Skill rating
124 skills. The A–F grade combines safety (60%) and quality (40%); tests add a bonus. The rating refreshes automatically from open catalogs.
ManufacturingLogistics and warehouseProcurementQuality controlContact centreField serviceFinanceCustomer supportindustry shortcuts
| # | Grade | Skill | Score ▾ | Safety | Quality | Process | Tests | Popularity | Updated |
|---|---|---|---|---|---|---|---|---|---|
| 101 | B | Analyzing session replays, extracting persona-based behavioral patterns, and storytelling UX issues. Reads the 'why' from real user operation logs. Works with Field/Echo for persona validation. | 100 | 65 | C | — | — | 2 h ago | |
| 102 | B | Optimizing frontend (re-render, memoization, lazy loading) and backend (N+1, indexing, caching, async) performance, plus continuous auto-tuning loops for GC/threadpool/cache/worker settings. | 100 | 65 | C | — | — | 2 h ago | |
| 103 | B | Comprehending and investigating codebases: structure mapping, feature discovery, data flow tracing for 'does X exist?' or 'how does Y work?'. Includes a conversational ask mode. Does not write code. | 100 | 65 | C | — | — | 2 h ago | |
| 104 | B | Proposing, configuring, debugging, and maintaining Claude Code hooks (PreToolUse/PostToolUse/Stop and other lifecycle events). Use for workflow automation or quality gates via hooks. | 91 | 77 | C | — | — | 2 h ago | |
| 105 | B | Auditing AI CLI configs and designing, configuring, or debugging Claude Code hooks. Use for Codex/agy/Claude Code config reviews, hook lifecycle automation, quality gates, or MCP governance. | 91 | 77 | C | — | — | 2 h ago | |
| 106 | B | Simulating business strategy via short/mid/long-term scenario planning from financial, market, and competitive data. Applies SWOT/PESTLE/Porter, KPI forecasting, roadmaps. Does not write code. | 94 | 69 | C | — | — | 2 h ago | |
| 107 | B | Analyzing code statically for security flaws: hardcoded secrets, SQL injection, input validation, security headers, dependency CVEs. Not for runtime exploit checks (Probe) or code review (Judge). | 93 | 69 | B | — | — | 2 h ago | |
| 108 | B | Orchestrating multi-specialist task chains and scope-adaptive product delivery: classifies intent, selects and executes the minimum viable chain, aggregates results, and verifies acceptance criteria. | 96 | 64 | B | — | — | 2 h ago | |
| 109 | B | Improving usability, interaction quality, cognitive load reduction, feedback design, and a11y compliance. Use when improving UX usability or interaction feel. | 82 | 81 | B | — | — | 2 h ago | |
| 110 | B | Automating browsers via Playwright and Chrome DevTools for data collection, form interaction, screenshot capture, and network monitoring. Task completion focus (vs Voyager for E2E testing). | 92 | 65 | B | — | — | 2 h ago | |
| 111 | B | Engineering detection rules (Sigma/YARA), detection coverage mapping, threat hunting hypotheses, Purple Team Blue side, Detection-as-Code CI/CD. Use when defensive verification is needed. | 78 | 77 | B | — | — | 2 h ago | |
| 112 | B | Integrating OWASP ZAP/Burp Suite/Nuclei, planning penetration tests, executing DAST, and scanning for vulnerabilities. For runtime vulnerability validation. Complements Sentinel static analysis. | 82 | 69 | B | — | — | 2 h ago | |
| 113 | B | Orchestrating migrations, upgrades, and modernization across frameworks, libraries, APIs, databases, and dependencies. Generates codemods, applies Strangler Fig, verifies equivalence, plans rollback. | 82 | 65 | C | — | — | 2 h ago | |
| 114 | C | anvilIntegrationVS CodeSoftware developmentInfrastructuresimota/agent-skillsAgent Skillsnot recommended Building CLI/TUI tools and configuring personal developer environments. Use for terminal interfaces, dotfiles, shell/editor/terminal setup, or macOS AppleScript/JXA automation. | 71 | 77 | C | — | — | 2 h ago | |
| 115 | C | Designing red team attack scenarios, threat models, MITRE ATT&CK/OWASP application, Purple Team exercises, and AI/LLM red teaming. Use when adversarial security validation is needed. | 67 | 81 | C | — | — | 2 h ago | |
| 116 | C | Defining KPIs, tracking events, and dashboards: North Star Metric, funnel and cohort analysis, test-intelligence views. GA4/Amplitude/Mixpanel/PostHog. Use when metrics design is needed. | 64 | 77 | C | — | — | 2 h ago | |
| 117 | A | Converting document formats (Markdown/Word/Excel/PDF/HTML) and generating reusable conversion scripts. Use for distributable specs, accessibility-compliant PDFs, or Pandoc/LibreOffice pipelines. | 100 | 75 | F will not run | — | — | 2 h ago | |
| 118 | B | Converting a supplied prompt into an executable specification: detects vague quality/quantity/explanation/style/design/technical/judgment wording, role and persona theater, and self-contradiction, the | 100 | 72 | F will not run | — | — | 2 h ago | |
| 119 | B | Verifying YAGNI, cutting scope, and proposing complexity reductions. A 'subtraction' agent questioning the justification for every feature, dependency, doc, and config. Does not write code. | 100 | 63 | F will not run | — | — | 2 h ago | |
| 120 | B | Tuning database queries via EXPLAIN ANALYZE, query plan optimization, index recommendations, and slow query detection. Not for schema/migrations (Schema) or non-DB performance (Bolt). | 100 | 57 | F will not run | — | — | 2 h ago | |
| 121 | B | Designing web-to-iOS/Android porting strategy: feature parity matrices, native architecture maps, phased Strangler-Fig roadmaps. Not for same-language migration (Shift) or native impl (Native). | 100 | 57 | F will not run | — | — | 2 h ago | |
| 122 | D | Implementing production iOS/Android/macOS native features (SwiftUI, Compose) and iterating a screen against a reference design. Not for cross-platform RN/Flutter (Port) or web (Artisan). | 31 | 73 | C | — | — | 2 h ago | |
| 123 | D | cullProcedureGitHubVS CodeSoftware developmentAI and agentssimota/agent-skillsAgent Skillsnot recommended Scanning and eradicating supply-chain malware (Shai-Hulud/S1ngularity npm/PyPI worms): IoC scan, OS/IDE persistence, safe credential rotation. Not for SAST (Sentinel) or skill/MCP audit (Chain). | 27 | 73 | B | — | — | 2 h ago | |
| 124 | F | Auditing skill/plugin/MCP supply chains and live package compromise: manifests, hidden injection, IoC scans, persistence-first eradication, and gated credential rotation. Not for app SAST (Sentinel). | 0 | 64 | F will not run | — | — | 2 h ago |