Skills.
Give your AI a better way to work.
A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.
Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.
Category: Security
1,738 results · page 43 of 58
- View details
sast-configSkillSecurity
Reviews and tunes SAST tool configurations against OWASP ASVS 4.0.3 and CWE Top 25. Auto-invoked when reviewing Semgrep rules, CodeQL queries, SAST CI integration, or false positive triage workflows. Produces a SAST maturity assessment covering rule authoring, severity tuning, custom rule developmen
Ready to connect★ 63
- View details
scanner-tuningSkillSecurity
Tunes vulnerability scanners to reduce false positives, optimize scan policies, and improve result accuracy. Covers false positive identification patterns, scan policy configuration, authenticated vs unauthenticated scanning tradeoffs, severity override criteria, plugin/check selection, scan schedul
Ready to connect★ 63
- View details
secure-code-reviewSkillSecurity
Performs a structured security code review against OWASP ASVS 4.0.3 verification requirements and CWE Top 25. Auto-invoked on pull request reviews, when code touching authentication, authorization, cryptography, or input handling is shared. Produces findings mapped to ASVS controls and CWE identifie
Ready to connect★ 63
- View details
security-engineerSkillSecurity
Security Engineer role bundle for building security into products and infrastructure. Orchestrates code review, pipeline hardening, vulnerability response, and infrastructure review workflows. Auto-invoked when the user needs help with secure development practices, CI/CD security, vulnerability mana
Ready to connect★ 63
- View details
security-updatesSkillSecurity
Secure boot and firmware update workflows for Zephyr RTOS. Covers MCUboot integration, production image signing, DFU protocols (MCUmgr), fail-safe rollback mechanisms, and mbedTLS crypto basics. Trigger when implementing over-the-air (OTA) updates, securing the boot process, or managing cryptographi
Ready to connect★ 63
- View details
segmentationSkillSecurity
Performs a structured network segmentation review against NIST SP 800-207 (Zero Trust Architecture) and CIS Controls v8 (Control 12 -- Network Infrastructure Management). Auto-invoked when reviewing network architecture, VLAN configurations, micro-segmentation policies, or DMZ designs. Produces a se
Ready to connect★ 63
- View details
soc2-gapSkillSecurity
Performs a SOC 2 Type II readiness gap analysis against AICPA Trust Services Criteria. Auto-invoked when discussing SOC 2 compliance, audit preparation, or security program maturity. Walks through all Common Criteria (CC1-CC9) plus selected additional criteria, identifies gaps, and produces a remedi
Ready to connect★ 63
- View details
vcisoSkillSecurity
Virtual CISO role bundle for organizations without a full-time CISO. Orchestrates security program assessment, compliance readiness, risk management, and board-level reporting. Auto-invoked when the user asks for security program guidance, compliance assessment, risk posture evaluation, or board rep
Ready to connect★ 63
- View details
vuln-researchSkillSecurity
How to find, confirm, and report a security vulnerability with an AI session — in this repo's own sandbox boundary, in a dependency, or upstream. Activate when the user asks to "find vulnerabilities", "look for a bypass", "attack the sandbox", "audit this for security bugs", "is this exploitable", "
Ready to connect★ 63
- View details
zero-trust-assessmentSkillSecurity
Performs a Zero Trust Architecture maturity assessment against NIST SP 800-207 and the CISA Zero Trust Maturity Model v2. Evaluates all five CISA ZT pillars (Identity, Devices, Networks, Applications & Workloads, Data) across maturity stages. Covers microsegmentation readiness, continuous verificati
Ready to connect★ 63
- View details
agentic-code-reviewSkillSecurity
Use when reviewing a diff, pull request, branch, or AI-generated code for correctness, security, regression, test, performance, and maintainability risks before merge.
Ready to connect★ 62
- View details
cash-auditSkillSecurity
Audit changed code for security sharp edges — dangerous defaults, type confusion, and silent failures
Ready to connect★ 62
- View details
thermo-nuclear-reviewSkillSecurity
Comprehensive security and correctness audit of a branch's changes. Use for thermo nuclear, thermonuclear, or deep review requests, or branch/PR diff audits focused on bugs, breaking changes, security issues, devex regressions, and feature-gate leaks.
Ready to connect★ 62
- View details
thermosSkillSecurity
Launch both thermo-nuclear review subagents in parallel, then synthesize their findings. Use for thermos, double thermo review, or combined bug/security and code-quality branch audits.
Ready to connect★ 62
- View details
api-connectionSkillSecurity
Configure and use Backoffice API connections. Use when creating outbound HTTP API integrations, configuring OAuth or bearer authentication, starting API OAuth flows, checking auth status, or executing authenticated API requests from automations.
Ready to connect★ 61
- View details
behavioral-analysisSkillSecurity
Analyzes security risks in the AI Agent/MCP Skill catalog. Used when users request to inspect, audit, review, or scan the Skill catalog for potential security risks, including command injection, data leakage, prompt word attacks, stealth access, remote execution, or other malicious activities within
Ready to connect★ 61
- View details
mcp-connectionSkillSecurity
Configure and use Backoffice MCP servers. Use when registering remote MCP endpoints, authenticating MCP servers with OAuth or bearer tokens, listing MCP tools, or calling MCP tools from automations.
Ready to connect★ 61
- View details
quality-engineerSkillSecurity
Quality validation specialist covering functional, performance, and security testing to ensure production readiness through evidence-based testing.
Ready to connect★ 61
- View details
review-forkSkillSecurity
Safety-first review of an external pull request from an untrusted fork. Fetches the diff read-only into an isolated worktree, scans for supply-chain / exfiltration / CI-tampering threats, checks scope, then delegates correctness review. Never builds or runs the fork's code.
Ready to connect★ 61
- View details
attack-chainsSkillSecurity
Detect multi-step exploit sequences where individual steps may appear benign but combine into critical vulnerabilities. Use when analyzing protocols for flash-loan-to-governance chains, oracle manipulation sequences, or cross-contract re-entrancy paths inspired by real-world exploits like Ronin, Wor
Ready to connect★ 60
- View details
context-detectionSkillSecurity
Automatically identify the type of protocol being audited to load appropriate checklists, templates, and vulnerability patterns without manual configuration. Use when starting any new audit to classify the protocol (DeFi lending, AMM, bridge, governance, etc.) and surface the most relevant checks.
Ready to connect★ 60
- View details
cyber-auditSkillSecurity
Lets your agent run security exposure checks and save a structured audit report locally.
Ready to connect★ 59
- View details
effective-agent-skillsSkillSecurity
Lets your agent write and review its own skill instructions, including triggers and safety notes.
Ready to connect★ 59
- View details
fix-reviewSkillSecurity
Lets your agent check whether a fix commit resolves audit findings without introducing new bugs.
Ready to connect★ 60
- View details
longbridge-market-dataSkillSecurity
Real-time quotes, K-line charts, order book, trade ticks, intraday capital flow, market sentiment temperature, trading session schedule, security lists, exchange rates, and IPO calendar for HK/US/A-share/SG via Longbridge. Also covers ADR premium and FX carry frameworks. Triggers: "股价", "行情", "K线",
Ready to connect★ 60
- View details
methodologySkillSecurity
Comprehensive audit methodology guides covering the full security auditor workflow -- from preparation and AI-assisted analysis through formal verification, economic modeling, report writing, and skill quality scoring. Use when learning audit workflows, selecting testing strategies, or authoring new
Ready to connect★ 60
- View details
move-scannerSkillSecurity
Use when the user wants to audit Move smart contracts for security vulnerabilities, scan Aptos or Sui contracts for resource safety, capability leaks, or module upgrade issues, review Move-based DeFi protocols for object model and linear type violations, or analyze cross-module trust boundaries.
Ready to connect★ 60
- View details
security-checklistSkillSecurity
Lets your agent check a reference security checklist for guidance during reviews.
Ready to connect★ 60
- View details
skillsSkillSecurity
Root skill definition for the Web3 Audit Plugin providing AI-powered smart contract security auditing across EVM, Solana, Move, Cairo, CosmWasm, and TON platforms. Use as the top-level entry point for understanding plugin capabilities, supported chains, and skill routing.
Ready to connect★ 60
- View details
solana-scannerSkillSecurity
Use when auditing Solana programs for security vulnerabilities, reviewing Anchor or Pinocchio/native Rust smart contracts, checking CPI safety, PDA validation, account ownership, signer verification, or Token-2022 security.
Ready to connect★ 60
What is a skill?
A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.
52,524 of the 52,958 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.
Install one and every AI you use gets it
Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.
Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.