Skills.
Give your AI a better way to work.
A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.
Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.
Category: Security
1,738 results · page 52 of 58
- View details
arkweb-security-patch-impactSkillSecurity
Determine whether ArkWeb M144 or configured baseline is affected by an upstream Chromium vulnerability.
Ready to connect
- View details
arkweb-security-patch-intakeSkillSecurity
Parse ArkWeb security issue inputs such as CVE, Chromium bug, Gerrit CL, PR, and advisory links into an auditable vulnerability intelligence report.
Ready to connect
- View details
arkweb-security-patch-judgeSkillSecurity
Judge ArkWeb state-machine step outputs and produce strict verdict JSON for state transitions.
Ready to connect
- View details
arkweb-security-patch-mergeSkillSecurity
Apply upstream Chromium patches into ArkWeb with deterministic patch normalization, batch planning, issue-scoped diff checks, and controlled manual merge fallback.
Ready to connect
- View details
arkweb-security-patch-reportSkillSecurity
Produce final ArkWeb archive or auto merge report from workflow outputs.
Ready to connect
- View details
arkweb-security-patch-reviewSkillSecurity
Review merged ArkWeb security patches for correctness, vulnerability coverage, and regression risk.
Ready to connect
- View details
arkweb-security-patch-riskSkillSecurity
Assess residual risk after ArkWeb security patch merge, review, and build verification.
Ready to connect
- View details
audio_pr_createSkillSecurity
Use when managing GitCode repositories with the oh-gc CLI — including authentication, issues, PRs, reviewers, testers, labels, releases, and repository configuration. Use this skill when the user wants to commit code, create an ISSUE, create a PR, update a PR, or perform other GitCode web operations
Ready to connect
- View details
bugbountyrulesSkillSecurity
Use for ANY bug bounty, penetration test, or web/API/mobile security assessment: recon, testing endpoints, analyzing Burp traffic or any bug-bounty platform's MCP (HackerOne, Intigriti, Bugcrowd, YesWeHack, Immunefi), reviewing APKs, bypassing a WAF, enforcing scope, hunting a specific vuln class, v
Ready to connect
- View details
defense-in-depthSkillSecurity
Apply layered security architecture. Use when designing security controls, hardening systems, or reviewing security posture. Covers multiple security layers.
Ready to connect
- View details
identity-accessSkillSecurity
Implement identity and access management. Use when designing authentication, authorization, or user management. Covers OAuth2, OIDC, and RBAC.
Ready to connect
- View details
oauth-2-0-setupSkillSecurity
Implement OAuth 2.0 authentication flows including authorization code with PKCE, client credentials, and device code for secure API integration.
Ready to connect
- View details
oh-distributed-security-design-reviewSkillSecurity
A skill specialized for security code review of OpenHarmony distributed systems. Triggered when the user asks to "review code security implementation", "code security review", "security code review", or makes a similar distributed system code security review request. This skill provides detailed rev
Ready to connect
- View details
ohos-req-feasibility-analysisSkillSecurity
Use when evaluating an OHOS requirement in Phase 0.2, especially for 02-feasibility.md, capability gaps, candidate technical paths, compatibility, security, dependencies, effort, risk, or validation planning. Triggers: 02-feasibility.md, 可行性分析, capability gap, 候选技术路径, 兼容性分析, 工作量估算, 500行人月. Do NOT us
Ready to connect
- View details
ohos-test-fuzz-generationSkillSecurity
Generates LLVM libFuzzer FUZZ test cases for C/C++ projects, performs review against 26 security rules, and generates semantic seed data. Compatible with OpenHarmony / Linux / Android build systems.
Ready to connect
- View details
- View details
openharmony-security-reviewSkillSecurity
Use when reviewing OpenHarmony C++ system service code for security vulnerabilities, particularly IPC handlers, multithreaded components, or code handling sensitive user data
Ready to connect
- View details
sec-agentshield-wrapperSkillSecurity
Pre-flight security analysis before code changes — identifies trust boundary risks, dangerous patterns, and provides proceed/caution/block advisory before implementation starts
Ready to connect
- View details
aspnet-identitySkillSecurity
ASP.NET Core Identity for authentication, roles, claims, and external providers. Covers Identity setup, customization, and token-based auth.
Ready to connect
- View details
checking-legal-and-safety-wordingSkillSecurity
Reviews public text for license, warranty, compliance, safety, security, certification, and fitness claims that go too far, then rewrites them to stay inside the real limits. Use when shipping or editing public docs, READMEs, or rollout copy. Do not use for internal code comments, or for deciding ac
Ready to connect
- View details
google-cloud-recipe-authSkillSecurity
Provides expert guidance on authenticating and authorizing to Google Cloud services and APIs, covering human users, service identities, Application Default Credentials (ADC), and best practices for secure access.
Ready to connect
- View details
google-cloud-waf-securitySkillSecurity
Generates security-focused guidance for Google Cloud workloads based on the design principles and recommendations in the Google Cloud Well-Architected Framework (WAF). Use this skill to evaluate a workload, identify security requirements, and provide actionable recommendations for IAM, network secur
Ready to connect
- View details
jwtSkillSecurity
JSON Web Tokens for authentication. Covers token structure, signing, and validation. Use for stateless authentication.
Ready to connect
- View details
nextauthSkillSecurity
NextAuth.js authentication for Next.js. Covers providers, sessions, and callbacks. Use for Next.js authentication.
Ready to connect
- View details
oauth2SkillSecurity
OAuth 2.0 authorization framework. Covers flows, tokens, and provider integration. Use for third-party authentication.
Ready to connect
- View details
spring-authorization-serverSkillSecurity
Spring Authorization Server for building OAuth 2.1 and OpenID Connect providers.
Ready to connect
- View details
spring-bootSkillSecurity
Spring Boot 3 Java framework with enterprise patterns. Covers REST controllers, services, repositories, JPA entities, MapStruct mappers, Lombok, JWT security, Flyway migrations, and global exception handling.
Ready to connect
- View details
spring-graphqlSkillSecurity
Spring for GraphQL - building GraphQL APIs with Spring Boot. Covers queries, mutations, subscriptions, @BatchMapping, DataLoader, and security.
Ready to connect
- View details
spring-ldapSkillSecurity
Spring LDAP for LDAP/Active Directory integration and authentication. Covers LdapTemplate, @Entry mapping, LdapRepository, and Spring Security integration.
Ready to connect
- View details
spring-profilesSkillSecurity
Configuration and profiles management in Spring Boot 3.x. Covers @Profile, @ConfigurationProperties, property sources, YAML/properties, external configuration, secrets management, and environment-specific beans.
Ready to connect
What is a skill?
A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.
52,524 of the 52,958 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.
Install one and every AI you use gets it
Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.
Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.