Skills.
Give your AI a better way to work.
A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.
Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.
Filter by category
54,220 results · page 414 of 1,808
- View details
correlateSkillSecurity
Lets your agent link individual security findings into complete attack chains.
Ready to connect★ 944
- View details
correlatorSkillSecurity
Lets your agent combine separate security findings into higher-impact attack chains.
Ready to connect★ 944
- View details
cors-hunterSkillSecurity
Lets your agent test websites for misconfigured CORS policies like origin reflection and null origin bypass.
Ready to connect★ 944
- View details
costSkillSecurity
Lets your agent show cost tracking and ROI figures for the current engagement.
Ready to connect★ 944
- View details
csrf-hunterSkillSecurity
Lets your agent test websites for missing CSRF protections that could let attackers forge user actions.
Ready to connect★ 944
- View details
dast-devils-advocateSkillSecurity
Has your agent challenge and downgrade security scan findings by trying to disprove each one.
Ready to connect★ 944
- View details
dupcheckSkillSearch
Lets your agent check if a vulnerability has already been reported by searching platform activity and local findings.
Ready to connect★ 944
- View details
file-uploadSkillFiles & storage
Lets your agent test file upload features for security flaws like bypassed filters and unsafe filenames.
Ready to connect★ 944
- View details
fullscanSkillSecurity
Lets your agent run a full security assessment that reuses past findings and skips already-checked areas.
Ready to connect★ 944
- View details
graphql-auditSkillSecurity
Lets your agent security-test GraphQL APIs for injection, authorization bypasses, and query abuse.
Ready to connect★ 944
- View details
huntSkillSecurity
Lets your agent run targeted security tests against a target website to find vulnerabilities like XSS or SQLi.
Ready to connect★ 944
- View details
hunt-info-disclosureSkillSecurity
Guides your agent to hunt for exposed secrets, leaked files like .env or .git, and debug endpoints on a target.
Ready to connect★ 944
- View details
hunt-xssSkillSecurity
Lets your agent hunt for XSS bugs using patterns from 1,500+ public bug bounty reports and verified CVEs.
Ready to connect★ 944
- View details
hunting-methodologySkillSecurity
Guides your coding agent through bug bounty hunting with structured agents, commands, and exploit chain building.
Ready to connect★ 944
- View details
idor-hunterSkillSecurity
Lets your agent test web apps and APIs for access control flaws that let one user read another user's data.
Ready to connect★ 944
- View details
info-disclosureSkillFiles & storage
Lets your agent hunt for exposed sensitive data like API keys, .env files, debug endpoints, and leaked source code.
Ready to connect★ 944
- View details
js-analyzerSkillFiles & storage
Lets your agent analyze JavaScript files or URLs to find hardcoded secrets, XSS flows, and API endpoints.
Ready to connect★ 944
- View details
llm-ai-hunterSkillSecurity
Lets your agent analyze AI systems for vulnerabilities like prompt injection and data poisoning.
Ready to connect★ 944
- View details
monitorSkillMonitoring & ops
Lets your agent watch target websites in authorized bug bounty programs and detect changes over time.
Ready to connect★ 944
- View details
nuclei-writerSkillSecurity
Lets your agent write custom nuclei templates to check a known vulnerability pattern across many targets.
Ready to connect★ 944
- View details
oauth-hunterSkillSecurity
Helps your agent find security flaws in login systems like OAuth, SAML, and JWT tokens.
Ready to connect★ 944
- View details
open-redirectSkillSecurity
Lets your agent test web app redirect parameters, login flows, and OAuth callbacks for open redirect vulnerabilities.
Ready to connect★ 944
- View details
pentest-agents-hunting-methodologySkillSecurity
Lets your agent run structured security testing and bug bounty hunting workflows against target systems.
Ready to connect★ 944
- View details
pentest-agents-recon-methodologySkillSecurity
Guides your agent through bug bounty reconnaissance, from passive subdomain discovery to organizing attack candidates.
Ready to connect★ 944
- View details
pipelineSkillSecurity
Lets your agent run reconnaissance and scanning on a target to rank attack surfaces before a pentest.
Ready to connect★ 944
- View details
poc-builderSkillSecurity
Helps your agent turn a confirmed vulnerability into reproduction steps, demo pages, and bug bounty reports.
Ready to connect★ 944
- View details
privilege-escalationSkillSecurity
Lets your agent test whether user roles and permissions can be bypassed to gain higher access.
Ready to connect★ 944
- View details
qualitySkillSecurity
Lets your agent score a pentest report draft or finding before you submit it.
Ready to connect★ 944
- View details
quality-checkSkillSecurity
Lets your agent score a draft report for completeness, clarity, and accuracy before you submit it.
Ready to connect★ 944
- View details
quickscanSkillSecurity
Lets your agent run a quick security scan on a target with passive recon and vulnerability checks.
Ready to connect★ 944
What is a skill?
A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.
53,788 of the 54,220 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.
Install one and every AI you use gets it
Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.
Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.