Skills.
Give your AI a better way to work.
A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.
Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.
Filter by category
53,863 results · page 165 of 1,796
- View details
hunt-fintech-graphqlSkillSecurity
Lets your agent hunt fintech GraphQL vulnerabilities like transfer mutations, IDOR queries, and double-spend bugs.
Ready to connect★ 4k
- View details
hunt-forgot-passwordSkillCommunication
Lets your agent test password reset and account recovery flows for common security flaws like token leaks and replay.
Ready to connect★ 4k
- View details
hunt-graphqlSkillSecurity
Lets your agent hunt for GraphQL vulnerabilities like IDOR, SSRF, and auth bypass using patterns from real bug bounty reports.
Ready to connect★ 4k
- View details
hunt-grpcSkillFiles & storage
Lets your agent scan gRPC servers for security weaknesses like missing authentication and exposed services.
Ready to connect★ 4k
- View details
hunt-host-headerSkillSecurity
Lets your agent test websites for host header attacks like password reset poisoning and cache poisoning.
Ready to connect★ 4k
- View details
hunt-html-injectionSkillSecurity
Guides your agent to find HTML injection flaws where user input is rendered as raw HTML in web responses.
Ready to connect★ 4k
- View details
hunt-http-smugglingSkillAI & models
Lets your agent test websites for HTTP request smuggling flaws where proxies and servers disagree on request boundaries.
Ready to connect★ 4k
- View details
hunt-idorSkillSecurity
Guides your agent through testing websites for IDOR access-control bugs using patterns from real bug bounty reports.
Ready to connect★ 4k
- View details
hunt-jwt-cryptoSkillSecurity
Lets your agent find JWT authentication flaws that let attackers forge tokens for any identity.
Ready to connect★ 4k
- View details
hunt-k8sSkillCloud & infra
Lets your agent scan Kubernetes and Docker setups for known security weaknesses and misconfigurations.
Ready to connect★ 4k
- View details
hunt-laravelSkillSecurity
Lets your agent scan Laravel apps for common vulnerabilities like debug mode leaks and known exploits.
Ready to connect★ 4k
- View details
hunt-ldapSkillSearch
Teaches your agent how to find LDAP and XPath injection flaws like auth bypass and data exfiltration.
Ready to connect★ 4k
- View details
hunt-lfiSkillFiles & storage
Lets your agent test web apps for file inclusion and path traversal flaws that could expose or overwrite files.
Ready to connect★ 4k
- View details
hunt-llm-aiSkillWeb & browsing
Helps your agent find and test AI security bugs like prompt injection and data exfiltration in LLM apps.
Ready to connect★ 4k
- View details
hunt-mfa-bypassSkillCommunication
Hunts for MFA and 2FA bypass weaknesses in a target app across seven known attack patterns.
Ready to connect★ 4k
- View details
hunt-miscSkillSecurity
Guides your agent through hunting miscellaneous vulnerabilities using patterns from 225 public bug bounty reports.
Ready to connect★ 4k
- View details
hunt-nextjsSkillSecurity
Lets your agent scan a Next.js app for known vulnerabilities like auth bypass, cache poisoning, and SSRF.
Ready to connect★ 4k
- View details
hunt-nodejsSkillFiles & storage
Lets your agent scan Node.js code for vulnerabilities like prototype pollution, eval injection, and path traversal.
Ready to connect★ 4k
- View details
hunt-nosqliSkillDatabases & data
Lets your agent test apps that use MongoDB, CouchDB, or Redis for NoSQL injection flaws.
Ready to connect★ 4k
- View details
hunt-ntlm-infoSkillAI & models
Lets your agent probe internet-facing Windows servers for NTLM responses that leak internal network details.
Ready to connect★ 4k
- View details
hunt-oauthSkillSecurity
Lets your agent hunt for OAuth login vulnerabilities using lessons from 19 public bug bounty reports.
Ready to connect★ 4k
- View details
hunt-open-redirectSkillSecurity
Lets your agent find open redirect vulnerabilities in web apps, including chains leading to account takeover.
Ready to connect★ 4k
- View details
hunt-race-conditionSkillSecurity
Guides your agent to find and test race condition bugs in web apps using techniques from real bug bounty reports.
Ready to connect★ 4k
- View details
hunt-rag-vectorSkillDatabases & data
Lets your agent test RAG pipelines for poisoned vector stores and cross-tenant embedding leaks.
Ready to connect★ 4k
- View details
hunt-rceSkillSecurity
Guides your agent through finding remote code execution vulnerabilities using patterns from 67 public bug bounty reports.
Ready to connect★ 4k
- View details
hunt-samlSkillAI & models
Lets your agent analyze SAML and SSO logins for attack patterns like signature wrapping and comment injection.
Ready to connect★ 4k
- View details
hunt-sessionSkillCommunication
Lets your agent test web apps for session management flaws like fixation, weak session IDs, and token reuse.
Ready to connect★ 4k
- View details
hunt-sharepointSkillSecurity
Lets your agent scan on-prem SharePoint servers for known vulnerabilities and exposed login endpoints.
Ready to connect★ 4k
- View details
hunt-source-leakSkillFiles & storage
Lets your agent scan websites for leaked source maps, exposed .env/.git files, API docs, and hardcoded secrets.
Ready to connect★ 4k
- View details
hunt-spa-apiSkillWeb & browsing
Lets your agent find a web app's hidden backend API from its JavaScript and test it for missing access controls.
Ready to connect★ 4k
What is a skill?
A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.
53,430 of the 53,863 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.
Install one and every AI you use gets it
Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.
Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.