The library
Everything we index — ranked by what works, never by stars.
forSalesMarketingHRFinanceLegalOpsProductEngineeringDataProductivitySupportsetup≤ plug & play≤ + a key≤ multi-tool
WORKS 48★381WORKS 48★819WORKS 48★819WORKS 48★819WORKS 48★819WORKS 58★1,318WORKS 48★819WORKS 48★3,035WORKS 48★230WORKS 48★230WORKS 48★230WORKS 48★3,035WORKS 48★381WORKS 48★3,035WORKS 48★1WORKS 48★1WORKS 48★819WORKS 48★819WORKS 48★3,035WORKS 48★9WORKS 48★3,035WORKS 48★3,035WORKS 48★3WORKS 48★819WORKS 48★3,035WORKS 48★819WORKS 48★102WORKS 48★2,144WORKS 48★2,094WORKS 45★0WORKS 48★819WORKS 48★819WORKS 48★819WORKS 48★1,791WORKS 48★1,791WORKS 48★1,791WORKS 48★1,791WORKS 48★1,791WORKS 48★819WORKS 48★1,791WORKS 48★1,791WORKS 48★1,791WORKS 48★1,791WORKS 48★1,791WORKS 48★1,791WORKS 48★819WORKS 48★819WORKS 48★819WORKS 48★819WORKS 48★1,791
Organize personnel documentsskillHRLegalL1
aktenstruktur-und-dokumentenintake · When organizing German legal personnel files and identifying missing documentation in administrative disputes.
Orchestrate GDPR-compliant mass notification wavesskillLegalOpsL3
massenbenachrichtigung · Coordinating large-scale user communication
Assess coercion risk in legal noticesskillLegalL1
druckmittel-falsche · When assessing whether a threat of criminal charges constitutes unlawful coercion under German law.
Audit legal risks before submissionskillLegalL1
bietet-fehlerkatalog · Preventing practice-damaging errors in client-facing legal responses before sending.
Navigate telecom co-use rightsskillLegalL2
mitnutzung-gebaeude-netze · Scoping shared telecom infrastructure access without double-digging.
Review contracts with risk layersskillLegalOpsL2
contract-review · Non-invasive contract review with structured risk encoding (reviewer name = severity) for stakeholders.
Audit AI legal work for complianceskillLegalL1
anwaltliche-ki-nutzung-quellencheck-brao · Assessing BRAO rules for lawyers using AI tools.
Automate DocuSign document signingskillLegalOpsL2
docusign-automation · Automate document preparation, signing, and tracking workflows without manual DocuSign UI.
Detect counterfeit Shopify sellersskillLegalOpsL1
brand-protection-shopify · DTC brand holders who need automated monitoring of Shopify stores and social ads without hiring legal counsel.
Detect TikTok Shop counterfeits and fraudskillLegalOpsL1
brand-protection-tiktok · Fast-moving DTC brands needing continuous TikTok surveillance for unauthorized resellers and counterfeit ads.
Detect Walmart unauthorized sellers and MAP violationsskillLegalOpsL1
brand-protection-walmart · Brands selling via Walmart marketplace who need continuous unauthorized-seller and counterfeit detection.
Detect deepfakes and verify mediaskillLegalL2
resemble-detect · Batch media authenticity verification when real-world consequences demand AI detection scores.
Legal education and bar complianceskillLegalL1
fortbildung · Notary regulatory defense where continuing ed credits + practice alignment must be proven bulletproof.
Verify stablecoin MiCA complianceskillLegalFinanceL1
feedoracle-compliance · Audit workflows requiring verifiable compliance evidence
Add legal citations to Word documentsskillLegalL2
legal-citation-automator · Batch footnote repairs in Word documents when citation text is already verified and DOCX compatibility matters.
Check and format legal footnotesskillLegalL1
legal-citation-comprehensive · Complex legal citation diagnosis across multiple source types when the handbook rule index is available locally.
Analyze German administrative law proceduresskillLegalL1
eilrechtsschutz-paragraf-80-vwgo · Advising on German administrative law emergency relief when norm anchors, case law, and evidence gaps are explicitly tracked.
German legal compliance checks on manager/board compensation with AO § 6a and EStG § 8(3) focus, providing legal-memo output ready for Rechtsabteilung.skillLegalL2
rechtsabteilung-vga-geschaeftsfuehrer · German legal compliance checks on manager/board compensation with AO § 6a and EStG § 8(3) focus, providing legal-memo output ready for Rechtsabteilung.
Verify threat mitigations for phaseskillLegalL2
gsd:secure-phase · Retroactively auditing threat mitigations before shipping a production phase
Manage SOC 2 compliance frameworkskillLegalOpsL3
soc2 · When initializing SOC 2 compliance framework and understanding your current control status.
Enforce mortgage regulatory complianceskillLegalFinanceL2
mortgage-compliance · Protecting lenders from regulatory violations by rejecting non-compliant interactions before they reach borrowers
Defend against mortgage AI attacksskillEngineeringLegalL3
security-guardrails · Defending lending agents from adversarial manipulation while preserving legitimate borrower interactions
Prepare targeted security review packageskillLegalEngineeringL2
red-team-bundler · Preparing code for adversarial testing without exposing sensitive data.
Coordinate foreclosure administration outputsskillLegalL1
output-waehlen · German real-estate insolvency: ensuring ZVG court filings address the correct party with right legal form and tight deadlines.
Understand equity and term sheetsskillFinanceLegalL1
explain-equity-terms · Activate for ANY equity, legal, or term sheet question related to startup investing or fundraising. Triggers include: "what is a SAFE", "explain this term sheet", "what does pro-rata mean", "what is liquidation preference", "explain anti-dilution", "ISO vs NSO", "what is a 83(b) election", "what is carried interest", "explain drag-along", "what is a valuation cap", "what does MFN mean", "explain convertible note vs SAFE", "what is a down round", "explain vesting cliff", "what does fully diluted mean", "term sheet question", "equity question", "what does this clause mean". Also triggers when a user pastes legal text from a term sheet, SAFE, or subscription agreement and asks what it means. Works on claude.ai and Claude Code.
Identify missing documents for incorporationskillLegalOpsL1
unterlagen-luecken · Lücken- und Beschaffungsliste für Gesellschaftsgründung: trennt fehlende Tatsachen von fehlenden Belegen (Gesellschaftsvertrag, Notarurkunde, Liste Gesellschafter), nennt pro Lücke Beweisthema, Beschaffungsweg (Handelsregister AG), Frist und Ersatznachweis.
Audit Solidity contracts for security risksskillEngineeringLegalL2
scv-scan · Unknown (see artifact 4931)
Red team Active Directory networksskillLegalL3
offensive-active-directory · When you need to map Active Directory attack paths and identify privilege escalation vectors in an authorized pentest.
Draft Real Estate and Legal DocsskillLegalL2
notaire · handling complex property and inheritance transactions
Audit systems and complianceskillLegalFinanceL2
audit-skill · reviewing pull requests for production readiness
Audit ESG claims in venture dealsskillLegalFinanceL2
esg-impact-venture · Impact investing when ESG screening accelerates deal qualification over manual review.
Audit nonprofit mergers and governanceskillLegalL2
fusion-vereine · German association mergers need Vereinsrecht-specific compliance mapping.
Evaluate street infrastructure drainage rightsskillLegalL1
strassenentwaesserung · German legal practice when street-drainage rights/obligations require statutory analysis.
Audit enterprise VPN attack surfaceskillLegalL1
enterprise-vpn-attack · Perimeter testing when SSL VPN appliances are initial-access points.
Redact evidence for bug bounty submissionsskillLegalL1
evidence-hygiene · Bug-bounty submissions when cookie leakage and unauthorized PII exposure risks matter.
Hunt API security misconfigurationsskillLegalL1
hunt-api-misconfig · API security testing when parameter-binding and object-serialization flaws enable escalation.
Hunt ASP.NET-specific vulnerabilitiesskillLegalL1
hunt-aspnet · Legacy ASP.NET pentesting when ViewState, machineKey, and trace endpoint disclosure matter.
Hunt account takeover vulnerabilitiesskillLegalL1
hunt-ato · Authentication testing when multiple ATO paths (password-reset, email-change, JWT, MFA-bypass) require systematic coverage.
Map regulatory compliance frameworkskillLegalL1
eu-ebene-und-better-regulation · German legal practice when proposed rules require EU compliance justification.
Hunt authentication bypass vulnerabilitiesskillLegalL1
hunt-auth-bypass · SSO security testing when SAML signature stripping and parser-differential attacks apply.
Hunt brute force and rate limiting gapsskillLegalL1
hunt-brute-force · Use for hunt missing/weak rate limiting — login brute force, otp/2fa brute force (10^6 keyspace), password-reset-token brute, credential stuffing, username/email enumeration via error-string / status-code / timing differences, weak password policy, missing captcha, ip-based rate-limit bypass via x-forwarded-for and friends, redos. distinguishes hard lockout vs soft ip-throttle vs captcha-injection vs silent shadow-throttling (avoids false-negative 'no rate limit' conclusions). medium to critical depending on what the brute reaches (otp→ato = critical).
Hunt business logic vulnerabilitiesskillLegalL1
hunt-business-logic · Use for hunting skill for business logic vulnerabilities. built from 12 public bug bounty reports. covers coupon-race-stacking (instacart, stripe, reverb), negative-quantity-in-cart price tampering (upserve, eternal/zomato), decimal/fraction price-field overflow (shipt), client-side checkout amount trust on paypal redirect (wordpress.org), price-per-unit mass-assignment (krisp), and archived-price swap / cart-toctou (stripe). use when hunting business logic — heavy emphasis on financial-impact-demonstrated cases.
Hunt cache poisoning vulnerabilitiesskillLegalL1
hunt-cache-poison · Use for hunting skill for cache poison vulnerabilities. built from 10 public bug bounty reports including x-forwarded-host poisoning, x-http-method-override / gcs cache, reflected→stored xss via cache, classic omer-gil web cache deception, cloudflare cache deception armor bypass, session-token cache deception, akamai hop-by-hop smuggling → server-side edge poisoning, and kettle's 2024 path-normalization wcd against cloudflare/fastly/gcp. use when hunting cache poisoning, web cache deception, cdn-fronted apps.
Hunt cloud infrastructure misconfigurationsskillLegalL1
hunt-cloud-misconfig · Use for hunt cloud / infrastructure misconfigurations. aws: public s3 buckets (s3:getobject anonymous), permissive bucket policies (putobjectacl public-write), exposed cloudfront origin, public lambda function url, public rds snapshot, iam credentials in js bundles, aws metadata accessible via ssrf. gcp: public gcs buckets, exposed cloud run services, leaked service account json. azure: public blob containers, exposed function app. (kubernetes/docker exposure is owned by hunt-k8s; ci/cd pipeline attacks by hunt-cicd; post-credential iam escalation by cloud-iam-deep.) detection: targeted dorking, certificate transparency, js bundle secret extraction, port scan for known service ports. validate: actual data read / write / rce. use when hunting cloud-native storage and compute misconfig (s3/gcs/blob, imds-via-ssrf, serverless, public managed services).
Hunt CORS misconfiguration exploitsskillLegalL1
hunt-cors · Use for hunt cors misconfiguration — origin-reflection with credentials, null-origin trust, subdomain-regex bypass (unanchored vs unescaped-dot vs prefix-only), pre-flight (options) gating bypass, postmessage origin checks. high only when an attacker-controlled origin can perform a credentialed cross-origin read of sensitive data and you have proven it in a browser. use when testing api endpoints, spas, or any app emitting access-control-* headers.
Prüfe Anlagenverweis und TatsachenvortragskillLegalL1
baut-beweislast-benennt-bereits-excel · Use for prüft, ob die anlage eine konkrete darlegung trägt oder nur einen pauschalen anlagenverweis kaschiert; trennt tatsachenvortrag, beweisangebot und bloße hintergrundunterlage im anlagen zu schriftsätzen. liefert priorisierten output mit norm-pinpoints, risikoampel und nächstem arbeitsschritt.
PE teams needing audit-ready closing documentation with live German legal norm verification instead of templated checklists.skillLegalL1
rechtsabteilung-pe-closing-continuation-fund · PE teams needing audit-ready closing documentation with live German legal norm verification instead of templated checklists.
Prüfe Verbraucherschutz BeweiseskillLegalL1
smart-device-agb-redlinen-beschwerde · German consumer advocates needing to verify statutory deadlines and evidence requirements in smart-device complaints.
Prüfen Markenrecht Benutzungsschonfrist FashionskillLegalL2
benutzungsschonfrist-und-rechtserhaltende-benutzung · Preparing evidence bundles to defend luxury/fashion trademarks against non-use revocation.
Detect SAML and SSO attacksskillLegalOpsL1
hunt-saml · Discovering saml vulnerabilities when generic scanners miss domain-specific chains.