SKILLEMALL.ai

Skill rating

2 738 skills. The A–F grade combines safety (60%) and quality (40%); tests add a bonus. The rating refreshes automatically from open catalogs.

2 738
#GradeSkillScore ▾SafetyQualityProcessTestsPopularityUpdated
301A
Static analysis security scanner for third-party OpenClaw skills. Detects eval/spawn risks, malicious dependencies, typosquatting, and prompt injection patterns before installation. Use when vetting s
949887C↓ 1 660 ★ 12 Jun 2026
302A
Review UI code for Web Interface Guidelines compliance. Use when asked to "review my UI", "check accessibility", "audit design", "review UX", or "check my site against best practices".
9710092C↓ 51918 Jun 2026
303A
Is this link safe or a scam? Paste any URL from LINE, SMS, or email to instantly detect phishing, fraud, or fake websites. 🚨 Identify scam links before you click 🔍 Detect phishing pages (fake Shope
9410084C↓ 1 149 ★ 115 Jul 2026
304A
Scans any website for GDPR/DSGVO compliance from the terminal — no API key or signup needed — and reports a 0-100 score plus key findings (trackers, cookies, consent banner, pre-consent tracking, font
9610091B↓ 516 ★ 11 Jul 2026
305A
Security review workflow for OpenClaw skills and other small code folders. Use when auditing a skill before publishing or installing it, checking for dangerous code patterns, possible hardcoded secret
949887D↓ 1 89311 May 2026
306A
Configure Huawei Cloud OBS static website hosting with Python SDK and a custom domain. Use when the user needs to enable or repair OBS website hosting, set index or error pages, expose an existing buc
979994B↓ 67111 d ago
307A
AI Compliance Readiness Assessment — evaluate how prepared an organization is for AI governance regulations (EU AI Act, NIST AI RMF, HHS mandates, state bar AI rules). Scores readiness across 8 dimens
9310083B↓ 1 177 ★ 211 May 2026
308A
Build a staff shift schedule that matches coverage to demand while hitting a labor-cost target. Use when asked to build a shift schedule, staff a rota, plan coverage for a restaurant/retail/shift-base
9310083B★ 1 36125 h ago
309A
Assess and reduce the risk of exposing a confidential journalistic source. Use when a reporter is working with a confidential source, a whistleblower, or sensitive leaked material and needs to protect
9310083B★ 1 36125 h ago
310A
Design a fair, consistent tenant screening process for a rental. Use when asked how to screen tenants, set rental criteria, evaluate rental applicants, or build a tenant screening process. Produces a
9310083B★ 1 36125 h ago
311A
Simulate defending your planning application before the committee that decides it — the neighbour objections read into the record, the character-of-the-area catch-all, the parking pile-on, the council
9310083B★ 1 36125 h ago
312A
Assess physical and transition climate risk for a site, product, or portfolio with scenario-based structure. Use when asked to run a climate risk assessment, evaluate physical or transition risk, prep
9310083B★ 1 36125 h ago
313A
Produce a regulatory impact analysis (RIA) weighing the costs, benefits, and alternatives of a proposed rule. Use when asked to assess a regulation's impact, do a cost-benefit analysis of a policy, ju
9310083B★ 1 36125 h ago
314A
Write a test strategy document from a feature spec, PRD, or system description. Use when asked to create a test plan, write a test strategy, define QA approach, or plan testing for a feature or releas
939983B★ 1 36125 h ago
315A
Run a quarterly loan covenant compliance review: covenant table with required vs actual vs headroom, trend and trajectory-to-breach analysis, waiver and amendment options with pricing implications, ea
9310083B★ 1 36125 h ago
316A
Apply a team's writing style consistently — extract the house style from exemplar documents into a checkable rule card, run the conformance pass on new drafts, and fix violations without flattening th
9310083B★ 1 36125 h ago
317A
Write a compelling, accurate real-estate listing description. Use when asked to write a property listing, an MLS/Zillow description, a real-estate listing, or to make a property description more appea
9310083B★ 1 36125 h ago
318A
Simulate defending your study or protocol before an ethics committee — the consent-comprehension probe, the vulnerable-participant challenge, the minimal-risk fight, the data-retention question you di
9310083B★ 1 36125 h ago
319A
Write an AI usage policy people can actually follow — approved tools, data rules, disclosure duties, and review obligations, in one page instead of legal fog. Use when asked for a company AI policy, a
9310083B★ 1 36125 h ago
320A
Write an internal KYC/AML escalation memo: a factual time-stamped trigger description, customer-profile vs activity mismatch analysis, red-flag taxonomy mapping, outstanding information, and a recomme
9310083C★ 1 36125 h ago
321A
Build a technology radar for an engineering team, categorizing technologies into Adopt/Trial/Assess/Hold quadrants following the ThoughtWorks Tech Radar format. Use when asked to create a tech radar,
9310083B★ 1 36125 h ago
322A
Stress-test a plan, strategy, PRD, or launch by simulating hostile expert personas who attack it from every angle. Use when asked to red-team, stress-test, pre-mortem, pressure-test, play devil's advo
9310083B★ 1 36125 h ago
323A
Audit and score OpenClaw AgentSkills against structural compliance, quality standards, and OpenClaw-specific architecture patterns. Produces a 0-100 score with A-F grade, dimensional breakdown, and ac
9610091B↓ 64221 May 2026
324A
VBrokers (华盛通 VCL HK) trading automation via OpenAPI Gateway running on localhost port 11111. Use when: setting up VBrokers or 华盛通 account access, authenticating trading sessions, checking portfolio o
959989D↓ 1 00818 May 2026
325A
Get the latest cybersecurity news, vulnerability disclosures, and threat intelligence. Aggregates CVEs from NIST NVD, CISA KEV catalog, and security advisories via a unified feed API. No API key neede
9610090C↓ 69514 Jul 2026
326A
Chinese content remix tool with API-powered platform rules (中文内容一键改写多平台分发+平台适配规则API). Transform one piece of content into platform-native versions for 小红书/抖音/公众号/知乎/微博/视频号 with real platform rules via
9610090C↓ 59121 May 2026
327A
Perform a comprehensive read-only security audit of Clawdbot's own configuration. This is a knowledge-based skill that teaches Clawdbot to identify hardening opportunities across the system. Use when
9410086D★ 6637 Mar 2026
328A
Swift Concurrency review and remediation for Swift 6.2+. Use when asked to review Swift Concurrency usage, improve concurrency compliance, or fix Swift concurrency compiler errors in a feature or file
9410084C★ 6637 Mar 2026
329A
GPG AES-256 encrypted credential management. Requires: GPG (gnupg) installed, Python 3.8+, CRED_MASTER_PASS env var for non-interactive use. Use when the user needs to securely store, retrieve, or man
9510087C↓ 95218 May 2026
330A
Complete cryptocurrency wallet management for Web3, DeFi, and blockchain applications. Create and manage EVM (Ethereum, Polygon, BSC, Arbitrum, Optimism, Base, Avalanche) and Solana wallets with encry
929882D↓ 2 568 ★ 111 May 2026
331A
Use when optimizing existing Claude skills, checking skill quality, auditing skill compliance, or when skills have obvious issues. Triggers on skill optimization requests, quality checks, or skill imp
9510088C↓ 91611 May 2026
332A
Defensive Bash scripting for Linux: safe foundations, argument parsing, production patterns, ShellCheck compliance. Use when writing bash scripts, shell scripts, cron jobs, or CLI tools in bash.
9410086D↓ 1 89623 h ago
333A
Audit Node.js HTTP servers and web apps for security vulnerabilities. Checks OWASP Top 10, CORS, auth bypass, XSS, path traversal, hardcoded secrets, missing headers, rate limiting, and input validati
9410084C↓ 1 62611 May 2026
334A
Security leadership for growth-stage companies. Risk quantification in dollars, compliance roadmap (SOC 2/ISO 27001/HIPAA/GDPR), security architecture strategy, incident response leadership, and board
929095C★ 2 14120 Jul 2026
335A
Use when executing implementation plans with independent tasks in the current session
9210081D★ 2 14120 Jul 2026
336A
Next.js 16 Cache Components - PPR, use cache directive, cacheLife, cacheTag, updateTag
9210081D★ 2 14120 Jul 2026
337A
Use when reviewing code for security vulnerabilities, implementing authentication flows, auditing OWASP Top 10, configuring CORS/CSP headers, handling secrets, input validation, SQL injection preventi
929981C★ 2 14120 Jul 2026
338A
Build evidence-oriented readiness checklists for frameworks such as SOC 2, HIPAA, PCI DSS, and GDPR, with gaps and remediation priorities. Use when the user needs an internal readiness assessment or c
9610089B★ 18236 d ago
339A
查询阿里云四款安全产品(云安全中心 / WAF / 云防火墙 / RASP)对指定漏洞的防护覆盖情况,输入 CVE 编号或 AVD 编号即可返回各产品是否已覆盖。当客户或售前 SA 问"我们产品能不能防住 CVE-XXXX?"、"WAF 覆盖这个漏洞了吗?"、"新爆出来的 XX 漏洞有没有覆盖?"、"高危漏洞 YY 我们这边什么情况"时使用本 Skill。基于 avd.aliyun.com 高危漏
9810094C↓ 38322 Jun 2026
340A
面向一人公司和小微团队提供日常法务支持:合同审查、劳动用工、知识产权、公司治理与合规体检。Use when the user asks about contract risks, hiring/firing compliance, trademark/copyright issues, registered capital, shareholder liability, or industry c
9410084C↓ 864 ★ 111 May 2026
341A
Set up feelgoodbot file integrity monitoring and TOTP step-up authentication for macOS. Use when the user wants to detect malware, monitor for system tampering, set up security alerts, or require OTP
9210079B↓ 2 403 ★ 111 May 2026
342A
Run AI-powered application security scans on codebases. Use when asked to scan code for security vulnerabilities, generate threat models, review code for security issues, run incremental security scan
9410085C↓ 1 49711 May 2026
343A
Key lifecycle management with Volcengine KMS. Use when users need key creation, rotation policies, encryption/decryption workflows, or key permission troubleshooting.
9410084C↓ 1 43811 May 2026
344A
Audit HTTP security headers for any website. Use when a user asks to check security headers, harden a web server, audit HSTS/CSP/X-Frame-Options compliance, find information leaks (Server, X-Powered-B
9510087C↓ 81811 May 2026
345A
Perform 12-Factor App compliance analysis on any codebase. Use when evaluating application architecture, auditing SaaS applications, or reviewing cloud-native applications against the original 12-Fact
9510087C↓ 83011 May 2026
346A
Scan any website for third-party scripts, trackers, and security risks. Detects PCI DSS compliance issues, missing CSP headers, fingerprinting scripts, and privacy risks. Use when asked to scan a site
9510088C↓ 80111 May 2026
347A
Automates Snyk security vulnerability scanning, GitHub issue reporting, and auto-fix PR creation for repositories. Use when scanning repositories for security vulnerabilities, generating vulnerability
9510087C↓ 82318 May 2026
348A
Security audit gate — scans agent skills for malware, prompt injection, and data exfiltration before installation
939983B↓ 1 256 ★ 117 May 2026
349A
Find and send local files to a chat channel (Telegram, Discord, WhatsApp, Signal, Slack). Also manages encrypted credential files with age encryption. Use when the user asks to receive, send, or share
9510087C↓ 81518 May 2026
350A
TCPA consent verification for lead generation. Use when adding consent capture to web forms, verifying lead consent before contact, claiming/managing consent sessions, pulling proof for disputed leads
9510088C↓ 76711 May 2026