Skill rating
2 687 skills. The A–F grade combines safety (60%) and quality (40%); tests add a bonus. The rating refreshes automatically from open catalogs.
ManufacturingLogistics and warehouseProcurementQuality controlContact centreField serviceFinanceCustomer supportindustry shortcuts
| # | Grade | Skill | Score ▾ | Safety | Quality | Process | Tests | Popularity | Updated |
|---|---|---|---|---|---|---|---|---|---|
| 2651 | B | pentestcompanion-workspaceProcedureWordSlackSecuritySoftware developmentLord1Egypt/RA-SkillsAgent Skills Self-hosted pentest management workspace for tracking engagements, running tools, auto-importing findings, and generating reports | 93 | 63 | F will not run | — | ★ 5 | 10 Jul 2026 | |
| 2652 | B | treatment-plansGeneratorLaTeXPDFWriting and documentsSoftware developmentLord1Egypt/RA-SkillsAgent Skills Generate concise (3-4 page), focused medical treatment plans in LaTeX/PDF format for all clinical specialties. Supports general medical treatment, rehabilitation therapy, mental health care, chronic d | 90 | 67 | F will not run | — | ★ 5 | 10 Jul 2026 | |
| 2653 | B | OWASP security patterns, secrets management, security testing | 95 | 60 | F will not run | — | ★ 5 | 10 Jul 2026 | |
| 2654 | B | Provides cryptography attack techniques for CTF challenges. Use when attacking encryption, hashing, signatures, ZKP, PRNG, or mathematical crypto problems involving RSA, AES, ECC, lattices, LWE, CVP, | 93 | 63 | F will not run | — | ★ 5 | 10 Jul 2026 | |
| 2655 | C | Backup and restore an OpenClaw workspace with incremental backups, integrity verification, health checks, optional config encryption and optional WebDAV upload. Supports full/incremental backup strate | 76 | 71 | F will not run | — | ↓ 964 | 2 Jun 2026 | |
| 2656 | D | 82 | 0 | D | — | ★ 14 | 16 Jun 2026 | ||
| 2657 | B | AI-powered penetration testing assistant using local LLM (metatron-qwen via Ollama) on Parrot OS Linux | 93 | 60 | F will not run | — | ★ 5 | 10 Jul 2026 | |
| 2658 | B | Web2 bug bounty hunting agent — evidence-based vulnerability finder and report writer. Use when: auditing web apps/APIs for HackerOne, Bugcrowd, Intigriti, YesWeHack; hunting XSS, SQLi, NoSQLi, SSRF, | 73 | 86 | F will not run | — | ★ 14 | 16 Jun 2026 | |
| 2659 | B | Use when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security. Invoke for SAST scans, penetration testing, DevSecOps practices, cloud security reviews. | 84 | 68 | F will not run | — | ★ 14 | 16 Jun 2026 | |
| 2660 | B | AI-powered autonomous penetration testing framework with multi-agent system, real security tool execution, and compliance reporting | 93 | 57 | F will not run | — | ★ 5 | 10 Jul 2026 | |
| 2661 | B | Guides authoring of high-quality YARA-X detection rules for malware identification. Use when writing, reviewing, or optimizing YARA rules. Covers naming conventions, string selection, performance opti | 83 | 69 | F will not run | — | ★ 5 | 10 Jul 2026 | |
| 2662 | C | Skill Security — 安全审计扫描器,帮助你快速发现 Skill 中的安全风险。轻量 SAST 污点追踪(Python AST + JS 词法近似,source→sink 证据链降误报)、规则引擎(YAML 规则包热插拔扩展)、社区规则(schema 校验 + 来源记录 + 签名验证)、提示注入 ML 语义检测(ONNX + 正则降级)、系统级行为捕获(eBPF Linux / ETW | 88 | 45 | F will not run | — | ↓ 945 | 2 d ago | |
| 2663 | C | Handle operations requiring user confirmation, permission verification, and strict adherence to explicit instructions. Activate when: (1) Operations need sudo/elevated permissions, (2) File deletion o | 65 | 69 | F will not run | — | ↓ 936 ★ 1 | 18 May 2026 | |
| 2664 | F | Conduct comprehensive security audits and vulnerability analysis on codebases. Use when explicitly asked for security analysis, code security review, vulnerability assessment, SAST scanning, or identi | 4 | 80 | D | — | ↓ 3 429 ★ 1 | 11 May 2026 | |
| 2665 | C | alibabacloud-sas-openclaw-securityAnalyzerData and analyticsSecurityClawHubAgent Skillsnot recommended Perform security operations on OpenClaw environments by calling Alibaba Cloud Security Center (SAS) and ECS APIs via the aliyun CLI. Supports asset queries, vulnerability detection, baseline checks, a | 58 | 82 | F will not run | — | ↓ 793 | 18 May 2026 | |
| 2666 | C | STRIDE threat modeling, DREAD risk scoring, secret detection, and secure architecture design. Use when conducting threat models, reviewing code for vulnerabilities, designing defense-in-depth, or scan | 72 | 76 | F will not run | — | ★ 5 | 10 Jul 2026 | |
| 2667 | D | clawdbot-update-plusProcedureWhatsAppWriting and documentsSoftware developmentmodbender/skill-library-mcpAgent Skillsnot recommended Full backup, update, and restore for Clawdbot - config, workspace, and skills with auto-rollback | 24 | 69 | C | — | ★ 14 | 16 Jun 2026 | |
| 2668 | D | Safe command execution for OpenClaw Agents with automatic danger pattern detection, risk assessment, user approval workflow, and audit logging. Use when agents need to execute shell commands that may | 23 | 71 | D | — | ★ 14 | 16 Jun 2026 | |
| 2669 | C | talos-os-expertProcedureKubernetesGitHubSecurityInfrastructureLord1Egypt/RA-SkillsAgent Skillsnot recommended Elite Talos Linux expert specializing in immutable Kubernetes OS, secure cluster deployment, machine configurations, talosctl CLI operations, upgrades, and production-grade security hardening. Expert | 79 | 63 | F will not run | — | ★ 5 | 10 Jul 2026 | |
| 2670 | C | 基于人民卫生出版社《诊断学》第10版的临床诊断技能集合 — 183 项核心诊断技能,涵盖病史采集、 体格检查、实验室检验解读、心电图与影像分析、常见症状鉴别诊断、专科操作规范及临床推理方法。 | 92 | 31 | F will not run | — | ↓ 450 | 6 Jun 2026 | |
| 2671 | C | architecture-visualization-governanceAnalyzerData and analyticsSecurityLeoYeAI/openclaw-master-skillsAgent Skills Visualize and govern your cloud architectures. Get architecture assessments, risk heatmaps, and compliance dashboards in one place. | 63 | 63 | F will not run | — | ★ 2 141 | 20 Jul 2026 | |
| 2672 | C | Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project. | 81 | 56 | F will not run | — | ★ 5 | 10 Jul 2026 | |
| 2673 | C | Security engineering toolkit for threat modeling, vulnerability analysis, secure architecture, and penetration testing. Includes STRIDE analysis, OWASP guidance, cryptography patterns, and security sc | 70 | 66 | F will not run | — | ★ 14 | 16 Jun 2026 | |
| 2674 | C | Visualize and govern your cloud architectures. Get architecture assessments, risk heatmaps, and compliance dashboards in one place. | 63 | 63 | F will not run | — | ↓ 692 | 18 May 2026 | |
| 2675 | C | macOS security bypass playbook. Use when targeting macOS endpoints and need to bypass TCC, Gatekeeper, SIP, sandbox, code signing, or entitlement-based protections during authorized red team or pentes | 69 | 68 | F will not run | — | ★ 5 | 10 Jul 2026 | |
| 2676 | F | Windows 服务器运维工具箱 - 磁盘分析、临时文件清理、IIS 站点管理、批量文件操作、服务状态监控、Windows Update 诊断、实时性能监控、安全审计、注册表启动项审计、磁盘健康检测、网络端口监控、事件日志诊断、已安装程序管理、用户会话监控、计划任务审计、文件共享审计、DNS网卡诊断、SSL证书过期检测、防火墙规则审计、服务崩溃恢复状态、系统文件修复、存储池管理、备份状态检查、Do | 16 | 58 | D | — | ↓ 1 351 | 2 d ago | |
| 2677 | F | Detect API keys, tokens, and credentials in code with 50+ patterns, entropy analysis, and multiple report formats | 10 | 69 | C | — | ↓ 504 | 13 Jul 2026 | |
| 2678 | F | Analyze a DeFi protocol for vulnerabilities, mechanism safety, and risk factors. Use when the user wants to audit a DeFi project, check protocol security, or assess risk. Trigger words include "audit | 0 | 75 | B | — | ↓ 786 ★ 1 | 11 May 2026 | |
| 2679 | C | 100 | 0 | F will not run | — | ↓ 803 | 11 May 2026 | ||
| 2680 | C | 100 | 0 | F will not run | — | ↓ 847 | 17 May 2026 | ||
| 2681 | C | AppSec patterns aligned with OWASP Top 10:2025 and NIST SSDF. Use when implementing auth, input validation, crypto, or reviewing security posture. | 59 | 76 | F will not run | — | ★ 5 | 10 Jul 2026 | |
| 2682 | F | security-analysisAnalyzerAI and agentsSecuritymodbender/skill-library-mcpAgent Skillsnot recommended Conduct comprehensive security audits and vulnerability analysis on codebases. Use when explicitly asked for security analysis, code security review, vulnerability assessment, SAST scanning, or identi | 4 | 80 | D | — | ★ 14 | 16 Jun 2026 | |
| 2683 | C | Python Security ScanProcedureSecuritySoftware developmentLord1Egypt/RA-SkillsAgent Skillsnot recommended Comprehensive security vulnerability scanner for Python projects including Flask, Django, and FastAPI applications. Detects OWASP Top 10 vulnerabilities, injection flaws, insecure deserialization, aut | 53 | 77 | F will not run | — | ★ 5 | 10 Jul 2026 | |
| 2684 | F | lobsterguardAnalyzerTelegramDockerInfrastructureAI and agentsmodbender/skill-library-mcpAgent Skillsnot recommended Bilingual security auditor for OpenClaw. 68 checks across 6 categories, 11 auto-fixes, OWASP Agentic AI Top 10 coverage, forensic detection, real-time threat interception, and guided hardening. | 0 | 73 | C | — | ★ 14 | 16 Jun 2026 | |
| 2685 | C | container-escape-techniquesProcedureDockerKubernetesInfrastructureSecurityLord1Egypt/RA-SkillsAgent Skills Container escape playbook. Use when operating inside a Docker container, LXC, or Kubernetes pod and need to escape to the host via privileged mode, capabilities, Docker socket, cgroup abuse, namespace | 53 | 70 | F will not run | — | ★ 5 | 10 Jul 2026 | |
| 2686 | F | src-hunterProcedureData and analyticsResearchsickn33/agentic-awesome-skillsAgent Skillsnot recommended Bug-bounty/SRC vulnerability-hunting workflow: five-phase methodology (intake, recon, enumeration, hunt, report) with attack playbooks for SQLi, XSS, RCE, SSRF, IDOR, CSRF, path traversal, and file up | 0 | 66 | F will not run | — | ★ 46 317 | 30 h ago | |
| 2687 | F | Safety monitoring and tripwire detection for AI agents. Protects against unauthorized file access, dangerous commands, and excessive activity. Auto-halts on critical violations. Honeypot tripwires det | 0 | 61 | F will not run | — | ↓ 1 020 | 11 May 2026 |