Skill rating
2 738 skills. The A–F grade combines safety (60%) and quality (40%); tests add a bonus. The rating refreshes automatically from open catalogs.
ManufacturingLogistics and warehouseProcurementQuality controlContact centreField serviceFinanceCustomer supportindustry shortcuts
| # | Grade | Skill | Score ▾ | Safety | Quality | Process | Tests | Popularity | Updated |
|---|---|---|---|---|---|---|---|---|---|
| 1051 | B | Create Standard Operating Procedures with step-by-step workflows, RACI matrices, process maps, approval chains, and version control | 100 | 72 | C | — | ★ 203 | 26 Feb 2026 | |
| 1052 | B | 🛡️ AI Agent Immune System — Security scanner + PII sanitizer + intent-action mismatch detector. 285+ patterns, OWASP Agentic AI Top 10. 100% local, zero cloud dependencies. | 100 | 72 | C | — | ↓ 682 | 19 May 2026 | |
| 1053 | B | Add educational comments to the file specified, or prompt asking for file to comment if one is not provided. | 100 | 69 | C | — | ↓ 998 | 11 May 2026 | |
| 1054 | B | Pre-flight trust verification for AI agents. Verify behavior, detect injection vulnerabilities, check for PII leaks, and measure reliability before granting Write/Execute permissions. | 100 | 72 | C | — | ↓ 573 | 11 May 2026 | |
| 1055 | B | Use when the user operates Alibaba Cloud Container Service for Kubernetes (ACK). Covers cluster lifecycle (create / modify / delete / upgrade), node pools & nodes (create, modify, delete, repair, fix | 93 | 82 | B | — | ↓ 712 | 32 d ago | |
| 1056 | B | Legal status analysis and corporate structuring pack. Legal form comparison, tax simulation, social protection analysis, governance structuring, and compliance checklist. 5 legal status tools. | 100 | 70 | C | — | ↓ 932 | 11 May 2026 | |
| 1057 | B | Global landed cost calculator for traders shipping to the US. Combines live USITC tariffs, Section 232/301/AD-CVD duties, real-time exchange rates (ECB), ocean freight costs, UFLPA compliance, and cus | 100 | 71 | C | — | ↓ 929 | 11 May 2026 | |
| 1058 | B | Unsafe deserialization vulnerability scanner (OWASP A08:2021). Detects Python pickle/yaml/eval, Java ObjectInputStream/XStream/XMLDecoder, PHP unserialize, Ruby Marshal.load, Node.js eval/new Function | 100 | 63 | D | — | ★ 2 141 | 20 Jul 2026 | |
| 1059 | B | GraphQL schema static auditor. Reads any .graphql SDL file or introspection JSON to detect N+1 exposure hotspots (nested list-within-list queries with no dataloader hint), unbounded query depth vulner | 100 | 63 | D | — | ★ 2 141 | 20 Jul 2026 | |
| 1060 | B | Server-Side Request Forgery (SSRF) vulnerability scanner (OWASP A10:2021). Detects URL-fetching sinks in Python/Java/Node.js/PHP/Go/Ruby that accept user-controlled URLs without validation. Flags clou | 100 | 63 | D | — | ★ 2 141 | 20 Jul 2026 | |
| 1061 | B | Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them. Security audit tool that detects data exfiltration, system modification attempts, | 94 | 72 | C | — | ★ 2 141 | 20 Jul 2026 | |
| 1062 | B | Integrate Chinese payment methods (WeChat Pay, Alipay, UnionPay) into applications. Teach AI agents how to implement payment flows, handle callbacks, manage refunds, and comply with Chinese payment re | 100 | 72 | C | — | ↓ 587 | 26 May 2026 | |
| 1063 | B | Memory system for AI agents on OpenClaw-like hosts. File-based multi-layer memory: fresh daily layer (5-day rotation), mesh graph, auto-log of every exchange, cross-layer grep search, compliance check | 100 | 71 | C | — | ↓ 1 174 | 7 d ago | |
| 1064 | A | 跨境电商产品合规速查(8品类×8市场)。用户输入产品类别和目的地国家/市场, 自动查询并输出该品类在该市场的全套合规要求:产品认证、标签规范、包装要求、 测试标准、限制物质/禁用成分、进口文件清单、平台额外要求(如亚马逊合规)、 特殊注意事项。覆盖电子产品/玩具/化妆品/食品/纺织品/医疗器械/家居用品/ 儿童用品 8 大品类 × 美国/欧盟/英国/日本/澳大利亚/加拿大/韩国/中东GCC 8 大 | 100 | 76 | C | — | ↓ 482 | 21 Jun 2026 | |
| 1065 | B | Encrypted multi-node agent storage with automatic FilStream network discovery. Client-side ChaCha20-Poly1305 encryption, per-object DEKs, HKDF key derivation from ETH wallet. Replicates across memory | 98 | 75 | C | — | ↓ 524 | 18 May 2026 | |
| 1066 | A | Use when adding or verifying a Mailtrap sending domain, DNS propagation issues, registrar or DNS provider steps, compliance after verification, or click tracking. Domain must be verified before sendin | 99 | 80 | C | — | ↓ 243 | 41 d ago | |
| 1067 | B | Authentication and compliance audit pack. OAuth 2.1/OIDC Discovery, token scope enforcement, tool deprecation lifecycle, circuit breaker, GDPR residency, DID identity, model routing, and resource link | 100 | 70 | C | — | ↓ 861 | 11 May 2026 | |
| 1068 | A | ISO 27001 ISMS implementation and cybersecurity governance for HealthTech and MedTech companies. Use for ISMS design, security risk assessment, control implementation, ISO 27001 certification, securit | 93 | 94 | C | — | ★ 14 | 16 Jun 2026 | |
| 1069 | A | You are a compliance expert specializing in regulatory requirements for software systems including GDPR, HIPAA, SOC2, PCI-DSS, and other industry standards. Perform compliance audits and provide imple | 99 | 83 | B | — | ★ 14 | 16 Jun 2026 | |
| 1070 | A | Judge whether an email is important/urgent using content-based analysis rather than sender name or mailbox labels (which can be spoofed). Use when asked to triage emails, decide priority, detect phish | 100 | 83 | B | — | ★ 14 | 16 Jun 2026 | |
| 1071 | A | You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, ou | 100 | 83 | B | — | ★ 14 | 16 Jun 2026 | |
| 1072 | A | Enables authenticated interaction with Slack for sending, editing, deleting, reacting to, and managing messages and pins via a secure bot token. | 100 | 83 | C | — | ★ 14 | 16 Jun 2026 | |
| 1073 | A | FDA regulatory consultant for medical device companies. Provides 510(k)/PMA/De Novo pathway guidance, QSR (21 CFR 820) compliance, HIPAA assessments, and device cybersecurity. Use when user mentions F | 94 | 91 | C | — | ★ 14 | 16 Jun 2026 | |
| 1074 | A | Detect SQL injection vulnerabilities in your codebase. Use when you need to find unsafe database queries before they get exploited. | 99 | 84 | C | — | ★ 14 | 16 Jun 2026 | |
| 1075 | A | This skill should be used when the user asks to "test for SQL injection vulnerabilities", "perform SQLi attacks", "bypass authentication using SQL injection", "extract database information through inj | 99 | 84 | C | — | ★ 14 | 16 Jun 2026 | |
| 1076 | A | twilio-communicationsGeneratorWhatsAppSecuritySoftware developmentmodbender/skill-library-mcpAgent Skills Build communication features with Twilio: SMS messaging, voice calls, WhatsApp Business API, and user verification (2FA). Covers the full spectrum from simple notifications to complex IVR systems and | 100 | 83 | D | — | ★ 14 | 16 Jun 2026 | |
| 1077 | A | AI Compliance Readiness Assessment — evaluate how prepared an organization is for AI governance regulations (EU AI Act, NIST AI RMF, HHS mandates, state bar AI rules). Scores readiness across 8 dimens | 100 | 83 | B | — | ★ 14 | 16 Jun 2026 | |
| 1078 | A | Create, structure, and publish OpenClaw skills to ClawHub that pass the security scanner with clean ratings. Covers frontmatter schema, env var declarations, script safety, config change patterns, and | 96 | 88 | C | — | ★ 14 | 16 Jun 2026 | |
| 1079 | A | Integrate Stripe, PayPal, and payment processors. Handles checkout flows, subscriptions, webhooks, and PCI compliance. Use PROACTIVELY when implementing payments, billing, or subscription features. | 100 | 83 | B | — | ★ 14 | 16 Jun 2026 | |
| 1080 | A | This skill should be used when the user asks to "intercept HTTP traffic", "modify web requests", "use Burp Suite for testing", "perform web vulnerability scanning", "test with Burp Repeater", "analyze | 99 | 84 | C | — | ★ 14 | 16 Jun 2026 | |
| 1081 | A | Security scanner for OpenClaw/ClawHub skills. Detects malware, reverse shells, credential theft, prompt injection, memory poisoning, typosquatting, and suspicious prerequisites before installation. Us | 92 | 94 | C | — | ★ 14 | 16 Jun 2026 | |
| 1082 | A | Wireshark Network Traffic AnalysisAnalyzerData and analyticsSecuritymodbender/skill-library-mcpAgent Skills This skill should be used when the user asks to "analyze network traffic with Wireshark", "capture packets for troubleshooting", "filter PCAP files", "follow TCP/UDP streams", "detect network anomalie | 99 | 84 | B | — | ★ 14 | 16 Jun 2026 | |
| 1083 | A | Coach and generate Xiaohongshu (小红书/RedNote/XHS) note writing. Use when the user wants help writing XHS notes (标题/正文/标签/评论引导/封面文案), improving engagement, or turning raw points into a publish-ready not | 100 | 83 | B | — | ★ 14 | 16 Jun 2026 | |
| 1084 | A | When user asks to generate a password, create PIN, make passphrase, check password strength, generate API key, create secure token, manage password ideas, generate username, bulk passwords, or any pas | 99 | 84 | D | — | ★ 14 | 16 Jun 2026 | |
| 1085 | A | Fetches latest articles from CyberSecurityRSS OPML feeds, applies AI/rule-based scoring, merges CVE and major vulnerability events, and generates a bilingual daily digest for cybersecurity researchers | 99 | 85 | C | — | ★ 14 | 16 Jun 2026 | |
| 1086 | A | Audit agent skills for security threats before installing them. Use AUTOMATICALLY when about to install any skill (clawhub install, skill installation), when asked to check if a skill is safe, scan fo | 93 | 92 | C | — | ★ 14 | 16 Jun 2026 | |
| 1087 | A | Implement quantum-resistant encryption using the CIFER SDK (cifer-sdk npm package). Covers SDK initialization, wallet setup, secret creation, text encryption/decryption, and file encryption/decryption | 99 | 84 | C | — | ★ 14 | 16 Jun 2026 | |
| 1088 | A | Comprehensive SecOps skill for application security, vulnerability management, compliance, and secure development practices. Includes security scanning, vulnerability assessment, compliance checking, | 95 | 91 | D | — | ★ 14 | 16 Jun 2026 | |
| 1089 | A | Instantly check if a file, URL, domain, or IP is malicious using VirusTotal. Paste any MD5/SHA1/SHA256 hash, URL, domain name, or IP address into the chat and get a full threat report — detection rat | 100 | 82 | B | — | ★ 14 | 16 Jun 2026 | |
| 1090 | A | threat-radar — Continuous Security Scanning & CVE AlertingIntegrationDockerWhatsAppSecurityInfrastructuremodbender/skill-library-mcpAgent Skills Continuous security posture monitoring that scans your running services, Docker images, and software dependencies for known CVEs. Alerts you via WhatsApp/Telegram/Discord when new vulnerabilities a... | 100 | 82 | C | — | ★ 14 | 16 Jun 2026 | |
| 1091 | A | Deep-dive security audit with 1,000 iterations (~4-8 hours). Use when user says 'deep security audit', 'ralph ultra', 'compliance audit prep', 'thorough security review', 'before major release', or 's | 97 | 88 | C | — | ★ 14 | 16 Jun 2026 | |
| 1092 | A | Network reconnaissance and port scanning using Nmap. Use when asked to scan a target, find open ports, detect services, check for vulnerabilities, or perform network reconnaissance. | 100 | 82 | B | — | ★ 14 | 16 Jun 2026 | |
| 1093 | A | AI supply chain security scanner — check packages for CVEs, look up MCP servers in the 427+ server threat registry, assess blast radius, generate SBOMs, enforce compliance (OWASP, MITRE ATLAS, EU AI A | 100 | 83 | C | — | ★ 14 | 16 Jun 2026 | |
| 1094 | A | E-Discovery costs $3,000+ per GB when outsourced. edisclaw processes, deduplicates, culls, and searches ESI collections locally for a fraction of the cost—giving small firms the same firepower as Big | 100 | 83 | D | — | ★ 14 | 16 Jun 2026 | |
| 1095 | A | Safely triage and remediate GitHub dependency hygiene issues with explicit guardrails. Use when Dependabot PRs fail, pnpm lockfiles break, transitive vulnerabilities appear (e.g., glob/lodash/brace-ex | 100 | 83 | C | — | ★ 14 | 16 Jun 2026 | |
| 1096 | A | Optimize any form that is NOT signup or account registration — including lead capture, contact, demo request, application, survey, quote, and checkout forms. Use when the goal is to increase form comp | 100 | 83 | B | — | ★ 14 | 16 Jun 2026 | |
| 1097 | A | Security and vulnerability scanner for OpenClaw code, plugins, skills, and Node.js dependencies. Powered by OpenClaw AI models. | 100 | 82 | C | — | ★ 14 | 16 Jun 2026 | |
| 1098 | A | Meta-skill for secure network tunnel setup, geo-access diagnostics, and leak-aware task resumption by orchestrating shell-scripting, curl-http, wireguard, tailscale, dns, ipinfo, and moltguard. Use wh | 100 | 82 | B | — | ★ 14 | 16 Jun 2026 | |
| 1099 | B | Encrypted credential management for OpenClaw — keeps API keys, tokens, and passwords out of the AI agent's context window. AES-256-GCM encryption, subprocess-scoped injection, automatic output scrubbi | 100 | 72 | C | — | ↓ 606 | 19 May 2026 | |
| 1100 | B | Consultor jurídico estratégico para o ordenamento brasileiro. Use quando o usuário pedir para analisar, revisar, redigir ou negociar contratos (prestação de serviços, SaaS, NDAs, DPA/LGPD, termos de u | 100 | 71 | C | — | ↓ 860 | 11 May 2026 |