Skill rating
2 687 skills. The A–F grade combines safety (60%) and quality (40%); tests add a bonus. The rating refreshes automatically from open catalogs.
ManufacturingLogistics and warehouseProcurementQuality controlContact centreField serviceFinanceCustomer supportindustry shortcuts
| # | Grade | Skill | Score ▾ | Safety | Quality | Process | Tests | Popularity | Updated |
|---|---|---|---|---|---|---|---|---|---|
| 101 | A | Audit and fix all skills in the workspace for compliance with skill-creator requirements. Use when asked to "refine skills", "audit skills", "check skill quality", or "fix non-compliant skills". Exhau | 100 | 92 | D | — | ↓ 1 712 | 18 May 2026 | |
| 102 | A | 中国合同审查工具。Use when user needs to review contracts, identify risks, check compliance, or get legal suggestions. Supports labor contracts, sales contracts, rental agreements, service contracts. 中国合同审查、合同 | 100 | 84 | C | — | ↓ 2 416 ★ 3 | 11 May 2026 | |
| 103 | A | When the user wants to create or optimize popups, modals, overlays, slide-ins, or banners for conversion purposes. Also use when the user mentions "exit intent," "popup conversions," "modal optimizati | 100 | 88 | C | — | ★ 2 141 | 20 Jul 2026 | |
| 104 | A | Plan and execute authorized Metasploit assessments for OpenClaw tasks with repeatable workflows, including target triage, exploit module selection, option tuning, .rc generation, controlled execution, | 99 | 91 | D | — | ↓ 1 376 ★ 1 | 17 May 2026 | |
| 105 | A | 美国加州消费者隐私法(CCPA/CPRA)合规检查、风险评估和文档生成工具。
为涉及加州消费者数据的业务提供全面的CCPA/CPRA合规解决方案。
Use when: 需要进行CCPA/CPRA合规自查、消费者权利保障检查、选择退出机制实现、
数据销售合规检查、服务提供商管理、隐私合规体系建设。
🎉 版本1.0.5重要更新:
- 🔧 全新统一化CLI接口,与PIPL、GDPR工具体验一致
| 100 | 89 | D | — | ↓ 1 834 ★ 1 | 22 Jul 2026 | |
| 106 | A | Scan project dependencies for license compatibility issues, GPL contamination, and compliance violations. Supports npm, pip, Go, Rust, and Ruby ecosystems. Use when asked to audit licenses, check lice | 100 | 94 | C | — | ↓ 746 | 11 May 2026 | |
| 107 | A | Security check for OpenClaw skills. Scan any ClawHub skill for malware, prompt injection, data theft, wallet stealing, and dangerous permissions BEFORE installing. Always use this skill when installin | 99 | 94 | B | — | ↓ 1 260 | 18 May 2026 | |
| 108 | A | Run Azure compliance and security audits with azqr plus Key Vault expiration checks. Covers best-practice assessment, resource review, policy/compliance validation, and security posture checks. WHEN: | 100 | 85 | C | — | ★ 3 010 | 2 d ago | |
| 109 | A | Use when reviewing code for security vulnerabilities, implementing authentication flows, auditing OWASP Top 10, configuring CORS/CSP headers, handling secrets, input validation, SQL injection preventi | 99 | 81 | C | — | ↓ 27 976 ★ 47 | 11 May 2026 | |
| 110 | A | Execute plans via delegate_task subagents (2-stage review). | 100 | 81 | C | — | ★ 244 884 | 11 h ago | |
| 111 | A | Audit codebases and infrastructure for security issues. Use when scanning dependencies for vulnerabilities, detecting hardcoded secrets, checking OWASP top 10 issues, verifying SSL/TLS, auditing file | 98 | 84 | C | — | ↓ 14 935 ★ 25 | 11 May 2026 | |
| 112 | A | accessibility-compliance-accessibility-auditAnalyzerSecuritysickn33/agentic-awesome-skillsAgent Skills You are an accessibility expert specializing in WCAG compliance, inclusive design, and assistive technology compatibility. Conduct audits, identify barriers, and provide remediation guidance. | 100 | 80 | B | — | ★ 46 317 | 16 h ago | |
| 113 | A | You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, ou | 100 | 80 | B | — | ★ 46 317 | 16 h ago | |
| 114 | A | azure-security-keyvault-keys-dotnetIntegrationAzureInfrastructureSecuritysickn33/agentic-awesome-skillsAgent Skills Azure Key Vault Keys SDK for .NET. Client library for managing cryptographic keys in Azure Key Vault and Managed HSM. Use for key creation, rotation, encryption, decryption, signing, and verification. | 100 | 81 | B | — | ★ 46 317 | 16 h ago | |
| 115 | A | mailtrap-setting-up-sending-domainAnalyzerCloudflareAWSSecurityWriting and documentssickn33/agentic-awesome-skillsAgent Skills Add or verify a Mailtrap sending domain, troubleshoot DNS propagation, publish SPF/DKIM/DMARC records, and complete compliance. | 99 | 81 | C | — | ★ 46 317 | 16 h ago | |
| 116 | A | Review payment data flows and engineering control evidence for a scoped PCI assessment, without claiming certification. | 100 | 81 | B | — | ★ 46 317 | 16 h ago | |
| 117 | A | fda-medtech-compliance-auditorAnalyzerQuality controlSecuritysickn33/agentic-awesome-skillsAgent Skills Expert AI auditor for Medical Device (SaMD) compliance, IEC 62304, and 21 CFR Part 820. Reviews DHFs, technical files, and software validation. | 100 | 81 | B | — | ★ 46 317 | 16 h ago | |
| 118 | A | You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, ou | 100 | 80 | B | — | ★ 46 317 | 16 h ago | |
| 119 | A | API security testing workflow for REST and GraphQL APIs covering authentication, authorization, rate limiting, input validation, and security best practices. | 98 | 84 | B | — | ★ 46 317 | 16 h ago | |
| 120 | A | Assess worker-classification and compliance risk for temporary event staffing in the US and Canada — W-2 vs 1099, misclassification penalties, joint-employer liability, COI, and wage/hour rules. Inclu | 100 | 81 | C | — | ★ 46 317 | 16 h ago | |
| 121 | A | Provide comprehensive techniques for attacking Microsoft Active Directory environments. Covers reconnaissance, credential harvesting, Kerberos attacks, lateral movement, privilege escalation, and doma | 96 | 85 | C | — | ★ 46 317 | 16 h ago | |
| 122 | A | Conduct comprehensive security assessments of SMTP (Simple Mail Transfer Protocol) servers to identify vulnerabilities including open relays, user enumeration, weak authentication, and misconfiguratio | 97 | 85 | C | — | ★ 46 317 | 16 h ago | |
| 123 | A | Web and App implementation guide for High Contrast Design. Trigger when user wants accessibility-focused design, extreme legibility, or stark visual impact. | 100 | 81 | C | — | ★ 46 317 | 16 h ago | |
| 124 | A | fda-food-safety-auditorAnalyzerSecurityWriting and documentssickn33/agentic-awesome-skillsAgent Skills Expert AI auditor for FDA Food Safety (FSMA), HACCP, and PCQI compliance. Reviews food facility records and preventive controls. | 100 | 81 | C | — | ★ 46 317 | 16 h ago | |
| 125 | A | Identify and exploit HTML injection vulnerabilities that allow attackers to inject malicious HTML content into web applications. This vulnerability enables attackers to modify page appearance, create | 100 | 81 | C | — | ★ 46 317 | 16 h ago | |
| 126 | A | Identify and exploit authentication and session management vulnerabilities in web applications. Broken authentication consistently ranks in the OWASP Top 10 and can lead to account takeover, identity | 100 | 81 | C | — | ★ 46 317 | 16 h ago | |
| 127 | A | Execute comprehensive SQL injection vulnerability assessments on web applications to identify database security flaws, demonstrate exploitation techniques, and validate input sanitization mechanisms. | 99 | 81 | C | — | ★ 46 317 | 16 h ago | |
| 128 | A | Review files for compliance with Web Interface Guidelines. | 100 | 81 | B | — | ★ 46 317 | 16 h ago | |
| 129 | A | Audit and migrate an existing Markdown renderer to Markstream while preserving custom renderers, security policy, streaming behavior, and explicit parity gaps. | 100 | 80 | C | — | ★ 46 317 | 16 h ago | |
| 130 | A | Country-specific Odoo localization: tax configuration, e-invoicing (CFDI, FatturaPA, SAF-T), fiscal reporting, and country chart of accounts setup. | 100 | 81 | C | — | ★ 46 317 | 16 h ago | |
| 131 | A | Audit an Agent Skill, MCP server, connector, or desktop extension before installation by tracing code, dependencies, permissions, credentials, data flow, and irreversible actions. | 100 | 79 | C | — | ★ 46 317 | 16 h ago | |
| 132 | A | Run an AFP 100-point or AUSTRAC safe-harbour identity check over a set of documents, and report exactly what's missing. Use when the user asks to check identity documents, verify someone's ID for onbo | 100 | 79 | B | — | ★ 46 317 | 16 h ago | |
| 133 | A | Rigorous visual validation expert specializing in UI testing, design system compliance, and accessibility verification. | 100 | 81 | B | — | ★ 46 317 | 16 h ago | |
| 134 | A | Locate vulnerability fixes in vendor patches, diff binaries across versions, and build N-day PoCs. Attack-side complement to binary-diff for authorized research. | 96 | 86 | D | — | ★ 46 317 | 16 h ago | |
| 135 | A | Use when CrossFrame Suite routes explicit Chinese analysis of public issues, platform governance, policy, institutional responsibility, appeals, or compliance evidence. | 100 | 80 | C | — | ★ 46 317 | 16 h ago | |
| 136 | A | Master software architect specializing in modern architecture | 100 | 81 | B | — | ★ 46 317 | 16 h ago | |
| 137 | A | Expert firmware analyst specializing in embedded systems, IoT security, and hardware reverse engineering. | 99 | 81 | B | — | ★ 46 317 | 16 h ago | |
| 138 | A | Authorized reverse engineering of custom binary protocols, Protobuf/gRPC schemas, WebSocket frames, and PCAP-driven protocol recovery. | 96 | 86 | D | — | ★ 46 317 | 16 h ago | |
| 139 | A | Find similar vulnerabilities and bugs across codebases using pattern-based analysis. Use when hunting bug variants, building CodeQL/Semgrep queries, analyzing security vulnerabilities, or performing s | 100 | 81 | B | — | ★ 46 317 | 16 h ago | |
| 140 | A | Master essential security scanning tools for network discovery, vulnerability assessment, web application testing, wireless security, and compliance validation. This skill covers tool selection, confi | 99 | 81 | C | — | ★ 46 317 | 16 h ago | |
| 141 | A | Reverse engineer EDR internals (user-mode hook tables, ETW, AMSI) and study bypass techniques such as direct syscalls, Hell's Gate, and call-stack spoofing. Lab-only red-team research. | 96 | 86 | D | — | ★ 46 317 | 16 h ago | |
| 142 | A | Expert at handling file uploads and cloud storage. Covers S3, Cloudflare R2, presigned URLs, multipart uploads, and image optimization. Knows how to handle large files without blocking. | 100 | 81 | B | — | ★ 46 317 | 16 h ago | |
| 143 | A | Provide systematic methodologies for identifying and exploiting Insecure Direct Object Reference (IDOR) vulnerabilities in web applications. | 98 | 84 | B | — | ★ 46 317 | 16 h ago | |
| 144 | A | Design a PostgreSQL-specific schema. Covers best-practices, data types, indexing, constraints, performance patterns, and advanced features | 100 | 81 | C | — | ★ 46 317 | 16 h ago | |
| 145 | A | client-secret-exposure-auditAnalyzerGitHubDockerSecurityAI and agentssickn33/agentic-awesome-skillsHermes Audit a deployed web app for secrets exposed to the browser: hardcoded API keys/tokens in JS, secrets in HTML meta/attributes/comments, publicly reachable source/config/deploy files, and header/CORS m | 100 | 79 | B | — | ★ 46 317 | 16 h ago | |
| 146 | A | Guides Qdrant multi-tenant scaling. Use when someone asks 'how to scale tenants', 'one collection per tenant?', 'tenant isolation', 'dedicated shards', or reports tenant performance issues. Also use w | 100 | 80 | D | — | ★ 38 928 | 36 h ago | |
| 147 | A | qdrant-monitoring-setupProcedureKubernetesInfrastructureData and analyticsgithub/awesome-copilotAgent Skills Guides Qdrant monitoring setup including Prometheus scraping, health probes, Hybrid Cloud metrics, alerting, and log centralization. Use when someone asks 'how to set up monitoring', 'Prometheus confi | 100 | 80 | D | — | ★ 38 928 | 36 h ago | |
| 148 | A | Full STRIDE-A threat model analysis and incremental update skill for repositories and systems. Supports two modes: (1) Single analysis — full STRIDE-A threat model of a repository, producing architect | 98 | 84 | C | — | ★ 38 928 | 36 h ago | |
| 149 | A | Audit and manage dependencies across multi-language projects. Identifies vulnerabilities, license conflicts, transitive dependency risks, and safe-upgrade paths. Use when auditing third-party packages | 98 | 83 | D | — | ★ 25 878 | 14 d ago | |
| 150 | A | Security leadership for growth-stage companies. Risk quantification in dollars, compliance roadmap (SOC 2/ISO 27001/HIPAA/GDPR), security architecture strategy, incident response leadership, and board | 90 | 95 | C | — | ★ 25 878 | 14 d ago |