Skill rating
2 738 skills. The A–F grade combines safety (60%) and quality (40%); tests add a bonus. The rating refreshes automatically from open catalogs.
ManufacturingLogistics and warehouseProcurementQuality controlContact centreField serviceFinanceCustomer supportindustry shortcuts
| # | Grade | Skill | Score ▾ | Safety | Quality | Process | Tests | Popularity | Updated |
|---|---|---|---|---|---|---|---|---|---|
| 301 | A | Static analysis security scanner for third-party OpenClaw skills. Detects eval/spawn risks, malicious dependencies, typosquatting, and prompt injection patterns before installation. Use when vetting s | 98 | 87 | C | — | ↓ 1 660 ★ 1 | 2 Jun 2026 | |
| 302 | A | Review UI code for Web Interface Guidelines compliance. Use when asked to "review my UI", "check accessibility", "audit design", "review UX", or "check my site against best practices". | 100 | 92 | C | — | ↓ 519 | 18 Jun 2026 | |
| 303 | A | Is this link safe or a scam? Paste any URL from LINE, SMS, or email to instantly detect phishing, fraud, or fake websites.
🚨 Identify scam links before you click
🔍 Detect phishing pages (fake Shope | 100 | 84 | C | — | ↓ 1 149 ★ 1 | 15 Jul 2026 | |
| 304 | A | Scans any website for GDPR/DSGVO compliance from the terminal — no API key or signup needed — and reports a 0-100 score plus key findings (trackers, cookies, consent banner, pre-consent tracking, font | 100 | 91 | B | — | ↓ 516 ★ 1 | 1 Jul 2026 | |
| 305 | A | Security review workflow for OpenClaw skills and other small code folders. Use when auditing a skill before publishing or installing it, checking for dangerous code patterns, possible hardcoded secret | 98 | 87 | D | — | ↓ 1 893 | 11 May 2026 | |
| 306 | A | Configure Huawei Cloud OBS static website hosting with Python SDK and a custom domain. Use when the user needs to enable or repair OBS website hosting, set index or error pages, expose an existing buc | 99 | 94 | B | — | ↓ 671 | 11 d ago | |
| 307 | A | AI Compliance Readiness Assessment — evaluate how prepared an organization is for AI governance regulations (EU AI Act, NIST AI RMF, HHS mandates, state bar AI rules). Scores readiness across 8 dimens | 100 | 83 | B | — | ↓ 1 177 ★ 2 | 11 May 2026 | |
| 308 | A | Build a staff shift schedule that matches coverage to demand while hitting a labor-cost target. Use when asked to build a shift schedule, staff a rota, plan coverage for a restaurant/retail/shift-base | 100 | 83 | B | — | ★ 1 361 | 25 h ago | |
| 309 | A | Assess and reduce the risk of exposing a confidential journalistic source. Use when a reporter is working with a confidential source, a whistleblower, or sensitive leaked material and needs to protect | 100 | 83 | B | — | ★ 1 361 | 25 h ago | |
| 310 | A | Design a fair, consistent tenant screening process for a rental. Use when asked how to screen tenants, set rental criteria, evaluate rental applicants, or build a tenant screening process. Produces a | 100 | 83 | B | — | ★ 1 361 | 25 h ago | |
| 311 | A | the-planning-committeeGeneratorData and analyticsAI and agentsmohitagw15856/pm-claude-skillsAgent Skills Simulate defending your planning application before the committee that decides it — the neighbour objections read into the record, the character-of-the-area catch-all, the parking pile-on, the council | 100 | 83 | B | — | ★ 1 361 | 25 h ago | |
| 312 | A | Assess physical and transition climate risk for a site, product, or portfolio with scenario-based structure. Use when asked to run a climate risk assessment, evaluate physical or transition risk, prep | 100 | 83 | B | — | ★ 1 361 | 25 h ago | |
| 313 | A | Produce a regulatory impact analysis (RIA) weighing the costs, benefits, and alternatives of a proposed rule. Use when asked to assess a regulation's impact, do a cost-benefit analysis of a policy, ju | 100 | 83 | B | — | ★ 1 361 | 25 h ago | |
| 314 | A | test-strategy-docGeneratorPlaywrightSoftware developmentInfrastructuremohitagw15856/pm-claude-skillsAgent Skills Write a test strategy document from a feature spec, PRD, or system description. Use when asked to create a test plan, write a test strategy, define QA approach, or plan testing for a feature or releas | 99 | 83 | B | — | ★ 1 361 | 25 h ago | |
| 315 | A | Run a quarterly loan covenant compliance review: covenant table with required vs actual vs headroom, trend and trajectory-to-breach analysis, waiver and amendment options with pricing implications, ea | 100 | 83 | B | — | ★ 1 361 | 25 h ago | |
| 316 | A | Apply a team's writing style consistently — extract the house style from exemplar documents into a checkable rule card, run the conformance pass on new drafts, and fix violations without flattening th | 100 | 83 | B | — | ★ 1 361 | 25 h ago | |
| 317 | A | Write a compelling, accurate real-estate listing description. Use when asked to write a property listing, an MLS/Zillow description, a real-estate listing, or to make a property description more appea | 100 | 83 | B | — | ★ 1 361 | 25 h ago | |
| 318 | A | Simulate defending your study or protocol before an ethics committee — the consent-comprehension probe, the vulnerable-participant challenge, the minimal-risk fight, the data-retention question you di | 100 | 83 | B | — | ★ 1 361 | 25 h ago | |
| 319 | A | Write an AI usage policy people can actually follow — approved tools, data rules, disclosure duties, and review obligations, in one page instead of legal fog. Use when asked for a company AI policy, a | 100 | 83 | B | — | ★ 1 361 | 25 h ago | |
| 320 | A | Write an internal KYC/AML escalation memo: a factual time-stamped trigger description, customer-profile vs activity mismatch analysis, red-flag taxonomy mapping, outstanding information, and a recomme | 100 | 83 | C | — | ★ 1 361 | 25 h ago | |
| 321 | A | Build a technology radar for an engineering team, categorizing technologies into Adopt/Trial/Assess/Hold quadrants following the ThoughtWorks Tech Radar format. Use when asked to create a tech radar, | 100 | 83 | B | — | ★ 1 361 | 25 h ago | |
| 322 | A | Stress-test a plan, strategy, PRD, or launch by simulating hostile expert personas who attack it from every angle. Use when asked to red-team, stress-test, pre-mortem, pressure-test, play devil's advo | 100 | 83 | B | — | ★ 1 361 | 25 h ago | |
| 323 | A | Audit and score OpenClaw AgentSkills against structural compliance, quality standards, and OpenClaw-specific architecture patterns. Produces a 0-100 score with A-F grade, dimensional breakdown, and ac | 100 | 91 | B | — | ↓ 642 | 21 May 2026 | |
| 324 | A | VBrokers (华盛通 VCL HK) trading automation via OpenAPI Gateway running on localhost port 11111. Use when: setting up VBrokers or 华盛通 account access, authenticating trading sessions, checking portfolio o | 99 | 89 | D | — | ↓ 1 008 | 18 May 2026 | |
| 325 | A | Get the latest cybersecurity news, vulnerability disclosures, and threat intelligence. Aggregates CVEs from NIST NVD, CISA KEV catalog, and security advisories via a unified feed API. No API key neede | 100 | 90 | C | — | ↓ 695 | 14 Jul 2026 | |
| 326 | A | Chinese content remix tool with API-powered platform rules (中文内容一键改写多平台分发+平台适配规则API). Transform one piece of content into platform-native versions for 小红书/抖音/公众号/知乎/微博/视频号 with real platform rules via | 100 | 90 | C | — | ↓ 591 | 21 May 2026 | |
| 327 | A | clawdbot-self-security-auditAnalyzerTelegramSecurityData and analyticssundial-org/awesome-openclaw-skillsAgent Skills Perform a comprehensive read-only security audit of Clawdbot's own configuration. This is a knowledge-based skill that teaches Clawdbot to identify hardening opportunities across the system. Use when | 100 | 86 | D | — | ★ 663 | 7 Mar 2026 | |
| 328 | A | swift-concurrency-expertAnalyzerSoftware developmentSecuritysundial-org/awesome-openclaw-skillsAgent Skills Swift Concurrency review and remediation for Swift 6.2+. Use when asked to review Swift Concurrency usage, improve concurrency compliance, or fix Swift concurrency compiler errors in a feature or file | 100 | 84 | C | — | ★ 663 | 7 Mar 2026 | |
| 329 | A | GPG AES-256 encrypted credential management. Requires: GPG (gnupg) installed, Python 3.8+, CRED_MASTER_PASS env var for non-interactive use. Use when the user needs to securely store, retrieve, or man | 100 | 87 | C | — | ↓ 952 | 18 May 2026 | |
| 330 | A | Complete cryptocurrency wallet management for Web3, DeFi, and blockchain applications. Create and manage EVM (Ethereum, Polygon, BSC, Arbitrum, Optimism, Base, Avalanche) and Solana wallets with encry | 98 | 82 | D | — | ↓ 2 568 ★ 1 | 11 May 2026 | |
| 331 | A | Use when optimizing existing Claude skills, checking skill quality, auditing skill compliance, or when skills have obvious issues. Triggers on skill optimization requests, quality checks, or skill imp | 100 | 88 | C | — | ↓ 916 | 11 May 2026 | |
| 332 | A | Defensive Bash scripting for Linux: safe foundations, argument parsing, production patterns, ShellCheck compliance. Use when writing bash scripts, shell scripts, cron jobs, or CLI tools in bash. | 100 | 86 | D | — | ↓ 1 896 | 23 h ago | |
| 333 | A | Audit Node.js HTTP servers and web apps for security vulnerabilities. Checks OWASP Top 10, CORS, auth bypass, XSS, path traversal, hardcoded secrets, missing headers, rate limiting, and input validati | 100 | 84 | C | — | ↓ 1 626 | 11 May 2026 | |
| 334 | A | Security leadership for growth-stage companies. Risk quantification in dollars, compliance roadmap (SOC 2/ISO 27001/HIPAA/GDPR), security architecture strategy, incident response leadership, and board | 90 | 95 | C | — | ★ 2 141 | 20 Jul 2026 | |
| 335 | A | subagent-driven-developmentProcedureSoftware developmentAI and agentsLeoYeAI/openclaw-master-skillsAgent Skills Use when executing implementation plans with independent tasks in the current session | 100 | 81 | D | — | ★ 2 141 | 20 Jul 2026 | |
| 336 | A | next-cache-componentsProcedureData and analyticsSoftware developmentLeoYeAI/openclaw-master-skillsAgent Skills Next.js 16 Cache Components - PPR, use cache directive, cacheLife, cacheTag, updateTag | 100 | 81 | D | — | ★ 2 141 | 20 Jul 2026 | |
| 337 | A | Use when reviewing code for security vulnerabilities, implementing authentication flows, auditing OWASP Top 10, configuring CORS/CSP headers, handling secrets, input validation, SQL injection preventi | 99 | 81 | C | — | ★ 2 141 | 20 Jul 2026 | |
| 338 | A | compliance-checklist-generationGeneratorAWSGitHubSecurityLegalseb1n/awesome-ai-agent-skillsAgent Skills Build evidence-oriented readiness checklists for frameworks such as SOC 2, HIPAA, PCI DSS, and GDPR, with gaps and remediation priorities. Use when the user needs an internal readiness assessment or c | 100 | 89 | B | — | ★ 182 | 36 d ago | |
| 339 | A | 查询阿里云四款安全产品(云安全中心 / WAF / 云防火墙 / RASP)对指定漏洞的防护覆盖情况,输入 CVE 编号或 AVD 编号即可返回各产品是否已覆盖。当客户或售前 SA 问"我们产品能不能防住 CVE-XXXX?"、"WAF 覆盖这个漏洞了吗?"、"新爆出来的 XX 漏洞有没有覆盖?"、"高危漏洞 YY 我们这边什么情况"时使用本 Skill。基于 avd.aliyun.com 高危漏 | 100 | 94 | C | — | ↓ 383 | 22 Jun 2026 | |
| 340 | A | 面向一人公司和小微团队提供日常法务支持:合同审查、劳动用工、知识产权、公司治理与合规体检。Use when the user asks about contract risks, hiring/firing compliance, trademark/copyright issues, registered capital, shareholder liability, or industry c | 100 | 84 | C | — | ↓ 864 ★ 1 | 11 May 2026 | |
| 341 | A | Set up feelgoodbot file integrity monitoring and TOTP step-up authentication for macOS. Use when the user wants to detect malware, monitor for system tampering, set up security alerts, or require OTP | 100 | 79 | B | — | ↓ 2 403 ★ 1 | 11 May 2026 | |
| 342 | A | Run AI-powered application security scans on codebases. Use when asked to scan code for security vulnerabilities, generate threat models, review code for security issues, run incremental security scan | 100 | 85 | C | — | ↓ 1 497 | 11 May 2026 | |
| 343 | A | Key lifecycle management with Volcengine KMS. Use when users need key creation, rotation policies, encryption/decryption workflows, or key permission troubleshooting. | 100 | 84 | C | — | ↓ 1 438 | 11 May 2026 | |
| 344 | A | Audit HTTP security headers for any website. Use when a user asks to check security headers, harden a web server, audit HSTS/CSP/X-Frame-Options compliance, find information leaks (Server, X-Powered-B | 100 | 87 | C | — | ↓ 818 | 11 May 2026 | |
| 345 | A | Perform 12-Factor App compliance analysis on any codebase. Use when evaluating application architecture, auditing SaaS applications, or reviewing cloud-native applications against the original 12-Fact | 100 | 87 | C | — | ↓ 830 | 11 May 2026 | |
| 346 | A | Scan any website for third-party scripts, trackers, and security risks. Detects PCI DSS compliance issues, missing CSP headers, fingerprinting scripts, and privacy risks. Use when asked to scan a site | 100 | 88 | C | — | ↓ 801 | 11 May 2026 | |
| 347 | A | Automates Snyk security vulnerability scanning, GitHub issue reporting, and auto-fix PR creation for repositories. Use when scanning repositories for security vulnerabilities, generating vulnerability | 100 | 87 | C | — | ↓ 823 | 18 May 2026 | |
| 348 | A | Security audit gate — scans agent skills for malware, prompt injection, and data exfiltration before installation | 99 | 83 | B | — | ↓ 1 256 ★ 1 | 17 May 2026 | |
| 349 | A | Find and send local files to a chat channel (Telegram, Discord, WhatsApp, Signal, Slack). Also manages encrypted credential files with age encryption. Use when the user asks to receive, send, or share | 100 | 87 | C | — | ↓ 815 | 18 May 2026 | |
| 350 | A | TCPA consent verification for lead generation. Use when adding consent capture to web forms, verifying lead consent before contact, claiming/managing consent sessions, pulling proof for disputed leads | 100 | 88 | C | — | ↓ 767 | 11 May 2026 |