Skills.
Give your AI a better way to work.
A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.
Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.
Filter by category
55,055 results · page 739 of 1,836
- View details
av-edr-evasionSkillSecurity
Guides an agent through making exploit payloads evade antivirus and EDR detection, including AMSI and ETW bypass techniques.
Ready to connect★ 276
- View details
command-injectionSkillSecurity
Lets your agent learn how to find and test OS command injection flaws during authorized penetration tests.
Ready to connect★ 276
- View details
cors-misconfigurationSkillSecurity
Lets your agent find and exploit CORS misconfigurations on websites during authorized penetration tests.
Ready to connect★ 276
- View details
credential-dumpingSkillDatabases & data
Lets your agent extract credentials from Active Directory using techniques like DCSync, NTDS.dit dumps, and LAPS password retrieval.
Ready to connect★ 276
- View details
csrfSkillSecurity
Lets your agent test websites for CSRF vulnerabilities during authorized penetration tests.
Ready to connect★ 276
- View details
database-enumerationSkillDatabases & data
Lets your agent scan database services for weak passwords, unauthenticated access, and command execution risks.
Ready to connect★ 276
- View details
deserialization-dotnetSkillSecurity
Lets your agent exploit .NET deserialization vulnerabilities during authorized penetration tests.
Ready to connect★ 276
- View details
deserialization-javaSkillSecurity
Lets your agent exploit Java deserialization vulnerabilities during authorized penetration tests.
Ready to connect★ 276
- View details
file-upload-bypassSkillFiles & storage
Guides your agent through bypassing file upload restrictions during authorized penetration tests.
Ready to connect★ 276
- View details
gpo-abuseSkillSecurity
Lets your agent learn how attackers abuse Group Policy Objects to move and escalate privileges in Active Directory.
Ready to connect★ 276
- View details
idorSkillSecurity
Lets your agent test web apps for IDOR and broken access control flaws during authorized penetration tests.
Ready to connect★ 276
- View details
infrastructure-enumerationSkillSecurity
Lets your agent scan infrastructure services like DNS, SMTP, and web servers to identify exposed services and misconfigurations.
Ready to connect★ 276
- View details
jwt-attacksSkillSecurity
Lets your agent find and test JWT token vulnerabilities during authorized penetration tests.
Ready to connect★ 276
- View details
kerberos-delegationSkillSecurity
Lets your agent test Kerberos delegation misconfigurations in Active Directory for privilege escalation paths.
Ready to connect★ 276
- View details
kerberos-roastingSkillSecurity
Lets your agent extract and crack Kerberos service tickets and AS-REP hashes to recover passwords offline.
Ready to connect★ 276
- View details
kerberos-ticket-forgingSkillSecurity
Lets your agent forge Kerberos tickets like Golden and Silver Tickets for testing domain compromise scenarios.
Ready to connect★ 276
- View details
ldap-injectionSkillSecurity
Lets your agent test for and exploit LDAP injection vulnerabilities during authorized penetration tests.
Ready to connect★ 276
- View details
linux-cron-service-abuseSkillSecurity
Lets your agent practice escalating Linux privileges through cron jobs, systemd timers, services, and sockets.
Ready to connect★ 276
- View details
linux-discoverySkillSecurity
Lets your agent scan a Linux system for privilege escalation opportunities and map its attack surface.
Ready to connect★ 276
- View details
linux-file-path-abuseSkillFiles & storage
Runs checks for Linux privilege escalation flaws like writable critical files, NFS misconfigs, and shared library hijacking.
Ready to connect★ 276
- View details
linux-kernel-exploitsSkillSecurity
Lets your agent find and run Linux kernel exploits to escalate privileges or escape restricted shells.
Ready to connect★ 276
- View details
linux-sudo-suid-capabilitiesSkillSecurity
Lets your agent find and use sudo misconfigurations and SUID binaries to escalate privileges on Linux.
Ready to connect★ 276
- View details
network-reconSkillSecurity
Lets your agent scan networks to discover hosts, open ports, and fingerprint operating systems.
Ready to connect★ 276
- View details
oauth-attacksSkillSecurity
Teaches your agent how OAuth 2.0 and OpenID Connect flaws are exploited during authorized penetration testing.
Ready to connect★ 276
- View details
pass-the-hashSkillSecurity
Lets your agent authenticate to Windows Active Directory services using stolen hashes or tickets instead of passwords.
Ready to connect★ 276
- View details
password-reset-poisoningSkillSecurity
Lets your agent test password reset flows for exploitable weaknesses during authorized penetration tests.
Ready to connect★ 276
- View details
password-sprayingSkillSecurity
Lets your agent test password guesses against login services while avoiding account lockouts.
Ready to connect★ 276
- View details
php-code-injectionSkillSecurity
Lets your agent test PHP apps for code injection flaws through eval, assert, and similar functions.
Ready to connect★ 276
- View details
pivoting-tunnelingSkillSecurity
Lets your agent route network traffic through compromised hosts to reach internal networks.
Ready to connect★ 276
- View details
python-code-injectionSkillSecurity
Lets your agent test web apps for Python code injection flaws where user input is evaluated as code.
Ready to connect★ 276
What is a skill?
A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.
54,624 of the 55,055 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.
Install one and every AI you use gets it
Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.
Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.