Skill rating
2 738 skills. The A–F grade combines safety (60%) and quality (40%); tests add a bonus. The rating refreshes automatically from open catalogs.
ManufacturingLogistics and warehouseProcurementQuality controlContact centreField serviceFinanceCustomer supportindustry shortcuts
| # | Grade | Skill | Score ▾ | Safety | Quality | Process | Tests | Popularity | Updated |
|---|---|---|---|---|---|---|---|---|---|
| 351 | A | Use when a compliance officer, security analyst, or auditor needs to assess an organization's controls against a regulatory framework (GDPR, SOC 2, ISO 27001, HIPAA, PCI-DSS, NIST CSF). Guides structu | 100 | 87 | B | — | ↓ 832 | 28 May 2026 | |
| 352 | A | Audit project dependencies for outdated packages, security vulnerabilities, and breaking changes. Use when someone asks to "check for outdated packages", "audit dependencies", "find vulnerable depende | 100 | 90 | C | — | ★ 150 | 25 h ago | |
| 353 | A | Apply Islamic ethical constraints to AI responses about religion, Quran, Hadith, Sharia rulers, and Islamic practice. Use this skill whenever a user asks any question related to Islam, Muslims, the Qu | 100 | 84 | B | — | ↓ 1 302 | 17 May 2026 | |
| 354 | A | Use this skill for security scanning: check transaction safety, is this transaction safe, pre-execution check, security scan, token risk scanning, honeypot detection, DApp/URL phishing detection, mess | 97 | 90 | C | — | ↓ 1 291 | 18 May 2026 | |
| 355 | A | Manage web search result knowledge capture with safe URL rules, staging, user confirmation, archiving, audit logs, and multi-platform adapters for IMA, Tencent Docs, Feishu Wiki, DingTalk Docs, Obsidi | 100 | 88 | C | — | ↓ 766 | 11 May 2026 | |
| 356 | A | Use this skill when a nonprofit grant writer, program manager, or development director needs to turn a funder RFP or NOFO into a structured grant proposal. Extracts funder requirements, gathers projec | 100 | 87 | B | — | ↓ 772 | 28 May 2026 | |
| 357 | A | Audit and validate Prisma Access configurations against best practices and security standards. Use when reviewing security policies, checking for misconfigurations, or validating compliance with PAN-O | 100 | 87 | C | — | ↓ 722 | 11 May 2026 | |
| 358 | A | Judge whether an email is important/urgent using content-based analysis rather than sender name or mailbox labels (which can be spoofed). Use when asked to triage emails, decide priority, detect phish | 100 | 83 | B | — | ↓ 2 128 | 17 May 2026 | |
| 359 | A | Assess third-party vendor risk for AI and SaaS products. Evaluates security posture, data handling, compliance, financial stability, and operational resilience. Use when onboarding new vendors, conduc | 98 | 87 | B | — | ↓ 1 213 | 17 May 2026 | |
| 360 | A | Use when user needs to check import/export compliance requirements for specific products and countries. Use when verifying product certifications, tariffs, sanctions, or regulatory requirements. Use w | 100 | 88 | C | — | ↓ 715 | 11 May 2026 | |
| 361 | A | Compliance expert for snyk-agent-scan — the agent skill file scanner — NOT for other Snyk CLI tools (snyk test, snyk code SAST, snyk iac, snyk container). Fixes alerts through content restructuring, n | 96 | 93 | B | evals | ↓ 756 | 24 d ago | |
| 362 | B | GitHub supply-chain forensics: recovery, IOCs, reporting. | 99 | 75 | D | — | ★ 245 156 | 14 h ago | |
| 363 | B | Hardens code against vulnerabilities. Use when auditing an input handler for vulnerabilities, when handling user input, authentication, data storage, or external integrations, or when checking a login | 100 | 72 | C | — | ★ 94 014 | 2 d ago | |
| 364 | B | security-scanning-security-hardeningIntegrationSecurityInfrastructuresickn33/agentic-awesome-skillsAgent Skills Coordinate multi-layer security scanning and hardening across application, infrastructure, and compliance controls. | 96 | 78 | B | — | ★ 46 368 | 16 h ago | |
| 365 | B | Automate AWS secrets rotation for RDS, API keys, and credentials | 100 | 72 | C | — | ★ 46 368 | 16 h ago | |
| 366 | B | container-security-hardeningAnalyzerDockerKubernetesSecuritysickn33/agentic-awesome-skillsAgent Skills Harden Docker/container images and runtime deployments with secure base images, non-root users, CVE scanning, SBOM/signing, seccomp/AppArmor, and Kubernetes pod security controls. Use for Dockerfile s | 94 | 81 | C | — | ★ 46 368 | 16 h ago | |
| 367 | B | Comprehensive AWS security posture assessment using AWS CLI and security best practices | 100 | 72 | B | — | ★ 46 368 | 16 h ago | |
| 368 | B | Provide systematic methodologies for automated SQL injection detection and exploitation using SQLMap. | 97 | 78 | C | — | ★ 46 368 | 16 h ago | |
| 369 | B | supply-chain-risk-auditorAnalyzerGitHubSoftware developmentData and analyticssickn33/agentic-awesome-skillsAgent Skills Identifies dependencies at heightened risk of exploitation or takeover. Use when assessing supply chain attack surface, evaluating dependency health, or scoping security engagements. | 95 | 81 | B | — | ★ 46 368 | 16 h ago | |
| 370 | B | stride-analysis-patternsAnalyzerSecurityWriting and documentssickn33/agentic-awesome-skillsAgent Skills Apply STRIDE methodology to systematically identify threats. Use when analyzing system security, conducting threat modeling sessions, or creating security documentation. | 97 | 77 | B | — | ★ 46 368 | 16 h ago | |
| 371 | B | ⚠️ AUTHORIZED USE ONLY > This skill is for educational purposes or authorized security assessments only. > You must have explicit, written permission from the system owner before using this tool. > Mi | 95 | 81 | C | — | ★ 46 368 | 16 h ago | |
| 372 | B | Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns. Use when writing Semgrep rules or building custom static analysis detections. | 94 | 81 | B | — | ★ 46 368 | 16 h ago | |
| 373 | B | Provide a comprehensive checklist for planning, executing, and following up on penetration tests. Ensure thorough preparation, proper scoping, and effective remediation of discovered vulnerabilities. | 95 | 81 | B | — | ★ 46 368 | 16 h ago | |
| 374 | B | Provide a comprehensive command reference for penetration testing tools including network scanning, exploitation, password cracking, and web application testing. Enable quick command lookup during sec | 95 | 81 | B | — | ★ 46 368 | 16 h ago | |
| 375 | B | Comprehensive security auditing workflow covering web application testing, API security, penetration testing, vulnerability scanning, and security hardening. | 95 | 81 | C | — | ★ 46 368 | 16 h ago | |
| 376 | B | Run read-only exposure checks for security advisories and write a structured local audit report. | 100 | 73 | C | — | ★ 46 368 | 16 h ago | |
| 377 | B | create-technical-spikeGeneratorWriting and documentsInfrastructuregithub/awesome-copilotAgent Skills Create time-boxed technical spike documents for researching and resolving critical development decisions before implementation. | 100 | 72 | D | — | ★ 38 969 | 2 d ago | |
| 378 | B | Search WeChat Official Account articles using OpenClaw's web search, Tavily API, and web fetch capabilities with compliance-focused design. | 100 | 72 | C | — | ↓ 4 305 ★ 9 | 17 May 2026 | |
| 379 | A | Audit ecommerce listings, ad copy, and creator content against TikTok Shop policies to catch violations before they trigger penalties. Use when reviewing new listings, vetting creator videos and capti | 100 | 84 | D | — | ↓ 1 293 | 11 Jun 2026 | |
| 380 | A | 火山引擎合规最佳实践助手:一是根据用户诉求(要满足的合规标准、关键词、关注的风险等级), 从火山引擎官方内置的合规包模板里推荐该开启哪些、并标出哪些已开启;二是汇总账号当前的合规 态势,把已生效规则/合规包(官方内置 + 用户自定义)的评估结果按类别(法规 / 最佳实践 / 自定义)与严重度聚合成一份合规总览报告;三是当官方基线没覆盖时,指导用户写一条 Rego 策略 作为自定义合规规则并注册评估 | 100 | 92 | C | — | ↓ 412 | 12 d ago | |
| 381 | A | Multi-ecosystem dependency audit — find outdated, vulnerable, unused, and license-incompatible packages across npm, pip, cargo, go, and composer. Use when asked to check dependency health, audit packa | 100 | 87 | C | — | ↓ 714 | 11 May 2026 | |
| 382 | A | URL safety scanner and domain reputation checker. Use when: checking if a URL is safe before visiting, scanning links in emails/messages, verifying domains for phishing/malware/scam. NOT for: submitti | 100 | 81 | D | — | ↓ 1 976 ★ 1 | 18 May 2026 | |
| 383 | A | Use this skill when a customs broker, trade-compliance analyst, importer, or trade counsel needs to classify a product under HTSUS, EU CN/TARIC, or another national tariff schedule. Walks GRI 1–6 in o | 100 | 87 | B | — | ↓ 799 | 28 May 2026 | |
| 384 | A | Assess data privacy compliance across 20 control areas with 63 controls covering governance, consent, security, breach response, vendor management, and cross-border transfers. Use when evaluating priv | 100 | 86 | B | — | ↓ 1 174 | 17 May 2026 | |
| 385 | A | Build search queries for network asset discovery platforms (space测绘). Use when users want to find network assets, discover attack surfaces, investigate vulnerabilities (CVE), or search for specific se | 100 | 88 | C | evals | ↓ 716 | 11 May 2026 | |
| 386 | A | Encryption and decryption toolkit for string and byte data. Supports Fernet (AES-128) symmetric encryption, fallback XOR encryption, custom password protection, code obfuscation, and batch processing. | 100 | 84 | D | — | ↓ 1 132 | 11 May 2026 | |
| 387 | A | AI-powered global compliance checker, document generator, and risk assessor for GDPR, CCPA, SOC2, ISO27001, HIPAA and more | 100 | 86 | C | — | ↓ 1 143 | 18 May 2026 | |
| 388 | A | You are an accessibility auditor with expertise in web accessibility standards, assistive technology testing, and inclusive design practices. Use when: wcag 2.1/2.2 aa and aaa compliance, screen reade | 100 | 87 | B | — | ↓ 701 | 11 May 2026 | |
| 389 | A | Expert change management advisor for enterprise transformations. Assess readiness, diagnose adoption risks, build sponsor plans, and drive stakeholder adoption in cybersecurity, cloud, AI, and complia | 100 | 87 | C | — | ↓ 692 | 11 May 2026 | |
| 390 | A | Backup and restore files with compression and encryption. Use when user needs to backup important files, create scheduled backups, sync folders, encrypt sensitive backups, or restore from backup archi | 100 | 87 | C | — | ↓ 688 | 18 May 2026 | |
| 391 | A | Implement quantum-resistant encryption using the CIFER SDK (cifer-sdk npm package). Covers SDK initialization, wallet setup, secret creation, text encryption/decryption, and file encryption/decryption | 99 | 84 | C | — | ↓ 1 898 | 11 May 2026 | |
| 392 | A | Audit code for security issues - sensitive data exposure, dependency vulnerabilities, SQL injection, hardcoded secrets. Use when the user asks for security check, dependency scan, or before deploying. | 100 | 84 | C | — | ↓ 1 114 | 11 May 2026 | |
| 393 | A | When the user faces brand impersonation, fake websites, phishing sites, or trademark infringement. Also use when the user mentions "fake site," "impersonation," "phishing site," "trademark infringemen | 100 | 88 | B | — | ↓ 670 | 11 May 2026 | |
| 394 | A | Supernal Coding CLI for development workflows - task management, requirements tracking, testing, git automation, ralph loops, compliance, and documentation. Use for task management (sc task), project | 100 | 84 | C | — | ↓ 1 098 | 17 May 2026 | |
| 395 | A | API 安全扫描工具。对 REST API 端点进行自动化安全审计,检测 OWASP Top 10 漏洞、
认证/授权问题、敏感数据泄露、速率限制缺失等常见安全隐患。输出结构化安全报告。
适合开发者在部署前快速自检,也适合安全团队做轻量级审计。 | 100 | 87 | C | — | ↓ 712 | 24 May 2026 | |
| 396 | A | You are a blockchain developer specializing in Web3 technologies and decentralized applications. Use when: blockchain platforms, smart contract development, defi protocols, web3 development, common vu | 100 | 87 | C | — | ↓ 657 | 11 May 2026 | |
| 397 | A | Secure communication using the Pieter Theijssen triple-layer XOR encryption algorithm. Use when encrypting or decrypting messages, files, or any sensitive data that needs to be transmitted securely ov | 100 | 87 | C | — | ↓ 657 | 18 May 2026 | |
| 398 | A | Scan AI agent skills for security vulnerabilities — detects code injection, prompt injection, credential exfiltration, supply chain attacks, and 69+ threat patterns. Use when installing new skills, au | 100 | 84 | D | — | ↓ 1 069 | 11 May 2026 | |
| 399 | A | Linux security auditing tool that checks SSH configuration, open/listening ports, firewall rules (ufw/iptables/nftables), failed login attempts, sudoers permissions, world-writable files, and SUID bin | 100 | 87 | D | — | ↓ 693 | 11 May 2026 | |
| 400 | A | Assess GDPR compliance readiness and generate gap analysis with remediation guidance. Use when evaluating data privacy compliance, GDPR readiness, EU data protection, privacy impact assessments, data | 100 | 86 | B | — | ↓ 1 089 | 11 May 2026 |