Skills.

Give your AI a better way to work.

A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.

Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.

Category: Security

1,738 results · page 43 of 58

  • sast-configSkillSecurity

    Reviews and tunes SAST tool configurations against OWASP ASVS 4.0.3 and CWE Top 25. Auto-invoked when reviewing Semgrep rules, CodeQL queries, SAST CI integration, or false positive triage workflows. Produces a SAST maturity assessment covering rule authoring, severity tuning, custom rule developmen

    Ready to connect★ 63

    github.com/unitoneai/securityskills63 stars

    View details
  • scanner-tuningSkillSecurity

    Tunes vulnerability scanners to reduce false positives, optimize scan policies, and improve result accuracy. Covers false positive identification patterns, scan policy configuration, authenticated vs unauthenticated scanning tradeoffs, severity override criteria, plugin/check selection, scan schedul

    Ready to connect★ 63

    github.com/unitoneai/securityskills63 stars

    View details
  • secure-code-reviewSkillSecurity

    Performs a structured security code review against OWASP ASVS 4.0.3 verification requirements and CWE Top 25. Auto-invoked on pull request reviews, when code touching authentication, authorization, cryptography, or input handling is shared. Produces findings mapped to ASVS controls and CWE identifie

    Ready to connect★ 63

    github.com/unitoneai/securityskills63 stars

    View details
  • security-engineerSkillSecurity

    Security Engineer role bundle for building security into products and infrastructure. Orchestrates code review, pipeline hardening, vulnerability response, and infrastructure review workflows. Auto-invoked when the user needs help with secure development practices, CI/CD security, vulnerability mana

    Ready to connect★ 63

    github.com/unitoneai/securityskills63 stars

    View details
  • security-updatesSkillSecurity

    Secure boot and firmware update workflows for Zephyr RTOS. Covers MCUboot integration, production image signing, DFU protocols (MCUmgr), fail-safe rollback mechanisms, and mbedTLS crypto basics. Trigger when implementing over-the-air (OTA) updates, securing the boot process, or managing cryptographi

    Ready to connect★ 63

    github.com/beriberikix/zephyr-agent-skills63 stars

    View details
  • segmentationSkillSecurity

    Performs a structured network segmentation review against NIST SP 800-207 (Zero Trust Architecture) and CIS Controls v8 (Control 12 -- Network Infrastructure Management). Auto-invoked when reviewing network architecture, VLAN configurations, micro-segmentation policies, or DMZ designs. Produces a se

    Ready to connect★ 63

    github.com/unitoneai/securityskills63 stars

    View details
  • soc2-gapSkillSecurity

    Performs a SOC 2 Type II readiness gap analysis against AICPA Trust Services Criteria. Auto-invoked when discussing SOC 2 compliance, audit preparation, or security program maturity. Walks through all Common Criteria (CC1-CC9) plus selected additional criteria, identifies gaps, and produces a remedi

    Ready to connect★ 63

    github.com/unitoneai/securityskills63 stars

    View details
  • vcisoSkillSecurity

    Virtual CISO role bundle for organizations without a full-time CISO. Orchestrates security program assessment, compliance readiness, risk management, and board-level reporting. Auto-invoked when the user asks for security program guidance, compliance assessment, risk posture evaluation, or board rep

    Ready to connect★ 63

    github.com/unitoneai/securityskills63 stars

    View details
  • vuln-researchSkillSecurity

    How to find, confirm, and report a security vulnerability with an AI session — in this repo's own sandbox boundary, in a dependency, or upstream. Activate when the user asks to "find vulnerabilities", "look for a bypass", "attack the sandbox", "audit this for security bugs", "is this exploitable", "

    Ready to connect★ 63

    github.com/alexandermattturner/agent-glovebox63 stars

    View details
  • zero-trust-assessmentSkillSecurity

    Performs a Zero Trust Architecture maturity assessment against NIST SP 800-207 and the CISA Zero Trust Maturity Model v2. Evaluates all five CISA ZT pillars (Identity, Devices, Networks, Applications & Workloads, Data) across maturity stages. Covers microsegmentation readiness, continuous verificati

    Ready to connect★ 63

    github.com/unitoneai/securityskills63 stars

    View details
  • agentic-code-reviewSkillSecurity

    Use when reviewing a diff, pull request, branch, or AI-generated code for correctness, security, regression, test, performance, and maintainability risks before merge.

    Ready to connect★ 62

    github.com/dominiktobureto/awesome-grok-build62 stars

    View details
  • cash-auditSkillSecurity

    Audit changed code for security sharp edges — dangerous defaults, type confusion, and silent failures

    Ready to connect★ 62

    github.com/cashwu/iphonelocationmove62 stars

    View details
  • thermo-nuclear-reviewSkillSecurity

    Comprehensive security and correctness audit of a branch's changes. Use for thermo nuclear, thermonuclear, or deep review requests, or branch/PR diff audits focused on bugs, breaking changes, security issues, devex regressions, and feature-gate leaks.

    Ready to connect★ 62

    github.com/ahonn/dotfiles62 stars

    View details
  • thermosSkillSecurity

    Launch both thermo-nuclear review subagents in parallel, then synthesize their findings. Use for thermos, double thermo review, or combined bug/security and code-quality branch audits.

    Ready to connect★ 62

    github.com/ahonn/dotfiles62 stars

    View details
  • api-connectionSkillSecurity

    Configure and use Backoffice API connections. Use when creating outbound HTTP API integrations, configuring OAuth or bearer authentication, starting API OAuth flows, checking auth status, or executing authenticated API requests from automations.

    Ready to connect★ 61

    github.com/rejot-dev/fragno61 stars

    View details
  • behavioral-analysisSkillSecurity

    Analyzes security risks in the AI Agent/MCP Skill catalog. Used when users request to inspect, audit, review, or scan the Skill catalog for potential security risks, including command injection, data leakage, prompt word attacks, stealth access, remote execution, or other malicious activities within

    Ready to connect★ 61

    github.com/huta0kj/vetix61 stars

    View details
  • mcp-connectionSkillSecurity

    Configure and use Backoffice MCP servers. Use when registering remote MCP endpoints, authenticating MCP servers with OAuth or bearer tokens, listing MCP tools, or calling MCP tools from automations.

    Ready to connect★ 61

    github.com/rejot-dev/fragno61 stars

    View details
  • quality-engineerSkillSecurity

    Quality validation specialist covering functional, performance, and security testing to ensure production readiness through evidence-based testing.

    Ready to connect★ 61

    github.com/vinix24/vnx-orchestration57 stars

    View details
  • review-forkSkillSecurity

    Safety-first review of an external pull request from an untrusted fork. Fetches the diff read-only into an isolated worktree, scans for supply-chain / exfiltration / CI-tampering threats, checks scope, then delegates correctness review. Never builds or runs the fork's code.

    Ready to connect★ 61

    github.com/thalesgroup/fred60 stars

    View details
  • attack-chainsSkillSecurity

    Detect multi-step exploit sequences where individual steps may appear benign but combine into critical vulnerabilities. Use when analyzing protocols for flash-loan-to-governance chains, oracle manipulation sequences, or cross-contract re-entrancy paths inspired by real-world exploits like Ronin, Wor

    Ready to connect★ 60

    github.com/0x-shashi/web3-audit-skills57 stars

    View details
  • context-detectionSkillSecurity

    Automatically identify the type of protocol being audited to load appropriate checklists, templates, and vulnerability patterns without manual configuration. Use when starting any new audit to classify the protocol (DeFi lending, AMM, bridge, governance, etc.) and surface the most relevant checks.

    Ready to connect★ 60

    github.com/0x-shashi/web3-audit-skills57 stars

    View details
  • cyber-auditSkillSecurity

    Lets your agent run security exposure checks and save a structured audit report locally.

    Ready to connect★ 59

    github.com/matyasstoch/david-skills60 stars

    View details
  • effective-agent-skillsSkillSecurity

    Lets your agent write and review its own skill instructions, including triggers and safety notes.

    Ready to connect★ 59

    github.com/matyasstoch/david-skills60 stars

    View details
  • fix-reviewSkillSecurity

    Lets your agent check whether a fix commit resolves audit findings without introducing new bugs.

    Ready to connect★ 60

    github.com/0x-shashi/web3-audit-skills57 stars

    View details
  • longbridge-market-dataSkillSecurity

    Real-time quotes, K-line charts, order book, trade ticks, intraday capital flow, market sentiment temperature, trading session schedule, security lists, exchange rates, and IPO calendar for HK/US/A-share/SG via Longbridge. Also covers ADR premium and FX carry frameworks. Triggers: "股价", "行情", "K线",

    Ready to connect★ 60

    github.com/longbridge/skills60 stars

    View details
  • methodologySkillSecurity

    Comprehensive audit methodology guides covering the full security auditor workflow -- from preparation and AI-assisted analysis through formal verification, economic modeling, report writing, and skill quality scoring. Use when learning audit workflows, selecting testing strategies, or authoring new

    Ready to connect★ 60

    github.com/0x-shashi/web3-audit-skills57 stars

    View details
  • move-scannerSkillSecurity

    Use when the user wants to audit Move smart contracts for security vulnerabilities, scan Aptos or Sui contracts for resource safety, capability leaks, or module upgrade issues, review Move-based DeFi protocols for object model and linear type violations, or analyze cross-module trust boundaries.

    Ready to connect★ 60

    github.com/0x-shashi/web3-audit-skills57 stars

    View details
  • security-checklistSkillSecurity

    Lets your agent check a reference security checklist for guidance during reviews.

    Ready to connect★ 60

    github.com/albinotonnina/echos60 stars

    View details
  • skillsSkillSecurity

    Root skill definition for the Web3 Audit Plugin providing AI-powered smart contract security auditing across EVM, Solana, Move, Cairo, CosmWasm, and TON platforms. Use as the top-level entry point for understanding plugin capabilities, supported chains, and skill routing.

    Ready to connect★ 60

    github.com/0x-shashi/web3-audit-skills57 stars

    View details
  • solana-scannerSkillSecurity

    Use when auditing Solana programs for security vulnerabilities, reviewing Anchor or Pinocchio/native Rust smart contracts, checking CPI safety, PDA validation, account ownership, signer verification, or Token-2022 security.

    Ready to connect★ 60

    github.com/0x-shashi/web3-audit-skills57 stars

    View details

What is a skill?

A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.

52,524 of the 52,958 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.

Install one and every AI you use gets it

Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.

Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.

See how to connect your AI