Skills.

Give your AI a better way to work.

A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.

Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.

Filter by category

54,220 results · page 433 of 1,808

  • arbitrary-write-to-rceSkillDev tools

    Guides an agent through converting an arbitrary memory-write bug into code execution using exploitation techniques.

    Ready to connect★ 842

    github.com/zyrexnn/cybermes730 stars

    View details
  • auth-secSkillSecurity

    Routes your agent to the right authentication and authorization security testing topic like sessions, JWT, OAuth, or CSRF.

    Ready to connect★ 842

    github.com/zyrexnn/cybermes730 stars

    View details
  • authbypass-authentication-flawsSkillSecurity

    Runs a playbook for testing whether login flows, password resets, and session controls can be bypassed.

    Ready to connect★ 842

    github.com/zyrexnn/cybermes730 stars

    View details
  • autonomous-godmode-hunterSkillSecurity

    Lets your agent run authorized security scans on a target and turn confirmed bugs into proof-of-concept scripts and reports.

    Ready to connect★ 842

    github.com/zyrexnn/cybermes730 stars

    View details
  • binary-protection-bypassSkillDev tools

    Guides your agent through identifying and bypassing binary protections like ASLR and DEP in ELF executables.

    Ready to connect★ 842

    github.com/zyrexnn/cybermes730 stars

    View details
  • browser-exploitation-v8SkillWeb & browsing

    Lets your agent follow a playbook for exploiting JavaScript engine bugs to escape Chrome's sandbox.

    Ready to connect★ 842

    github.com/zyrexnn/cybermes730 stars

    View details
  • business-logic-and-idorSkillDev tools

    Lets your agent test whether an app's user permissions can be bypassed, such as accessing other users' data.

    Ready to connect★ 842

    github.com/zyrexnn/cybermes730 stars

    View details
  • business-logic-vulnSkillDev tools

    Routes security testing tasks toward business logic flaws like race conditions and pricing bugs.

    Ready to connect★ 842

    github.com/zyrexnn/cybermes730 stars

    View details
  • business-logic-vulnerabilitiesSkillSecurity

    Gives your agent a playbook for finding business logic flaws like price manipulation and authorization gaps.

    Ready to connect★ 842

    github.com/zyrexnn/cybermes730 stars

    View details
  • classical-cipher-analysisSkillDev tools

    Lets your agent analyze and break classical ciphers like substitution, Vigenere, transposition, and XOR in CTF challenges.

    Ready to connect★ 842

    github.com/zyrexnn/cybermes730 stars

    View details
  • clickjackingSkillDev tools

    Lets your agent test whether web pages can be framed and check clickjacking protections like X-Frame-Options.

    Ready to connect★ 842

    github.com/zyrexnn/cybermes730 stars

    View details
  • cmdi-command-injectionSkillDev tools

    Teaches your agent to spot and prevent cases where user input could run shell commands.

    Ready to connect★ 842

    github.com/zyrexnn/cybermes730 stars

    View details
  • code-obfuscation-deobfuscationSkillDev tools

    Lets your agent analyze and reverse obfuscated code like junk code, control flow flattening, and string encryption.

    Ready to connect★ 842

    github.com/zyrexnn/cybermes730 stars

    View details
  • container-escape-techniquesSkillCloud & infra

    Gives your agent a playbook of techniques for breaking out of a Docker, LXC, or Kubernetes container to the host.

    Ready to connect★ 842

    github.com/zyrexnn/cybermes730 stars

    View details
  • cors-cross-origin-misconfigurationSkillWeb & browsing

    Guides your agent through testing websites for CORS misconfigurations that expose authenticated APIs.

    Ready to connect★ 842

    github.com/zyrexnn/cybermes730 stars

    View details
  • crlf-injectionSkillFiles & storage

    Lets your agent detect and fix cases where user input injects carriage-return line-feed characters into HTTP headers, redirects, cookies, or logs.

    Ready to connect★ 842

    github.com/zyrexnn/cybermes730 stars

    View details
  • csp-bypass-advancedSkillSecurity

    Gives your agent techniques for finding and exploiting weaknesses in a site's Content Security Policy to bypass XSS blocks.

    Ready to connect★ 842

    github.com/zyrexnn/cybermes730 stars

    View details
  • csrf-cross-site-request-forgerySkillSecurity

    Gives your agent a playbook for testing web apps against CSRF attacks and weak anti-CSRF defenses.

    Ready to connect★ 842

    github.com/zyrexnn/cybermes730 stars

    View details
  • csv-formula-injectionSkillFiles & storage

    Guides your agent to spot and prevent malicious spreadsheet formulas hidden in CSV exports and imports.

    Ready to connect★ 842

    github.com/zyrexnn/cybermes730 stars

    View details
  • custom-ai-router-assessmentSkillDev tools

    Lets your agent assess self-hosted AI API gateways built on custom Next.js-style web stacks.

    Ready to connect★ 842

    github.com/zyrexnn/cybermes730 stars

    View details
  • dangling-markup-injectionSkillDev tools

    Lets your agent learn how to test for dangling markup attacks that leak page data when JavaScript execution is blocked.

    Ready to connect★ 842

    github.com/zyrexnn/cybermes730 stars

    View details
  • defi-attack-patternsSkillSecurity

    Lets your agent analyze DeFi attacks like flash loans, oracle manipulation, and bridge exploits.

    Ready to connect★ 842

    github.com/zyrexnn/cybermes730 stars

    View details
  • dependency-confusionSkillCloud & infra

    Lets your agent test whether internal package names could be hijacked through public registries in supply-chain attacks.

    Ready to connect★ 842

    github.com/zyrexnn/cybermes730 stars

    View details
  • deserialization-insecureSkillFiles & storage

    Lets your agent detect and assess insecure deserialization risks in Java, PHP, and Python apps.

    Ready to connect★ 842

    github.com/zyrexnn/cybermes730 stars

    View details
  • dns-rebinding-attacksSkillWeb & browsing

    Teaches your agent how to test web apps for DNS rebinding attacks that bypass origin checks via browser requests.

    Ready to connect★ 842

    github.com/zyrexnn/cybermes730 stars

    View details
  • email-header-injectionSkillCommunication

    Guides your agent through testing email systems for header injection and spoofing flaws.

    Ready to connect★ 842

    github.com/zyrexnn/cybermes730 stars

    View details
  • evidence-collectionSkillMonitoring & ops

    Lets your agent capture, timestamp, and format verifiable security evidence like HTTP logs, PoC scripts, and screenshots.

    Ready to connect★ 842

    github.com/zyrexnn/cybermes730 stars

    View details
  • file-access-vulnSkillFiles & storage

    Lets your agent run tests for file access vulnerabilities like unsafe downloads, path traversal, and insecure uploads.

    Ready to connect★ 842

    github.com/zyrexnn/cybermes730 stars

    View details
  • fix-security-vulnerabilities-with-strixSkillSecurity

    Lets your agent triage and patch security vulnerabilities found by Strix scans, then re-scan to verify fixes.

    Ready to connect★ 842

    github.com/zyrexnn/cybermes730 stars

    View details
  • format-string-exploitationSkillDocs & knowledge

    Teaches your agent how printf format string vulnerabilities are exploited to read or write memory.

    Ready to connect★ 842

    github.com/zyrexnn/cybermes730 stars

    View details

What is a skill?

A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.

53,788 of the 54,220 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.

Install one and every AI you use gets it

Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.

Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.

See how to connect your AI