Skills.
Give your AI a better way to work.
A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.
Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.
Category: Security
1,840 results · page 54 of 62
- View details
api-design-opsSkillSecurity
API design patterns for REST, gRPC, and GraphQL. Use for: api design, REST, gRPC, GraphQL, protobuf, schema design, api versioning, pagination, rate limiting, error format, OpenAPI, API authentication, JWT, OAuth2, API gateway, webhook, idempotency.
Ready to connect
- View details
asus-router-opsSkillSecurity
ASUS router config and hardening: Asuswrt-Merlin, security hardening, encrypted DNS (DoT/DoH), VPN (WireGuard/OpenVPN), guest networks, VLAN/IoT isolation, AiMesh, AiProtection. Triggers on: asus router, asuswrt, merlin, wireguard router, AiProtection, AiMesh, nvram, jffs, IoT isolation.
Ready to connect
- View details
copilot-github-actionsSkillSecurity
Automate GitHub Copilot CLI in GitHub Actions workflows. USE FOR: installing/running `copilot -p` in workflow steps, choosing GITHUB_TOKEN vs a personal access token (COPILOT_GITHUB_TOKEN) for authentication, setting the copilot-requests write permission, minimal-permission tool allowlisting (--allo
Ready to connect
- View details
deps-upgradeSkillSecurity
Use when dependency upgrades need tiered batches for CVEs, a major release, forced compatibility, scheduled hygiene, a pre-release lockfile audit, or a cadence-driven or vulnerability-triggered sweep. Classifies each update on a risk ladder, verifies it, or defers it with a reason. Not for PR queue
Ready to connect
- View details
f-star-effectful-verificationSkillSecurity
Use when effectful, security-sensitive code needs refinement-typed, SMT-backed verification in F*, in the HACL* or Project Everest style.
Ready to connect
- View details
github-opsSkillSecurity
GitHub remote operations: repo creation, metadata, releases, issue/PR management with preview-before-send, and read-only security auditing. Triggers on: push to github, ship release, gh release, audit github repo, gh issue, gh pr, merge PR, branch protection, secret scanning, SECURITY.md.
Ready to connect
- View details
laravel-opsSkillSecurity
Laravel framework patterns, Eloquent ORM, authentication, queues, and testing. Use for: laravel, eloquent, artisan, blade, php, sanctum, livewire, inertia, pest, phpunit, forge, vapor, queue, middleware, migration, factory, seeder.
Ready to connect
- View details
linkedin-ads-weeklySkillSecurity
Runs a weekly optimise-and-report cycle on a LinkedIn Ads account. Pulls the account (via the read tools of the linkedin-ads MCP, or a pasted export when the API is not authenticated), runs ten optimisation levers split by the data volume each needs, proposes a ranked change list, and — once LinkedI
Ready to connect
- View details
mcp-best-practicesSkillSecurity
Build, harden, and debug production MCP servers with the TypeScript SDK. Use when writing or reviewing an MCP server or its tools - picking a transport, designing tool schemas and results, handling errors, adding OAuth, cutting token bloat, or migrating SDK versions. Also covers MCP Apps, extensions
Ready to connect
- View details
mobile-security-coderSkillSecurity
Gives your agent expert guidance on writing secure mobile code, covering input validation and WebView safety.
Ready to connect
- View details
oauth-providersSkillSecurity
Debug OAuth sign-in failures and add new OAuth providers to Keating (web + CLI). Use when a provider's "Sign in with …" flow fails, when adding a new OAuth provider, or when changing redirect URIs, token exchange, or refresh behavior.
Ready to connect
- View details
odylith-security-hardeningSkillSecurity
Apply Odylith security-hardening guidance to bounded product changes.
Ready to connect
- View details
pr-prepSkillSecurity
Use when creating a pull request for this project - triggers on "open a PR", "create a PR", "gh pr create", or any request to open/create a PR. Commits pending work, runs parallel CGU + security checks, writes a French PR description, then creates the PR with confirmation.
Ready to connect
- View details
privy-integrationSkillSecurity
Integrates Privy authentication, embedded wallets, and agent payment protocols into web and agentic apps. Covers React SDK (PrivyProvider, hooks, wagmi), Node.js SDK, smart wallets (ERC-4337), x402 and MPP machine payments, Tempo chain, and agentic wallets with policies. Use when setting up Privy au
Ready to connect
- View details
skill-doctorSkillSecurity
Use when a user wants agent setup graded from conversation history. Produces an HTML report with 0-10 scores, evidence-cited findings, and ranked suggestions. Not for skill fixing — use skill-improver; not for security scanning — use skill-scanner.
Ready to connect
- View details
supply-chain-defenseSkillSecurity
Behavioural-first defense against poisoned npm/PyPI packages in the publish-to-advisory window CVE tools miss. Use before every install or version bump: 7-day cooldown gate, Socket.dev behavioural score, stale-OIDC audit, publish-token rotation, and a worm-persistence self-scan.
Ready to connect
- View details
techdebtSkillSecurity
Technical debt detection and remediation. Run at session end to find duplicated code, dead imports, security issues, and complexity hotspots. Triggers: 'find tech debt', 'scan for issues', 'check code quality', 'wrap up session', 'ready to commit', 'before merge', 'code review prep'. Always uses par
Ready to connect
- View details
dependency-rebase-rulesSkillSecurity
Guidelines for working with rebase rules related to package.json dependencies, versions, and overrides. Covers CVE pins, version conflict detection, and package-lock.json handling. Referenced by rebase, fix-rebase-rules, validate-rebase-rules, and add-rebase-rules skills.
Ready to connect
- View details
github-issuesSkillSecurity
Read, summarize, and triage GitHub issues and pull requests for a repository using the authenticated GitHub MCP server. Invoke whenever the user asks about open issues, wants a repo's issues summarized or triaged, asks to find issues by label or author, or asks to draft an issue.
Ready to connect
- View details
ai-generated-business-code-reviewSkillSecurity
Use when reviewing or scoring AI-generated business/application code quality in any language, especially when a numeric score, risk level, or must-fix checklist is requested, or when C++ code must comply with OpenHarmony C++ and security standards
Ready to connect
- View details
api-integrationSkillSecurity
Integrate with external APIs using REST clients, webhook consumers, SDK wrappers, and polling patterns with proper authentication, error handling, and retry logic.
Ready to connect
- View details
arkweb-committer-reviewSkillSecurity
ArkWeb Committer code review. Reviews code quality, architecture compliance, security, and performance risks from a Committer's perspective. Runs as an independent subagent. Trigger words: 代码检视, Committer review, 代码审查.
Ready to connect
- View details
arkweb-security-patch-conflictSkillSecurity
Resolve ArkWeb patch merge conflicts while preserving upstream security fix intent.
Ready to connect
- View details
arkweb-security-patch-fetchSkillSecurity
Fetch and normalize the exact upstream Chromium security patch for ArkWeb integration.
Ready to connect
- View details
arkweb-security-patch-impactSkillSecurity
Determine whether ArkWeb M144 or configured baseline is affected by an upstream Chromium vulnerability.
Ready to connect
- View details
arkweb-security-patch-intakeSkillSecurity
Parse ArkWeb security issue inputs such as CVE, Chromium bug, Gerrit CL, PR, and advisory links into an auditable vulnerability intelligence report.
Ready to connect
- View details
arkweb-security-patch-judgeSkillSecurity
Judge ArkWeb state-machine step outputs and produce strict verdict JSON for state transitions.
Ready to connect
- View details
arkweb-security-patch-mergeSkillSecurity
Apply upstream Chromium patches into ArkWeb with deterministic patch normalization, batch planning, issue-scoped diff checks, and controlled manual merge fallback.
Ready to connect
- View details
arkweb-security-patch-reportSkillSecurity
Produce final ArkWeb archive or auto merge report from workflow outputs.
Ready to connect
- View details
arkweb-security-patch-reviewSkillSecurity
Review merged ArkWeb security patches for correctness, vulnerability coverage, and regression risk.
Ready to connect
What is a skill?
A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.
54,764 of the 55,196 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.
Install one and every AI you use gets it
Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.
Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.