SKILLEMALL.ai

Skill rating

2 688 skills. The A–F grade combines safety (60%) and quality (40%); tests add a bonus. The rating refreshes automatically from open catalogs.

2 688
#GradeSkillScore ▾SafetyQualityProcessTestsPopularityUpdated
2551B
Configure Static Application Security Testing (SAST) tools for automated vulnerability detection in application code. Use when setting up security scanning, implementing DevSecOps practices, or automa
899975F will not run★ 1416 Jun 2026
2552B
Define and implement Service Level Indicators (SLIs) and Service Level Objectives (SLOs) with error budgets and alerting. Use when establishing reliability targets, implementing SRE practices, or meas
8910072F will not run★ 1416 Jun 2026
2553B
Que22ries Hu22a22wei Cloud identity and access ma2222nagement resources (IAM) via read-only Python SDK. Covers users, groups, policies, agencies, AK/SK, MFA devices, login/password/ACL policies, secur
869868F will not run↓ 75927 Jul 2026
2554B
快手全场景数据查询助手。支持App和Web双端API,覆盖视频详情、用户数据、搜索、热榜、直播、评论等全功能。
8510063F will not run↓ 5022 Jun 2026
2555B
微博全场景数据查询助手。整合App/Web/V2多版本API,覆盖微博详情、用户数据、AI搜索、高级搜索、热搜榜单、评论、视频等全功能。
8510063F will not run↓ 4942 Jun 2026
2556B
B站视频、用户、评论、弹幕、直播数据查询助手。支持App和Web双端API。
8510063F will not run↓ 4682 Jun 2026
2557B
China company search and business registry skill by Fengniao (Riskbird). Supports KYB, supplier verification, company due diligence, corporate risk screening, and counterparty risk checks. Retrieves b
8410059F will not run↓ 72011 May 2026
2558A
Smart contract vulnerability playbook. Use when auditing Solidity/EVM contracts for reentrancy, integer overflow, access control, delegatecall, flash loan, signature replay, and MEV-related attack pat
9010075F will not run★ 510 Jul 2026
2559A
Expression Language injection playbook. Use when Java EL, SpEL, OGNL, or MVEL expressions may evaluate attacker-controlled input in Spring, Struts2, Confluence, or similar frameworks.
9010075F will not run★ 510 Jul 2026
2560A
Creates, updates, validates, and displays the architectural DNA of a project through two shared documents: docs/specs/architecture.md (technology stack, architectural rules, security constraints, AI g
909582F will not run★ 510 Jul 2026
2561A
Hardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external integrations. Use when building any feature that accepts untrusted data, manages user sess
9010076F will not run★ 510 Jul 2026
2562A
Operations management across process optimization, efficiency, and continuous improvement. Use when designing workflows, building capacity plans, evaluating vendors, running Lean Six Sigma DMAIC proje
9010076F will not run★ 510 Jul 2026
2563A
DeFi attack pattern playbook. Use when analyzing flash loan attacks, price oracle manipulation, MEV sandwich attacks, governance exploits, bridge vulnerabilities, and token standard edge cases in dece
9010075F will not run★ 510 Jul 2026
2564A
Configure Static Application Security Testing (SAST) tools for automated vulnerability detection in application code. Use when setting up security scanning, implementing DevSecOps practices, or automa
9010075F will not run★ 510 Jul 2026
2565A
CRLF injection playbook. Use when user input reaches HTTP response headers, Location redirects, Set-Cookie values, or log files where carriage-return/line-feed characters can split or inject content.
9010075F will not run★ 510 Jul 2026
2566A
Use when hardening Go code at API boundaries — copying slices/maps, verifying interface compliance, using defer for cleanup, time.Time/time.Duration, or avoiding mutable globals. Also use when reviewi
9010076F will not run★ 510 Jul 2026
2567C
601000D★ 510 Jul 2026
2568B
Multi-platform backup and restore for Hermes Agent and OpenClaw. Backs up configuration, memories, skills, sessions, and workspace. Features: optional encryption, optional cloud storage (S3/Google Dri
849962F will not run↓ 69518 May 2026
2569D
57950C↓ 1329 d ago
2570B
Security advisory feed with automated NVD CVE polling for OpenClaw-related vulnerabilities. Updated daily.
809951F will not run★ 2 14120 Jul 2026
2571B
Psychological profiling through natural conversation using narrative identity research (McAdams), self-defining memory elicitation (Singer), and Motivational Interviewing (OARS framework). Use when yo
8810069F will not run★ 1416 Jun 2026
2572D
Security scanner and hardening tool for OpenClaw. Use when the user asks about security, wants to scan installed skills for malware or vulnerabilities, audit their OpenClaw configuration, check their
583986C★ 1416 Jun 2026
2573B
Conduct enterprise-grade financial research with multi-source synthesis, regulatory compliance tracking, and verified market analysis. Use when user needs comprehensive financial analysis requiring 10
899973F will not run★ 510 Jul 2026
2574B
Master Robert Cialdini's 6 (+1) Principles of Persuasion from "Influence: The Psychology of Persuasion" (1984). Ethically apply the psychology of compliance to marketing. Use when: Designing landing p
8910073F will not run★ 510 Jul 2026
2575B
Format string exploitation playbook. Use when printf-family functions receive user-controlled format strings, enabling arbitrary stack reads (%p/%s), arbitrary memory writes (%n/%hn/%hhn), GOT/hook ov
8910072F will not run★ 510 Jul 2026
2576B
Binary protection bypass playbook. Use when identifying and bypassing ASLR, PIE, NX/DEP, stack canary, RELRO, FORTIFY_SOURCE, CET, and MTE protections in ELF binaries to enable exploitation.
899975F will not run★ 510 Jul 2026
2577B
Email header injection and spoofing playbook. Use when testing contact forms, email APIs, password reset flows, or any feature that constructs SMTP messages with user-controlled fields. Covers CRLF in
8910072F will not run★ 510 Jul 2026
2578B
Hash attack playbook. Use when exploiting length extension, MD5/SHA1 collisions, HMAC timing leaks, birthday attacks, or hash-based proof of work in CTF and authorized testing scenarios.
8910072F will not run★ 510 Jul 2026
2579B
Use when needing to understand content moderation policies, avoid content removal, or successfully navigate Xiaohongshu's content review process
8910072F will not run★ 510 Jul 2026
2580B
Heap exploitation playbook. Use when targeting ptmalloc2/glibc heap vulnerabilities including UAF, double free, overflow, off-by-one/null, and leveraging tcache/fastbin/unsortedbin attacks for arbitra
8910072F will not run★ 510 Jul 2026
2581A
Hardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external integrations. Use when building any feature that accepts untrusted data, manages user sess
9010076F will not run★ 29 Apr 2026
2582B
Static ReDoS (Regular Expression Denial of Service) vulnerability scanner and regex quality auditor for codebases. Walks all source files to extract regex literals, detects catastrophic backtracking p
8310057F will not run↓ 62623 Jun 2026
2583B
Browse curated penetration testing resources and exploit databases. Use when planning security audits, researching vulns, or building toolkits.
818773F will not run↓ 1 64617 May 2026
2584D
57950F★ 1416 Jun 2026
2585B
Security audit and threat model for OpenClaw gateway hosts. Use to verify OpenClaw configuration, exposure, skills/plugins, filesystem hygiene, and to produce an OK/VULNERABLE report with evidence and
879968F will not run★ 1416 Jun 2026
2586B
Run a structured health check of your ecommerce seller account — covering listing quality, policy compliance, performance metrics, and account standing — to catch problems before they catch you.
8210055F will not run↓ 8409 Jun 2026
2587B
Argues that emotional intelligence becomes strategically critical precisely because of AI -- not despite it -- and provides leaders with practices for developing the soft skills that constitute the hu
8210056F will not run↓ 77811 May 2026
2588B
Parse and analyze email headers to trace the origin of phishing emails, verify sender authenticity, and identify spoofing through SPF, DKIM, and DMARC validation.
889872F will not run★ 510 Jul 2026
2589B
Apply CIS benchmarks and secure Linux servers. Configure SSH, manage users, implement firewall rules, and enable security features. Use when hardening Linux systems for production or meeting security
8810069F will not run★ 510 Jul 2026
2590B
Framework for defining and implementing Service Level Indicators (SLIs), Service Level Objectives (SLOs), and error budgets.
8810069F will not run★ 510 Jul 2026
2591B
Kerberos attack playbook for Active Directory. Use when targeting AD authentication via AS-REP roasting, Kerberoasting, golden/silver/diamond tickets, delegation abuse, or pass-the-ticket attacks.
889872F will not run★ 510 Jul 2026
2592B
Fast synchronous key-value storage for React Native via react-native-mmkv (Nitro-backed). Covers creating and configuring MMKV instances, reading/writing all value types (string, number, boolean, buff
8810071F will not run★ 510 Jul 2026
2593B
Symmetric cipher attack playbook. Use when exploiting block cipher mode weaknesses (CBC padding oracle, ECB cut-and-paste, bit flipping), stream cipher key reuse, or meet-in-the-middle attacks.
889972F will not run★ 510 Jul 2026
2594B
Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns. Use when writing Semgrep rules or building custom static analysis detections.
889479F will not run★ 510 Jul 2026
2595B
HTTP request smuggling and desynchronization testing. Use when front proxies, CDNs, or load balancers disagree with the origin on message framing (Content-Length vs Transfer-Encoding), on HTTP/2→HTTP/
889972F will not run★ 510 Jul 2026
2596B
ToB SaaS产品PRD AI助手。用于创建、评审、优化ToB SaaS产品的产品需求文档。支持三种场景:(1)独立新产品从0到1构建,(2)独立新能力功能级创新开发,(3)现有能力迭代优化与发布管理。内置市场调研、价值分析、竞品对标、功能设计、上下游影响评估、发布管理等全流程PRD组件。当用户需要撰写ToB SaaS PRD、进行产品规划、设计功能方案、评审产品文档时使用此技能。
8410060F will not run↓ 50411 Jul 2026
2597B
Senior Regulatory Affairs Manager for HealthTech and MedTech companies. Provides regulatory strategy development, submission management, pathway analysis, global compliance coordination, and cross-fun
8610066F will not run★ 1416 Jun 2026
2598B
Senior Quality Manager Responsible Person (QMR) for HealthTech and MedTech companies. Provides quality system governance, management review leadership, regulatory compliance oversight, and quality per
8610066F will not run★ 1416 Jun 2026
2599B
Build a minimal but real security policy for sensitive apps. The output is a single, coherent Blue Book document using MUST/SHOULD/CAN language, with explicit assumptions, scope, and security gates.
8710067F will not run★ 510 Jul 2026
2600B
Memory forensics playbook using Volatility 2/3. Use when analyzing memory dumps for malware analysis, credential extraction, process investigation, code injection detection, and incident response time
879772F will not run★ 510 Jul 2026