Skills.
Give your AI a better way to work.
A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.
Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.
Filter by category
54,220 results · page 415 of 1,808
- View details
race-conditionSkillSecurity
Lets your agent test for race condition flaws like double-spend and parallel request abuse.
Ready to connect★ 944
- View details
rce-hunterSkillSecurity
Lets your agent test websites for code injection flaws that let attackers run commands on a server.
Ready to connect★ 944
- View details
reconSkillSearch
Lets your agent scan a target's domains, ports, and services to map its exposed tech footprint.
Ready to connect★ 944
- View details
recon-rankerSkillSecurity
Lets your agent turn recon results into a prioritized list of attack targets with ready-to-run test commands.
Ready to connect★ 944
- View details
report-writerSkillDocs & knowledge
Lets your agent turn penetration test findings into formal reports, executive summaries, and bug bounty submissions.
Ready to connect★ 944
- View details
resumeSkillDocs & knowledge
Lets your agent resume a past security testing hunt, showing its history and untested targets.
Ready to connect★ 944
- View details
sastSkillFiles & storage
Lets your agent scan source code for security vulnerabilities using multi-pass static analysis.
Ready to connect★ 944
- View details
sast-danger-mapperSkillFiles & storage
Lets your agent scan a source file and list risky operations like memory access, type casts, and deallocation patterns.
Ready to connect★ 944
- View details
sast-devils-advocateSkillSecurity
Lets your agent challenge security scan alerts by trying to prove each one is a false positive.
Ready to connect★ 944
- View details
sast-entry-mapperSkillFiles & storage
Lets your agent find where untrusted external data enters a source file and list each input-handling function.
Ready to connect★ 944
- View details
sast-exploit-builderSkillSecurity
Lets your agent turn a confirmed software crash into a working exploit, from denial-of-service up to code execution.
Ready to connect★ 944
- View details
sast-file-rankerSkillFiles & storage
Lets your agent scan a repository and rank source files 1-5 by how likely they are to have exploitable security flaws.
Ready to connect★ 944
- View details
sast-flow-tracerSkillFiles & storage
Lets your agent trace how data flows through code from entry points to dangerous operations to find vulnerabilities.
Ready to connect★ 944
- View details
sast-gap-analyzerSkillSecurity
Analyzes traced code flows to find where security checks are missing, insufficient, or can be bypassed.
Ready to connect★ 944
- View details
sast-hunterSkillSecurity
Lets your agent write, compile, and run proof-of-concept tests for suspected code vulnerabilities to confirm or reject them.
Ready to connect★ 944
- View details
sast-methodologySkillSecurity
Gives your agent a structured framework for running security bug hunts and building exploit chains autonomously.
Ready to connect★ 944
- View details
scope-checkSkillFiles & storage
Lets your agent check whether testing targets are allowed before starting security tests.
Ready to connect★ 944
- View details
sqli-hunterSkillDatabases & data
Lets your agent test web endpoints for SQL injection vulnerabilities using several attack techniques.
Ready to connect★ 944
- View details
ssrf-hunterSkillFiles & storage
Lets your agent test web app URL parameters and webhooks for server-side request forgery vulnerabilities.
Ready to connect★ 944
- View details
subdomain-takeoverSkillSecurity
Lets your agent find dangling DNS records pointing to unclaimed cloud resources that could be taken over.
Ready to connect★ 944
- View details
submitSkillSecurity
Lets your agent draft a vulnerability report from findings and submit it to a bug bounty program after your review.
Ready to connect★ 944
- View details
syncSkillSecurity
Lets your agent pull program details, policies, and activity from bug bounty platforms like HackerOne or Bugcrowd.
Ready to connect★ 944
- View details
validateSkillSecurity
Lets your agent check whether a security finding is real by running it through a structured validation checklist.
Ready to connect★ 944
- View details
validatorSkillSecurity
Lets your agent test security findings against a 7-question gate and 4-gate checklist to drop weak ones early.
Ready to connect★ 944
- View details
vuln-classesSkillSecurity
Lets your agent run security bug-hunting workflows to find and test software vulnerabilities.
Ready to connect★ 944
- View details
vuln-scannerSkillSecurity
Lets your agent scan a website for known security vulnerabilities using quick, standard, or thorough profiles.
Ready to connect★ 944
- View details
waf-profilerSkillDocs & knowledge
Lets your agent identify a website's firewall, map its blocking rules, and document how it behaves before security testing.
Ready to connect★ 944
- View details
web3-auditorSkillSecurity
Lets your agent audit smart contracts and DeFi code for security vulnerabilities and build proof-of-concept exploits.
Ready to connect★ 944
- View details
xss-hunterSkillSecurity
Lets your agent analyze web apps for cross-site scripting flaws including reflected, stored, and DOM-based types.
Ready to connect★ 944
- View details
xxe-hunterSkillFiles & storage
Lets your agent test XML-parsing features like file uploads and SOAP services for XXE vulnerabilities.
Ready to connect★ 944
What is a skill?
A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.
53,788 of the 54,220 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.
Install one and every AI you use gets it
Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.
Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.