SKILLEMALL.ai

Skill rating

2 738 skills. The A–F grade combines safety (60%) and quality (40%); tests add a bonus. The rating refreshes automatically from open catalogs.

2 738
#GradeSkillScore ▾SafetyQualityProcessTestsPopularityUpdated
1801A
Search the U.S. National Vulnerability Database for CVEs, CVSS scores, affected versions, and severity ratings — by keyword, product (CPE name), CVE ID, or date range. Trigger phrases: `look up CVE`,
929588A10 Jul 2026
1802A
Security audit workflow - vulnerability scan → verification
929981D10 Jul 2026
1803A
Design abstract strategy games with perfect information, no randomness, and strategic depth. Use when designing a board game, exploring abstract strategy games, brainstorming game mechanics, or evalua
9210081C10 Jul 2026
1804A
Guides Qdrant monitoring setup including Prometheus scraping, health probes, Hybrid Cloud metrics, alerting, and log centralization. Use when someone asks 'how to set up monitoring', 'Prometheus confi
9210080D10 Jul 2026
1805A
General-purpose security auditing guide. Covers OWASP Top 10, dependency vulnerabilities, authentication, authorization, input validation, and secret management. Use this when performing a security
9210081C10 Jul 2026
1806A
Expose a local service to the public internet using ngrok. Starts a tunnel, optionally adds OAuth or WAF via Traffic Policy. Use when asked to expose, tunnel, share, or make a local service publicly a
9210079B10 Jul 2026
1807A
Extract and document a writer's distinctive voice patterns for consistent reproduction. Use when you need to capture writing voice, analyze writing style, create a voice guide, or write in someone's e
9210081C10 Jul 2026
1808A
Implement Google's Material Design 3 (Material You) UI system. Primary: Jetpack Compose Material3 (MaterialTheme, components, adaptive layout). Also Flutter and limited web (@material/web, maintenance
929982D10 Jul 2026
1809A
Scan code for security vulnerabilities including OWASP Top 10, secrets, and misconfigurations. Use when you need comprehensive security analysis of a codebase.
929588C10 Jul 2026
1810A
Umbrella skill for Capgo cloud workflows. Use when the user needs native builds, OTA releases, store publishing, or organization-level Capgo operations and the request spans more than one Capgo workfl
9210080C10 Jul 2026
1811A
Manage long-term fate and fortune across a shared world. Use when powerful entities feel permanent, when the world becomes static, when you need probabilistic death/fall mechanics, or when campaigns n
9210081D10 Jul 2026
1812A
Review orchestrator: assess your application and recommend the right combination of design, security, privacy, compliance, resilience, performance, SEO, and GEO reviews.
9210080D10 Jul 2026
1813A
Identifies error-prone APIs, dangerous configurations, and footgun designs that enable security mistakes. Use when reviewing API designs, configuration schemas, cryptographic library ergonomics, or ev
929588C10 Jul 2026
1814A
Implement PCI DSS compliance requirements for secure handling of payment card data and payment systems. Use when securing payment processing, achieving PCI compliance, or implementing payment card sec
929588C10 Jul 2026
1815A
小说大纲/世界观/人设设计,适用于用户说"帮我写个小说大纲"、"设计主角人设"、"做世界观设定"、"搭小说剧情框架"、"写分卷细纲"、"给我设计小说人物"、"做个玄幻世界观"、"帮我梳理小说剧情"、"小说人物设定"、"写小说分章大纲"、"爽点排布规划"、"做小说人设卡"、"构建小说世界"等需求,生成完整的世界观、人物卡、剧情大纲、爽点规划,自动合规检查避免侵权风险,**大批量章节细纲生成时使用子A
9210080D10 Jul 2026
1816A
Write the canonical ai-env blueprint plan for a multi-step task (Step 3 of /task). Runs one brainstorming round, uses ai-workspace/plans/TEMPLATE.md, and writes ai-workspace/plans/<name>.md. Skipped f
9210079B10 Jul 2026
1817A
Security vulnerability detection and variant analysis skill. Use when hunting for dangerous APIs, footgun patterns, error-prone configurations, and vulnerability variants across codebases. Combines sh
929588D10 Jul 2026
1818A
Design for everyone by treating accessibility as a first-class design discipline, not a compliance checklist. Part of the Intent design strategy system. Covers WCAG 2.2 for designers, screen reader ex
9210079B10 Jul 2026
1819B
Holland风场衰减叠加降水风暴潮与暴露度的损失估算
8610065C↓ 23842 d ago
1820B
暴露敏感性与适应能力三分量归一化干旱脆弱性评估
8610065C↓ 23642 d ago
1821B
8510063C↓ 59244 d ago
1822B
国内营销文案合规审核指南。涵盖广告法通用红线、全平台统一规则、微信生态、抖音、小红书各平台的违禁词、替换表达和风控逻辑。写国内营销/推广文案前加载此 skill。
8610065C↓ 22340 d ago
1823B
Open source license reference — SPDX identifiers, permissive vs copyleft comparison, license compatibility matrix, patent clauses, and compliance scanning tools
8310057D↓ 67811 May 2026
1824B
Zero‑exposure cross‑device script authorization using MGC Blackbox seal functionality. Scripts are encrypted with target node's RSA public key, transferred as ciphertext, and decrypted only during exe
8510063C↓ 54528 d ago
1825B
Full GDPR compliance audit for any website or codebase using the ETALON CLI. Scans for trackers (111k+ domain database), tests consent violations, checks privacy policy vs reality, maps PII data flows
8310058D↓ 62911 May 2026
1826B
Audits HTML/CSS for WCAG 2.1 compliance. Color contrast, ARIA labels, keyboard navigation, screen reader support.
8110053F↓ 1 82811 May 2026
1827B
当用户说『agent乱调工具』『误删了文件』『不该发邮件却发了』『怎么给AI的工具加权限边界』,或在给 agent 接工具(文件/网络/数据库/消息/支付)想防危险动作时使用。把每次 tool call 当『需授权操作』:按 读/写/删/外发/支付 分级,危险动作先拦截+提示确认,低风险放行。理论根基:LGD 三律(有籍·有证·有门禁)。触发词:工具调用安全、agent权限、tool call g
8710067D↓ 764 d ago
1828B
Plan campaign visuals and hooks for legal services promotions. Use when working on paid campaign planning for legal ops teams, attorneys, compliance teams.
839565D↓ 64511 May 2026
1829B
欧盟REACH法规专家助手;基于完整中文知识库提供SVHC候选物质查询、化学品合规评估、注册流程指导、法规解读等专业服务。不访问欧盟网站,完全基于国内公开资源和中文化知识库回答
8510062D↓ 31416 Jul 2026
1830B
基于睿观的产品图片政策合规检测,通过视觉相似度匹配识别潜在违规商品。当用户提到政策合规检查、产品图片合规、违规检测、禁售商品筛查、基于图片的合规审查、上架前风险排查、policy compliance detection, product compliance review, violation detection, image compliance check, product image ri
849272C↓ 76932 d ago
1831B
PIPL Audit — 个人信息保护法合规深度审计(基于《个人信息保护法》PIPL 2021-11-01 施行 及配套规则),覆盖 9 大审计域 32 项审计检查(审计范围/告知同意/处理原则/敏感信息与未成年人/ 个人权利/自动化决策/跨境传输/数据安全与事件响应/治理与持续合规)。免费安装; 评分运行于 CQDev 云端合规引擎。无 Key 时自动匿名试用(5 次真实云端评分 / 7 天窗口
8510063D↓ 29735 d ago
1832B
GraphQL schema static auditor. Reads any .graphql SDL file or introspection JSON to detect N+1 exposure hotspots (nested list-within-list queries with no dataloader hint), unbounded query depth vulner
8310057D↓ 63623 Jun 2026
1833B
AI 安全与红队测试实操手册——覆盖 AI 系统六大攻击面(提示注入、越权与工具滥用、数据与隐私泄露、幻觉与质量缺陷、供应链与模型投毒、拒绝服务),OWASP LLM Top 10 风险映射,完整红队测试流程(目标定义/攻击面建模/用例设计/执行/报告/修复复测),直接与间接提示注入测试用例库、Agent 越权与沙箱逃逸测试、训练数据泄露与记忆攻击测试、幻觉检测基准,附漏洞分级与修复建议、零依赖本
869868C↓ 16519 d ago
1834B
内容合规审核守卫(v25.0合并content-compliance-checker),三级审核(敏感词→AI语义→平台规则)+U19管道合规步骤(委托risk-detector 10类风险检测)。触发:内容审核/合规检查/敏感词检测/发布前审核/文案审核/U19/风控检查 不触发:内容发布/内容生成/价格调整
8510063C↓ 21431 d ago
1835B
X (Twitter) (x.com). Use this skill for ANY X (Twitter) request — reading, creating, updating, and deleting data. Whenever a task involves X (Twitter), use this skill instead of calling the API direct
838284C↓ 64316 Jun 2026
1836B
age file encryption reference — the modern, simple alternative to GPG. Covers key generation, X25519 encryption, SSH key support, passphrase mode, pipe patterns, SOPS integration, YubiKey plugins, and
8210056D↓ 98111 May 2026
1837B
Solidity smart contract security audit assistant following EEA EthTrust V3 specification. Performs structured audit workflow: vulnerability scanning, security analysis, audit reports. Detects reentran
798963C★ 2 14120 Jul 2026
1838B
IPQualityScore (ipqualityscore.com). Use this skill for ANY IPQualityScore request — searching and reading data. Whenever a task involves IPQualityScore, use this skill instead of calling the API dire
838284C↓ 59716 Jun 2026
1839B
Server-Side Request Forgery (SSRF) vulnerability scanner (OWASP A10:2021). Detects URL-fetching sinks in Python/Java/Node.js/PHP/Go/Ruby that accept user-controlled URLs without validation. Flags clou
8310057D↓ 58223 Jun 2026
1840B
Cybercentry Cyber Security Consultant on ACP - Instant expert-level cyber security advisory powered by @centry_agent. Get threat intelligence, defence recommendations, and remediation advice for a fra
879969C★ 1416 Jun 2026
1841B
商标异议·无效申请推理引擎(SJ-IRAC):基于法条要件、证据链与风险分级的专业级审查与攻防系统。
8710067B★ 1416 Jun 2026
1842B
Check data compliance with construction standards. Validate data against ISO 19650, IFC, COBie, UniFormat standards.
8710068C★ 1416 Jun 2026
1843B
Production-grade model router for OpenClaw: prefix routing (@codex/@mini), timezone-aware schedule switching, verify-after-switch, rollback, lock protection, and JSONL audit logs.
8710068C★ 1416 Jun 2026
1844B
Assess Active Directory identity attack paths including roasting, relay, and delegation abuse.
879576C★ 1416 Jun 2026
1845B
This skill should be used when the user asks to "identify web application vulnerabilities", "explain common security flaws", "understand vulnerability categories", "learn about injection attacks", "re
879674C★ 1416 Jun 2026
1846B
You are a Go production engineering expert. Follow this system for every Go project — from architecture decisions through production deployment. Apply phases sequentially for new projects; use indi...
8710067D★ 1416 Jun 2026
1847B
Security self-assessment tool for AI agents. Run this against your own configuration to get a structured threat model report with RED/AMBER/GREEN ratings across six security domains — decision boundar
8710068C★ 1416 Jun 2026
1848B
Analyze supply chain vulnerabilities, map supplier dependencies, and generate risk mitigation plans.
8710067C★ 1416 Jun 2026
1849B
Set up authorized C2 simulation workflows and measure defensive detection outcomes.
879576C★ 1416 Jun 2026
1850B
商标驳回复审推理引擎(SJ-IRAC):面向CNIPA驳回通知的要件化论证、证据链工程与A–E风险闸门,输出审查员可读、可直接提交的复审材料结构。
8710067B★ 1416 Jun 2026