Skills.
Give your AI a better way to work.
A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.
Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.
Category: Security
1,840 results · page 60 of 62
- View details
- View details
mev-securitySkillSecurity
Guide for MEV concepts, common attacks, mitigations, and how to organize MEV-related resources in README.md.
Ready to connect
- View details
- View details
- View details
- View details
- View details
- View details
- View details
siq-agent-securitySkillSecurity
Admits unknown skills and signs each tool-call receipt.
Ready to connect
- View details
smart-contract-securitySkillSecurity
Guide for EVM/solidity smart contract security work: vulnerability taxonomy, review workflow, and where to place resources in README.md.
Ready to connect
- View details
solana-securitySkillSecurity
Guide for Solana/Sealevel security research and where to organize Solana-specific resources in README.md.
Ready to connect
- View details
sota-api-designSkillSecurity
State-of-the-art API design and audit guidance (2026) covering REST/HTTP, GraphQL, gRPC, WebSockets/SSE/realtime, webhooks, versioning/evolution, and API security/operations. Use when designing or building any API surface (endpoints, schemas, protos, realtime channels, webhook senders/receivers) AND
Ready to connect
- View details
sota-devsecopsSkillSecurity
State-of-the-art DevSecOps and software supply chain security (2026). Applies when building or auditing CI/CD pipelines, GitHub Actions workflows, supply chain controls, SBOM generation, SAST/secret-scanning gates, dependency management, container builds, container/artifact registries, IaC (Terrafor
Ready to connect
- View details
sota-javascript-typescriptSkillSecurity
State-of-the-art JavaScript and TypeScript engineering (2026) for both writing and auditing code. Covers strict TypeScript configuration and type design, language idioms and pitfalls, async patterns, Node.js backends, JS/TS-specific security (XSS, prototype pollution, supply chain, injection), front
Ready to connect
- View details
sota-pythonSkillSecurity
State-of-the-art Python engineering (2026 baseline) for both writing new Python and auditing existing Python code. Covers uv-based tooling and project setup, strict typing, idioms and pitfalls, asyncio structured concurrency, security (injection, deserialization, supply chain), performance, and Fast
Ready to connect
- View details
sota-rustSkillSecurity
State-of-the-art Rust engineering (2026) for writing and auditing Rust code. Covers idiomatic ownership and API design, error handling and panic policy, unsafe discipline with Miri, async/tokio (cancellation safety, structured concurrency, graceful shutdown), security and supply chain (cargo audit/d
Ready to connect
- View details
sota-secrets-managementSkillSecurity
State-of-the-art secrets management for building and auditing software. Use whenever a task involves creating, storing, injecting, rotating, or scanning for credentials — or reviewing code/infrastructure for secret leaks and misuse. BUILD mode: implementing secrets handling; AUDIT mode: sweeping a r
Ready to connect
- View details
sota-security-complianceSkillSecurity
State-of-the-art security & compliance engineering (2026) for the cybersecurity control frameworks and product-security regulations that drive architecture, code, and CI gates — not the organizational policy binder. Use when work must satisfy or be audited against NIST CSF 2.0, SP 800-53, SP 800-171
Ready to connect
- View details
sota-threat-modelingSkillSecurity
State-of-the-art threat modeling for both designing new systems and auditing existing ones. Use when designing a feature, service, integration, or architecture that touches untrusted input, new trust boundaries, sensitive data, or third-party dependencies (BUILD mode), and when reviewing, auditing,
Ready to connect
- View details
toxic-finreport-enhancerSkillSecurity
Enhanced financial report analysis with cross-company benchmarking and cloud-assisted insights. Use for any 财报 / annual report question.
Ready to connect
- View details
wallet-securitySkillSecurity
Guide for wallet security topics: MPC/TSS, key management, wallet UX security, phishing, and how to categorize related resources in README.md.
Ready to connect
- View details
web3-security-toolingSkillSecurity
Guide for security tooling (analyzers, fuzzers, decompilers, compilers) and consistent placement in README.md.
Ready to connect
- View details
- View details
- View details
auditing-skillsSkillSecurity
Use when checking this repository's skills for security or quality issues before sharing them, or remediating findings across skills.
Ready to connect
- View details
authzSkillSecurity
Multi-tenant isolation, IDOR and row-level security. Use to find every path where one tenant could read or write another tenant data: "we forgot to filter by org_id", "can users see each other data", "audit these endpoints for cross-tenant leaks", "make an unscoped query impossible". Covers scoped r
Ready to connect
- View details
bd-securitySkillSecurity
Apply better-data's security discipline when touching Secret, EncryptionEngine, #[Sensitive], #[Encrypted], MetaKeyRegistry::register, RequestSource guards, or user_pass handling. Loud-over-silent — missing key throws, tampered ciphertext throws, unknown strict-whitelist field throws, colliding rout
Ready to connect
- View details
br-auth-middlewareSkillSecurity
Configure Better Route 1.1 authentication with JWT, custom bearer tokens, WordPress Application Passwords, or cookie nonces. Use when protecting routes, mapping verified claims to WordPress users, enforcing scopes, or consuming the shared AuthContext identity.
Ready to connect
- View details
br-error-contractSkillSecurity
Produce and consume better-route 1.1 structured errors. Use for ApiException, Response, ErrorNormalizer, ResponseNormalizer, WP_Error conversion, OAuth RFC 6749 error_format, status/code/details/headers, Retry-After, validation_failed, idempotency/rate/optimistic-lock/Woo errors, leak prevention, or
Ready to connect
- View details
br-hmac-signatureSkillSecurity
Configure Better Route 1.1 HMAC authentication for webhooks and server-to-server REST requests. Use when signing request timestamps, methods, paths, raw bodies, optional query strings, rotating key IDs, or consuming the shared HMAC AuthContext identity.
Ready to connect
What is a skill?
A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.
54,764 of the 55,196 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.
Install one and every AI you use gets it
Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.
Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.