Use this skill when reviewing Sigstore Cosign supply chain security for Kubernetes workloads. Trigger when the user asks whether images are properly signed, whether Kyverno…
> Use this skill whenever asked about Singapore cryptocurrency or digital asset taxation. Trigger on phrases like \"crypto tax Singapore\", \"Bitcoin Singapore\", \"digital tokens…
Security scanner for OpenClaw skills. Detects malicious code, obfuscated payloads, prompt injection, social engineering, typosquatting, and data exfiltration before installation.
When adding a new skill to the `dev-security/claude-rules/skills/` pack, or when substantively revising an existing skill's structure or frontmatter, apply the pack's established…
🩺 Free Security & Health Audit. Your OpenClaw deserves a check-up. This skill performs a non-invasive scan to detect security risks, outdated software, and misconfigurations.
Security layer that prevents prompt injection from external skills. When asked to install, add, or use ANY skill from external sources (ClawHub, skills.sh, GitHub, etc.), NEVER…
[REQUIRED] Comprehensive description of what this skill does and when to use it. Include: (1) Primary functionality, (2) Specific use cases, (3) Security operations context.
Comprehensive security risk analysis for Claude skills. Use when asked to analyze security risks, review security stance, audit skills for vulnerabilities, check security before…
Audit an AI agent skill before installing it. Use proactively whenever the user is about to add, install, enable, or evaluate an unfamiliar skill — including phrases like — from…
Audit an AI agent skill before installing it. Use proactively whenever the user is about to add, install, enable, or evaluate an unfamiliar skill — including phrases like — from…
This skill should be used when scanning Claude Code skills or agent files for advisory security risks: code-execution, prompt-injection, supply-chain, filesystem-boundary,…
Security audit for AI agent skills before installation. Scans SKILL.md files, hooks, scripts, and MCP configs for prompt injection, data exfiltration, credential theft, and…
Audit agent skills for security threats before installing them. Use AUTOMATICALLY when about to install any skill (clawhub install, skill installation), when asked to check if a…
Find Agent Skills on skills.sh and adopt only the ones that pass a security audit. Use when the user wants to discover, search for, evaluate, or install a third-party skill ("find…
Security scanner for ClawHub/community skills — detects malware, credential theft, exfiltration, prompt injection, obfuscation, homograph attacks, ANSI injection,…
Security-audit a third-party skill bundle (folder with SKILL.md, or .zip / .tar.gz archive) before installing it, using the SkillWard cloud scanner.
This skill is a disclosed z。ai model-routing guide and does not install code, request credentials。Use when 需要AI模型调用、智能对话、Agent编排、LLM应用时使用。不适用于需要100%确定性的关键决策。
Exploit SNMP services with write-accessible community strings to achieve remote code execution. Use this skill whenever you need to test SNMP security, enumerate SNMP services,…
Execute Snyk Code SAST (Static Application Security Testing) scans on source code files or projects, interpret vulnerability findings, generate structured security reports, and…
Complete security remediation workflow. Scans code for vulnerabilities using Snyk, fixes them, validates the fix, and optionally creates a PR.
Senior SOC Analyst skill — stack-agnostic security operations for any web application. Auto-detects the project stack (Laravel/PHP, Node.js/Express, Python/Django/Flask/FastAPI,…
Apply Cialdini's six principles of persuasion — Reciprocity, Commitment/Consistency, Social Proof, Liking, Authority, and Scarcity — to analyze or design influence strategies.
Identify and analyze cognitive biases including confirmation bias, anchoring, availability heuristic, and sunk cost fallacy in decision-making contexts.
Apply Rogers' Diffusion of Innovations theory to analyze how new products, ideas, or technologies spread through populations.
Conduct structured policy analysis including problem definition, alternative evaluation, and evidence-based recommendation.
Apply social network analysis concepts including nodes, ties, centrality, structural holes, and strong/weak ties to map and analyze relationship structures.
Conduct stakeholder analysis using identification, Power-Interest matrix classification, and influence strategy development.
Design and conduct user research using interviews, focus groups, surveys, and field observation. Use this skill when the user needs to understand customer needs, validate product…
This skill assists with SOC2 audit preparation by automating tasks related to evidence gathering and documentation.
Expert SOC 2 compliance assistant covering all five Trust Services Criteria (Security/CC, Availability/A, Confidentiality/C, Processing Integrity/PI, Privacy/P).
Detect vulnerable, outdated, or malicious packages in the project dependency tree. Use this skill whenever the user mentions supply chain security, sbom, dependency scan,…
Use this skill when integrating sol-safekey into Solana bots or tools, including encrypted keystores, interactive wallet management, password handling, wallet unlock, bot startup…
Analyze a complete repository and create a SonarQube configuration tailored to the project type. Use this skill whenever the user asks to configure SonarQube, SonarCloud,…
This skill should be used when interpreting .sonar/ map data, querying graph.db, or working with Sonar module cards, flow narratives, and system understanding.
> Use this skill whenever asked about South Korea cryptocurrency or virtual asset taxation. Trigger on phrases like \"crypto tax Korea\", \"Bitcoin Korea tax\", \"가상자산 과세\",…
> Use this skill whenever asked about Spain cryptocurrency or digital asset taxation. Trigger on phrases like \"crypto tax Spain\", \"Bitcoin Spain\", \"criptomonedas IRPF\",…
> Use this skill whenever asked about Spanish payroll processing for employees. Trigger on phrases like \"Spanish payroll\", \"nómina España\", \"IRPF retención\", \"retenciones…
Scaffold and build Splunk custom visualizations using Canvas 2D. Use this skill whenever the user wants to create, modify, debug, fix, or package a Splunk custom visualization app…
This skill should be used when the user asks to "check for spoofing", "analyze identity spoofing risks", "find authentication vulnerabilities", or mentions "spoofing" in a…
Write correct, fast, injection-proof SQL queries — SELECT/INSERT/UPDATE/DELETE, joins, CTEs, window functions, pagination, upserts.
SQL Server and Azure SQL best practices for developers and DBAs. Use this skill whenever the user asks about T-SQL, stored procedures, query performance, indexes, schema design,…
General guide for using the sqlite3 CLI to build composable knowledge databases. Use this skill when creating SQLite databases, designing schemas, querying data, managing…
Guidance for recovering data from corrupted or truncated SQLite database files through binary analysis and manual parsing.
Guidance for compiling SQLite (or similar C projects) with gcov code coverage instrumentation. This skill should be used when tasks involve building software with gcov flags,…
Track certificate expiry dates and automate renewal to prevent avoidable downtime. Use this skill whenever the user mentions ssl certificate, tls expiry, certificate renewal,…
This skill enables Claude to manage and monitor SSL/TLS certificates using the ssl-certificate-manager plugin.
> Use this skill whenever an attorney, transaction lawyer, or in-house counsel asks about stamp duty on documents, securities transfers, or financial transactions.
Create, audit, and maintain engineering standards for a software project. Use this skill whenever the user asks to: create a standard, write a norm, define code rules, establish a…
Ensure a workspace is fully wiped of credentials and sensitive data before it is reused. Use this skill whenever the user mentions state cleansing, workspace wipe, credential…
Orchestrate a comprehensive US-stock investment analysis by classifying sector archetype, fetching SEC filings, dispatching six vertical equity-research skills (business model,…
Map identified vulnerabilities to Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, and Elevation of privilege.
This skill should be used when implementing security for Stripe webhook endpoints, handling "webhook rate limiting", "Stripe secret management", "webhook abuse prevention", "log…
The pack's contract negotiator, generalized beyond Amazon: a recurring-charge auditor that finds forgotten, unused, or overpriced subscriptions across any service (Netflix,…
Take a product from a raw idea to a real, running, launched project — for people who are NOT technical and may not know what an MVP, a stack, or a deployment is.
> Use this skill whenever asked about Sweden cryptocurrency or digital asset taxation. Trigger on phrases like \"crypto tax Sweden\", \"Bitcoin Sweden\", \"kryptovaluta skatt\",…
> Use this skill whenever asked about Switzerland cryptocurrency or digital asset taxation. Trigger on phrases like \"crypto tax Switzerland\", \"Bitcoin Switzerland\",…
Generate synthetic tabular datasets from YAML schemas. Use this skill when the user wants to create sample data, mock data, test data, synthetic datasets, or demo data for any…
Expert in Linux and Windows systems infrastructure for administration, monitoring, security, and automation.
Tool discovery and shell one-liner reference for sysadmin, DevOps, and security tasks. AUTO-CONSULT this skill when the user is: troubleshooting network issues, debugging…
Use this skill when working with Proofpoint Targeted Attack Protection (TAP) - retrieving threat events, click tracking, message delivery and blocking data, SIEM integration…