Skills.

Give your AI a better way to work.

A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.

Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.

Category: Security

1,840 results · page 61 of 62

  • br-jwks-jwt-authSkillSecurity

    Configure Better Route 1.1 RS256 or ES256 JWT verification from a local or HTTPS JWKS. Use when integrating OIDC/OAuth bearer tokens, selecting keys by kid, validating issuer/audience/lifetime, or operating JWKS caching and refresh behavior safely.

    Ready to connect

    github.com/lonsdale201/wp-agent-skills22 stars

    View details
  • br-owned-resource-guardsSkillSecurity

    Add Better Route 1.1 ownership authorization to raw routes and Resource DSL endpoints. Use when authenticated users may access only their own records, orders, profiles, memberships, tokens, or subscriptions.

    Ready to connect

    github.com/lonsdale201/wp-agent-skills22 stars

    View details
  • br-resource-policySkillSecurity

    Configure better-route 1.1 Resource action and field authorization. Use for ResourcePolicy::publicReadPrivateWrite, adminOnly, capabilities, callbacks, Resource::policy, permissionCallback, per-action rules, wildcard rules, fieldPolicy, public Resource OpenAPI security, ownership policies, or review

    Ready to connect

    github.com/lonsdale201/wp-agent-skills22 stars

    View details
  • ci-pipelineSkillSecurity

    CI pipeline discipline: lint→build→test→quality→security, fail-fast, deterministic build, secret handling, PR gates.

    Ready to connect

    github.com/byerlikaya/claude-starter-kit22 stars

    View details
  • colyseus-authoritative-multiplayerSkillSecurity

    Use when planning, implementing, or QA-reviewing MMOOMM realtime multiplayer with Colyseus rooms, server-authoritative simulation, room authentication, Schema state, fixed tick processing, client interpolation or reconciliation, reconnection, or MVP scaling. Applies to `@universo-react/colyseus-serv

    Ready to connect

    github.com/teknokomo/universo-platformo-react22 stars

    View details
  • deserialization-securitySkillSecurity

    Block unsafe deserialization and unsafe XML parsing in Java, Python, .NET, PHP, and Ruby: gadget chains, unrestricted type resolution, external entity expansion, and safer formats. Use when parsing or deserializing data from an untrusted source, wiring cookies, sessions, queues, or RPC payloads, or

    Ready to connect

    github.com/shieldnet-360/secure-vibe22 stars

    View details
  • dynamic-verificationSkillSecurity

    Confirm or refute a vulnerability candidate against a live target with a deterministic probe, respecting authorization and scope. Use when a SAST or LLM review flags a possible injection or SSRF, when triaging a finding before filing a bug or shipping a fix, or when a verification result turns out w

    Ready to connect

    github.com/shieldnet-360/secure-vibe22 stars

    View details
  • erc8128SkillSecurity

    Sign and verify HTTP requests with Ethereum wallets using ERC-8128. Use when building authenticated APIs that need wallet-based auth, making signed requests to ERC-8128 endpoints, implementing request verification in servers, or working with agent-to-server authentication. Covers both the @slicekit/

    Ready to connect

    github.com/slice-so/erc812822 stars

    View details
  • forge-security-reviewSkillSecurity

    Performs a white-box security review of Atlassian Forge apps using structured, Forge-specific security rules and evidence-driven reporting. Use when the user asks for a Forge security review, security audit, vuln assessment, pentest-style code review, authz review, tenant isolation analysis, web tri

    Ready to connect

    github.com/atlassian/forge-skills22 stars

    View details
  • graphql-securitySkillSecurity

    Bound and control a GraphQL endpoint: operation cost budgets, cost-based rate limiting, pre-registered operations, alias and batch abuse on authentication paths, introspection, cache keying, and untyped scalar inputs. Use when generating schemas, resolvers, or server config, wiring limits or persist

    Ready to connect

    github.com/shieldnet-360/secure-vibe22 stars

    View details
  • llm-app-securitySkillSecurity

    Securing a feature that calls an LLM: prompt injection as an unsolved input problem, bounding what model output is allowed to reach, tool authorization against the human rather than the model, approval gates on consequential actions, RAG context provenance, system-prompt leakage, and cost limits. Us

    Ready to connect

    github.com/shieldnet-360/secure-vibe22 stars

    View details
  • ml-securitySkillSecurity

    The model and data artifacts: checkpoint formats that execute code on load, provenance for a model you did not train, training-data poisoning and the ingestion controls that bound it, PII that survives into weights, and notebooks that commit their own output. Use when loading a model from disk, a Hu

    Ready to connect

    github.com/shieldnet-360/secure-vibe22 stars

    View details
  • protocol-securitySkillSecurity

    Transport security where the client establishes trust: TLS version floor, certificate chain and hostname verification, the trust store, connecting by IP, mTLS and workload identity as authentication, gRPC channel credentials, and SMTP STARTTLS. Use when generating HTTP, gRPC, or SMTP clients and ser

    Ready to connect

    github.com/shieldnet-360/secure-vibe22 stars

    View details
  • review-or-optimize-agent-skillSkillSecurity

    Use when the user asks to review, audit, tune, or optimize an agent skill or SKILL.md for trigger precision, progressive disclosure, portability, deterministic mechanics, authority, or security. Select it first and resolve the target inside the workflow, including when the request points at "this sk

    Ready to connect

    github.com/eugenelim/agent-ready-repo22 stars

    View details
  • saas-securitySkillSecurity

    Wiring your application to a third-party SaaS platform: verifying an inbound webhook against the vendor's own scheme rather than a generalized one, why a valid signature identifies the sender and not the user in the payload, replay windows, one credential per integration and per environment, least-p

    Ready to connect

    github.com/shieldnet-360/secure-vibe22 stars

    View details
  • security-checklists-referenceSkillSecurity

    Route into the compiled OKF bundle `security-checklists` using generated indexes.

    Ready to connect

    github.com/eugenelim/agent-ready-repo22 stars

    View details
  • security-regression-testsSkillSecurity

    Turning a confirmed and fixed finding into a permanent guard: proving the test fails without the fix, asserting the effect and not only the status code, seeding the two principals an authorization test needs, making a timing or out-of-band proof deterministic enough for CI, and keeping the test in a

    Ready to connect

    github.com/shieldnet-360/secure-vibe22 stars

    View details
  • ship-it-or-fix-itSkillSecurity

    Oracle-frozen Builder and independent-Judge convergence cycle. Load ONLY when the operator explicitly sets Governance Dial G2 for the task, or explicitly names this skill or an active work unit already running it. Never auto-activate on task class, such as security, auth, or payments. If a task seem

    Ready to connect

    github.com/ezra144israel/governed-agent-skills22 stars

    View details
  • dependabot-reviewSkillSecurity

    Reviews open Dependabot PRs, classifies by risk (patch/minor/major, security, lockfile-only), and merges safe ones or advises on what to do. Use when user mentions "dependabot", "dependabot PRs", "dependency updates", "merge dependabot", "review dependabot", "dependency PRs", "bump PRs", "update dep

    Ready to connect

    github.com/joaquimscosta/arkhe-claude-plugins21 stars

    View details
  • emergency_triageSkillSecurity

    Use this skill as the FIRST action in clinic_agent whenever any symptom could indicate a life-threatening emergency. Triggered by keywords like 胸痛, 呼吸困难, 意识丧失, 大出血, 口眼歪斜, 抽搐, 过敏, 高烧40度 or similar red-flag language. Produces a mandatory safety check that must be shown to the user before any other res

    Ready to connect

    github.com/wananing/smart-health-assistant21 stars

    View details
  • fec-code-reviewSkillSecurity

    Use when the user asks for general frontend code review, PR review, merge-readiness assessment, architecture maintainability, type-safety, rendering/state risks, style consistency, testability gaps, or a cross-cutting review summary. Delegate deep security, accessibility, E2E, or performance investi

    Ready to connect

    github.com/bovinphang/frontend-craft21 stars

    View details
  • fec-dependency-upgradeSkillSecurity

    Use when planning, implementing, or reviewing frontend dependency upgrades, package migrations, lockfile changes, major framework version bumps, CVE remediation, peer dependency conflicts, ESM/CJS shifts, build-tool compatibility, or CI verification matrices; Chinese triggers include dependency upgr

    Ready to connect

    github.com/bovinphang/frontend-craft21 stars

    View details
  • fec-testing-strategySkillSecurity

    Use when planning or reviewing a frontend testing strategy, selecting the right test layer by risk, mapping coverage across static checks, unit tests, component tests, integration tests, E2E, Storybook/visual regression, a11y, security, performance, or CI gates. Do not use to write individual compon

    Ready to connect

    github.com/bovinphang/frontend-craft21 stars

    View details
  • review-securitySkillSecurity

    Internal security review pass of the agentic-workflow review pack — composed in-turn by review-change and product-audit; not a menu entry. Checks secrets, input validation, injection, authn/authz, PII exposure, and dependency risk on the changed surface. Findings only; never edits code.

    Ready to connect

    github.com/gtrabanco/agentic-workflow21 stars

    View details
  • skills-registry-securitySkillSecurity

    Checks the third-party security audit status of a skill published to a skills registry (skills.sh) across every cached surface, decides whether a failing finding is real or points at content already removed, and drives a stale badge to green unattended. Runs a real install to capture what users see,

    Ready to connect

    github.com/starslingdev/skills21 stars

    View details
  • spring-boot-securitySkillSecurity

    Spring Security 7 implementation for Spring Boot 4. Use when configuring authentication, authorization, OAuth2/JWT resource servers, method security, or CORS/CSRF. Covers the mandatory Lambda DSL migration, SecurityFilterChain patterns, @PreAuthorize, and password encoding. For testing secured endpo

    Ready to connect

    github.com/joaquimscosta/arkhe-claude-plugins21 stars

    View details
  • spring-boot-testingSkillSecurity

    Guides your agent to pick the right Spring Boot testing approach with JUnit 6 and AssertJ.

    Ready to connect

    github.com/joaquimscosta/arkhe-claude-plugins21 stars

    View details
  • header-injectionSkillSecurity

    Detects HTTP response header construction from user input vulnerable to CRLF

    Ready to connect

    github.com/thejefflarson/soundcheck20 stars

    View details
  • hotspotsSkillSecurity

    Maps security-sensitive code locations in a codebase to focus review effort.

    Ready to connect

    github.com/thejefflarson/soundcheck20 stars

    View details
  • ipc-securitySkillSecurity

    Detects IPC receivers that accept input without verifying caller identity. Use

    Ready to connect

    github.com/thejefflarson/soundcheck20 stars

    View details

What is a skill?

A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.

54,764 of the 55,196 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.

Install one and every AI you use gets it

Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.

Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.

See how to connect your AI