Skill rating
2 738 skills. The A–F grade combines safety (60%) and quality (40%); tests add a bonus. The rating refreshes automatically from open catalogs.
ManufacturingLogistics and warehouseProcurementQuality controlContact centreField serviceFinanceCustomer supportindustry shortcuts
| # | Grade | Skill | Score ▾ | Safety | Quality | Process | Tests | Popularity | Updated |
|---|---|---|---|---|---|---|---|---|---|
| 601 | A | Use when monitoring open-source software for newly disclosed vulnerabilities, analyzing CVE impact and mitigation, or when a specific software and CVE need deep vulnerability analysis | 100 | 84 | C | — | ↓ 456 | 15 Jun 2026 | |
| 602 | A | Use when checking for security vulnerabilities in NanoClaw skills, before installing new skills, or when asked about security advisories affecting the bot | 99 | 80 | C | — | ↓ 1 825 | 23 Jun 2026 | |
| 603 | A | AI合规审查 - 按次付费,新用户注册送5次免费。广告法/数据隐私/金融营销/劳动用工/电商平台五大场景一键检测,AI智能识别违规点、引用法条、给出修改建议,企业营销文案/合同/招聘文案合规自检必备。 💡 企业定制/智能体开发/AI全案服务,合作微信17392371127(郭总) | 100 | 85 | B | — | ↓ 763 | 25 Jul 2026 | |
| 604 | B | Identify, assess, and fix security vulnerabilities in Go modules using govulncheck. Handle common vulnerabilities like JWT issues and ensure application stability during fixes. | 100 | 72 | D | — | ↓ 2 728 ★ 1 | 11 May 2026 | |
| 605 | A | Cybersecurity assistant for CTF challenges, penetration testing, network recon, vulnerability assessment, and security research. Use when: (1) solving CTF challenges (web, crypto, pwn, forensics, rev, | 92 | 91 | B | — | ↓ 1 105 | 11 May 2026 | |
| 606 | A | 中小商家电商合规快速筛查工具。
基于《电子商务法》《个人信息保护法》《广告法》《消费者权益保护法》
《网络交易监督管理办法》《七日无理由退货暂行办法》等行业法规,
面向电商平台上的中小商家,5 分钟快速自查店铺合规风险。
Use when: 上新商品前检查广告用语、被投诉后自查合规、
店铺数据安全评估、直播营销前的话术检查。
🎉 v1.0.0 首发 - 免费版:
- 🛒 4 大模块 12 | 100 | 87 | D | — | ↓ 301 | 27 Jul 2026 | |
| 607 | A | Navigate privacy regulations (GDPR, CCPA), review DPAs, and handle data subject requests. Use when reviewing data processing agreements, responding to data subject access or deletion requests, assessi | 100 | 83 | C | — | ★ 199 | 26 Feb 2026 | |
| 608 | A | Systematically audit AWS S3 bucket permissions to identify publicly accessible buckets, overly permissive ACLs, misconfigured bucket policies, and missing encryption settings using AWS CLI, S3audit, a | 100 | 82 | C | — | ↓ 667 | 26 May 2026 | |
| 609 | A | Hire, onboard, and manage overseas talent in minutes. Get hiring sequences, role scorecards, interview rubrics, onboarding plans, and compliance checklists for any overseas market — install and build | 100 | 82 | B | — | ↓ 666 | 19 Jun 2026 | |
| 610 | A | Find bugs, security vulnerabilities, and code quality issues in local branch changes. Use when asked to review changes, find bugs, security review, or audit code on the current branch. | 100 | 83 | C | — | ↓ 570 | 11 May 2026 | |
| 611 | A | MUKI asset fingerprinting tool for red team reconnaissance. Use when performing authorized penetration testing, asset discovery, service fingerprinting, vulnerability scanning, and attack surface mapp | 97 | 81 | B | — | ↓ 1 651 | 17 May 2026 | |
| 612 | B | DeFi risk analysis toolkit powered by WACH.AI via x402 payments using AWAL wallet custody. Use when the user asks to check if a token is safe, assess DeFi risk, detect honeypots, analyze liquidity, ho | 89 | 88 | B | — | ↓ 1 805 ★ 2 | 17 May 2026 | |
| 613 | A | You are an enterprise compliance and regulatory specialist using proven patterns from production AI systems (Oracle, IBM Watson Governance). Use when: regulatory expertise, audit types, data subject r | 100 | 82 | D | — | ↓ 575 | 11 May 2026 | |
| 614 | A | You are a fintech specialist with deep expertise in payment systems, financial regulations, security compliance, and modern financial. Use when: 1. payment systems, 2. regulatory compliance, 3. securi | 99 | 84 | C | — | ↓ 558 | 18 May 2026 | |
| 615 | A | Auditing Terraform infrastructure-as-code for security misconfigurations using Checkov, tfsec, Terrascan, and OPA/Rego policies to detect overly permissive IAM policies, public resource exposure, miss | 100 | 82 | C | — | ↓ 607 | 26 May 2026 | |
| 616 | B | AI legal documents and contract drafting powered by CellCog. Contracts, NDAs, terms of service, privacy policies, freelance agreements, employment contracts, compliance reviews, legal research. Precis | 100 | 70 | D | — | ↓ 3 553 ★ 2 | 22 d ago | |
| 617 | A | This skill details how to conduct cloud security audits using Center for Internet Security benchmarks for AWS, Azure, and GCP. It covers interpreting CIS Foundations Benchmark controls, running automa | 100 | 82 | B | — | ↓ 591 | 26 May 2026 | |
| 618 | B | /em -challenge — Pre-Mortem Plan Analysis | 100 | 72 | C | — | ★ 2 141 | 20 Jul 2026 | |
| 619 | B | api-security-best-practicesIntegrationInfrastructureSecurityLeoYeAI/openclaw-master-skillsAgent Skills Implement secure API design patterns including authentication, authorization, input validation, rate limiting, and protection against common API vulnerabilities | 99 | 74 | C | — | ★ 2 141 | 20 Jul 2026 | |
| 620 | B | postgresql-table-designProcedurePostgreSQLAI and agentsSecurityLeoYeAI/openclaw-master-skillsAgent Skills Design a PostgreSQL-specific schema. Covers best-practices, data types, indexing, constraints, performance patterns, and advanced features | 100 | 72 | C | — | ★ 2 141 | 20 Jul 2026 | |
| 621 | B | Security ScannerProcedureGitHubSoftware developmentInfrastructureLeoYeAI/openclaw-master-skillsAgent Skills Scan AI agent skills for security vulnerabilities, dangerous code patterns, and undeclared permissions. Three-layer analysis: dependency CVE scanning, static code analysis, and permission auditing. Re | 100 | 72 | C | — | ★ 2 141 | 20 Jul 2026 | |
| 622 | B | Complete A-Z Discord server administration. Channel/role/member management, AutoMod, webhooks, templates, audit logs, scheduled events, threads, and full server control via CLI. | 100 | 72 | D | — | ★ 2 141 | 20 Jul 2026 | |
| 623 | A | How to use the `npx corp` CLI to manage corporate entities, governance, cap tables, finance, agents, and compliance for TheCorporation platform. Use this skill whenever the user mentions `npx corp`, T | 100 | 80 | D | — | ↓ 906 | 18 May 2026 | |
| 624 | A | Track compliance requirements and generate audit trail reports. Use when auditing controls, checking policies, generating audit trails. | 100 | 74 | C | — | ↓ 1 600 ★ 1 | 11 May 2026 | |
| 625 | A | Security audit engine for OpenClaw configurations. Detects vulnerabilities, misconfigurations, secret leaks, and over-privileged agents. Use when the user asks about security, hardening, config review | 100 | 90 | C | — | ↓ 154 | 18 Jun 2026 | |
| 626 | A | Run security audits on codebases using static analysis, dependency scanning, and manual code review patterns. Covers OWASP Top 10, secrets detection, dependency vulnerabilities, and infrastructure mis | 97 | 84 | D | — | ↓ 926 | 11 May 2026 | |
| 627 | A | Manage residential rental properties — tenant screening, lease tracking, maintenance coordination, rent collection monitoring, vacancy optimization, and compliance reminders. Built for small landlords | 100 | 80 | B | — | ↓ 894 | 11 May 2026 | |
| 628 | A | iso-27001-evidence-collectionAnalyzerGitHubGoogle CloudSecuritymodbender/skill-library-mcpAgent Skills Collect, organize, and validate evidence for ISO 27001 and SOC 2 audits. API-first approach with CLI commands for major cloud platforms. Produces timestamped, auditor-ready evidence packages. | 99 | 93 | C | — | ★ 14 | 16 Jun 2026 | |
| 629 | A | Review UI code for Web Interface Guidelines compliance. Use when asked to "review my UI", "check accessibility", "audit design", "review UX", or "check my site against best practices". | 100 | 92 | C | — | ★ 14 | 16 Jun 2026 | |
| 630 | A | Audit and fix all skills in the workspace for compliance with skill-creator requirements. Use when asked to "refine skills", "audit skills", "check skill quality", or "fix non-compliant skills". Exhau | 100 | 92 | D | — | ★ 14 | 16 Jun 2026 | |
| 631 | A | Prompt-injection / jailbreak firewall for AI agents. Scan any untrusted text — a post/comment/DM from another agent, a tool result, scraped web content — BEFORE your agent acts on it. Self-hosted dete | 100 | 84 | C | — | ↓ 463 | 3 Jul 2026 | |
| 632 | A | Captures policy gaps, compliance risks, recruiting process issues, onboarding friction, retention signals, candidate experience problems, and offboarding gaps to enable continuous HR improvement. Use | 100 | 81 | C | — | ↓ 905 | 17 d ago | |
| 633 | A | Audit social content-marketing note content for policy compliance and shadowban / traffic-throttling risk. Scans for banned words, superlative / absolute-claim (极限词) violations, and sensitive content, | 100 | 84 | C | — | ↓ 318 | 34 d ago | |
| 634 | A | Generate multiple UGC script variants from one base script while keeping key product facts and compliance boundaries. Use when teams need fast creative diversity for testing. | 100 | 79 | C | — | ↓ 806 | 11 May 2026 | |
| 635 | B | SecOps checks for endpoints: EDR, Sysmon, updates, EVTX on heartbeat, least privilege, network visibility, credential protection (Kerberos/NTLM/pass-the-hash), device inventory and known vulnerabiliti | 99 | 68 | C | — | ↓ 2 901 ★ 4 | 11 May 2026 | |
| 636 | A | Captures clause risks, compliance gaps, precedent shifts, contract deviations, regulatory changes, and litigation exposure to enable continuous legal operations improvement. Use when: (1) An unfavorab | 100 | 81 | C | — | ↓ 890 | 17 d ago | |
| 637 | A | FERPA compliance reference — student records privacy, educational rights, consent requirements, and institutional obligations under the Family Educational Rights and Privacy Act. Use when handling stu | 100 | 79 | C | — | ↓ 832 | 11 May 2026 | |
| 638 | A | Threat modeling with STRIDE, PASTA, and attack trees. Analyze architectures for security gaps, extract security requirements, build data flow diagrams, and prioritize risks. For secure-by-design plann | 100 | 80 | C | — | ↓ 807 | 11 May 2026 | |
| 639 | A | Evaluate hook security, performance, and SDK compliance. Use for audits | 100 | 78 | D | — | ↓ 1 732 | 19 d ago | |
| 640 | A | EU AI Act risk classification, Article 12 compliance logging, and self-assessment reports — deadline August 2, 2026 | 100 | 81 | C | — | ↓ 799 | 11 May 2026 | |
| 641 | A | Secure sensitive data management with AES-256-GCM encryption. Store API keys, database credentials, passwords, and certificates. | 99 | 78 | B | — | ↓ 535 ★ 2 | 17 May 2026 | |
| 642 | A | BOM (bill of materials) vulnerability scanner that parses 8 lockfile formats, matches versions against an OSV-verified advisory database, and emits provenance-stamped findings. Use when auditing depen | 99 | 90 | D | — | ↓ 204 | 9 d ago | |
| 643 | A | Bonded warehouse reference — customs procedures, duty deferral, FTZ operations, compliance requirements. Use when managing bonded storage, customs clearance, or duty suspension logistics. | 100 | 79 | C | — | ↓ 834 | 11 May 2026 | |
| 644 | A | Controle interno municipal brasileiro — implantação, operação e auditoria interna em prefeituras e câmaras municipais. Use quando o usuário perguntar sobre: (1) Sistema de Controle Interno municipal ( | 100 | 81 | C | — | ↓ 795 | 11 May 2026 | |
| 645 | A | Expert in threat modeling methodologies, security architecture review, and risk assessment. Masters STRIDE, PASTA, attack trees, and security requirement extraction. Use for security architecture revi | 100 | 80 | D | — | ↓ 793 | 11 May 2026 | |
| 646 | A | OSHA compliance reference — workplace safety standards, hazard categories, inspection prep, and recordkeeping. Use when reviewing safety regulations, preparing for audits, or building safety programs. | 100 | 79 | C | — | ↓ 783 | 11 May 2026 | |
| 647 | A | COPPA compliance reference — children's online privacy, parental consent, data collection rules, FTC enforcement. Use when building apps for children under 13 or reviewing COPPA obligations. | 100 | 79 | C | — | ↓ 805 | 11 May 2026 | |
| 648 | B | Complete Bittensor SDK reference — Subtensor, AsyncSubtensor, Metagraph, Axon, Dendrite, Synapse, chain_data models, extrinsics (sync + async), extras (subtensor_api, dev_framework, timelock), and uti | 99 | 75 | D | — | ↓ 2 133 ★ 1 | 27 May 2026 | |
| 649 | A | Memory forensics with Volatility and related tools. Acquire RAM dumps, extract processes and DLLs, investigate rootkits and fileless malware, recover credentials from memory, and reconstruct timelines | 94 | 84 | B | — | ↓ 1 310 ★ 1 | 11 May 2026 | |
| 650 | A | Achieve PCI DSS compliance for handling payment card data — scoping, controls, and SAQ selection. Use when storing, processing, or transmitting payment card data, building e-commerce security, or achi | 98 | 85 | C | — | ★ 150 | 35 h ago |