SKILLEMALL.ai

Skill rating

2 738 skills. The A–F grade combines safety (60%) and quality (40%); tests add a bonus. The rating refreshes automatically from open catalogs.

2 738
#GradeSkillScore ▾SafetyQualityProcessTestsPopularityUpdated
2701B
Provides cryptography attack techniques for CTF challenges. Use when attacking encryption, hashing, signatures, ZKP, PRNG, or mathematical crypto problems involving RSA, AES, ECC, lattices, LWE, CVP,
819363F will not run★ 510 Jul 2026
2702C
Backup and restore an OpenClaw workspace with incremental backups, integrity verification, health checks, optional config encryption and optional WebDAV upload. Supports full/incremental backup strate
747671F will not run↓ 9742 Jun 2026
2703D
49820D★ 1416 Jun 2026
2704B
AI-powered penetration testing assistant using local LLM (metatron-qwen via Ollama) on Parrot OS Linux
809360F will not run★ 510 Jul 2026
2705B
Web2 bug bounty hunting agent — evidence-based vulnerability finder and report writer. Use when: auditing web apps/APIs for HackerOne, Bugcrowd, Intigriti, YesWeHack; hunting XSS, SQLi, NoSQLi, SSRF,
787386F will not run★ 1416 Jun 2026
2706B
Use when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security. Invoke for SAST scans, penetration testing, DevSecOps practices, cloud security reviews.
788468F will not run★ 1416 Jun 2026
2707B
AI-powered autonomous penetration testing framework with multi-agent system, real security tool execution, and compliance reporting
799357F will not run★ 510 Jul 2026
2708B
Queries Huawei Cloud identity and access management resources (IAM) via read-only Python SDK. Covers users, groups, policies, agencies, AK/SK, MFA devices, login/password/ACL policies, security compli
768268F will not run↓ 5442 d ago
2709B
Guides authoring of high-quality YARA-X detection rules for malware identification. Use when writing, reviewing, or optimizing YARA rules. Covers naming conventions, string selection, performance opti
778369F will not run★ 510 Jul 2026
2710C
Skill Security — 安全审计扫描器,帮助你快速发现 Skill 中的安全风险。轻量 SAST 污点追踪(Python AST + JS 词法近似,source→sink 证据链降误报)、规则引擎(YAML 规则包热插拔扩展)、社区规则(schema 校验 + 来源记录 + 签名验证)、提示注入 ML 语义检测(ONNX + 正则降级)、系统级行为捕获(eBPF Linux / ETW
718845F will not run↓ 9623 d ago
2711C
Dropbox Business API integration with managed OAuth. Full admin access to team members, groups, team folders, devices, audit logs, member file access, sharing, and file requests for Dropbox Business t
668537F will not run↓ 1 836 ★ 229 h ago
2712D
Agent 安全防护体系——事件驱动拦截(Hook Engine)+ 三层护栏(输入/工具/输出)+ 迭代循环(Ralph Loop)+ 操作追踪(Operation Tracer)
432275C↓ 9742 d ago
2713C
Handle operations requiring user confirmation, permission verification, and strict adherence to explicit instructions. Activate when: (1) Operations need sudo/elevated permissions, (2) File deletion o
676569F will not run↓ 941 ★ 118 May 2026
2714F
Conduct comprehensive security audits and vulnerability analysis on codebases. Use when explicitly asked for security analysis, code security review, vulnerability assessment, SAST scanning, or identi
34480D↓ 3 434 ★ 111 May 2026
2715C
Perform security operations on OpenClaw environments by calling Alibaba Cloud Security Center (SAS) and ECS APIs via the aliyun CLI. Supports asset queries, vulnerability detection, baseline checks, a
685882F will not run↓ 80018 May 2026
2716C
STRIDE threat modeling, DREAD risk scoring, secret detection, and secure architecture design. Use when conducting threat models, reviewing code for vulnerabilities, designing defense-in-depth, or scan
747276F will not run★ 510 Jul 2026
2717D
Full backup, update, and restore for Clawdbot - config, workspace, and skills with auto-rollback
422469C★ 1416 Jun 2026
2718D
Safe command execution for OpenClaw Agents with automatic danger pattern detection, risk assessment, user approval workflow, and audit logging. Use when agents need to execute shell commands that may
422371D★ 1416 Jun 2026
2719C
Wrike API integration with managed OAuth. Manage tasks, folders, projects, spaces, team collaboration, and administrative functions (users, invitations, access roles, audit log, data export). All writ
668537F will not run↓ 1 40028 h ago
2720C
Elite Talos Linux expert specializing in immutable Kubernetes OS, secure cluster deployment, machine configurations, talosctl CLI operations, upgrades, and production-grade security hardening. Expert
737963F will not run★ 510 Jul 2026
2721C
基于人民卫生出版社《诊断学》第10版的临床诊断技能集合 — 183 项核心诊断技能,涵盖病史采集、 体格检查、实验室检验解读、心电图与影像分析、常见症状鉴别诊断、专科操作规范及临床推理方法。
689231F will not run↓ 4526 Jun 2026
2722C
Visualize and govern your cloud architectures. Get architecture assessments, risk heatmaps, and compliance dashboards in one place.
636363F will not run★ 2 14120 Jul 2026
2723C
Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.
718156F will not run★ 510 Jul 2026
2724C
Security engineering toolkit for threat modeling, vulnerability analysis, secure architecture, and penetration testing. Includes STRIDE analysis, OWASP guidance, cryptography patterns, and security sc
687066F will not run★ 1416 Jun 2026
2725C
Visualize and govern your cloud architectures. Get architecture assessments, risk heatmaps, and compliance dashboards in one place.
636363F will not run↓ 69718 May 2026
2726C
macOS security bypass playbook. Use when targeting macOS endpoints and need to bypass TCC, Gatekeeper, SIP, sandbox, code signing, or entitlement-based protections during authorized red team or pentes
696968F will not run★ 510 Jul 2026
2727F
Windows 服务器运维工具箱 - 磁盘分析、临时文件清理、IIS 站点管理、批量文件操作、服务状态监控、Windows Update 诊断、实时性能监控、安全审计、注册表启动项审计、磁盘健康检测、网络端口监控、事件日志诊断、已安装程序管理、用户会话监控、计划任务审计、文件共享审计、DNS网卡诊断、SSL证书过期检测、防火墙规则审计、服务崩溃恢复状态、系统文件修复、存储池管理、备份状态检查、Do
331658D↓ 1 3673 d ago
2728F
Detect API keys, tokens, and credentials in code with 50+ patterns, entropy analysis, and multiple report formats
341069C↓ 50713 Jul 2026
2729F
Analyze a DeFi protocol for vulnerabilities, mechanism safety, and risk factors. Use when the user wants to audit a DeFi project, check protocol security, or assess risk. Trigger words include "audit
30075B↓ 791 ★ 111 May 2026
2730C
601000F will not run↓ 80711 May 2026
2731C
601000F will not run↓ 85417 May 2026
2732C
AppSec patterns aligned with OWASP Top 10:2025 and NIST SSDF. Use when implementing auth, input validation, crypto, or reviewing security posture.
665976F will not run★ 510 Jul 2026
2733F
Conduct comprehensive security audits and vulnerability analysis on codebases. Use when explicitly asked for security analysis, code security review, vulnerability assessment, SAST scanning, or identi
34480D★ 1416 Jun 2026
2734C
Comprehensive security vulnerability scanner for Python projects including Flask, Django, and FastAPI applications. Detects OWASP Top 10 vulnerabilities, injection flaws, insecure deserialization, aut
635377F will not run★ 510 Jul 2026
2735F
Bilingual security auditor for OpenClaw. 68 checks across 6 categories, 11 auto-fixes, OWASP Agentic AI Top 10 coverage, forensic detection, real-time threat interception, and guided hardening.
29073C★ 1416 Jun 2026
2736C
Container escape playbook. Use when operating inside a Docker container, LXC, or Kubernetes pod and need to escape to the host via privileged mode, capabilities, Docker socket, cgroup abuse, namespace
605370F will not run★ 510 Jul 2026
2737F
Bug-bounty/SRC vulnerability-hunting workflow: five-phase methodology (intake, recon, enumeration, hunt, report) with attack playbooks for SQLi, XSS, RCE, SSRF, IDOR, CSRF, path traversal, and file up
26066F will not run★ 46 36816 h ago
2738F
Safety monitoring and tripwire detection for AI agents. Protects against unauthorized file access, dangerous commands, and excessive activity. Auto-halts on critical violations. Honeypot tripwires det
24061F will not run↓ 1 02711 May 2026