Skills.

Give your AI a better way to work.

A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.

Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.

Category: Security

1,738 results · page 47 of 58

  • skill-vetter-zhSkillSecurity

    A security-first review tool for AI agent skills. Use before installing any skill from ClawHub, GitHub, or other sources. Checks for red flags, permission scopes, and suspicious patterns.

    Ready to connect★ 54

    github.com/l-lesteryu/openclaw-hot-skills-zh53 stars

    View details
  • threat-model-authoringSkillSecurity

    Draft phase 3.5 of a threat model from the orientation brief, surface analysis, and maintainer answers. USE WHEN writing threat-model.md to the canonical §1.1–§1.19 structure. Combines concise prose with the §1.7 trust table and contract matrix, §1.8 output statements, §1.17 disposition table, §1.1

    Ready to connect★ 54

    github.com/alpha-omega-security/threat-model54 stars

    View details
  • threat-model-backtestSkillSecurity

    Backtest phase 3.6 of threat-model production against historical findings before sign-off. USE WHEN a draft model must prove it can uniquely route real reports. Builds a stratified producer-side corpus across components and contract dimensions, clusters large corpora by sink and attack class, and ro

    Ready to connect★ 54

    github.com/alpha-omega-security/threat-model54 stars

    View details
  • threat-model-interviewSkillSecurity

    Run phase 3.4 maintainer question waves for threat-model production. USE WHEN inferred claims need ratification or interview-first versus draft-first mode must be chosen. Asks 3–7 prioritized proposed-answer questions per wave; wave 1 always covers scope, intended use, configuration support, and hos

    Ready to connect★ 54

    github.com/alpha-omega-security/threat-model54 stars

    View details
  • threat-model-reconSkillSecurity

    Orient and mine an open-source repository for threat-model production phases 3.1–3.2. USE WHEN starting a threat model or surveying security posture before modeling. Reads README, top-level docs, SECURITY/THREAT docs, maintainer issue rulings, and changelog rationale; carves component families; flag

    Ready to connect★ 54

    github.com/alpha-omega-security/threat-model54 stars

    View details
  • threat-model-sidecarSkillSecurity

    Emit and validate the §1.19 machine-readable companions: threat-model.yaml using schema threat-model-sidecar/v2, and the flat threat-model.json export conforming to schema.json. USE WHEN an orchestrated threat model is ready for publication, automated or AI-assisted triage, dependency compatibility

    Ready to connect★ 54

    github.com/alpha-omega-security/threat-model54 stars

    View details
  • threat-model-surfaceSkillSecurity

    Perform phase 3.3 deep analysis of an in-scope attack surface for a threat model. USE WHEN the orientation brief is ready and code must be read to derive the §1.7 per-input trust table and contract-dimension matrix, §1.5 no-surprise side-effects inventory, §1.4 reachability preconditions, and §1.8 o

    Ready to connect★ 54

    github.com/alpha-omega-security/threat-model54 stars

    View details
  • threat-model-triageSkillSecurity

    Triage one inbound vulnerability report, scanner hit, fuzzer artifact, or AI finding against a finished threat model. USE WHEN asked whether a finding is valid or in scope. Applies the §1.1 routing algorithm and §1.17 precedence to assign exactly one closed disposition with section and provenance ci

    Ready to connect★ 54

    github.com/alpha-omega-security/threat-model54 stars

    View details
  • threat-modelerSkillSecurity

    STRIDE threat modeling and privacy impact assessment to generate security/privacy requirements. Use before requirement-architect to shift security left.

    Ready to connect★ 54

    github.com/agile-v/agile_v_skills54 stars

    View details
  • working-overnightSkillSecurity

    Run governed, unattended overnight work. Pulls from a defined work source (gated tickets, tickets to gate, or investigations like full/security reviews that create tickets), implements safe work as branch-plus-PR without ever merging, defers you-only decisions instead of guessing, and writes a morni

    Ready to connect★ 54

    github.com/agigante80/actual-mcp-server48 stars

    View details
  • auditor-skillSkillSecurity

    **AUDIT SKILL** — Comprehensive on-chain Solana program auditor and full-stack security review for ANY programming language. USE FOR: auditing Solana/Anchor programs, reviewing smart contract security, checking for vulnerabilities (missing signers, unchecked accounts, arithmetic overflow, CPI attack

    Ready to connect★ 53

    github.com/solanabr/auditor-skill53 stars

    View details
  • c-security-reviewSkillSecurity

    Use when the user requests a userspace C or C++ security review with an explicit threat model, severity filter, and model. Runs a partitioned read-only audit and writes report, SARIF, and findings to a .c-review-results run directory. Not for kernel drivers, managed languages, or embedded code.

    Ready to connect★ 52

    github.com/outlinedriven/outline-driven-development53 stars

    View details
  • chain-vulnerability-scannerSkillSecurity

    Use when a supported Algorand, Cairo, Cosmos SDK, Solana, Substrate, or TON codebase needs chain-specific vulnerability scanning. Returns reachability-backed findings routed to the matching ecosystem reference. Not for generic non-chain security review — route that to security-review.

    Ready to connect★ 52

    github.com/outlinedriven/outline-driven-development53 stars

    View details
  • confirmed-security-reviewSkillSecurity

    Use when the user asks for a security review, vulnerability audit, or review of injection, XSS, auth, or crypto. Returns only HIGH-confidence vulnerabilities with attacker-controlled input confirmed, or a cleared report. Not for CodeQL analysis — use codeql-security-analysis.

    Ready to connect★ 52

    github.com/outlinedriven/outline-driven-development53 stars

    View details
  • devexpress-xaf-securitySkillSecurity

    XAF Security System covering authentication (password, Windows, OAuth2), user and role setup for EF Core and XPO, authorization and Permission Policy, type/object/member/navigation permissions, current-user and role checks, security APIs including ApplicationUser, ISecurityUserWithRoles, ISecurityPr

    Ready to connect★ 53

    github.com/devexpress/agent-skills53 stars

    View details
  • sdp-tokenizationSkillSecurity

    Explain, plan, and prototype tokenization workflows on Solana Developer Platform using the supported public docs and API surface. Use when a consumer wants to issue a stablecoin, tokenized security, loyalty token, or other asset with SDP.

    Ready to connect★ 53

    github.com/solana-foundation/solana-developer-platform52 stars

    View details
  • security-sentinelSkillSecurity

    Use this agent when you need to perform security audits, vulnerability assessments, or security reviews of code. This includes checking for common security vulnerabilities, validating input handling, reviewing authentication/authorization implementations, scanning for hardcoded secrets, and ensuring

    Ready to connect★ 53

    github.com/ratacat/claude-skills52 stars

    View details
  • ase-code-analyzeSkillSecurity

    Analyze the source code for problems in either the logic and semantics and its related control flow, performance and efficiency, or security.

    Ready to connect★ 52

    github.com/rse/ase52 stars

    View details
  • claude-agent-sdkSkillSecurity

    Build autonomous AI agents with Claude Agent SDK. Structured outputs (v0.1.45, Nov 2025) guarantee JSON schema validation, plugins system, hooks for event-driven workflows. Use when: building coding agents with validated JSON responses, SRE systems, security auditors, or troubleshooting CLI not foun

    Ready to connect★ 52

    github.com/ovachiever/droid-tings52 stars

    View details
  • council-planSkillSecurity

    Architect a feature with the Carmack Council before writing code. Use when explicitly asked to plan a feature, do a "council plan", "carmack plan", or invoke /council-plan. Carmack's philosophy chairs a council of domain experts — Troy Hunt (security), Martin Fowler (refactoring), Kent C. Dodds (fro

    Ready to connect★ 52

    github.com/samjhudson01/carmack-council52 stars

    View details
  • council-reviewSkillSecurity

    Perform a rigorous Carmack Council code review. Use when explicitly asked to review code, do a "council review", "carmack review", or invoke /council-review. Carmack's philosophy chairs a council of domain experts — Troy Hunt (security), Martin Fowler (refactoring), Kent C. Dodds (frontend), Matteo

    Ready to connect★ 52

    github.com/samjhudson01/carmack-council52 stars

    View details
  • crisp-executeSkillSecurity

    CRISP Execute — Sprint execution loop with change request management, security gates, product gates, and stakeholder reporting. Use after Phase S (Spec) is complete and crisp-state.json shows ready_for_execute: true. Triggers on "start sprint", "begin build", "execute", "sprint 1", "run sprints", or

    Ready to connect★ 52

    github.com/radekamirko/c.r.i.s.p52 stars

    View details
  • fda-consultant-specialistSkillSecurity

    Lets your agent give guidance on FDA medical device submissions, quality system compliance, HIPAA, and device cybersecurity.

    Ready to connect★ 52

    github.com/ovachiever/droid-tings52 stars

    View details
  • Gemini CLISkillSecurity

    Consult Google Gemini CLI for second opinions on architecture, debugging, and security audits. Use Gemini's 1M+ context window for comprehensive code analysis. Compare Flash (fast) vs Pro (thorough) vs 3-Pro-Preview (cutting-edge).

    Ready to connect★ 52

    github.com/ovachiever/droid-tings52 stars

    View details
  • information-security-manager-iso27001SkillSecurity

    Lets your agent run ISO 27001 security risk assessments, check control compliance, and generate gap analysis reports.

    Ready to connect★ 52

    github.com/ovachiever/droid-tings52 stars

    View details
  • isms-audit-expertSkillSecurity

    Lets your agent plan ISO 27001 audits, assess security controls, document findings, and prepare certification paperwork.

    Ready to connect★ 52

    github.com/ovachiever/droid-tings52 stars

    View details
  • skill-snitchSkillSecurity

    Security auditing for MOOLLM skills - static analysis and runtime surveillance

    Ready to connect★ 52

    github.com/simhacker/moollm52 stars

    View details
  • find-promptSkillSecurity

    Route the current task to the right prompt(s) in this library, load them, and adopt them as your operating instructions for the rest of the conversation. Use when the user names a task ("add OAuth", "set up hooks", "review this PR", "pick a model"), asks which prompt to use, or says to "use the righ

    Ready to connect★ 51

    github.com/rtur2003/claude-code-promts-skills51 stars

    View details
  • quarkus-securitySkillSecurity

    Quarkus Security best practices for authentication, authorization, JWT/OIDC, RBAC, input validation, CSRF, secrets management, and dependency security.

    Ready to connect★ 51

    github.com/fmarzochi/egc48 stars

    View details
  • quarkus-verificationSkillSecurity

    Verification loop for Quarkus projects: build, static analysis, tests with coverage, security scans, native compilation, and diff review before release or PR.

    Ready to connect★ 51

    github.com/fmarzochi/egc48 stars

    View details

What is a skill?

A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.

52,524 of the 52,958 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.

Install one and every AI you use gets it

Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.

Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.

See how to connect your AI