Skills.
Give your AI a better way to work.
A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.
Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.
Filter by category
54,220 results · page 434 of 1,808
- View details
fuzzing-and-content-discoverySkillFiles & storage
Lets your agent scan a website for hidden directories, backup files, config endpoints, and subdomains.
Ready to connect★ 842
- View details
ghost-bits-cast-attackSkillDatabases & data
Gives your agent a reference playbook of Java char-narrowing techniques used to bypass web filters in security testing.
Ready to connect★ 842
- View details
graphql-and-hidden-parametersSkillDev tools
Guides your agent through probing GraphQL APIs for introspection, hidden parameters, and authorization flaws.
Ready to connect★ 842
- View details
hackSkillSecurity
Routes your agent to the right security-testing skill for tasks like web app testing, recon, and exploit planning.
Ready to connect★ 842
- View details
hash-attack-techniquesSkillDev tools
Lets your agent apply hash attack techniques like length extension, MD5/SHA1 collisions, and HMAC timing leaks in CTFs.
Ready to connect★ 842
- View details
heap-exploitationSkillSecurity
Gives your agent a playbook for exploiting heap memory bugs like use-after-free and double free to gain code execution.
Ready to connect★ 842
- View details
http-host-header-attacksSkillDev tools
Lets your agent follow a playbook for testing and exploiting HTTP Host header injection flaws in web apps.
Ready to connect★ 842
- View details
http-parameter-pollutionSkillDev tools
Lets your agent test how duplicate HTTP parameters are handled to spot security bypass risks.
Ready to connect★ 842
- View details
http2-specific-attacksSkillDev tools
Gives your agent a playbook of HTTP/2-specific attacks like request smuggling and header injection for testing targets.
Ready to connect★ 842
- View details
idor-broken-object-authorizationSkillDev tools
Gives your agent a playbook for testing apps for IDOR and broken object-level authorization flaws.
Ready to connect★ 842
- View details
injection-checkingSkillDev tools
Lets your agent route web injection testing tasks to the right workflow for XSS, SQL injection, SSRF, XXE, SSTI, command, and NoSQL injection.
Ready to connect★ 842
- View details
insecure-source-code-managementSkillDev tools
Lets your agent check websites for exposed source code folders, backup files, and config files during security testing.
Ready to connect★ 842
- View details
ios-pentesting-tricksSkillFiles & storage
Lets your agent follow a step-by-step playbook for testing iOS apps for security flaws during authorized pentests.
Ready to connect★ 842
- View details
js-recon-secret-huntingSkillDev tools
Lets your agent download website JavaScript files and scan them for leaked API keys, tokens, and hidden endpoints.
Ready to connect★ 842
- View details
lattice-crypto-attacksSkillCommerce & finance
Gives your agent methods for breaking RSA, DSA, ECDSA, and knapsack-based cryptography using lattice techniques.
Ready to connect★ 842
- View details
linux-lateral-movementSkillFiles & storage
Guides an agent through moving between compromised Linux hosts using SSH, credential, and filesystem techniques.
Ready to connect★ 842
- View details
macos-process-injectionSkillDev tools
Gives your agent a playbook for injecting code into running or launching macOS processes using several exploitation techniques.
Ready to connect★ 842
- View details
macos-security-bypassSkillSecurity
Gives your agent a playbook for bypassing macOS protections like TCC, Gatekeeper, and SIP during authorized security tests.
Ready to connect★ 842
- View details
managed-pentesting-with-strixSkillDocs & knowledge
Lets your agent launch and manage security penetration tests on web apps and APIs and get compliance-ready reports.
Ready to connect★ 842
- View details
memory-forensics-volatilitySkillDocs & knowledge
Guides your agent through analyzing computer memory dumps to investigate malware and security incidents.
Ready to connect★ 842
- View details
mobile-ssl-pinning-bypassSkillDev tools
Guides your agent through bypassing SSL certificate pinning to intercept HTTPS traffic from mobile apps.
Ready to connect★ 842
- View details
network-protocol-attacksSkillDev tools
Gives your agent step-by-step playbooks for network attacks like ARP spoofing, DNS spoofing, and IDS evasion.
Ready to connect★ 842
- View details
nosql-injectionSkillSearch
Gives your agent a playbook for spotting NoSQL injection flaws in MongoDB-style queries and search filters.
Ready to connect★ 842
- View details
ntlm-relay-coercionSkillSecurity
Guides your agent through NTLM relay and authentication coercion techniques for privilege escalation testing.
Ready to connect★ 842
- View details
oast-blind-testingSkillDev tools
Lets your agent generate out-of-band test payloads to detect blind SSRF, blind RCE, and data leaks.
Ready to connect★ 842
- View details
oauth-oidc-misconfigurationSkillSecurity
Lets your agent run a checklist for finding OAuth and OpenID Connect login security flaws like bad redirect URIs.
Ready to connect★ 842
- View details
female-outfit-directorSkillMedia
Generates coordinated image prompts and video scripts for "multi-outfit collage first frame of the same character + beat-synced outfit-change short videos". Use when the user asks for realistic character outfit collages, five outfits, floating character stickers, hanfu/ancient-style/modern fashion o
Ready to connect★ 841
- View details
codex-autoresearchSkillDocs & knowledge
Lets your agent triage improvement work and run or resume measured improvement loops in a local project.
Ready to connect★ 839
- View details
cli-skillsSkillDev tools
Gives your agent guidance on writing Go command-line tools using LlamaFarm's Cobra, Bubbletea, and Lipgloss patterns.
Ready to connect★ 838
- View details
commit-push-prSkillSecurity
Lets your agent commit code changes, push them to GitHub, and open a pull request with quality checks.
Ready to connect★ 838
What is a skill?
A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.
53,788 of the 54,220 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.
Install one and every AI you use gets it
Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.
Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.