SKILLEMALL.ai

Skill rating

2 738 skills. The A–F grade combines safety (60%) and quality (40%); tests add a bonus. The rating refreshes automatically from open catalogs.

2 738
#GradeSkillScore ▾SafetyQualityProcessTestsPopularityUpdated
2051B
Scan codebase for environment variables, generate .env.example, validate .env, and ensure .gitignore safety
8510063D★ 1416 Jun 2026
2052B
Navigate freelance platforms as worker or client with proposals, pricing, vetting, and legal compliance.
8510063C★ 1416 Jun 2026
2053B
Security scanner for ClawHub skills. Vet third-party skills before installation — detect dangerous patterns, suspicious code, and risky dependencies.
859372D★ 1416 Jun 2026
2054B
Turn BloodHound attack path exports into dual-layer security reports — CISO executive prose on top, technical remediation playbook below. Automates Active Directory audit reporting for pentesters, blu
808670D↓ 96826 Jul 2026
2055B
防火墙配置工具包免费版,为个人开发者包含服务器防火墙配置与安全加固能力. 适用于需要firewall toolkit相关能力的开发场景,包含结构化的工作流程和可复用的模板,帮助用户快速完成任务并保持代码质量. 适用于需要firewall toolkit相关能力的开发场景,包含结构化的工作流程和配置指引.
829562C↓ 46027 Jul 2026
2056B
Global compliance checker with API-powered regulations database (出海合规检查+全球法规数据库API). Check GDPR readiness, CCPA compliance, data localization, cross-border data transfer, payment licensing, content mo
8010049C↓ 81627 May 2026
2057B
Technical SEO audit with GEO-specific checks — crawlability, indexability, security, performance, SSR, and AI crawler access
839566B↓ 26534 d ago
2058B
HIPAA Compliance Check — Health Insurance Portability and Accountability Act (HIPAA), 45 C.F.R. Parts 160 & 164 (Privacy, Security, Breach Notification Rules). Free to install; scoring runs on the CQ
8210055D↓ 64034 d ago
2059B
Create a test user (with explicit permission) to audit what authenticated users can access vs anonymous users. Detects IDOR, cross-user access, and privilege escalation.
899187C10 Jul 2026
2060B
Tailwind CSS accessibility patterns including WCAG 2.2 compliance, touch targets, focus management, and ARIA. PROACTIVELY activate for: (1) building accessible UI with Tailwind, (2) WCAG 2.2 complianc
8910072D10 Jul 2026
2061B
List all storage buckets and their configuration to identify the storage attack surface.
899482C10 Jul 2026
2062B
List all tables exposed via the Supabase PostgREST API to identify the attack surface.
899382C10 Jul 2026
2063B
Attempt to read data from exposed tables to verify actual data exposure and RLS effectiveness.
899482C10 Jul 2026
2064B
Implement secure JWT (JSON Web Token) authentication in Node.js applications with access/refresh tokens and role-based access control
8910072D10 Jul 2026
2065B
Test for user enumeration vulnerabilities through various authentication endpoints.
899384B10 Jul 2026
2066B
Expert in macOS Accessibility APIs (AXUIElement) for desktop automation. Specializes in secure automation of macOS applications with proper TCC permissions, element discovery, and system interaction.
899875D10 Jul 2026
2067B
Determine whether an app is ready to submit, then drive the current App Store release flow with asc, including validation, staging, review submission, first-time availability, subscriptions, IAP, Game
8910072B10 Jul 2026
2068B
⚠️ AUTHORIZED USE ONLY > This skill is for educational purposes or authorized security assessments only. > You must have explicit, written permission from the system owner before using this tool. > Mi
899581C10 Jul 2026
2069B
Test Row Level Security (RLS) policies for common bypass vulnerabilities and misconfigurations.
899384C10 Jul 2026
2070B
跨境电商选品智能体编排器。当用户需要进行完整的 Temu 选品流程、获取 5 款推荐产品、执行端到端选品分析时使用此 skill。自动调用 amazon-movers-shakers、temu-competitor-search、ali1688-sourcing、temu-pricing-calculator 等 skills,输出符合 V4.1 标准的完整选品报告。
8910072D10 Jul 2026
2071B
3D HUD rendering with Three.js and TresJS for JARVIS AI Assistant
8910072D10 Jul 2026
2072B
Comprehensive PostgreSQL-specific table design reference covering data types, indexing, constraints, performance patterns, and advanced features
8910073C10 Jul 2026
2073B
Provide a comprehensive checklist for planning, executing, and following up on penetration tests. Ensure thorough preparation, proper scoping, and effective remediation of discovered vulnerabilities.
899581B10 Jul 2026
2074B
Product compliance and safety — certifications, labeling requirements, restricted substances, documentation
8910072C10 Jul 2026
2075B
Provide a comprehensive command reference for penetration testing tools including network scanning, exploitation, password cracking, and web application testing. Enable quick command lookup during sec
899581C10 Jul 2026
2076B
Write competitive research proposals for NSF, NIH, DOE, DARPA, and Taiwan NSTC. Agency-specific formatting, review criteria, budget preparation, broader impacts, significance statements, innovation na
899579D10 Jul 2026
2077B
Quick reference for all Supabase security audit skills with usage examples and command overview.
899581D10 Jul 2026
2078B
Master PCI DSS (Payment Card Industry Data Security Standard) compliance for secure payment processing and handling of cardholder data.
899481B10 Jul 2026
2079B
Quarkus Security best practices for authentication, authorization, JWT/OIDC, RBAC, input validation, CSRF, secrets management, and dependency security.
8910072C10 Jul 2026
2080B
Solve CTF binary exploitation challenges by discovering and exploiting memory corruption vulnerabilities to read flags. Use for buffer overflows, format strings, heap exploits, ROP challenges, or any
8910072C10 Jul 2026
2081B
Real-time bidirectional communication with security focus on CSWSH prevention, authentication, and message validation
8910072D10 Jul 2026
2082B
Ethical hacking and security testing methodologies using penetration testing tools, exploit frameworks, and manual security validation. Use when assessing application security posture and identifying
899185D10 Jul 2026
2083B
Vue 3 and Nuxt 3 for JARVIS AI Assistant UI development with security-first patterns
8910072D10 Jul 2026
2084B
Prepare for App Store review and prevent rejections. Covers App Store review guidelines, app rejection reasons, PrivacyInfo.xcprivacy privacy manifest requirements, required API reason codes, in-app p
8910073Devals10 Jul 2026
2085B
Prepare for and respond to SEC and FINRA regulatory examinations across the full exam lifecycle. Use when the user asks about exam notification letters, document request lists, deficiency letter respo
899778C10 Jul 2026
2086B
優良な電子帳簿の要件チェック・コンプライアンス診断を実行する。 「優良な電子帳簿」「電帳法対応」「電子帳簿の要件確認」 「税務調査の準備」「75万円控除の条件」「帳簿の要件を満たしているか」 「e-bookkeeping compliance」で起動。
8910072C10 Jul 2026
2087B
REST API and WebSocket development with FastAPI emphasizing security, performance, and async patterns
8910072D10 Jul 2026
2088B
Identifies dependencies at heightened risk of exploitation or takeover. Use when assessing supply chain attack surface, evaluating dependency health, or scoping security engagements.
899580B10 Jul 2026
2089B
Install a pre-commit hook that scans .specstory/history for secrets before commits. Run when user says "set up secret scanning", "install specstory guard", "protect my history", or "check for secrets"
898990C10 Jul 2026
2090B
Constant-time testing detects timing side channels in cryptographic code. Use when auditing crypto implementations for timing vulnerabilities.
899973D10 Jul 2026
2091B
Analyzes urban development through planning lens using zoning, land use, comprehensive planning, and transit-oriented development frameworks. Provides insights on spatial organization, infrastructure,
8910072D10 Jul 2026
2092B
Vercel AI Gateway expert guidance. Use when configuring model routing, provider failover, cost tracking, or managing multiple AI providers through a unified API.
899581D10 Jul 2026
2093B
Use when preparing ANY app for submission, handling App Store rejections, writing appeals, or managing App Store Connect. Covers submission checklists, rejection troubleshooting, metadata requirements
899975D10 Jul 2026
2094B
Security code review for vulnerabilities. Use when asked to "security review", "find vulnerabilities", "check for security issues", "audit security", "OWASP review", or review code for injection, XSS,
898397C10 Jul 2026
2095B
Install, configure, and operate Strix for AI-driven application security testing. Use when you need to run authorized vulnerability scans against local codebases, GitHub repositories, staging URLs, do
898792Cevals10 Jul 2026
2096B
Review code changes against accepted ADRs for compliance violations
899581D10 Jul 2026
2097B
Help a local staffing agency owner or operator join TempGuru's partner network and win more event staffing work in their market. Use when an agency wants to join a staffing network, get overflow event
8210056B↓ 55431 d ago
2098B
Secure browser automation with Chrome profile support, vault integration, approval gates, and comprehensive audit logging. Use for authenticated sites, sensitive operations, or compliance requirements
788273C↓ 1 86118 May 2026
2099B
|- 功能涵盖: vulnerability, intel。
8310057C↓ 19944 d ago
2100B
当用户说『接了个MCP server不放心』『MCP工具能执行命令怕有风险』『怎么审计MCP权限』『第三方MCP会不会偷数据』,或要把某 MCP server(模型上下文协议)接进 agent、担心它是新攻击面时使用。把 MCP server 当『需审查的第三方』:扫工具清单里的 命令执行/文件系统写/网络外联/凭证暴露 四类风险,给风险评级与最小授权建议。理论根基:LGD 三律(有籍·有证·有门
8410061D↓ 773 d ago