Skill rating
2 688 skills. The A–F grade combines safety (60%) and quality (40%); tests add a bonus. The rating refreshes automatically from open catalogs.
ManufacturingLogistics and warehouseProcurementQuality controlContact centreField serviceFinanceCustomer supportindustry shortcuts
| # | Grade | Skill | Score ▾ | Safety | Quality | Process | Tests | Popularity | Updated |
|---|---|---|---|---|---|---|---|---|---|
| 2551 | B | sast-configurationAnalyzerGitHubSoftware developmentInfrastructuremodbender/skill-library-mcpAgent Skills Configure Static Application Security Testing (SAST) tools for automated vulnerability detection in application code. Use when setting up security scanning, implementing DevSecOps practices, or automa | 99 | 75 | F will not run | — | ★ 14 | 16 Jun 2026 | |
| 2552 | B | Define and implement Service Level Indicators (SLIs) and Service Level Objectives (SLOs) with error budgets and alerting. Use when establishing reliability targets, implementing SRE practices, or meas | 100 | 72 | F will not run | — | ★ 14 | 16 Jun 2026 | |
| 2553 | B | Que22ries Hu22a22wei Cloud identity and access ma2222nagement resources (IAM) via read-only Python SDK. Covers users, groups, policies, agencies, AK/SK, MFA devices, login/password/ACL policies, secur | 98 | 68 | F will not run | — | ↓ 759 | 27 Jul 2026 | |
| 2554 | B | 快手全场景数据查询助手。支持App和Web双端API,覆盖视频详情、用户数据、搜索、热榜、直播、评论等全功能。 | 100 | 63 | F will not run | — | ↓ 502 | 2 Jun 2026 | |
| 2555 | B | 微博全场景数据查询助手。整合App/Web/V2多版本API,覆盖微博详情、用户数据、AI搜索、高级搜索、热搜榜单、评论、视频等全功能。 | 100 | 63 | F will not run | — | ↓ 494 | 2 Jun 2026 | |
| 2556 | B | B站视频、用户、评论、弹幕、直播数据查询助手。支持App和Web双端API。 | 100 | 63 | F will not run | — | ↓ 468 | 2 Jun 2026 | |
| 2557 | B | China company search and business registry skill by Fengniao (Riskbird). Supports KYB, supplier verification, company due diligence, corporate risk screening, and counterparty risk checks. Retrieves b | 100 | 59 | F will not run | — | ↓ 720 | 11 May 2026 | |
| 2558 | A | Smart contract vulnerability playbook. Use when auditing Solidity/EVM contracts for reentrancy, integer overflow, access control, delegatecall, flash loan, signature replay, and MEV-related attack pat | 100 | 75 | F will not run | — | ★ 5 | 10 Jul 2026 | |
| 2559 | A | expression-language-injectionProcedureConfluenceSoftware developmentSecurityLord1Egypt/RA-SkillsAgent Skills Expression Language injection playbook. Use when Java EL, SpEL, OGNL, or MVEL expressions may evaluate attacker-controlled input in Spring, Struts2, Confluence, or similar frameworks. | 100 | 75 | F will not run | — | ★ 5 | 10 Jul 2026 | |
| 2560 | A | Creates, updates, validates, and displays the architectural DNA of a project through two shared documents: docs/specs/architecture.md (technology stack, architectural rules, security constraints, AI g | 95 | 82 | F will not run | — | ★ 5 | 10 Jul 2026 | |
| 2561 | A | Hardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external integrations. Use when building any feature that accepts untrusted data, manages user sess | 100 | 76 | F will not run | — | ★ 5 | 10 Jul 2026 | |
| 2562 | A | Operations management across process optimization, efficiency, and continuous improvement. Use when designing workflows, building capacity plans, evaluating vendors, running Lean Six Sigma DMAIC proje | 100 | 76 | F will not run | — | ★ 5 | 10 Jul 2026 | |
| 2563 | A | DeFi attack pattern playbook. Use when analyzing flash loan attacks, price oracle manipulation, MEV sandwich attacks, governance exploits, bridge vulnerabilities, and token standard edge cases in dece | 100 | 75 | F will not run | — | ★ 5 | 10 Jul 2026 | |
| 2564 | A | Configure Static Application Security Testing (SAST) tools for automated vulnerability detection in application code. Use when setting up security scanning, implementing DevSecOps practices, or automa | 100 | 75 | F will not run | — | ★ 5 | 10 Jul 2026 | |
| 2565 | A | CRLF injection playbook. Use when user input reaches HTTP response headers, Location redirects, Set-Cookie values, or log files where carriage-return/line-feed characters can split or inject content. | 100 | 75 | F will not run | — | ★ 5 | 10 Jul 2026 | |
| 2566 | A | Use when hardening Go code at API boundaries — copying slices/maps, verifying interface compliance, using defer for cleanup, time.Time/time.Duration, or avoiding mutable globals. Also use when reviewi | 100 | 76 | F will not run | — | ★ 5 | 10 Jul 2026 | |
| 2567 | C | 100 | 0 | D | — | ★ 5 | 10 Jul 2026 | ||
| 2568 | B | Multi-platform backup and restore for Hermes Agent and OpenClaw. Backs up configuration, memories, skills, sessions, and workspace. Features: optional encryption, optional cloud storage (S3/Google Dri | 99 | 62 | F will not run | — | ↓ 695 | 18 May 2026 | |
| 2569 | D | 95 | 0 | C | — | ↓ 132 | 9 d ago | ||
| 2570 | B | Security advisory feed with automated NVD CVE polling for OpenClaw-related vulnerabilities. Updated daily. | 99 | 51 | F will not run | — | ★ 2 141 | 20 Jul 2026 | |
| 2571 | B | Psychological profiling through natural conversation using narrative identity research (McAdams), self-defining memory elicitation (Singer), and Motivational Interviewing (OARS framework). Use when yo | 100 | 69 | F will not run | — | ★ 14 | 16 Jun 2026 | |
| 2572 | D | Security scanner and hardening tool for OpenClaw. Use when the user asks about security, wants to scan installed skills for malware or vulnerabilities, audit their OpenClaw configuration, check their | 39 | 86 | C | — | ★ 14 | 16 Jun 2026 | |
| 2573 | B | financial-deep-researchProcedureData and analyticsSoftware developmentLord1Egypt/RA-SkillsAgent Skills Conduct enterprise-grade financial research with multi-source synthesis, regulatory compliance tracking, and verified market analysis. Use when user needs comprehensive financial analysis requiring 10 | 99 | 73 | F will not run | — | ★ 5 | 10 Jul 2026 | |
| 2574 | B | Master Robert Cialdini's 6 (+1) Principles of Persuasion from "Influence: The Psychology of Persuasion" (1984). Ethically apply the psychology of compliance to marketing. Use when: Designing landing p | 100 | 73 | F will not run | — | ★ 5 | 10 Jul 2026 | |
| 2575 | B | Format string exploitation playbook. Use when printf-family functions receive user-controlled format strings, enabling arbitrary stack reads (%p/%s), arbitrary memory writes (%n/%hn/%hhn), GOT/hook ov | 100 | 72 | F will not run | — | ★ 5 | 10 Jul 2026 | |
| 2576 | B | Binary protection bypass playbook. Use when identifying and bypassing ASLR, PIE, NX/DEP, stack canary, RELRO, FORTIFY_SOURCE, CET, and MTE protections in ELF binaries to enable exploitation. | 99 | 75 | F will not run | — | ★ 5 | 10 Jul 2026 | |
| 2577 | B | Email header injection and spoofing playbook. Use when testing contact forms, email APIs, password reset flows, or any feature that constructs SMTP messages with user-controlled fields. Covers CRLF in | 100 | 72 | F will not run | — | ★ 5 | 10 Jul 2026 | |
| 2578 | B | Hash attack playbook. Use when exploiting length extension, MD5/SHA1 collisions, HMAC timing leaks, birthday attacks, or hash-based proof of work in CTF and authorized testing scenarios. | 100 | 72 | F will not run | — | ★ 5 | 10 Jul 2026 | |
| 2579 | B | Use when needing to understand content moderation policies, avoid content removal, or successfully navigate Xiaohongshu's content review process | 100 | 72 | F will not run | — | ★ 5 | 10 Jul 2026 | |
| 2580 | B | Heap exploitation playbook. Use when targeting ptmalloc2/glibc heap vulnerabilities including UAF, double free, overflow, off-by-one/null, and leveraging tcache/fastbin/unsortedbin attacks for arbitra | 100 | 72 | F will not run | — | ★ 5 | 10 Jul 2026 | |
| 2581 | A | Hardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external integrations. Use when building any feature that accepts untrusted data, manages user sess | 100 | 76 | F will not run | — | ★ 2 | 9 Apr 2026 | |
| 2582 | B | Static ReDoS (Regular Expression Denial of Service) vulnerability scanner and regex quality auditor for codebases. Walks all source files to extract regex literals, detects catastrophic backtracking p | 100 | 57 | F will not run | — | ↓ 626 | 23 Jun 2026 | |
| 2583 | B | Browse curated penetration testing resources and exploit databases. Use when planning security audits, researching vulns, or building toolkits. | 87 | 73 | F will not run | — | ↓ 1 646 | 17 May 2026 | |
| 2584 | D | 95 | 0 | F | — | ★ 14 | 16 Jun 2026 | ||
| 2585 | B | Security audit and threat model for OpenClaw gateway hosts. Use to verify OpenClaw configuration, exposure, skills/plugins, filesystem hygiene, and to produce an OK/VULNERABLE report with evidence and | 99 | 68 | F will not run | — | ★ 14 | 16 Jun 2026 | |
| 2586 | B | Run a structured health check of your ecommerce seller account — covering listing quality, policy compliance, performance metrics, and account standing — to catch problems before they catch you. | 100 | 55 | F will not run | — | ↓ 840 | 9 Jun 2026 | |
| 2587 | B | Argues that emotional intelligence becomes strategically critical precisely because of AI -- not despite it -- and provides leaders with practices for developing the soft skills that constitute the hu | 100 | 56 | F will not run | — | ↓ 778 | 11 May 2026 | |
| 2588 | B | analyzing-email-headers-for-phishing-investigationAnalyzerGmailOutlookSecuritySoftware developmentLord1Egypt/RA-SkillsAgent Skills Parse and analyze email headers to trace the origin of phishing emails, verify sender authenticity, and identify spoofing through SPF, DKIM, and DMARC validation. | 98 | 72 | F will not run | — | ★ 5 | 10 Jul 2026 | |
| 2589 | B | Apply CIS benchmarks and secure Linux servers. Configure SSH, manage users, implement firewall rules, and enable security features. Use when hardening Linux systems for production or meeting security | 100 | 69 | F will not run | — | ★ 5 | 10 Jul 2026 | |
| 2590 | B | Framework for defining and implementing Service Level Indicators (SLIs), Service Level Objectives (SLOs), and error budgets. | 100 | 69 | F will not run | — | ★ 5 | 10 Jul 2026 | |
| 2591 | B | Kerberos attack playbook for Active Directory. Use when targeting AD authentication via AS-REP roasting, Kerberoasting, golden/silver/diamond tickets, delegation abuse, or pass-the-ticket attacks. | 98 | 72 | F will not run | — | ★ 5 | 10 Jul 2026 | |
| 2592 | B | Fast synchronous key-value storage for React Native via react-native-mmkv (Nitro-backed). Covers creating and configuring MMKV instances, reading/writing all value types (string, number, boolean, buff | 100 | 71 | F will not run | — | ★ 5 | 10 Jul 2026 | |
| 2593 | B | Symmetric cipher attack playbook. Use when exploiting block cipher mode weaknesses (CBC padding oracle, ECB cut-and-paste, bit flipping), stream cipher key reuse, or meet-in-the-middle attacks. | 99 | 72 | F will not run | — | ★ 5 | 10 Jul 2026 | |
| 2594 | B | Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns. Use when writing Semgrep rules or building custom static analysis detections. | 94 | 79 | F will not run | — | ★ 5 | 10 Jul 2026 | |
| 2595 | B | HTTP request smuggling and desynchronization testing. Use when front proxies, CDNs, or load balancers disagree with the origin on message framing (Content-Length vs Transfer-Encoding), on HTTP/2→HTTP/ | 99 | 72 | F will not run | — | ★ 5 | 10 Jul 2026 | |
| 2596 | B | ToB SaaS产品PRD AI助手。用于创建、评审、优化ToB SaaS产品的产品需求文档。支持三种场景:(1)独立新产品从0到1构建,(2)独立新能力功能级创新开发,(3)现有能力迭代优化与发布管理。内置市场调研、价值分析、竞品对标、功能设计、上下游影响评估、发布管理等全流程PRD组件。当用户需要撰写ToB SaaS PRD、进行产品规划、设计功能方案、评审产品文档时使用此技能。 | 100 | 60 | F will not run | — | ↓ 504 | 11 Jul 2026 | |
| 2597 | B | Senior Regulatory Affairs Manager for HealthTech and MedTech companies. Provides regulatory strategy development, submission management, pathway analysis, global compliance coordination, and cross-fun | 100 | 66 | F will not run | — | ★ 14 | 16 Jun 2026 | |
| 2598 | B | Senior Quality Manager Responsible Person (QMR) for HealthTech and MedTech companies. Provides quality system governance, management review leadership, regulatory compliance oversight, and quality per | 100 | 66 | F will not run | — | ★ 14 | 16 Jun 2026 | |
| 2599 | B | Build a minimal but real security policy for sensitive apps. The output is a single, coherent Blue Book document using MUST/SHOULD/CAN language, with explicit assumptions, scope, and security gates. | 100 | 67 | F will not run | — | ★ 5 | 10 Jul 2026 | |
| 2600 | B | Memory forensics playbook using Volatility 2/3. Use when analyzing memory dumps for malware analysis, credential extraction, process investigation, code injection detection, and incident response time | 97 | 72 | F will not run | — | ★ 5 | 10 Jul 2026 |