Skills.
Give your AI a better way to work.
A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.
Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.
Filter by category
55,055 results · page 740 of 1,836
- View details
red-run-ctfSkillSecurity
Lets your agent run a multi-phase penetration test, mapping attack surfaces and chaining vulnerabilities.
Ready to connect★ 276
- View details
red-run-legacySkillSecurity
Runs the legacy red-run orchestrator manually when you specifically invoke it.
Ready to connect★ 276
- View details
remote-access-enumerationSkillSecurity
Lets your agent scan remote access services like SSH, RDP, and VNC for weak or anonymous logins and known vulnerabilities.
Ready to connect★ 276
- View details
request-smugglingSkillSecurity
Walks your agent through HTTP request smuggling testing during authorized penetration tests.
Ready to connect★ 276
- View details
sccm-exploitationSkillSecurity
Lets your agent enumerate and exploit Microsoft SCCM infrastructure to harvest credentials and escalate domain access.
Ready to connect★ 276
- View details
smb-enumerationSkillSearch
Lets your agent enumerate Windows network shares, test access, and check for SMB vulnerabilities.
Ready to connect★ 276
- View details
smb-share-webshellSkillFiles & storage
Lets your agent deploy webshells to web servers over writable SMB file shares to gain remote access.
Ready to connect★ 276
- View details
source-code-reviewSkillSecurity
Lets your agent review source code for security issues like hardcoded credentials, injection flaws, and weak authentication.
Ready to connect★ 276
- View details
sql-injection-blindSkillDatabases & data
Guides your agent through blind SQL injection testing techniques for authorized penetration tests.
Ready to connect★ 276
- View details
sql-injection-errorSkillDatabases & data
Guides your agent through error-based SQL injection testing steps during authorized penetration tests.
Ready to connect★ 276
- View details
sql-injection-stackedSkillDatabases & data
Guides your agent through stacked-query and second-order SQL injection testing during authorized pentests.
Ready to connect★ 276
- View details
sql-injection-unionSkillDatabases & data
Guides your agent through UNION-based SQL injection testing steps during authorized penetration tests.
Ready to connect★ 276
- View details
ssrfSkillSecurity
Guides your agent through server-side request forgery attacks during authorized penetration tests.
Ready to connect★ 276
- View details
ssti-freemarkerSkillSecurity
Guides your agent through exploiting Freemarker server-side template injection in authorized penetration tests.
Ready to connect★ 276
- View details
ssti-jinja2SkillSecurity
Guides an agent through Jinja2 server-side template injection testing during authorized penetration tests.
Ready to connect★ 276
- View details
ssti-twigSkillSecurity
Guides your agent through Twig/PHP template injection testing during authorized penetration tests.
Ready to connect★ 276
- View details
tomcat-manager-deploySkillFiles & storage
Lets your agent deploy WAR files to an Apache Tomcat server to run code remotely.
Ready to connect★ 276
- View details
trust-attacksSkillSecurity
Lets your agent enumerate Active Directory trust relationships and attempt cross-domain privilege escalation attacks.
Ready to connect★ 276
- View details
unknown-vector-analysisSkillSecurity
Lets your agent analyze custom apps, scripts, and binaries via source review, attack surface mapping, CVE research, and PoC work.
Ready to connect★ 276
- View details
web-discoverySkillSecurity
Lets your agent find web app injection points during authorized penetration tests and pick the right exploitation skill.
Ready to connect★ 276
- View details
windows-credential-harvestingSkillSecurity
Lets your agent extract saved usernames and passwords from a Windows machine to gain access to other systems.
Ready to connect★ 276
- View details
windows-discoverySkillSecurity
Lets your agent scan a Windows machine to find ways attackers could gain higher privileges.
Ready to connect★ 276
- View details
windows-kernel-exploitsSkillFiles & storage
Lets your agent research Windows kernel exploits and privilege escalation to SYSTEM.
Ready to connect★ 276
- View details
windows-service-dll-abuseSkillSecurity
Lets your agent find and test Windows service misconfigurations and DLL hijacks to escalate local privileges.
Ready to connect★ 276
- View details
windows-token-impersonationSkillSecurity
Lets your agent attempt Windows privilege escalation to SYSTEM using token privileges for security testing.
Ready to connect★ 276
- View details
windows-uac-bypassSkillSecurity
Lets your agent bypass Windows User Account Control to gain elevated privileges.
Ready to connect★ 276
- View details
xmpp-enumerationSkillSecurity
Lets your agent scan and fingerprint XMPP chat servers for open ports, users, and chat rooms.
Ready to connect★ 276
- View details
xss-domSkillSecurity
Guides your agent through testing websites for DOM-based cross-site scripting flaws.
Ready to connect★ 276
- View details
xss-reflectedSkillSecurity
Guides your agent through testing websites for reflected cross-site scripting flaws during authorized security tests.
Ready to connect★ 276
- View details
xss-storedSkillSecurity
Teaches your agent how to find and test stored and blind XSS flaws during authorized penetration tests.
Ready to connect★ 276
What is a skill?
A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.
54,624 of the 55,055 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.
Install one and every AI you use gets it
Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.
Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.