Skill rating
2 738 skills. The A–F grade combines safety (60%) and quality (40%); tests add a bonus. The rating refreshes automatically from open catalogs.
ManufacturingLogistics and warehouseProcurementQuality controlContact centreField serviceFinanceCustomer supportindustry shortcuts
| # | Grade | Skill | Score ▾ | Safety | Quality | Process | Tests | Popularity | Updated |
|---|---|---|---|---|---|---|---|---|---|
| 2051 | B | Scan codebase for environment variables, generate .env.example, validate .env, and ensure .gitignore safety | 100 | 63 | D | — | ★ 14 | 16 Jun 2026 | |
| 2052 | B | Navigate freelance platforms as worker or client with proposals, pricing, vetting, and legal compliance. | 100 | 63 | C | — | ★ 14 | 16 Jun 2026 | |
| 2053 | B | Security scanner for ClawHub skills. Vet third-party skills before installation — detect dangerous patterns, suspicious code, and risky dependencies. | 93 | 72 | D | — | ★ 14 | 16 Jun 2026 | |
| 2054 | B | Turn BloodHound attack path exports into dual-layer security reports — CISO executive prose on top, technical remediation playbook below. Automates Active Directory audit reporting for pentesters, blu | 86 | 70 | D | — | ↓ 968 | 26 Jul 2026 | |
| 2055 | B | 防火墙配置工具包免费版,为个人开发者包含服务器防火墙配置与安全加固能力. 适用于需要firewall toolkit相关能力的开发场景,包含结构化的工作流程和可复用的模板,帮助用户快速完成任务并保持代码质量. 适用于需要firewall toolkit相关能力的开发场景,包含结构化的工作流程和配置指引. | 95 | 62 | C | — | ↓ 460 | 27 Jul 2026 | |
| 2056 | B | Global compliance checker with API-powered regulations database (出海合规检查+全球法规数据库API). Check GDPR readiness, CCPA compliance, data localization, cross-border data transfer, payment licensing, content mo | 100 | 49 | C | — | ↓ 816 | 27 May 2026 | |
| 2057 | B | Technical SEO audit with GEO-specific checks — crawlability, indexability, security, performance, SSR, and AI crawler access | 95 | 66 | B | — | ↓ 265 | 34 d ago | |
| 2058 | B | HIPAA Compliance Check — Health Insurance Portability and Accountability Act (HIPAA), 45 C.F.R. Parts 160 & 164 (Privacy, Security, Breach Notification Rules).
Free to install; scoring runs on the CQ | 100 | 55 | D | — | ↓ 640 | 34 d ago | |
| 2059 | B | supabase-audit-authenticatedAnalyzerSupabaseData and analyticsSecurityLord1Egypt/RA-SkillsAgent Skills Create a test user (with explicit permission) to audit what authenticated users can access vs anonymous users. Detects IDOR, cross-user access, and privilege escalation. | 91 | 87 | C | — | — | 10 Jul 2026 | |
| 2060 | B | Tailwind CSS accessibility patterns including WCAG 2.2 compliance, touch targets, focus management, and ARIA.
PROACTIVELY activate for: (1) building accessible UI with Tailwind, (2) WCAG 2.2 complianc | 100 | 72 | D | — | — | 10 Jul 2026 | |
| 2061 | B | supabase-audit-buckets-listAnalyzerSupabaseSecurityWriting and documentsLord1Egypt/RA-SkillsAgent Skills List all storage buckets and their configuration to identify the storage attack surface. | 94 | 82 | C | — | — | 10 Jul 2026 | |
| 2062 | B | supabase-audit-tables-listIntegrationSupabaseSecurityWriting and documentsLord1Egypt/RA-SkillsAgent Skills List all tables exposed via the Supabase PostgREST API to identify the attack surface. | 93 | 82 | C | — | — | 10 Jul 2026 | |
| 2063 | B | Attempt to read data from exposed tables to verify actual data exposure and RLS effectiveness. | 94 | 82 | C | — | — | 10 Jul 2026 | |
| 2064 | B | Implement secure JWT (JSON Web Token) authentication in Node.js applications with access/refresh tokens and role-based access control | 100 | 72 | D | — | — | 10 Jul 2026 | |
| 2065 | B | supabase-audit-auth-usersAnalyzerSupabaseSoftware developmentSecurityLord1Egypt/RA-SkillsAgent Skills Test for user enumeration vulnerabilities through various authentication endpoints. | 93 | 84 | B | — | — | 10 Jul 2026 | |
| 2066 | B | Expert in macOS Accessibility APIs (AXUIElement) for desktop automation. Specializes in secure automation of macOS applications with proper TCC permissions, element discovery, and system interaction. | 98 | 75 | D | — | — | 10 Jul 2026 | |
| 2067 | B | Determine whether an app is ready to submit, then drive the current App Store release flow with asc, including validation, staging, review submission, first-time availability, subscriptions, IAP, Game | 100 | 72 | B | — | — | 10 Jul 2026 | |
| 2068 | B | ⚠️ AUTHORIZED USE ONLY > This skill is for educational purposes or authorized security assessments only. > You must have explicit, written permission from the system owner before using this tool. > Mi | 95 | 81 | C | — | — | 10 Jul 2026 | |
| 2069 | B | Test Row Level Security (RLS) policies for common bypass vulnerabilities and misconfigurations. | 93 | 84 | C | — | — | 10 Jul 2026 | |
| 2070 | B | 跨境电商选品智能体编排器。当用户需要进行完整的 Temu 选品流程、获取 5 款推荐产品、执行端到端选品分析时使用此 skill。自动调用 amazon-movers-shakers、temu-competitor-search、ali1688-sourcing、temu-pricing-calculator 等 skills,输出符合 V4.1 标准的完整选品报告。 | 100 | 72 | D | — | — | 10 Jul 2026 | |
| 2071 | B | 3D HUD rendering with Three.js and TresJS for JARVIS AI Assistant | 100 | 72 | D | — | — | 10 Jul 2026 | |
| 2072 | B | Comprehensive PostgreSQL-specific table design reference covering data types, indexing, constraints, performance patterns, and advanced features | 100 | 73 | C | — | — | 10 Jul 2026 | |
| 2073 | B | Provide a comprehensive checklist for planning, executing, and following up on penetration tests. Ensure thorough preparation, proper scoping, and effective remediation of discovered vulnerabilities. | 95 | 81 | B | — | — | 10 Jul 2026 | |
| 2074 | B | Product compliance and safety — certifications, labeling requirements, restricted substances, documentation | 100 | 72 | C | — | — | 10 Jul 2026 | |
| 2075 | B | Provide a comprehensive command reference for penetration testing tools including network scanning, exploitation, password cracking, and web application testing. Enable quick command lookup during sec | 95 | 81 | C | — | — | 10 Jul 2026 | |
| 2076 | B | Write competitive research proposals for NSF, NIH, DOE, DARPA, and Taiwan NSTC. Agency-specific formatting, review criteria, budget preparation, broader impacts, significance statements, innovation na | 95 | 79 | D | — | — | 10 Jul 2026 | |
| 2077 | B | Quick reference for all Supabase security audit skills with usage examples and command overview. | 95 | 81 | D | — | — | 10 Jul 2026 | |
| 2078 | B | Master PCI DSS (Payment Card Industry Data Security Standard) compliance for secure payment processing and handling of cardholder data. | 94 | 81 | B | — | — | 10 Jul 2026 | |
| 2079 | B | Quarkus Security best practices for authentication, authorization, JWT/OIDC, RBAC, input validation, CSRF, secrets management, and dependency security. | 100 | 72 | C | — | — | 10 Jul 2026 | |
| 2080 | B | Solve CTF binary exploitation challenges by discovering and exploiting memory corruption vulnerabilities to read flags. Use for buffer overflows, format strings, heap exploits, ROP challenges, or any | 100 | 72 | C | — | — | 10 Jul 2026 | |
| 2081 | B | Real-time bidirectional communication with security focus on CSWSH prevention, authentication, and message validation | 100 | 72 | D | — | — | 10 Jul 2026 | |
| 2082 | B | Ethical hacking and security testing methodologies using penetration testing tools, exploit frameworks, and manual security validation. Use when assessing application security posture and identifying | 91 | 85 | D | — | — | 10 Jul 2026 | |
| 2083 | B | Vue 3 and Nuxt 3 for JARVIS AI Assistant UI development with security-first patterns | 100 | 72 | D | — | — | 10 Jul 2026 | |
| 2084 | B | Prepare for App Store review and prevent rejections. Covers App Store review guidelines, app rejection reasons, PrivacyInfo.xcprivacy privacy manifest requirements, required API reason codes, in-app p | 100 | 73 | D | evals | — | 10 Jul 2026 | |
| 2085 | B | Prepare for and respond to SEC and FINRA regulatory examinations across the full exam lifecycle. Use when the user asks about exam notification letters, document request lists, deficiency letter respo | 97 | 78 | C | — | — | 10 Jul 2026 | |
| 2086 | B | 優良な電子帳簿の要件チェック・コンプライアンス診断を実行する。 「優良な電子帳簿」「電帳法対応」「電子帳簿の要件確認」 「税務調査の準備」「75万円控除の条件」「帳簿の要件を満たしているか」 「e-bookkeeping compliance」で起動。 | 100 | 72 | C | — | — | 10 Jul 2026 | |
| 2087 | B | REST API and WebSocket development with FastAPI emphasizing security, performance, and async patterns | 100 | 72 | D | — | — | 10 Jul 2026 | |
| 2088 | B | supply-chain-risk-auditorAnalyzerGitHubSoftware developmentData and analyticsLord1Egypt/RA-SkillsAgent Skills Identifies dependencies at heightened risk of exploitation or takeover. Use when assessing supply chain attack surface, evaluating dependency health, or scoping security engagements. | 95 | 80 | B | — | — | 10 Jul 2026 | |
| 2089 | B | Install a pre-commit hook that scans .specstory/history for secrets before commits. Run when user says "set up secret scanning", "install specstory guard", "protect my history", or "check for secrets" | 89 | 90 | C | — | — | 10 Jul 2026 | |
| 2090 | B | Constant-time testing detects timing side channels in cryptographic code. Use when auditing crypto implementations for timing vulnerabilities. | 99 | 73 | D | — | — | 10 Jul 2026 | |
| 2091 | B | Analyzes urban development through planning lens using zoning, land use, comprehensive planning,
and transit-oriented development frameworks.
Provides insights on spatial organization, infrastructure, | 100 | 72 | D | — | — | 10 Jul 2026 | |
| 2092 | B | Vercel AI Gateway expert guidance. Use when configuring model routing, provider failover, cost tracking, or managing multiple AI providers through a unified API. | 95 | 81 | D | — | — | 10 Jul 2026 | |
| 2093 | B | Use when preparing ANY app for submission, handling App Store rejections, writing appeals, or managing App Store Connect. Covers submission checklists, rejection troubleshooting, metadata requirements | 99 | 75 | D | — | — | 10 Jul 2026 | |
| 2094 | B | Security code review for vulnerabilities. Use when asked to "security review", "find vulnerabilities", "check for security issues", "audit security", "OWASP review", or review code for injection, XSS, | 83 | 97 | C | — | — | 10 Jul 2026 | |
| 2095 | B | Install, configure, and operate Strix for AI-driven application security testing. Use when you need to run authorized vulnerability scans against local codebases, GitHub repositories, staging URLs, do | 87 | 92 | C | evals | — | 10 Jul 2026 | |
| 2096 | B | Review code changes against accepted ADRs for compliance violations | 95 | 81 | D | — | — | 10 Jul 2026 | |
| 2097 | B | Help a local staffing agency owner or operator join TempGuru's partner network and win more event staffing work in their market. Use when an agency wants to join a staffing network, get overflow event | 100 | 56 | B | — | ↓ 554 | 31 d ago | |
| 2098 | B | Secure browser automation with Chrome profile support, vault integration, approval gates, and comprehensive audit logging. Use for authenticated sites, sensitive operations, or compliance requirements | 82 | 73 | C | — | ↓ 1 861 | 18 May 2026 | |
| 2099 | B | |- 功能涵盖: vulnerability, intel。 | 100 | 57 | C | — | ↓ 199 | 44 d ago | |
| 2100 | B | 当用户说『接了个MCP server不放心』『MCP工具能执行命令怕有风险』『怎么审计MCP权限』『第三方MCP会不会偷数据』,或要把某 MCP server(模型上下文协议)接进 agent、担心它是新攻击面时使用。把 MCP server 当『需审查的第三方』:扫工具清单里的 命令执行/文件系统写/网络外联/凭证暴露 四类风险,给风险评级与最小授权建议。理论根基:LGD 三律(有籍·有证·有门 | 100 | 61 | D | — | ↓ 77 | 3 d ago |