Skills.

Give your AI a better way to work.

A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.

Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.

Category: Security

1,738 results · page 46 of 58

  • bounty-apiSkillSecurity

    Use when bug-bountying an API target — REST, GraphQL, gRPC, WebSocket. Covers OWASP API Top 10 (BOLA, BFLA, mass assignment, rate limiting bypass, JWT issues, GraphQL abuse). Triggers on "bounty api", "graphql security", "rest api testing", "api top 10".

    Ready to connect★ 54

    github.com/26zl/cybersec-toolkit55 stars

    View details
  • building-attack-pattern-library-from-cti-reportsSkillSecurity

    Extract and catalog attack patterns from cyber threat intelligence reports

    Ready to connect★ 54

    github.com/26zl/cybersec-toolkit55 stars

    View details
  • building-automated-malware-submission-pipelineSkillSecurity

    'Builds an automated malware submission and analysis pipeline that collects

    Ready to connect★ 54

    github.com/26zl/cybersec-toolkit55 stars

    View details
  • building-detection-rules-with-sigmaSkillSecurity

    'Builds vendor-agnostic detection rules using the Sigma rule format for threat detection across SIEM platforms

    Ready to connect★ 54

    github.com/26zl/cybersec-toolkit55 stars

    View details
  • building-ioc-enrichment-pipeline-with-openctiSkillSecurity

    OpenCTI is an open-source platform for managing cyber threat intelligence

    Ready to connect★ 54

    github.com/26zl/cybersec-toolkit55 stars

    View details
  • building-threat-actor-profile-from-osintSkillSecurity

    Build comprehensive threat actor profiles using open-source intelligence

    Ready to connect★ 54

    github.com/26zl/cybersec-toolkit55 stars

    View details
  • building-threat-intelligence-enrichment-in-splunkSkillSecurity

    Build automated threat intelligence enrichment pipelines in Splunk Enterprise

    Ready to connect★ 54

    github.com/26zl/cybersec-toolkit55 stars

    View details
  • building-threat-intelligence-feed-integrationSkillSecurity

    'Builds automated threat intelligence feed integration pipelines connecting

    Ready to connect★ 54

    github.com/26zl/cybersec-toolkit55 stars

    View details
  • building-vulnerability-aging-and-sla-trackingSkillSecurity

    Implement a vulnerability aging dashboard and SLA tracking system to

    Ready to connect★ 54

    github.com/26zl/cybersec-toolkit55 stars

    View details
  • building-vulnerability-exception-tracking-systemSkillSecurity

    Build a vulnerability exception and risk acceptance tracking system with

    Ready to connect★ 54

    github.com/26zl/cybersec-toolkit55 stars

    View details
  • building-vulnerability-scanning-workflowSkillSecurity

    'Builds a structured vulnerability scanning workflow using tools like

    Ready to connect★ 54

    github.com/26zl/cybersec-toolkit55 stars

    View details
  • bypassing-authentication-with-forced-browsingSkillSecurity

    Discovering and accessing unprotected pages, APIs, and administrative

    Ready to connect★ 54

    github.com/26zl/cybersec-toolkit55 stars

    View details
  • collecting-open-source-intelligenceSkillSecurity

    'Collects and synthesizes open-source intelligence (OSINT) about threat

    Ready to connect★ 54

    github.com/26zl/cybersec-toolkit55 stars

    View details
  • collecting-threat-intelligence-with-mispSkillSecurity

    MISP (Malware Information Sharing Platform) is an open-source threat

    Ready to connect★ 54

    github.com/26zl/cybersec-toolkit55 stars

    View details
  • conducting-api-security-testingSkillSecurity

    'Conducts security testing of REST, GraphQL, and gRPC APIs to identify

    Ready to connect★ 54

    github.com/26zl/cybersec-toolkit55 stars

    View details
  • conducting-internal-network-penetration-testSkillSecurity

    Execute an internal network penetration test simulating an insider threat

    Ready to connect★ 54

    github.com/26zl/cybersec-toolkit55 stars

    View details
  • conjoint-diagnosticsSkillSecurity

    Reviews an existing conjoint study for threats to inference and returns prioritized findings across five areas — design integrity (attributes, profile restrictions, task count and satisficing, randomization, power), estimation (estimand clarity, reference levels, subgroups, clustered standard errors

    Ready to connect★ 55

    github.com/scdenney/open-science-skills55 stars

    View details
  • full-reviewSkillSecurity

    Run every review skill at once — build-check, then design-check, code-audit, security-audit, a11y-audit and perf-audit fanned out across parallel agents — and merge them into one deduplicated, severity-ranked report. Use when asked for a full/complete review, to review everything before shipping or

    Ready to connect★ 55

    github.com/arcasilesgroup/ai-engineering55 stars

    View details
  • review-routerSkillSecurity

    Decide which review lanes a change actually needs, then run exactly those — instead of spawning the whole chain at every diff size. Reads the diff's shape and blast radius, maps the evidence to lanes (code, security, a11y, perf, design, build), estimates the cost, shows the routing decision, and exe

    Ready to connect★ 55

    github.com/arcasilesgroup/ai-engineering55 stars

    View details
  • agile-v-adrSkillSecurity

    Authoring, approval, immutability, and supersession of Architecture Decision Records (ADRs) in the Agile V lifecycle. Load when recording a significant, long-lived architectural, platform, tooling, or security decision.

    Ready to connect★ 54

    github.com/agile-v/agile_v_skills54 stars

    View details
  • agile-v-complianceSkillSecurity

    Risk management, CAPA protocol, human gate approval records, AI agent security controls, and periodic revalidation. Load when running gates, handling CAPAs, or auditing compliance and security posture.

    Ready to connect★ 54

    github.com/agile-v/agile_v_skills54 stars

    View details
  • build-agent-nestjsSkillSecurity

    NestJS backend build agent for REST/GraphQL APIs, microservices, and enterprise backends. Extends build-agent with NestJS architectural patterns, dependency injection, testing strategies, and security best practices. Use when building NestJS applications.

    Ready to connect★ 54

    github.com/agile-v/agile_v_skills54 stars

    View details
  • edgeone-clawscan-zhSkillSecurity

    A comprehensive OpenClaw security scanning skill powered by Tencent Zhuque Lab's A.I.G (AI-Infra-Guard). Use when the user asks for a security checkup or security scan of the current OpenClaw environment, e.g. `开始安全体检`, `做一次安全体检`, `开始安全扫描`, `全面安全检查`, or `检查 OpenClaw 安全`; also use when the user asks

    Ready to connect★ 54

    github.com/l-lesteryu/openclaw-hot-skills-zh53 stars

    View details
  • gke-service-networkingSkillSecurity

    Configures GKE edge networking, traffic routing, load balancing, and private service endpoints. Use when configuring Gateway API manifests, standard Ingress, Cloud Armor WAF security policies, Container-Native Load Balancing (NEGs), Private Service Connect (PSC), or Google-managed SSL certificates o

    Ready to connect★ 54

    github.com/gke-labs/kube-agents53 stars

    View details
  • gke-workload-securitySkillSecurity

    Workflows for auditing and hardening the security of GKE workloads.

    Ready to connect★ 54

    github.com/gke-labs/kube-agents53 stars

    View details
  • mcporterSkillSecurity

    Use the mcporter CLI to list, configure, authenticate, and call MCP servers/tools (HTTP or stdio), including ephemeral servers, config editing, and CLI/type generation.

    Ready to connect★ 54

    github.com/l-lesteryu/openclaw-hot-skills-zh53 stars

    View details
  • moltguardSkillSecurity

    Open-source OpenClaw security plugin: local prompt sanitization + injection detection. Full source code at github.com/openguardrails/moltguard

    Ready to connect★ 54

    github.com/l-lesteryu/openclaw-hot-skills-zh53 stars

    View details
  • owasp-api-securitySkillSecurity

    OWASP API Security Top 10 testing patterns, injection payloads, auth bypass vectors, and security test generation for the actual-mcp-server MCP API. Use when writing security tests, reviewing tools or HTTP endpoints for vulnerabilities, or auditing input validation and authorization.

    Ready to connect★ 54

    github.com/agigante80/actual-mcp-server48 stars

    View details
  • review-security-k8s-agents-prompt-injectionSkillSecurity

    Reviews AI agent architectures (API gateways, WAFs, input sanitization) for prompt injection risks.

    Ready to connect★ 54

    github.com/gke-labs/kube-agents53 stars

    View details
  • review-security-k8s-agents-sandboxSkillSecurity

    Reviews AI agent execution sandboxes for code escape and lateral movement risks.

    Ready to connect★ 54

    github.com/gke-labs/kube-agents53 stars

    View details

What is a skill?

A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.

52,524 of the 52,958 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.

Install one and every AI you use gets it

Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.

Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.

See how to connect your AI