SKILLEMALL.ai

Skill rating

2 687 skills. The A–F grade combines safety (60%) and quality (40%); tests add a bonus. The rating refreshes automatically from open catalogs.

2 687
#GradeSkillScore ▾SafetyQualityProcessTestsPopularityUpdated
201A
Use when working with comprehensive review full review
9110078C★ 46 31717 h ago
202A
Static Application Security Testing (SAST) for code vulnerability analysis across multiple languages and frameworks
919978B★ 46 31717 h ago
203A
Provide a comprehensive, structured reference for the 100 most critical web application vulnerabilities organized by category. This skill enables systematic vulnerability identification, impact assess
919684C★ 46 31717 h ago
204A
Reference document for monopoly security-checklist.
919978C★ 46 31717 h ago
205A
Use when executing implementation plans with independent tasks in the current session
9110078C★ 46 31717 h ago
206A
Web application security testing workflow for OWASP Top 10 vulnerabilities including injection, XSS, authentication flaws, and access control issues.
919584C★ 46 31717 h ago
207A
PC and console game development principles. Engine selection, platform features, optimization strategies.
9110078B★ 46 31717 h ago
208A
Searches and explores Burp Suite project files (.burp) from the command line. Use when searching response headers or bodies with regex patterns, extracting security audit findings, dumping proxy histo
919584A★ 46 31717 h ago
209A
Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks.
919684B★ 46 31717 h ago
210A
6 production-ready AI engineering workflows: prompt evaluation (8-dimension scoring), context budget planning, RAG pipeline design, agent security audit (65-point checklist), eval harness building, an
9110078B★ 46 31717 h ago
211A
Provide comprehensive techniques for testing REST, SOAP, and GraphQL APIs during bug bounty hunting and penetration testing engagements. Covers vulnerability discovery, authentication bypass, IDOR exp
919782B★ 46 31717 h ago
212A
Enables ultra-granular, line-by-line code analysis to build deep architectural context before vulnerability or bug finding.
9110077C★ 46 31717 h ago
213A
CISO operacional enterprise para gestao total de credenciais e segredos.
919978B★ 46 31717 h ago
214A
Verify fix commits address audit findings without new bugs
9110078C★ 46 31717 h ago
215A
Scan ClawHub skills for security vulnerabilities BEFORE installing. Use when installing new skills from ClawHub to detect prompt injections, malware payloads, hardcoded secrets, and other threats. Wra
919585C↓ 14 539 ★ 518 May 2026
216A
Apply GDPR-compliant engineering practices across your codebase. Use this skill whenever you are designing APIs, writing data models, building authentication flows, implementing logging, handling user
919978F will not run★ 38 92836 h ago
217A
/cs:compliance-readiness <program> — Multi-framework compliance officer 6-question forcing interrogation of any compliance program. Use before starting a new framework, planning the annual audit calen
9110078F will not run★ 25 87814 d ago
218A
/cs:fda-qsr-audit-prep <scope> — FDA 21 CFR 820 (QSR / QMSR) audit 6-question forcing interrogation. Post-Feb 2026 substantially harmonized with ISO 13485. Use before annual internal QSR audit, pre-FD
9110078F will not run★ 25 87814 d ago
219A
/cs:ciso-review <plan> — Risk-paranoid interrogation of any plan that touches data, compliance, or production access. Use when launching features that handle customer data, before a SOC 2 / ISO audit,
9110078F will not run★ 25 87814 d ago
220A
/cs:cto-review <plan> — Architecture and scaling interrogation. Tech debt, scaling cliffs, team scaling, build-vs-buy. Use when committing to an architecture, planning for 10x load, or weighing a rebu
9110078F will not run★ 25 87814 d ago
221A
/cs:aims-audit <scope> — ISO/IEC 42001 AIMS internal-audit 6-question forcing interrogation. Use before certification stage 1, before annual internal audit cycles, or when onboarding a new AI system i
9110078F will not run★ 25 87814 d ago
222A
Privacy-aware structured memory management for AI agents. Three-tier memory model (Public / Internal-encrypted / Private-not-stored), with XOR+Base64 encryption, auto-cleanup, and generalization rules
9610089C↓ 691 ★ 119 May 2026
223A
Dependency management strategies for Golang projects — go.mod management, installing/upgrading packages, Minimal Version Selection, vulnerability scanning, outdated dependency tracking, binary size an
9610089Cevals↓ 1 24823 d ago
224A
Use this skill whenever the user needs to track, analyze, or respond to advertising platform changes across Meta (Facebook/Instagram), Google Ads, or competitor intelligence. Trigger for any of these
9710093B↓ 66811 May 2026
225A
UAE clinic regulatory compliance, audits, accreditation, and incident reporting. Trigger on: "DOH inspection", "DHA audit", "clinic accreditation", "JCI UAE", "CBAHI", "clinic audit", "infection contr
9710092B↓ 66716 May 2026
226A
Perform a thorough client-side / browser-facing security assessment of a target web application. Use this skill whenever the user asks to pentest, audit, or review the security of a website or web app
949692C↓ 1 252 ★ 217 May 2026
227A
Complete grant intelligence system for individuals, nonprofits, startups, researchers, and small businesses. Trigger whenever someone needs to find grants, write grant applications, understand eligibi
9610089B↓ 1 13611 May 2026
228A
Create and manage test data with factory patterns, fixture strategies, data anonymization, and synthetic data generation. Covers Fishery (TypeScript), FactoryBot (Ruby), Factory Boy (Python), database
9810094B★ 12010 Jun 2026
229A
Test payment and checkout flows end to end against PSP sandboxes — Stripe first, with the general pattern for Adyen/Braintree/PayPal. Covers Stripe test-mode card numbers and their decline codes, the
9810095C★ 12010 Jun 2026
230A
Scan web endpoints for CORS misconfigurations. Detect origin reflection, wildcard policies, null origin acceptance, credential leaks, subdomain trust, HTTP origin trust on HTTPS, preflight issues, and
9710092C↓ 64411 May 2026
231A
Analyze Apache Airflow DAG definitions for quality, reliability, and operational best practices. Checks task dependencies, SLA compliance, retry policies, resource allocation, sensor timeouts, trigger
9710092C↓ 64011 May 2026
232A
Create structured technical specification documents that bridge product requirements and engineering implementation. Use when writing a tech spec, engineering spec, system design doc, or API specifica
9410086B★ 1 35821 h ago
233A
Attack your own plan the way a smart adversary would — find the weakest point, the thing you're hoping nobody notices, and where it breaks under pressure. Use when asked to red-team this, attack my pl
949987B★ 1 35821 h ago
234A
Automated Vulnerability Verification and Payload Replay Probe. Dynamically executes HTTP requests and analyzes HTTP status codes/error traces (e.g., SQL Injection errors). Use when: Testing specific p
9610090C↓ 566 ★ 111 May 2026
235A
1099 vendor compliance pipeline for accounting firms. Pulls full-year General Ledger from QBO, aggregates vendor payments, applies IRS $600 threshold, classifies 1099-NEC vs 1099-MISC, checks corporat
9610090C↓ 1 01018 May 2026
236A
Use this skill when the user asks to export audit logs, find audit log location, view command history, 导出日志, 查看日志, 日志路径, 操作记录, 调用记录, 命令历史. Do NOT use for wallet balance, token search, swap, or any oth
9410084B↓ 2 185 ★ 111 May 2026
237A
Earn $5 USDC per verified novel malicious domain. Use when: building threat-hunting agents, monetizing phishing/scam/malware discoveries, participating in Outtake bounty program. NOT for: checking if
9410084C↓ 1 617 ★ 118 May 2026
238A
Apply GB/T 47041-2026, the Chinese national standard for service quality and assessment of rehabilitation institutions for children with autism. Use when asked about GB/T 47041, 孤独症儿童康复机构服务质量及评价规范, au
9710092C↓ 57311 May 2026
239A
初始化并启动 Chrome DevTools Protocol(CDP)模式,支持用 Playwright 和 browser-use Agent 远程控制真实 Chrome 浏览器。解决 Chrome 145+ App-Bound Encryption 限制,自动复制 Profile 到非默认路径以启用 CDP。适合自动化网页操作、数据提取、Form 填表、爬虫等场景。
9610091D↓ 98418 May 2026
240A
License compliance for your own repos. Ensures correct copyright headers, dual-license blocks, and LICENSE files across all source files.
9410084C↓ 1 536 ★ 111 May 2026
241A
Comprehensive security auditing for Clawdbot deployments. Scans for exposed credentials, open ports, weak configs, and vulnerabilities. Auto-fix mode included.
9510087C★ 6637 Mar 2026
242A
Assess any API or website's Graceful Boundaries conformance level and provide concrete guidance for reaching the next level. Use this skill when the user asks to check a URL's rate limit communication
9610089C↓ 1 0676 d ago
243A
ISO 27001 ISMS implementation and cybersecurity governance for HealthTech and MedTech companies. Use for ISMS design, security risk assessment, control implementation, ISO 27001 certification, securit
939394C★ 2 14120 Jul 2026
244A
FDA regulatory consultant for medical device companies. Provides 510(k)/PMA/De Novo pathway guidance, QSR (21 CFR 820) compliance, HIPAA assessments, and device cybersecurity. Use when user mentions F
939491C★ 2 14120 Jul 2026
245A
Cross-cloud security posture assessment covering IAM analysis, encryption audit, and public exposure detection across AWS, Azure, and GCP using [AWS]/[Azure]/[GCP] inline labels for provider-specific
939589C★ 2 14120 Jul 2026
246A
Microsoft 365 tenant administration for Global Administrators. Automate M365 tenant setup, Office 365 admin tasks, Azure AD user management, Exchange Online configuration, Teams administration, and se
939985C★ 2 14120 Jul 2026
247A
AI runtime security monitoring — context graph analysis, runtime audit log correlation with CVE findings, and vulnerability analytics queries. Use when the user mentions runtime monitoring, context gr
939885C★ 2 14120 Jul 2026
248A
Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices. Runs SAST/DAST scans, generates CVE remediation plans, check
939591D★ 2 14120 Jul 2026
249A
CTF-oriented ZIP cracking and recovery with the bundled ZipCracker engine. Use when Codex or OpenClaw needs to analyze or recover an encrypted ZIP in authorized contexts, including pseudo-encryption r
9410085B↓ 1 494 ★ 117 May 2026
250A
Designs compliance management and data privacy transparency frameworks for baby and maternity product stores (e.g. baby skincare, car seats). Use when the user mentions privacy policy, consent, parent
9610093Cevals↓ 90511 May 2026