Skills.
Give your AI a better way to work.
A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.
Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.
Category: Security
1,840 results · page 57 of 62
- View details
agentclash-cli-setupSkillSecurity
Use when configuring the AgentClash CLI, authenticating with device login or tokens, selecting a workspace, saving default config with link, creating project config with init, resolving API URL precedence, or diagnosing CLI access against production, local, or self-hosted backends.
Ready to connect
- View details
agentclash-security-evaluationSkillSecurity
Use when running client-side security stress harnesses against security challenge packs, measuring leak posture, Agent Vault routing, or HashiCorp Vault runtime leaks with agentclash security commands.
Ready to connect
- View details
auth-patternsSkillSecurity
JWT access/refresh tokens, Passport.js strategies, session management, OAuth. Use when implementing authentication, authorization, or setting up OAuth providers in a NestJS + Next.js app.
Ready to connect
- View details
healthbankoneSkillSecurity
Pull verified medical records and digital-identity context from Health Bank One (https://www.healthbankone.com) via their MCP server. HBO uses OAuth 2.x with per-consumer authorization, so this skill drives an authorization-code grant first, then runs the MCP pull, then ingests the redacted bundle i
Ready to connect
- View details
healthcheckSkillSecurity
Use when auditing or hardening the host running CrawClaw, including security posture review, exposure assessment, firewall or SSH hardening, periodic host audits, or version checks.
Ready to connect
- View details
plan-tddSkillSecurity
Turn a plain-language feature or module description into a reviewed TDD plan. Ask clarifying questions when context is missing, then design behavior cycles and assertions with edge, error, and security scenarios made explicit, and emit a self-contained HTML brief plus a machine-readable YAML plan th
Ready to connect
- View details
updateSkillSecurity
Automates and manages package updates and vulnerability fixes for Rito.
Ready to connect
- View details
cra-produktanforderungenSkillSecurity
Determination of the essential cybersecurity requirements per Annex I Regulation (EU) 2024/2847 – product security properties per Annex I Part I, vulnerability handling requirements per Annex I Part II, cybersecurity risk assessment per Art. 13 CRA, software bill of materials (SBOM),
Ready to connect
- View details
cra-vulnerability-managementSkillSecurity
Establishing and reviewing vulnerability management per Annex I Part II of Regulation (EU) 2024/2847 – coordinated vulnerability disclosure policy (CVD policy), contact point and intake channels for reports, triage and assessment, remediation via security updates, and secure update distribution with
Ready to connect
- View details
grundschuld-sicherungsrechtSkillSecurity
Land charge as loan security – creation and content under §§ 1191 ff. BGB, the collateral agreement as the contractual link between land charge and loan, submission to immediate enforcement under § 794 (1) no. 5 ZPO including clause issuance § 726 ZPO and successor-in-title clause § 727 ZPO.
Ready to connect
- View details
kritis-anwendungsbereich-registrierungSkillSecurity
Scope of application and registration under the KRITIS umbrella act – ten sectors § 4 (1) (energy, transport, finance, social security, health, water, food, IT and telecommunications, space, municipal waste disposal), sector exemptions § 4 (2), in particular for DOR
Ready to connect
- View details
zahlungsdiensthaftungSkillSecurity
Haftungsverteilung bei nicht autorisierten Zahlungsvorgängen. Zahlungsdiensterahmen § 675c BGB, Erstattungsanspruch bei nicht autorisiertem Zahlungsvorgang § 675u BGB, Haftung des Zahlers bei grober Fahrlässigkeit § 675v BGB. Use when eine unautorisierte Abbuchung, ein Phishing- oder Kartenmissbrauc
Ready to connect
- View details
better-auth-setupSkillSecurity
Guide implementation of OAuth 2.1 / OIDC authentication using Better Auth with the OIDC Provider plugin. Use this skill when setting up centralized authentication for multiple apps, implementing SSO across a platform, creating an OAuth authorization server, or integrating Better Auth as an identity
Ready to connect
- View details
better-auth-ssoSkillSecurity
Integrate with Better Auth SSO for OAuth2/OIDC authentication. Use this skill when implementing SSO login flows, PKCE authentication, token management, JWKS verification, or global logout in Next.js applications connecting to a Better Auth server.
Ready to connect
- View details
building-chat-interfacesSkillSecurity
Build AI chat interfaces with custom backends, authentication, and context injection. Use when integrating chat UI with AI agents, adding auth to chat, injecting user/page context, or implementing httpOnly cookie proxies. Covers ChatKitServer, useChatKit, and MCP auth patterns. NOT when building sim
Ready to connect
- View details
code-qualitySkillSecurity
Multi-language code quality standards and review for TypeScript, Python, Go, and Rust. Enforces type safety, security, performance, and maintainability. Use when writing, reviewing, or refactoring code. Includes review process, checklist, and Python PEP 8 deep-dive.
Ready to connect
- View details
configuring-better-authSkillSecurity
Implement OAuth 2.1 / OIDC authentication using Better Auth with MCP assistance. Use when setting up a centralized auth server (SSO provider), implementing SSO clients in Next.js apps, configuring PKCE flows, or managing tokens with JWKS verification. Uses Better Auth MCP for guided setup. NOT when
Ready to connect
- View details
domain-webSkillSecurity
Use when building web services. Keywords: web server, HTTP, REST API, GraphQL, WebSocket, axum, actix, warp, rocket, tower, hyper, reqwest, middleware, router, handler, extractor, state management, authentication, authorization, JWT, session, cookie, CORS, rate limiting, web development, HTTP servic
Ready to connect
- View details
prismatic-apiSkillSecurity
Prismatic API access patterns and GraphQL reference. Covers the two-tier access hierarchy (MCP tools → Prism CLI), CLI usage rules, GraphQL query patterns, pagination, authentication, and managing platform resources programmatically.
Ready to connect
- View details
system-architectSkillSecurity
System architecture skill for designing scalable, maintainable software systems. Covers microservices/monolith decisions, API design, DB selection, caching, security, and scalability planning.
Ready to connect
- View details
trailofbits-securitySkillSecurity
Security-focused static analysis and code auditing skills from Trail of Bits. Includes CodeQL deep analysis, Semgrep scanning, and SARIF result processing. Use when performing security audits, running static analysis, scanning for vulnerabilities, or processing scan results.
Ready to connect
- View details
astro-securitySkillSecurity
Use when configuring Content Security Policy (CSP) in Astro 7 — security headers, script/style hashes, nonces, or experimentalStaticHeaders.
Ready to connect
- View details
audit-algorandSkillSecurity
Perform structured security audits and adversarial reviews of TypeScript Algorand applications and LogicSigs compiled with PuyaTs. Use for vulnerability assessments, threat models, exploit analysis, mainnet-readiness reviews, security findings, and remediation guidance involving AVM contracts, gener
Ready to connect
- View details
auth-auditSkillSecurity
Use when auditing JWT, session, OAuth2/PKCE, password, or MFA implementations for security vulnerabilities and best-practice deviations.
Ready to connect
- View details
bump-dependencySkillSecurity
Research and safely apply npm dependency version bumps across the Plumber monorepo (root, backend, frontend, types). Use when the user asks to bump/update/upgrade a package, asks whether a version bump has breaking changes, or wants a dependency security patch applied.
Ready to connect
- View details
cve-researchSkillSecurity
Use when checking a specific dependency or package version for known CVEs and security advisories.
Ready to connect
- View details
design-webappSkillSecurity
Use when building or extending a dashboard, SaaS screen, or any authenticated app surface — use design-web instead for a marketing site.
Ready to connect
- View details
djangoSkillSecurity
Use when building Django applications. Covers ORM query performance, model design, migrations, Django REST Framework, security defaults, and testing.
Ready to connect
- View details
go-testing-qualitySkillSecurity
Use when writing or reviewing Go tests, adding coverage, benchmarking, or profiling a Go program. Not for CI/lint wiring (go-tooling-security) or non-Go tests.
Ready to connect
- View details
go-tooling-securitySkillSecurity
Use when setting up Go modules/workspaces, configuring golangci-lint v2, running govulncheck, or building a Go CI quality gate. Not for app logic or non-Go audits.
Ready to connect
What is a skill?
A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.
54,764 of the 55,196 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.
Install one and every AI you use gets it
Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.
Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.