Skill rating
2 738 skills. The A–F grade combines safety (60%) and quality (40%); tests add a bonus. The rating refreshes automatically from open catalogs.
ManufacturingLogistics and warehouseProcurementQuality controlContact centreField serviceFinanceCustomer supportindustry shortcuts
| # | Grade | Skill | Score ▾ | Safety | Quality | Process | Tests | Popularity | Updated |
|---|---|---|---|---|---|---|---|---|---|
| 1101 | B | Expert malware analyst specializing in defensive malware research, threat intelligence, and incident response. Masters sandbox analysis, behavioral analysis, and malware family identification. Handles | 89 | 87 | D | — | ↓ 847 | 11 May 2026 | |
| 1102 | B | Write high-quality YARA-X detection rules for malware hunting. Covers atom selection, string optimization, false positive reduction, module usage (PE, ELF, Macho), and Trail of Bits methodology. Inclu | 99 | 72 | D | — | ↓ 837 | 11 May 2026 | |
| 1103 | B | Audits Move contracts for security vulnerabilities before deployment using 7-category checklist. Triggers on: 'audit contract', 'security check', 'review security', 'check for vulnerabilities', 'secur | 100 | 71 | C | — | ↓ 824 | 11 May 2026 | |
| 1104 | B | 30-day countdown protocol for third-party compliance audits — EcoSure, health department, corporate brand audits. Milestone-driven preparation that makes perfect audit scores the natural outcome of th | 100 | 71 | C | — | ↓ 974 | 16 d ago | |
| 1105 | B | Complete DevOps toolkit for AI-assisted software development. Release pipeline, license compliance, copyright enforcement, repo visibility guard, identity file protection, manifest reconciler, and bes | 100 | 62 | C | — | ↓ 4 874 | 17 May 2026 | |
| 1106 | B | Framework skill: ClawHub Schema compliance, naming conventions, skill standardization, modularization, generalization, ecosystem registry, skill learning pipeline, starter scaffolding. | 100 | 65 | C | — | ↓ 3 097 | 11 May 2026 | |
| 1107 | B | Dependency audit and upgrade planner for Node.js, Python, Rust, Go, and Ruby projects. Scans for outdated packages, vulnerability CVEs, and breaking changes, then produces a prioritized upgrade plan w | 100 | 72 | C | — | ↓ 559 | 23 Jun 2026 | |
| 1108 | B | Build and manage MSHA Part 46 training programs for cement plants. Free CementOps Compliance Suite skill. Task training templates by equipment, toolbox talk generator, new miner orientation, complianc | 100 | 68 | C | — | ↓ 753 ★ 1 | 11 May 2026 | |
| 1109 | B | YOAP (Yongnian Open Agent Protocol) — Open A2A protocol with Smart Matching + E2E Encryption + Negotiation Threads + Group Channels | 100 | 70 | D | — | ↓ 766 | 11 May 2026 | |
| 1110 | B | Extract structured data from contracts, legal agreements, court filings, and compliance documents. Pre-built schemas for parties, clauses, dates, obligations. PII redaction for privilege review. 97%+ | 100 | 71 | D | — | ↓ 811 | 11 May 2026 | |
| 1111 | B | Expert guidance for Grype, the open-source vulnerability scanner by Anchore that finds known vulnerabilities (CVEs) in container images, filesystems, and SBOMs. Helps developers integrate Grype into C | 99 | 73 | C | — | ★ 150 | 2 d ago | |
| 1112 | B | 智能审核食品包装标签的合规性,支持图片/PDF设计稿;当用户需要审核标签强制性标识、营养标签规范性、声称用语合规性或格式要求时使用 | 100 | 69 | C | — | ↓ 749 | 11 May 2026 | |
| 1113 | B | BNB Chain security scanner — scan contracts, simulate transactions, detect phishing, investigate deployers, track scam campaigns, and audit wallet approvals via ShieldBot's API. | 100 | 70 | C | — | ↓ 784 | 11 May 2026 | |
| 1114 | B | Core Archon DID toolkit - identity management, verifiable credentials, encrypted messaging (dmail), Nostr integration, file encryption/signing, aliasing, authorization (challenge/response), groups, an | 95 | 74 | C | — | ↓ 1 266 | 17 May 2026 | |
| 1115 | B | Run security audits on Linux servers, web applications, and cloud infrastructure. Checks SSH hardening, firewall rules, open ports, SSL/TLS config, file permissions, and common vulnerabilities. Produc | 98 | 73 | C | — | ↓ 744 | 11 May 2026 | |
| 1116 | B | Analyzes URLs using heuristic algorithms to detect and identify phishing threats in real time. | 100 | 67 | C | — | ↓ 701 ★ 1 | 11 May 2026 | |
| 1117 | B | GitHub compliance evidence collection for auditclaw-grc. 9 read-only checks covering branch protection, secret scanning, 2FA, Dependabot, deploy keys, audit logs, webhooks, CODEOWNERS, and CI/CD secur | 100 | 73 | C | — | ↓ 457 | 11 May 2026 | |
| 1118 | B | AI-powered legal assistant for commercial transactions - provides contract review, transaction advisory, compliance checking, document generation, risk assessment, and negotiation support for business | 100 | 67 | C | — | ↓ 1 281 | 11 May 2026 | |
| 1119 | B | Extract structured data from medical records, lab reports, prescriptions, and clinical documents. Pre-built schemas for patient info, diagnoses, medications, vitals. PII redaction for HIPAA compliance | 100 | 71 | D | — | ↓ 751 | 11 May 2026 | |
| 1120 | B | Design and automate corporate employee onboarding programs with AI. Create adaptive learning paths by role, compliance training modules, microlearning sequences, and ROI dashboards for L&D departments | 100 | 69 | C | — | ↓ 837 | 13 Jul 2026 | |
| 1121 | B | Store and use sudo password for automated root commands. Essential companion for skills that need sudo access (like vpn-mesh). | 90 | 84 | D | — | ↓ 438 ★ 1 | 4 Jun 2026 | |
| 1122 | B | Authorized web pentest: recon, proof-based exploits, report. | 87 | 75 | D | — | ★ 245 503 | 12 h ago | |
| 1123 | A | input-validation-sanitization-auditorAnalyzerSoftware developmentSecurityLord1Egypt/RA-SkillsAgent Skills Identifies and fixes XSS, SQL injection, and command injection vulnerabilities with validation schemas, sanitization libraries, and safe coding patterns. Use for "input validation", "XSS prevention", | 100 | 92 | B | — | — | 10 Jul 2026 | |
| 1124 | A | Cloudflare Workers security with authentication, CORS, rate limiting, input validation. Use for securing APIs, JWT/API keys, or encountering auth failures, CORS errors, XSS/injection vulnerabilities. | 100 | 92 | C | — | — | 10 Jul 2026 | |
| 1125 | A | Create and secure S3 buckets following AWS best practices for access control, encryption, monitoring, and remediation of misconfigurations. Use when the user wants to secure a new bucket, audit an exi | 100 | 92 | C | — | — | 10 Jul 2026 | |
| 1126 | A | Audits and implements web accessibility (a11y) following WCAG 2.1 guidelines with ARIA patterns, keyboard navigation, screen reader support, and contrast checking. Use when users request "accessibilit | 100 | 92 | C | — | — | 10 Jul 2026 | |
| 1127 | A | Hardens API security with rate limiting, input validation, authentication, and protection against common attacks. Use when users request "API security", "secure API", "rate limiting", "input validatio | 100 | 92 | B | — | — | 10 Jul 2026 | |
| 1128 | A | Ingest OpenClaw agent history into the Obsidian wiki. Use this skill when the user wants to mine their past OpenClaw sessions for knowledge, import their ~/.openclaw folder, extract insights from prev | 100 | 93 | B | — | — | 10 Jul 2026 | |
| 1129 | A | Review docs/prose for Writing Guidelines compliance. Use when asked to "review my docs", "check writing style", "audit prose", "review docs voice and tone", or "check this page against the writing han | 100 | 92 | C | — | — | 10 Jul 2026 | |
| 1130 | A | Manages environment variables and secrets securely with encryption, rotation, and provider integration. Use when users request "secrets management", "environment variables", "API keys", "credentials s | 100 | 92 | C | — | — | 10 Jul 2026 | |
| 1131 | A | Ingest Hermes agent history into the Obsidian wiki. Use this skill when the user wants to mine their past Hermes sessions for knowledge, import their ~/.hermes folder, extract insights from previous H | 100 | 93 | B | — | — | 10 Jul 2026 | |
| 1132 | A | Review UI code for Web Interface Guidelines compliance. Use when asked to "review my UI", "check accessibility", "audit design", "review UX", or "check my site against best practices". | 100 | 92 | C | — | — | 10 Jul 2026 | |
| 1133 | A | Review UI code for Web Interface Guidelines compliance. Use when asked to "review my UI", "check accessibility", "audit design", "review UX", or "check my site against best practices". | 100 | 92 | C | — | — | 10 Jul 2026 | |
| 1134 | A | Review UI code for Web Interface Guidelines compliance. Use when asked to "review my UI", "check accessibility", "audit design", "review UX", or "check my site against best practices". | 100 | 92 | C | — | — | 10 Jul 2026 | |
| 1135 | A | Review UI code for Web Interface Guidelines compliance. Use when asked to "review my UI", "check accessibility", "audit design", "review UX", or "check my site against best practices". | 100 | 92 | C | — | — | 10 Jul 2026 | |
| 1136 | A | Review UI code for Web Interface Guidelines compliance. Use when asked to "review my UI", "check accessibility", "audit design", "review UX", or "check my site against best practices". | 100 | 92 | C | — | — | 10 Jul 2026 | |
| 1137 | A | Review UI code for Web Interface Guidelines compliance. Use when asked to "review my UI", "check accessibility", "audit design", "review UX", or "check my site against best practices". | 100 | 92 | C | — | — | 10 Jul 2026 | |
| 1138 | A | Review UI code for Web Interface Guidelines compliance. Use when asked to "review my UI", "check accessibility", "audit design", "review UX", or "check my site against best practices". | 100 | 92 | C | — | — | 10 Jul 2026 | |
| 1139 | A | Review UI code for Web Interface Guidelines compliance. Use when asked to "review my UI", "check accessibility", "audit design", "review UX", or "check my site against best practices". | 100 | 92 | C | — | — | 10 Jul 2026 | |
| 1140 | A | Decode and inspect JSON Web Tokens (JWTs) without verification. Use when the user provides a JWT string and wants to see its header, payload, or claims — e.g. "decode this JWT", "what's in this token" | 100 | 92 | B | — | — | 10 Jul 2026 | |
| 1141 | B | Classify a web business, then identify, draft, and checklist the compliance pages, notices, disclosures, user flows, and launch gates it needs. Use when the user wants a Privacy Policy, Cookie Policy | 95 | 79 | C | — | ↓ 484 | 9 Jun 2026 | |
| 1142 | A | Attacker's-eye security review of a diff, branch, or module — walks a fixed vulnerability catalog (missing authz on new endpoints, injection, secrets in code/logs, trusting client-sent identity, SSRF, | 98 | 86 | C | — | ↓ 38 | 30 d ago | |
| 1143 | B | Enhanced security with OWASP Top 10, dependency scanning, SAST/DAST, secrets detection, compliance checks, and security hardening guides. | 100 | 72 | C | — | ↓ 475 | 5 Jun 2026 | |
| 1144 | B | 跨境合规与贸易参考助手:认证清单(CE/FCC/GPSR)、关税估算、标签要求、 平台规则检查。经 Yufluent 云端 Harness 输出结构化 JSON 建议。 非法律或税务建议,结果须人工核实。Use for 合规、认证、关税、GPSR、CE、FCC、VAT、HS编码. | 95 | 79 | D | — | ↓ 519 | 15 Jun 2026 | |
| 1145 | A | 设计走查:将生成的 HTML/CSS 页面对照设计规范文档逐项审查,输出结构化合规报告。
当用户说"设计走查"、"走查页面"、"检查是否符合设计规范"、"审查设计合规"时触发。
生成任何 HTML/CSS 页面后也可主动触发,确保输出符合设计规范。
用户可指定任意设计规范文档路径,skill 会自动读取并逐项对照检查。 | 100 | 76 | C | — | ↓ 393 | 22 Jun 2026 | |
| 1146 | A | Activate when: a prepared 1040 or 1120-S is going to review; you are the second set of eyes on someone else's return; a firm wants one consistent review standard across reviewers; onboarding a prepare | 100 | 77 | C | — | ↓ 155 | 30 d ago | |
| 1147 | A | 网瘾中年的自媒体技能——微信公众号「网瘾中年」专用内容生产与发布全流程。覆盖选题评估、创作简报、爆款公式匹配、公众号原生写作、去AI味精修、AIGC合规守门、封面生成、草稿箱推送、数据复盘九个环节。触发词:"写一篇公众号""发一篇""推草稿箱""推送草稿""做选题""软广""日报排版""复盘阅读数据""爆款公式""网瘾中年"。不用于X/小红书/抖音等其他平台创作,不用于纯代码任务,不用于视频号发布 | 100 | 75 | D | — | ↓ 384 | 27 Jul 2026 | |
| 1148 | B | AI 漏洞追踪器 - 在 GitHub 和微信公众号搜索近一个月的 AI 相关漏洞(提示词注入、提示词越狱等),并推送到飞书表格。支持去重和翻译。
搜索关键字: prompt injection, prompt jailbreak, LLM vulnerability, AI security, adversarial prompt, jailbreak attack
数据源:
- GitHu | 99 | 72 | C | — | ↓ 697 | 18 May 2026 | |
| 1149 | B | Free developer guide for building paid skills on ClawHub. Explains the standard three-phase payment flow, SkillSpector compliance requirements, and common pitfalls for developers building ClawHub skil | 100 | 72 | C | — | ↓ 1 444 | 28 Jul 2026 | |
| 1150 | B | Reviews pull requests with scope validation, requirements compliance, and line comments | 100 | 68 | D | — | ↓ 1 412 | 20 d ago |