Skills.
Give your AI a better way to work.
A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.
Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.
Category: Security
1,738 results · page 47 of 58
- View details
skill-vetter-zhSkillSecurity
A security-first review tool for AI agent skills. Use before installing any skill from ClawHub, GitHub, or other sources. Checks for red flags, permission scopes, and suspicious patterns.
Ready to connect★ 54
- View details
threat-model-authoringSkillSecurity
Draft phase 3.5 of a threat model from the orientation brief, surface analysis, and maintainer answers. USE WHEN writing threat-model.md to the canonical §1.1–§1.19 structure. Combines concise prose with the §1.7 trust table and contract matrix, §1.8 output statements, §1.17 disposition table, §1.1
Ready to connect★ 54
- View details
threat-model-backtestSkillSecurity
Backtest phase 3.6 of threat-model production against historical findings before sign-off. USE WHEN a draft model must prove it can uniquely route real reports. Builds a stratified producer-side corpus across components and contract dimensions, clusters large corpora by sink and attack class, and ro
Ready to connect★ 54
- View details
threat-model-interviewSkillSecurity
Run phase 3.4 maintainer question waves for threat-model production. USE WHEN inferred claims need ratification or interview-first versus draft-first mode must be chosen. Asks 3–7 prioritized proposed-answer questions per wave; wave 1 always covers scope, intended use, configuration support, and hos
Ready to connect★ 54
- View details
threat-model-reconSkillSecurity
Orient and mine an open-source repository for threat-model production phases 3.1–3.2. USE WHEN starting a threat model or surveying security posture before modeling. Reads README, top-level docs, SECURITY/THREAT docs, maintainer issue rulings, and changelog rationale; carves component families; flag
Ready to connect★ 54
- View details
threat-model-sidecarSkillSecurity
Emit and validate the §1.19 machine-readable companions: threat-model.yaml using schema threat-model-sidecar/v2, and the flat threat-model.json export conforming to schema.json. USE WHEN an orchestrated threat model is ready for publication, automated or AI-assisted triage, dependency compatibility
Ready to connect★ 54
- View details
threat-model-surfaceSkillSecurity
Perform phase 3.3 deep analysis of an in-scope attack surface for a threat model. USE WHEN the orientation brief is ready and code must be read to derive the §1.7 per-input trust table and contract-dimension matrix, §1.5 no-surprise side-effects inventory, §1.4 reachability preconditions, and §1.8 o
Ready to connect★ 54
- View details
threat-model-triageSkillSecurity
Triage one inbound vulnerability report, scanner hit, fuzzer artifact, or AI finding against a finished threat model. USE WHEN asked whether a finding is valid or in scope. Applies the §1.1 routing algorithm and §1.17 precedence to assign exactly one closed disposition with section and provenance ci
Ready to connect★ 54
- View details
threat-modelerSkillSecurity
STRIDE threat modeling and privacy impact assessment to generate security/privacy requirements. Use before requirement-architect to shift security left.
Ready to connect★ 54
- View details
working-overnightSkillSecurity
Run governed, unattended overnight work. Pulls from a defined work source (gated tickets, tickets to gate, or investigations like full/security reviews that create tickets), implements safe work as branch-plus-PR without ever merging, defers you-only decisions instead of guessing, and writes a morni
Ready to connect★ 54
- View details
auditor-skillSkillSecurity
**AUDIT SKILL** — Comprehensive on-chain Solana program auditor and full-stack security review for ANY programming language. USE FOR: auditing Solana/Anchor programs, reviewing smart contract security, checking for vulnerabilities (missing signers, unchecked accounts, arithmetic overflow, CPI attack
Ready to connect★ 53
- View details
c-security-reviewSkillSecurity
Use when the user requests a userspace C or C++ security review with an explicit threat model, severity filter, and model. Runs a partitioned read-only audit and writes report, SARIF, and findings to a .c-review-results run directory. Not for kernel drivers, managed languages, or embedded code.
Ready to connect★ 52
- View details
chain-vulnerability-scannerSkillSecurity
Use when a supported Algorand, Cairo, Cosmos SDK, Solana, Substrate, or TON codebase needs chain-specific vulnerability scanning. Returns reachability-backed findings routed to the matching ecosystem reference. Not for generic non-chain security review — route that to security-review.
Ready to connect★ 52
- View details
confirmed-security-reviewSkillSecurity
Use when the user asks for a security review, vulnerability audit, or review of injection, XSS, auth, or crypto. Returns only HIGH-confidence vulnerabilities with attacker-controlled input confirmed, or a cleared report. Not for CodeQL analysis — use codeql-security-analysis.
Ready to connect★ 52
- View details
devexpress-xaf-securitySkillSecurity
XAF Security System covering authentication (password, Windows, OAuth2), user and role setup for EF Core and XPO, authorization and Permission Policy, type/object/member/navigation permissions, current-user and role checks, security APIs including ApplicationUser, ISecurityUserWithRoles, ISecurityPr
Ready to connect★ 53
- View details
sdp-tokenizationSkillSecurity
Explain, plan, and prototype tokenization workflows on Solana Developer Platform using the supported public docs and API surface. Use when a consumer wants to issue a stablecoin, tokenized security, loyalty token, or other asset with SDP.
Ready to connect★ 53
- View details
security-sentinelSkillSecurity
Use this agent when you need to perform security audits, vulnerability assessments, or security reviews of code. This includes checking for common security vulnerabilities, validating input handling, reviewing authentication/authorization implementations, scanning for hardcoded secrets, and ensuring
Ready to connect★ 53
- View details
ase-code-analyzeSkillSecurity
Analyze the source code for problems in either the logic and semantics and its related control flow, performance and efficiency, or security.
Ready to connect★ 52
- View details
claude-agent-sdkSkillSecurity
Build autonomous AI agents with Claude Agent SDK. Structured outputs (v0.1.45, Nov 2025) guarantee JSON schema validation, plugins system, hooks for event-driven workflows. Use when: building coding agents with validated JSON responses, SRE systems, security auditors, or troubleshooting CLI not foun
Ready to connect★ 52
- View details
council-planSkillSecurity
Architect a feature with the Carmack Council before writing code. Use when explicitly asked to plan a feature, do a "council plan", "carmack plan", or invoke /council-plan. Carmack's philosophy chairs a council of domain experts — Troy Hunt (security), Martin Fowler (refactoring), Kent C. Dodds (fro
Ready to connect★ 52
- View details
council-reviewSkillSecurity
Perform a rigorous Carmack Council code review. Use when explicitly asked to review code, do a "council review", "carmack review", or invoke /council-review. Carmack's philosophy chairs a council of domain experts — Troy Hunt (security), Martin Fowler (refactoring), Kent C. Dodds (frontend), Matteo
Ready to connect★ 52
- View details
crisp-executeSkillSecurity
CRISP Execute — Sprint execution loop with change request management, security gates, product gates, and stakeholder reporting. Use after Phase S (Spec) is complete and crisp-state.json shows ready_for_execute: true. Triggers on "start sprint", "begin build", "execute", "sprint 1", "run sprints", or
Ready to connect★ 52
- View details
fda-consultant-specialistSkillSecurity
Lets your agent give guidance on FDA medical device submissions, quality system compliance, HIPAA, and device cybersecurity.
Ready to connect★ 52
- View details
Gemini CLISkillSecurity
Consult Google Gemini CLI for second opinions on architecture, debugging, and security audits. Use Gemini's 1M+ context window for comprehensive code analysis. Compare Flash (fast) vs Pro (thorough) vs 3-Pro-Preview (cutting-edge).
Ready to connect★ 52
- View details
information-security-manager-iso27001SkillSecurity
Lets your agent run ISO 27001 security risk assessments, check control compliance, and generate gap analysis reports.
Ready to connect★ 52
- View details
isms-audit-expertSkillSecurity
Lets your agent plan ISO 27001 audits, assess security controls, document findings, and prepare certification paperwork.
Ready to connect★ 52
- View details
skill-snitchSkillSecurity
Security auditing for MOOLLM skills - static analysis and runtime surveillance
Ready to connect★ 52
- View details
find-promptSkillSecurity
Route the current task to the right prompt(s) in this library, load them, and adopt them as your operating instructions for the rest of the conversation. Use when the user names a task ("add OAuth", "set up hooks", "review this PR", "pick a model"), asks which prompt to use, or says to "use the righ
Ready to connect★ 51
- View details
quarkus-securitySkillSecurity
Quarkus Security best practices for authentication, authorization, JWT/OIDC, RBAC, input validation, CSRF, secrets management, and dependency security.
Ready to connect★ 51
- View details
quarkus-verificationSkillSecurity
Verification loop for Quarkus projects: build, static analysis, tests with coverage, security scans, native compilation, and diff review before release or PR.
Ready to connect★ 51
What is a skill?
A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.
52,524 of the 52,958 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.
Install one and every AI you use gets it
Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.
Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.