ready to connect★ 63

    github.com/dekaprayoga/aurixagent62 stars

    View details
  • model-supply-chainSkillSecurity

    Reviews AI/ML model supply chains for security risks including model provenance verification, training data lineage, fine-tuning pipeline integrity, inference dependency review, and backdoor detection. Auto-invoked when reviewing systems that download pre-trained models, fine-tune foundation models,

    Ready to connect★ 63

    github.com/unitoneai/securityskills63 stars

    View details
  • nist-csf-assessmentSkillSecurity

    Performs a NIST Cybersecurity Framework 2.0 assessment across all six functions (Govern, Identify, Protect, Detect, Respond, Recover) and their categories and subcategories. Auto-invoked when discussing cybersecurity maturity, risk posture evaluation, or NIST CSF alignment. Develops current and targ

    Ready to connect★ 63

    github.com/unitoneai/securityskills63 stars

    View details
  • owasp-top-10-webSkillSecurity

    Reviews web applications against the OWASP Top 10:2021 vulnerability categories. Auto-invoked when reviewing web application code, server configurations, or when a user asks for a general security review of a web application. Produces structured findings mapped to A01-A10 with CWE references, severi

    Ready to connect★ 63

    github.com/unitoneai/securityskills63 stars

    View details
  • patch-prioritizationSkillSecurity

    Prioritizes patches and manages remediation SLAs using SSVC 2.1 decision outcomes, EPSS v3 trend analysis, and CISA KEV catalog cross-referencing. Covers SLA frameworks by severity tier, compensating controls assessment, patch window scheduling, risk acceptance criteria, and exception management. Au

    Ready to connect★ 63

    github.com/unitoneai/securityskills63 stars

    View details
  • pci-dss-reviewSkillSecurity

    Performs a PCI DSS v4.0 compliance review across all 12 requirements and their sub-requirements. Auto-invoked when discussing payment card security, cardholder data protection, PCI compliance validation, or merchant/service provider assessment. Covers scope reduction strategies, SAQ vs ROC determina

    Ready to connect★ 63

    github.com/unitoneai/securityskills63 stars

    View details
  • pipeline-securitySkillSecurity

    Reviews CI/CD pipeline configurations against SLSA v1.0 build levels and OWASP Top 10 CI/CD Security Risks. Auto-invoked when reviewing GitHub Actions workflows, GitLab CI configs, Jenkins pipelines, or when discussing supply chain security. Produces a pipeline security assessment with SLSA level de

    Ready to connect★ 63

    github.com/unitoneai/securityskills63 stars

    View details
  • privileged-accessSkillSecurity

    Performs a Privileged Access Management (PAM) review against CIS Controls v8 (Controls 5.4, 6.5) and NIST SP 800-53 AC-6 (Least Privilege). Evaluates PAM tool effectiveness, just-in-time access patterns, break-glass procedures, session recording, and credential vaulting. Produces findings with sever

    Ready to connect★ 63

    github.com/unitoneai/securityskills63 stars

    View details
  • prompt-injectionSkillSecurity

    Tests LLM applications for prompt injection vulnerabilities per OWASP LLM01:2025. Covers direct injection (user input manipulating model behavior) and indirect injection (external content containing hidden instructions). Auto-invoked when reviewing LLM applications that process external content, bui

    Ready to connect★ 63

    github.com/unitoneai/securityskills63 stars

    View details
  • rbac-designSkillSecurity

    Guides the design and assessment of RBAC and ABAC authorization models against the NIST RBAC model (Sandhu et al.) and NIST SP 800-162 (ABAC guide). Auto-invoked when designing role hierarchies, evaluating permission boundaries, implementing ABAC policy patterns, performing role mining, or preventin

    Ready to connect★ 63

    github.com/unitoneai/securityskills63 stars

    View details

What is a skill?

A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.

52,524 of the 52,958 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.

Install one and every AI you use gets it

Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.

Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.

See how to connect your AI