Skills.
Give your AI a better way to work.
A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.
Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.
Filter by category
54,220 results · page 433 of 1,808
- View details
arbitrary-write-to-rceSkillDev tools
Guides an agent through converting an arbitrary memory-write bug into code execution using exploitation techniques.
Ready to connect★ 842
- View details
auth-secSkillSecurity
Routes your agent to the right authentication and authorization security testing topic like sessions, JWT, OAuth, or CSRF.
Ready to connect★ 842
- View details
authbypass-authentication-flawsSkillSecurity
Runs a playbook for testing whether login flows, password resets, and session controls can be bypassed.
Ready to connect★ 842
- View details
autonomous-godmode-hunterSkillSecurity
Lets your agent run authorized security scans on a target and turn confirmed bugs into proof-of-concept scripts and reports.
Ready to connect★ 842
- View details
binary-protection-bypassSkillDev tools
Guides your agent through identifying and bypassing binary protections like ASLR and DEP in ELF executables.
Ready to connect★ 842
- View details
browser-exploitation-v8SkillWeb & browsing
Lets your agent follow a playbook for exploiting JavaScript engine bugs to escape Chrome's sandbox.
Ready to connect★ 842
- View details
business-logic-and-idorSkillDev tools
Lets your agent test whether an app's user permissions can be bypassed, such as accessing other users' data.
Ready to connect★ 842
- View details
business-logic-vulnSkillDev tools
Routes security testing tasks toward business logic flaws like race conditions and pricing bugs.
Ready to connect★ 842
- View details
business-logic-vulnerabilitiesSkillSecurity
Gives your agent a playbook for finding business logic flaws like price manipulation and authorization gaps.
Ready to connect★ 842
- View details
classical-cipher-analysisSkillDev tools
Lets your agent analyze and break classical ciphers like substitution, Vigenere, transposition, and XOR in CTF challenges.
Ready to connect★ 842
- View details
clickjackingSkillDev tools
Lets your agent test whether web pages can be framed and check clickjacking protections like X-Frame-Options.
Ready to connect★ 842
- View details
cmdi-command-injectionSkillDev tools
Teaches your agent to spot and prevent cases where user input could run shell commands.
Ready to connect★ 842
- View details
code-obfuscation-deobfuscationSkillDev tools
Lets your agent analyze and reverse obfuscated code like junk code, control flow flattening, and string encryption.
Ready to connect★ 842
- View details
container-escape-techniquesSkillCloud & infra
Gives your agent a playbook of techniques for breaking out of a Docker, LXC, or Kubernetes container to the host.
Ready to connect★ 842
- View details
cors-cross-origin-misconfigurationSkillWeb & browsing
Guides your agent through testing websites for CORS misconfigurations that expose authenticated APIs.
Ready to connect★ 842
- View details
crlf-injectionSkillFiles & storage
Lets your agent detect and fix cases where user input injects carriage-return line-feed characters into HTTP headers, redirects, cookies, or logs.
Ready to connect★ 842
- View details
csp-bypass-advancedSkillSecurity
Gives your agent techniques for finding and exploiting weaknesses in a site's Content Security Policy to bypass XSS blocks.
Ready to connect★ 842
- View details
csrf-cross-site-request-forgerySkillSecurity
Gives your agent a playbook for testing web apps against CSRF attacks and weak anti-CSRF defenses.
Ready to connect★ 842
- View details
csv-formula-injectionSkillFiles & storage
Guides your agent to spot and prevent malicious spreadsheet formulas hidden in CSV exports and imports.
Ready to connect★ 842
- View details
custom-ai-router-assessmentSkillDev tools
Lets your agent assess self-hosted AI API gateways built on custom Next.js-style web stacks.
Ready to connect★ 842
- View details
dangling-markup-injectionSkillDev tools
Lets your agent learn how to test for dangling markup attacks that leak page data when JavaScript execution is blocked.
Ready to connect★ 842
- View details
defi-attack-patternsSkillSecurity
Lets your agent analyze DeFi attacks like flash loans, oracle manipulation, and bridge exploits.
Ready to connect★ 842
- View details
dependency-confusionSkillCloud & infra
Lets your agent test whether internal package names could be hijacked through public registries in supply-chain attacks.
Ready to connect★ 842
- View details
deserialization-insecureSkillFiles & storage
Lets your agent detect and assess insecure deserialization risks in Java, PHP, and Python apps.
Ready to connect★ 842
- View details
dns-rebinding-attacksSkillWeb & browsing
Teaches your agent how to test web apps for DNS rebinding attacks that bypass origin checks via browser requests.
Ready to connect★ 842
- View details
email-header-injectionSkillCommunication
Guides your agent through testing email systems for header injection and spoofing flaws.
Ready to connect★ 842
- View details
evidence-collectionSkillMonitoring & ops
Lets your agent capture, timestamp, and format verifiable security evidence like HTTP logs, PoC scripts, and screenshots.
Ready to connect★ 842
- View details
file-access-vulnSkillFiles & storage
Lets your agent run tests for file access vulnerabilities like unsafe downloads, path traversal, and insecure uploads.
Ready to connect★ 842
- View details
fix-security-vulnerabilities-with-strixSkillSecurity
Lets your agent triage and patch security vulnerabilities found by Strix scans, then re-scan to verify fixes.
Ready to connect★ 842
- View details
format-string-exploitationSkillDocs & knowledge
Teaches your agent how printf format string vulnerabilities are exploited to read or write memory.
Ready to connect★ 842
What is a skill?
A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.
53,788 of the 54,220 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.
Install one and every AI you use gets it
Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.
Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.