Skill rating
2 687 skills. The A–F grade combines safety (60%) and quality (40%); tests add a bonus. The rating refreshes automatically from open catalogs.
ManufacturingLogistics and warehouseProcurementQuality controlContact centreField serviceFinanceCustomer supportindustry shortcuts
| # | Grade | Skill | Score ▾ | Safety | Quality | Process | Tests | Popularity | Updated |
|---|---|---|---|---|---|---|---|---|---|
| 201 | A | comprehensive-review-full-reviewAnalyzerSoftware developmentSecuritysickn33/agentic-awesome-skillsAgent Skills Use when working with comprehensive review full review | 100 | 78 | C | — | ★ 46 317 | 17 h ago | |
| 202 | A | security-scanning-security-sastAnalyzerSecuritySoftware developmentsickn33/agentic-awesome-skillsAgent Skills Static Application Security Testing (SAST) for code vulnerability
analysis across multiple languages and frameworks | 99 | 78 | B | — | ★ 46 317 | 17 h ago | |
| 203 | A | Provide a comprehensive, structured reference for the 100 most critical web application vulnerabilities organized by category. This skill enables systematic vulnerability identification, impact assess | 96 | 84 | C | — | ★ 46 317 | 17 h ago | |
| 204 | A | Reference document for monopoly security-checklist. | 99 | 78 | C | — | ★ 46 317 | 17 h ago | |
| 205 | A | subagent-driven-developmentProcedureSoftware developmentAI and agentssickn33/agentic-awesome-skillsAgent Skills Use when executing implementation plans with independent tasks in the current session | 100 | 78 | C | — | ★ 46 317 | 17 h ago | |
| 206 | A | Web application security testing workflow for OWASP Top 10 vulnerabilities including injection, XSS, authentication flaws, and access control issues. | 95 | 84 | C | — | ★ 46 317 | 17 h ago | |
| 207 | A | PC and console game development principles. Engine selection, platform features, optimization strategies. | 100 | 78 | B | — | ★ 46 317 | 17 h ago | |
| 208 | A | burpsuite-project-parserProcedureSoftware developmentData and analyticssickn33/agentic-awesome-skillsAgent Skills Searches and explores Burp Suite project files (.burp) from the command line. Use when searching response headers or bodies with regex patterns, extracting security audit findings, dumping proxy histo | 95 | 84 | A | — | ★ 46 317 | 17 h ago | |
| 209 | A | Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks. | 96 | 84 | B | — | ★ 46 317 | 17 h ago | |
| 210 | A | 6 production-ready AI engineering workflows: prompt evaluation (8-dimension scoring), context budget planning, RAG pipeline design, agent security audit (65-point checklist), eval harness building, an | 100 | 78 | B | — | ★ 46 317 | 17 h ago | |
| 211 | A | api-fuzzing-bug-bountyIntegrationGitHubSecurityWriting and documentssickn33/agentic-awesome-skillsAgent Skills Provide comprehensive techniques for testing REST, SOAP, and GraphQL APIs during bug bounty hunting and penetration testing engagements. Covers vulnerability discovery, authentication bypass, IDOR exp | 97 | 82 | B | — | ★ 46 317 | 17 h ago | |
| 212 | A | Enables ultra-granular, line-by-line code analysis to build deep architectural context before vulnerability or bug finding. | 100 | 77 | C | — | ★ 46 317 | 17 h ago | |
| 213 | A | CISO operacional enterprise para gestao total de credenciais e segredos. | 99 | 78 | B | — | ★ 46 317 | 17 h ago | |
| 214 | A | Verify fix commits address audit findings without new bugs | 100 | 78 | C | — | ★ 46 317 | 17 h ago | |
| 215 | A | Scan ClawHub skills for security vulnerabilities BEFORE installing. Use when installing new skills from ClawHub to detect prompt injections, malware payloads, hardcoded secrets, and other threats. Wra | 95 | 85 | C | — | ↓ 14 539 ★ 5 | 18 May 2026 | |
| 216 | A | Apply GDPR-compliant engineering practices across your codebase. Use this skill whenever you are designing APIs, writing data models, building authentication flows, implementing logging, handling user | 99 | 78 | F will not run | — | ★ 38 928 | 36 h ago | |
| 217 | A | /cs:compliance-readiness <program> — Multi-framework compliance officer 6-question forcing interrogation of any compliance program. Use before starting a new framework, planning the annual audit calen | 100 | 78 | F will not run | — | ★ 25 878 | 14 d ago | |
| 218 | A | fda-qsr-audit-prepAnalyzerCustomer supportData and analyticsalirezarezvani/claude-skillsAgent Skills /cs:fda-qsr-audit-prep <scope> — FDA 21 CFR 820 (QSR / QMSR) audit 6-question forcing interrogation. Post-Feb 2026 substantially harmonized with ISO 13485. Use before annual internal QSR audit, pre-FD | 100 | 78 | F will not run | — | ★ 25 878 | 14 d ago | |
| 219 | A | /cs:ciso-review <plan> — Risk-paranoid interrogation of any plan that touches data, compliance, or production access. Use when launching features that handle customer data, before a SOC 2 / ISO audit, | 100 | 78 | F will not run | — | ★ 25 878 | 14 d ago | |
| 220 | A | /cs:cto-review <plan> — Architecture and scaling interrogation. Tech debt, scaling cliffs, team scaling, build-vs-buy. Use when committing to an architecture, planning for 10x load, or weighing a rebu | 100 | 78 | F will not run | — | ★ 25 878 | 14 d ago | |
| 221 | A | /cs:aims-audit <scope> — ISO/IEC 42001 AIMS internal-audit 6-question forcing interrogation. Use before certification stage 1, before annual internal audit cycles, or when onboarding a new AI system i | 100 | 78 | F will not run | — | ★ 25 878 | 14 d ago | |
| 222 | A | Privacy-aware structured memory management for AI agents. Three-tier memory model (Public / Internal-encrypted / Private-not-stored), with XOR+Base64 encryption, auto-cleanup, and generalization rules | 100 | 89 | C | — | ↓ 691 ★ 1 | 19 May 2026 | |
| 223 | A | Dependency management strategies for Golang projects — go.mod management, installing/upgrading packages, Minimal Version Selection, vulnerability scanning, outdated dependency tracking, binary size an | 100 | 89 | C | evals | ↓ 1 248 | 23 d ago | |
| 224 | A | Use this skill whenever the user needs to track, analyze, or respond to advertising platform changes across Meta (Facebook/Instagram), Google Ads, or competitor intelligence. Trigger for any of these | 100 | 93 | B | — | ↓ 668 | 11 May 2026 | |
| 225 | A | UAE clinic regulatory compliance, audits, accreditation, and incident reporting. Trigger on: "DOH inspection", "DHA audit", "clinic accreditation", "JCI UAE", "CBAHI", "clinic audit", "infection contr | 100 | 92 | B | — | ↓ 667 | 16 May 2026 | |
| 226 | A | Perform a thorough client-side / browser-facing security assessment of a target web application. Use this skill whenever the user asks to pentest, audit, or review the security of a website or web app | 96 | 92 | C | — | ↓ 1 252 ★ 2 | 17 May 2026 | |
| 227 | A | Complete grant intelligence system for individuals, nonprofits, startups, researchers, and small businesses. Trigger whenever someone needs to find grants, write grant applications, understand eligibi | 100 | 89 | B | — | ↓ 1 136 | 11 May 2026 | |
| 228 | A | test-data-managementGeneratorSupabasePlaywrightSoftware developmentSecuritypetrkindlmann/qa-skillsAgent Skills Create and manage test data with factory patterns, fixture strategies, data anonymization, and synthetic data generation. Covers Fishery (TypeScript), FactoryBot (Ruby), Factory Boy (Python), database | 100 | 94 | B | — | ★ 120 | 10 Jun 2026 | |
| 229 | A | Test payment and checkout flows end to end against PSP sandboxes — Stripe first, with the general pattern for Adyen/Braintree/PayPal. Covers Stripe test-mode card numbers and their decline codes, the | 100 | 95 | C | — | ★ 120 | 10 Jun 2026 | |
| 230 | A | Scan web endpoints for CORS misconfigurations. Detect origin reflection, wildcard policies, null origin acceptance, credential leaks, subdomain trust, HTTP origin trust on HTTPS, preflight issues, and | 100 | 92 | C | — | ↓ 644 | 11 May 2026 | |
| 231 | A | Analyze Apache Airflow DAG definitions for quality, reliability, and operational best practices. Checks task dependencies, SLA compliance, retry policies, resource allocation, sensor timeouts, trigger | 100 | 92 | C | — | ↓ 640 | 11 May 2026 | |
| 232 | A | technical-spec-templateGeneratorSecuritySoftware developmentmohitagw15856/pm-claude-skillsAgent Skills Create structured technical specification documents that bridge product requirements and engineering implementation. Use when writing a tech spec, engineering spec, system design doc, or API specifica | 100 | 86 | B | — | ★ 1 358 | 21 h ago | |
| 233 | A | Attack your own plan the way a smart adversary would — find the weakest point, the thing you're hoping nobody notices, and where it breaks under pressure. Use when asked to red-team this, attack my pl | 99 | 87 | B | — | ★ 1 358 | 21 h ago | |
| 234 | A | Automated Vulnerability Verification and Payload Replay Probe. Dynamically executes HTTP requests and analyzes HTTP status codes/error traces (e.g., SQL Injection errors). Use when: Testing specific p | 100 | 90 | C | — | ↓ 566 ★ 1 | 11 May 2026 | |
| 235 | A | 1099 vendor compliance pipeline for accounting firms. Pulls full-year General Ledger from QBO, aggregates vendor payments, applies IRS $600 threshold, classifies 1099-NEC vs 1099-MISC, checks corporat | 100 | 90 | C | — | ↓ 1 010 | 18 May 2026 | |
| 236 | A | Use this skill when the user asks to export audit logs, find audit log location, view command history, 导出日志, 查看日志, 日志路径, 操作记录, 调用记录, 命令历史. Do NOT use for wallet balance, token search, swap, or any oth | 100 | 84 | B | — | ↓ 2 185 ★ 1 | 11 May 2026 | |
| 237 | A | Earn $5 USDC per verified novel malicious domain. Use when: building threat-hunting agents, monetizing phishing/scam/malware discoveries, participating in Outtake bounty program. NOT for: checking if | 100 | 84 | C | — | ↓ 1 617 ★ 1 | 18 May 2026 | |
| 238 | A | Apply GB/T 47041-2026, the Chinese national standard for service quality and assessment of rehabilitation institutions for children with autism. Use when asked about GB/T 47041, 孤独症儿童康复机构服务质量及评价规范, au | 100 | 92 | C | — | ↓ 573 | 11 May 2026 | |
| 239 | A | 初始化并启动 Chrome DevTools Protocol(CDP)模式,支持用 Playwright 和 browser-use Agent 远程控制真实 Chrome 浏览器。解决 Chrome 145+ App-Bound Encryption 限制,自动复制 Profile 到非默认路径以启用 CDP。适合自动化网页操作、数据提取、Form 填表、爬虫等场景。 | 100 | 91 | D | — | ↓ 984 | 18 May 2026 | |
| 240 | A | License compliance for your own repos. Ensures correct copyright headers, dual-license blocks, and LICENSE files across all source files. | 100 | 84 | C | — | ↓ 1 536 ★ 1 | 11 May 2026 | |
| 241 | A | Comprehensive security auditing for Clawdbot deployments. Scans for exposed credentials, open ports, weak configs, and vulnerabilities. Auto-fix mode included. | 100 | 87 | C | — | ★ 663 | 7 Mar 2026 | |
| 242 | A | Assess any API or website's Graceful Boundaries conformance level and provide concrete guidance for reaching the next level. Use this skill when the user asks to check a URL's rate limit communication | 100 | 89 | C | — | ↓ 1 067 | 6 d ago | |
| 243 | A | ISO 27001 ISMS implementation and cybersecurity governance for HealthTech and MedTech companies. Use for ISMS design, security risk assessment, control implementation, ISO 27001 certification, securit | 93 | 94 | C | — | ★ 2 141 | 20 Jul 2026 | |
| 244 | A | FDA regulatory consultant for medical device companies. Provides 510(k)/PMA/De Novo pathway guidance, QSR (21 CFR 820) compliance, HIPAA assessments, and device cybersecurity. Use when user mentions F | 94 | 91 | C | — | ★ 2 141 | 20 Jul 2026 | |
| 245 | A | cloud-security-postureAnalyzerAWSGoogle CloudInfrastructureSecurityLeoYeAI/openclaw-master-skillsAgent Skills Cross-cloud security posture assessment covering IAM analysis, encryption audit, and public exposure detection across AWS, Azure, and GCP using [AWS]/[Azure]/[GCP] inline labels for provider-specific | 95 | 89 | C | — | ★ 2 141 | 20 Jul 2026 | |
| 246 | A | ms365-tenant-managerProcedureAzureData and analyticsSecurityLeoYeAI/openclaw-master-skillsAgent Skills Microsoft 365 tenant administration for Global Administrators. Automate M365 tenant setup, Office 365 admin tasks, Azure AD user management, Exchange Online configuration, Teams administration, and se | 99 | 85 | C | — | ★ 2 141 | 20 Jul 2026 | |
| 247 | A | AI runtime security monitoring — context graph analysis, runtime audit log correlation with CVE findings, and vulnerability analytics queries. Use when the user mentions runtime monitoring, context gr | 98 | 85 | C | — | ★ 2 141 | 20 Jul 2026 | |
| 248 | A | Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices. Runs SAST/DAST scans, generates CVE remediation plans, check | 95 | 91 | D | — | ★ 2 141 | 20 Jul 2026 | |
| 249 | A | CTF-oriented ZIP cracking and recovery with the bundled ZipCracker engine. Use when Codex or OpenClaw needs to analyze or recover an encrypted ZIP in authorized contexts, including pseudo-encryption r | 100 | 85 | B | — | ↓ 1 494 ★ 1 | 17 May 2026 | |
| 250 | A | Designs compliance management and data privacy transparency frameworks for baby and maternity product stores (e.g. baby skincare, car seats). Use when the user mentions privacy policy, consent, parent | 100 | 93 | C | evals | ↓ 905 | 11 May 2026 |