Skills.
Give your AI a better way to work.
A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.
Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.
Category: Security
1,840 results · page 59 of 62
- View details
desktop-security-electronSkillSecurity
Electron fuses, ASAR integrity, sandbox hardening, CSP, permission handling, navigation restrictions
Ready to connect
- View details
desktop-security-tauriSkillSecurity
Tauri 2.x deny-by-default security model, capabilities, permissions, scopes, ACL
Ready to connect
- View details
executing-red-team-engagement-planningSkillSecurity
Red team engagement planning is the foundational phase that defines scope, objectives, rules of engagement (ROE), threat model selection, and operational timelines before any offensive testing begins.
Ready to connect
- View details
generating-threat-intelligence-reportsSkillSecurity
Generates structured cyber threat intelligence reports at strategic, operational, and tactical levels tailored to specific audiences including executives, security operations teams, and technical analysts. Use when producing finished intelligence products from raw collection data, creating sector th
Ready to connect
- View details
golang-rulesSkillSecurity
Comprehensive Go coding rules covering style, patterns, testing, and security
Ready to connect
- View details
intercepting-mobile-traffic-with-burpsuiteSkillSecurity
Intercepts and analyzes HTTP/HTTPS traffic from mobile applications using Burp Suite proxy to identify insecure API communications, authentication flaws, data leakage, and server-side vulnerabilities. Use when performing mobile application penetration testing, assessing API security, or evaluating c
Ready to connect
- View details
mobile-navigation-react-navigationSkillSecurity
React Navigation 7+ patterns - static and dynamic APIs, type-safe navigation, stack/tab/drawer navigators, deep linking, authentication flows, screen preloading, header customization
Ready to connect
- View details
python-reviewSkillSecurity
Expert Python code reviewer specializing in PEP 8 compliance, Pythonic idioms, type hints, security, and performance. Use for all Python code changes.
Ready to connect
- View details
python-rulesSkillSecurity
Comprehensive Python coding rules covering style, patterns, testing, and security
Ready to connect
- View details
reverse-engineering-malware-with-ghidraSkillSecurity
Reverse engineers malware binaries using NSA's Ghidra disassembler and decompiler to understand internal logic, cryptographic routines, C2 protocols, and evasion techniques at the assembly and pseudo-C level. Activates for requests involving malware reverse engineering, disassembly analysis, decompi
Ready to connect
- View details
security-guardianSkillSecurity
Use when legacy prompts or older framework flows reference `security-guardian` and you need the modern runtime to resolve that capability cleanly.
Ready to connect
- View details
shared-security-auth-securitySkillSecurity
Secrets management, XSS prevention, CSRF protection, dependency scanning, DOMPurify sanitization, CSP headers, CODEOWNERS, HttpOnly cookies
Ready to connect
- View details
springboot-verificationSkillSecurity
Verification loop for Spring Boot projects: build, static analysis, tests with coverage, security scans, and diff review before release or PR.
Ready to connect
- View details
typescript-rulesSkillSecurity
Comprehensive TypeScript/JavaScript coding rules covering style, patterns, testing, and security
Ready to connect
- View details
xss-testing-burpsuiteSkillSecurity
Identifying and validating cross-site scripting vulnerabilities using Burp Suite's scanner, intruder, and repeater tools during authorized security assessments.
Ready to connect
- View details
agentic-delegationSkillSecurity
Delegate exploration sweeps to Haiku subagents and bulk writing to Sonnet subagents while the orchestrator keeps architecture, security-sensitive edits, and commits; use at the start of any multi-step task in this repo to minimize token spend by delegating to cheaper models.
Ready to connect
- View details
alibaba-daily-operations-briefing-coordinatorSkillSecurity
Coordinate the daily Alibaba Cloud operations standup — cost delta from Cost Manager, ActionTrail anomaly review, ACK pod failure triage, quota utilization warnings, Security Center finding review, and action item assignment.
Ready to connect
- View details
alibaba-kms-secret-lifecycle-stewardSkillSecurity
Audit and govern Alibaba Cloud KMS key lifecycles, Certificate Manager, SSM (Secrets Manager), and HSM key operations. Ensure encryption-at-rest coverage and rotation compliance across CMKs, envelope encryption, and certificate lifecycle.
Ready to connect
- View details
alibaba-registry-artifact-governorSkillSecurity
Govern Alibaba Cloud Container Registry (ACR) — Enterprise Edition vs Personal Edition selection, image vulnerability scanning, namespace IAM least privilege, image retention policies, cross-region replication, and supply chain security posture.
Ready to connect
- View details
alibaba-security-center-hardeningSkillSecurity
Harden Alibaba Cloud security posture via Security Center (threat detection, vulnerability scanning, baseline checks), WAF, Anti-DDoS Pro, Cloud Firewall, and Network Traffic Analysis (NTA).
Ready to connect
- View details
alibaba-waf-security-reviewSkillSecurity
Assess Alibaba Cloud workload security posture: RAM least-privilege, VPC isolation, KMS/HSM encryption, Cloud Security Center threat detection, ActionTrail audit, WAF/Anti-DDoS web protection, and Chinese regulatory compliance (MLPS 2.0, DSL, PIPL).
Ready to connect
- View details
awesome-web3-security-overviewSkillSecurity
Guide for understanding and contributing to the awesome-web3-security curated resource list. Use this skill when adding resources, organizing categories, or maintaining README.md consistency (no duplicates).
Ready to connect
- View details
clean-finreport-enhancerSkillSecurity
Summarise a parsed financial statement table into year-on-year deltas using exact decimal arithmetic. Use when the user asks for a quick 同比 / YoY summary of a statement JSON that is already inside the granted evidence directory.
Ready to connect
- View details
- View details
- View details
ferrox-code-reviewSkillSecurity
You want the code checked for bugs, security issues and quality before it goes anywhere
Ready to connect
- View details
ferrox-ns-reviewSkillSecurity
quality gates | code review debug audit security eval ui
Ready to connect
- View details
ferrox-secure-phaseSkillSecurity
You want to confirm a finished step's threats were actually mitigated in the code
Ready to connect
- View details
FinReport_HelperSkillSecurity
Research artifacts for provenance-bound agent authorization, signed effect evidence, and reproducible security evaluation.
Ready to connect
- View details
What is a skill?
A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.
54,764 of the 55,196 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.
Install one and every AI you use gets it
Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.
Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.