The library
Everything we index — ranked by what works, never by stars.
forSalesMarketingHRFinanceLegalOpsProductEngineeringDataProductivitySupportsetup≤ plug & play≤ + a key≤ multi-tool
● works · ● untested / no effect · ● hurts — every rank is measured against a no-skill baseline
untested★1→untested★1→untested★4→untested★0→untested★4→untested★377→untested★10→untested★324→untested★2,052→untested★2,052→untested★1→untested★2,052→untested★2,052→untested★1,049→untested★381→untested★2,052→untested★2,052→untested★2,052→untested★3→untested★2,052→untested★394→untested★1,911→untested★381→untested★381→untested★1,791→untested★381→untested★1,791→untested★381→untested★0→untested★819→untested★0→untested★1,791→untested★1,791→untested★1,791→untested★1,791→untested★1,791→untested★819→untested★1→untested★1,791→untested★1,791→untested★381→untested★1,791→untested★1,791→untested★381→untested★1,791→untested★0→untested★1,791→untested★381→untested★1,791→untested★381→
Structure Research ProposalskillProductL1
research-proposal · scoping novel research projects before implementation
Profile system resources and design experimentsskillEngineeringDataL1
system-info · planning compute resource allocation for ML training
Mock systems correctly in testsskillEngineeringL1
gotchas-with-skill · avoiding costly mistakes in framework usage
Generate modularity review documentsskillEngineeringL1
document · When producing final audit documents with balanced coupling analysis.
Configure VoiceMode permissionsskillOpsL1
2603-permissions_2c281257 · When you need to configure tool access without constant prompts.
Verify completed workskillEngineeringL1
verify · Before committing work to ensure requirements are actually met.
Document solved problems for team knowledgeskillOpsL1
compound · When capturing solutions to reduce repeated debugging and knowledge loss.
Get help with agent harnessskillL1
harness-help · When discovering available commands and orchestration capabilities.
Optimize meta tags and CTRskillMarketingL1
meta-tags-optimizer · Pages with low CTR needing title/description optimization for search.
Generate JSON-LD schema markupskillMarketingL1
schema-markup-generator · E-commerce/content sites needing rich snippets for search visibility.
Write human-sounding copyskillMarketingL1
anti-ai-slop-writing · Content needing AI assistance while maintaining human voice and nuance.
Build knowledge graph for entity discoveryskillMarketingDataL1
entity-optimizer · Knowledge graph optimization requiring structured entity markup refinement.
Manage multi-session project memoryskillOpsProductL1
memory-management · Systems requiring cache efficiency and memory leak prevention under load.
Review papers for academic qualityskillL1
peer-review · Academic or technical publication pipelines requiring rigorous peer feedback.
Guide sp.h standard library usageskillEngineeringL1
sp · C projects when a single-header stdlib replacement eliminates malloc/strlen/strcmp pitfalls.
Analyze backlinks and link gapsskillMarketingL1
backlink-analyzer · Link audits when gap analysis vs competitors and disavow recommendations guide strategy.
Optimize internal site architectureskillMarketingL1
internal-linking-optimizer · Internal linking when anchor-text optimization and pagerank flow guidance beat manual audits.
Audit on-page SEO and keywordsskillMarketingL1
on-page-seo-auditor · On-page SEO when element-by-element audit with competitor comparison guides optimization.
Generate NestJS DTOs with validation decoratorsskillEngineeringL1
dto-generator · NestJS projects scaffold DTOs faster with auto-discovery than manual scaffolding.
Map competitor content gaps and missing topicsskillMarketingL1
content-gap-analysis · Editorial planning beats brainstorming when you compare against a specific competitor set.
Apply Next.js best practices to projectsskillEngineeringL1
next-best-practices · Next.js refactors avoid pitfalls when you follow file conventions and RSC boundaries.
Fix tool-calling agent schema and behaviorskillEngineeringL1
tool-calling-tutor · Tool-calling agents work faster when you debug schema, invocation, and loop patterns.
Debug complex systems with multi-step reasoningskillEngineeringL1
sequential-think · Complex debugging beats quick answers when you systematize multi-layer reasoning.
Design products that work for everyoneskillProductL1
universal-design · Inclusive design reaches broader audiences than retrofitting accessibility later.
Orchestrate bug bounty hunting methodologyskillEngineeringL1
bb-methodology · Bug bounty sessions gain focus when you apply systematic 5-phase methodology.
Sharpen value propositions into powerful statementsskillSalesL1
value-prop-sharpener · Product positioning when weak generic messaging needs multi-dimensional resonance.
Report bugs to Bugcrowd with severity strategyskillEngineeringL1
bugcrowd-reporting · Bug bounty submissions when VRT defaults misalign with actual impact severity.
Create engaging LinkedIn posts for authorityskillMarketingL1
linkedin-post · Professional content distribution when personal voice, audience targeting, and engagement matter.
Analyze document library health and maintenanceskillOpsL1
content-analyst · Library governance when actual document state analysis informs feature prioritization.
Evaluate street infrastructure drainage rightsskillLegalL1
strassenentwaesserung · German legal practice when street-drainage rights/obligations require statutory analysis.
Refine OpenSpec proposals for completenessskillOpsL1
linear-iterate-on-plan · Technical planning when proposal quality gates improve before approval.
Audit enterprise VPN attack surfaceskillLegalL1
enterprise-vpn-attack · Perimeter testing when SSL VPN appliances are initial-access points.
Redact evidence for bug bounty submissionsskillLegalL1
evidence-hygiene · Bug-bounty submissions when cookie leakage and unauthorized PII exposure risks matter.
Hunt API security misconfigurationsskillLegalL1
hunt-api-misconfig · API security testing when parameter-binding and object-serialization flaws enable escalation.
Hunt ASP.NET-specific vulnerabilitiesskillLegalL1
hunt-aspnet · Legacy ASP.NET pentesting when ViewState, machineKey, and trace endpoint disclosure matter.
Hunt account takeover vulnerabilitiesskillLegalL1
hunt-ato · Authentication testing when multiple ATO paths (password-reset, email-change, JWT, MFA-bypass) require systematic coverage.
Map regulatory compliance frameworkskillLegalL1
eu-ebene-und-better-regulation · German legal practice when proposed rules require EU compliance justification.
Create product feature specificationsskillProductL1
feature · Test-driven development when executable specifications guide implementation.
Hunt authentication bypass vulnerabilitiesskillLegalL1
hunt-auth-bypass · SSO security testing when SAML signature stripping and parser-differential attacks apply.
Hunt brute force and rate limiting gapsskillLegalL1
hunt-brute-force · Use for hunt missing/weak rate limiting — login brute force, otp/2fa brute force (10^6 keyspace), password-reset-token brute, credential stuffing, username/email enumeration via error-string / status-code / timing differences, weak password policy, missing captcha, ip-based rate-limit bypass via x-forwarded-for and friends, redos. distinguishes hard lockout vs soft ip-throttle vs captcha-injection vs silent shadow-throttling (avoids false-negative 'no rate limit' conclusions). medium to critical depending on what the brute reaches (otp→ato = critical).
Adapt planning depth to PRD complexityskillProductL1
pm-organization-scale-adaptive · Use for adjust planning depth and agent behavior based on prd complexity level
Hunt business logic vulnerabilitiesskillLegalL1
hunt-business-logic · Use for hunting skill for business logic vulnerabilities. built from 12 public bug bounty reports. covers coupon-race-stacking (instacart, stripe, reverb), negative-quantity-in-cart price tampering (upserve, eternal/zomato), decimal/fraction price-field overflow (shipt), client-side checkout amount trust on paypal redirect (wordpress.org), price-per-unit mass-assignment (krisp), and archived-price swap / cart-toctou (stripe). use when hunting business logic — heavy emphasis on financial-impact-demonstrated cases.
Hunt cache poisoning vulnerabilitiesskillLegalL1
hunt-cache-poison · Use for hunting skill for cache poison vulnerabilities. built from 10 public bug bounty reports including x-forwarded-host poisoning, x-http-method-override / gcs cache, reflected→stored xss via cache, classic omer-gil web cache deception, cloudflare cache deception armor bypass, session-token cache deception, akamai hop-by-hop smuggling → server-side edge poisoning, and kettle's 2024 path-normalization wcd against cloudflare/fastly/gcp. use when hunting cache poisoning, web cache deception, cdn-fronted apps.
Maintain persistent memory across conversationsskillProductivityL1
memory-management · Use for persistent memory for claude across conversations. use when starting any task, before writing or editing code, before making decisions, when user mentions preferences or conventions, when user corrects your work, or when completing a task that overcame challenges. ensures claude never repeats mistakes and always applies learned patterns.
Hunt cloud infrastructure misconfigurationsskillLegalL1
hunt-cloud-misconfig · Use for hunt cloud / infrastructure misconfigurations. aws: public s3 buckets (s3:getobject anonymous), permissive bucket policies (putobjectacl public-write), exposed cloudfront origin, public lambda function url, public rds snapshot, iam credentials in js bundles, aws metadata accessible via ssrf. gcp: public gcs buckets, exposed cloud run services, leaked service account json. azure: public blob containers, exposed function app. (kubernetes/docker exposure is owned by hunt-k8s; ci/cd pipeline attacks by hunt-cicd; post-credential iam escalation by cloud-iam-deep.) detection: targeted dorking, certificate transparency, js bundle secret extraction, port scan for known service ports. validate: actual data read / write / rce. use when hunting cloud-native storage and compute misconfig (s3/gcs/blob, imds-via-ssrf, serverless, public managed services).
Choreograph animations with GSAP timelinesskillEngineeringL1
gsap-timeline · Use for official gsap skill for timelines — gsap.timeline(), position parameter, nesting, playback. use when sequencing animations, choreographing keyframes, or when the user asks about animation sequencing, timelines, or animation order (in gsap or when recommending a library that supports timelines).
Hunt CORS misconfiguration exploitsskillLegalL1
hunt-cors · Use for hunt cors misconfiguration — origin-reflection with credentials, null-origin trust, subdomain-regex bypass (unanchored vs unescaped-dot vs prefix-only), pre-flight (options) gating bypass, postmessage origin checks. high only when an attacker-controlled origin can perform a credentialed cross-origin read of sensitive data and you have proven it in a browser. use when testing api endpoints, spas, or any app emitting access-control-* headers.
Verify facts through multi-step checkingskillL1
cove · Use for apply chain-of-verification (cove) prompting to improve response accuracy through self-verification. use when complex questions require fact-checking, technical accuracy, or multi-step reasoning.
Find CSRF vulnerabilities in web appsskillEngineeringL1
hunt-csrf · Use for hunting skill for csrf vulnerabilities. built from 15 public bug bounty reports including modern variants — samesite=lax sibling-subdomain bypass (argo cd cve-2024-22424), graphql mutations-via-get (gitlab $3,370), framework-wide csrf middleware disabled (stripe dashboard $5,000), path-traversal csrf-token bypass (github enterprise cve-2022-23732 $10k), origin-omission bypass (tiktok $2,500), oauth-state null-byte (streamlabs), websocket csrf / cswsh (coda), default-samesite email-change → ato (yoyo games $400), social-account-link csrf (hackerone), json-csrf via text/plain on email-change (tiktok $500). use when hunting modern csrf — heavy emphasis on chain-to-ato patterns.
Run TUnit tests with PlaywrightskillEngineeringL1
tunit · Use for run tunit tests with playwright. use when user asks to run tests, execute tests, or check if tests pass.