SKILLEMALL.ai

Skill rating

2 738 skills. The A–F grade combines safety (60%) and quality (40%); tests add a bonus. The rating refreshes automatically from open catalogs.

2 738
#GradeSkillScore ▾SafetyQualityProcessTestsPopularityUpdated
551A
Attaches the exact CycloneDX or SPDX SBOM to a software release. Use when a release build is prepared for delivery; an SBOM must be valid, conformant, or ready to deliver; document conformance, PURL s
9710093C↓ 844 d ago
552A
Secure credential manager using AES-256 (Fernet) encryption. Stores, retrieves, and rotates secrets using a mandatory Master Key. Use for managing API keys, database credentials, and other sensitive t
9210079C↓ 1 34911 May 2026
553A
Analyze a GitHub pull request for mergeability — predict whether it will get merged based on technical, architectural, process, social, and compliance factors. Use when asked to review a PR, check if
9810094C↓ 4832 d ago
554A
Generate container runtime threat models analyzing attack surfaces across container components, images, privileges, network exposure, and security controls. Use when threat modeling containerized appl
939786B↓ 77711 May 2026
555A
When the user wants to create or optimize popups, modals, overlays, slide-ins, or banners for conversion purposes. Also use when the user mentions "exit intent," "popup conversions," "modal optimizati
9510088Cevals↓ 32230 Jul 2026
556A
Apply the Google Cloud Well-Architected Framework's Security pillar — security by design, zero trust with IAP and BeyondCorp, shift-left scanning in CI/CD, Binary Authorization, VPC Service Controls,
9410085C★ 15035 h ago
557A
Implement HIPAA compliance for healthcare applications — PHI handling, encryption, audit logging, access controls, and Business Associate Agreements. Use when building healthtech apps, handling patien
9410085D★ 15035 h ago
558A
California Consumer Privacy Act (CCPA) / CPRA compliance for businesses handling California resident data. Use when serving California users, building privacy features, implementing consumer data righ
9410085C★ 15035 h ago
559A
Assists with managing secrets, encryption keys, and dynamic credentials using HashiCorp Vault. Use when configuring secret engines, setting up dynamic database credentials, implementing access policie
9410085C★ 15035 h ago
560A
Scan code for security vulnerabilities, misconfigurations, and exposed secrets. Use when a user asks to audit security, find vulnerabilities, check for OWASP issues, scan for secrets, review dependenc
9410085D★ 15035 h ago
561A
Implement tamper-evident audit logs for compliance (SOC 2, HIPAA, PCI DSS). Use when building compliance audit trails, tracking who did what and when, or implementing immutable event logs that satisfy
9410085C★ 15035 h ago
562A
Accept payments with Paddle as merchant of record. Use when a user asks to add subscription billing without handling tax compliance, accept international payments, implement a payment system where Pad
9410085C★ 15035 h ago
563A
Shodan API integration for discovering internet-connected devices and services. Use when: mapping attack surface, finding exposed services by port/product/CVE, IoT device discovery, IP reputation chec
9410085C★ 15035 h ago
564A
Scan web servers for vulnerabilities with Nikto. Use when a user asks to audit web server configuration, find outdated software, detect dangerous files, check for misconfigurations, or perform web ser
9410085D★ 15035 h ago
565A
Scan containers, filesystems, and repos for vulnerabilities with Trivy. Use when a user asks to scan Docker images for CVEs, audit filesystem for secrets, check IaC for misconfigurations, or add secur
9410085C★ 15035 h ago
566A
Discover hidden content, directories, subdomains, and API endpoints with ffuf — the fastest web fuzzer. Use when someone asks to "find hidden directories", "fuzz URLs", "discover API endpoints", "subd
949790D★ 15035 h ago
567A
Find and fix vulnerabilities in code and dependencies with Snyk. Use when a user asks to scan for security vulnerabilities, audit npm packages, check Docker images for CVEs, or integrate security into
9410085C★ 15035 h ago
568A
Write high-quality YARA-X detection rules for malware identification and threat hunting. Covers naming conventions, string selection, performance optimization, and false positive reduction. Use when w
939984D↓ 79211 May 2026
569A
Upgrade project dependencies safely — inventories current→target versions from the actual manifest/lockfile, reads the real changelog/release notes for every major bump (a breaking-change claim withou
9610090C↓ 18929 d ago
570A
This skill should be used when the user asks to "pentest SSH services", "enumerate SSH configurations", "brute force SSH credentials", "exploit SSH vulnerabilities", "perform SSH tunneling", or "audit
929587C↓ 711 ★ 118 May 2026
571A
Pre-flight checklist for ClawHub skill publishing. Focus: metadata completeness, dependency transparency, security scope documentation. Use when: (1) preparing new skill, (2) before republish. NOT for
9310083C↓ 80111 May 2026
572A
Check an Amazon listing or draft for shopper clarity, supported claims, keyword intent, visual proof, and publish-blocking gaps. Use before rewriting or publishing a title, bullets, A+ content, or ima
9510087B↓ 46343 d ago
573A
学术论文润色修改全流程SOP。从审稿意见解析、论文全息诊断、可视化批注生成、分级改写执行到终审自检的完整闭环。当用户需要根据期刊审稿意见修改论文、需要论文润色、需要去AI味、需要学术写作规范检查时触发。典型触发:"修改这篇论文""根据审稿意见润色""去AI味""按期刊要求压缩字数""帮我看看这篇论文能不能通过"。
9310082C↓ 533 ★ 113 Jun 2026
574B
Optimize conversion rates with funnel analysis, A/B testing, statistical significance, and compliance-safe experiments.
8810069C↓ 1 995 ★ 611 May 2026
575A
A local missing person assistance tool for organizing cases, managing clues, generating notices, and providing search guidance.
9310082C↓ 7605 Jun 2026
576A
Handles B2B presales and renewal negotiations with value-shift tactics and compliance checks. Use when the user mentions customer pushback on price, budget constraints, competitor comparison, or value
9210080C↓ 1 21111 May 2026
577A
Assesses architecture decisions, ADR compliance, and coupling
9210081D↓ 1 52519 d ago
578B
Expert malware analyst specializing in defensive malware research, threat intelligence, and incident response. Masters sandbox analysis, behavioral analysis, and malware family identification.
878984C★ 46 36826 h ago
579B
Pre-install security scanner for AI agent skills. 7.5% of 14,706 skills are malicious. Audit before you trust.
879773C★ 46 36826 h ago
580B
Update an existing specification file for the solution, optimized for Generative AI consumption based on new requirements or updates to any existing code.
8710068C★ 38 9692 d ago
581A
You are a healthcare technology specialist with deep expertise in medical software development, regulatory compliance, interoperability. Use when: 1. healthcare standards & interoperability, 2. regula
939984D↓ 69911 May 2026
582A
Pre-publication compliance and quality reviewer. Checks factual citations, customer redaction, product naming, competitor rules, internal information, formatting, and AI traces; outputs a pre-review r
9410084B↓ 8107 d ago
583A
Scan/clean Maya scene malware on Windows. Use for Maya杀毒, Maya病毒扫描, Maya病毒查杀, 清理Maya病毒, 病毒查杀, Maya antivirus, Maya virus scan/removal; not general antivirus.
9610091C↓ 16326 d ago
584A
Create and permanently coin new words on Sugarchain, or discover the latest words from Lingry's public Stream. On first use, show the newest Lingry word and offer immediate word creation or discovery.
939984C↓ 710 ★ 115 d ago
585A
Validate email addresses with format checking and risk scoring. Use when users need to verify email format, check disposable emails, or validate bulk email lists. Handles RFC 5322 compliance, domain e
9310082B↓ 70911 May 2026
586A
Query TrendAI Vision One threat intelligence. Use when: looking up IOCs (IP, domain, hash, URL, email), checking threat feeds, reading intelligence reports, managing suspicious objects, or hunting thr
939295B↓ 67511 May 2026
587A
Security scanner for OpenClaw skills and plugins. Scans for hardcoded secrets, dangerous exec patterns, dependency vulnerabilities, and network egress. Use when auditing installed skills/plugins, befo
939983D↓ 67211 May 2026
588A
Evaluates test suites for coverage gaps, TDD/BDD compliance, and anti-patterns
9210081C↓ 1 42319 d ago
589A
Build cookie consent banners and track opt-in compliance status. Use when implementing GDPR consent, auditing cookies, generating privacy banners.
9210080C↓ 1 11918 May 2026
590A
Verified Latin American compliance data for autonomous AI agents. Use when an agent needs OFAC/UN/EU/UK sanctions screening, KYB entity verification (Colombia, Mexico, Brazil, Chile, Peru), LATAM cent
9410085C↓ 322 ★ 13 Jul 2026
591B
Security scanner for Moltbot skills. Scan GitHub repositories for vulnerabilities before installation.
8810069D↓ 2 818 ★ 311 May 2026
592A
Automated code review, quality gates, and PR analysis. Integrates with GitHub, GitLab, Bitbucket. Enforce style guides, detect bugs, security vulnerabilities, performance issues. Auto-approve safe PRs
9210081D↓ 1 15818 May 2026
593A
Test application security against OWASP Top 10 (2025) with automated CI tooling: OWASP ZAP (DAST), dependency/supply-chain scanning (OSV-Scanner, SBOM, provenance), Semgrep SAST, auth/session tests (J
949493C★ 12110 Jun 2026
594A
Publish, optimize, and scale Android apps on Google Play with release automation, ASO, policy compliance, and rejection recovery.
9110077C↓ 1 003 ★ 111 May 2026
595B
Secure local password storage tool with AES-256-GCM encryption. Store, retrieve, and manage passwords with CLI commands.
8810071C↓ 2 265 ★ 411 May 2026
596A
Deploy a compliance and governance system with 4 agents. Use this skill when: 1. User wants to set up automated compliance enforcement 2. User is configuring a policy engine, auditor, certifier, or re
939589C↓ 63711 May 2026
597A
Subpoena law reference — types of subpoenas, service requirements, compliance obligations, and motion to quash. Use when issuing, receiving, or responding to subpoenas in legal proceedings.
9210079C↓ 1 18211 May 2026
598A
Use when planning, implementing, or reviewing frontend dependency upgrades, package migrations, lockfile changes, major framework version bumps, CVE remediation, peer dependency conflicts, ESM/CJS shi
9410084D↓ 4236 Jun 2026
599A
Form a US LLC or nonprofit corporation for the user by running the intake yourself through Corpus. Use when the user wants to start a company, form an LLC, incorporate, set up a nonprofit, register a
9610089B↓ 997 d ago
600A
Get a practical, step-by-step privacy compliance checklist for any market — GDPR, CCPA, LGPD, PIPL, and more. Skip the legal jargon and get an actionable readiness plan with templates for privacy poli
9310082B↓ 68219 Jun 2026