The library
Everything we index — ranked by what works, never by stars.
forSalesMarketingHRFinanceLegalOpsProductEngineeringDataProductivitySupportsetup≤ plug & play≤ + a key≤ multi-tool
● works · ● untested / no effect · ● hurts — every rank is measured against a no-skill baseline
untested★381→untested★2,052→untested★381→untested★2,052→untested★819→untested★3→untested★2,052→untested★381→untested★2,052→untested★426→untested★2,052→untested★394→untested★1,994→untested★381→untested★0→untested★1,911→untested★381→untested★381→untested★1,791→untested★2,333→untested★1,791→untested★381→untested★1,791→untested★381→untested★381→untested★1,791→untested★381→untested★0→untested★1,791→untested★819→untested★0→untested★1,791→untested★381→untested★1,791→untested★381→untested★2→untested★1,791→untested★1,791→untested★381→untested★0→untested★1,791→untested★819→untested★1→untested★1,791→untested★1,791→untested★381→untested★0→untested★1,791→untested★2→untested★1,791→
Apply shadcn/ui component stylingskillEngineeringProductL2
apply-shadcn · UI development when shadcn library components reduce custom CSS and maintain consistency.
Check technical SEO complianceskillMarketingL2
technical-seo-checker · Technical SEO when infrastructure audits (crawl/indexing/speed) uncover blocked opportunities.
Configure CI/CD GitHub Actions workflowsskillEngineeringL3
testing-ci · CI setup when automated testing + deployment gates reduce manual integration friction.
Benchmark competitor strategiesskillMarketingProductL2
competitor-analysis · Competitive analysis when gap analysis vs top competitors informs content/keyword prioritization.
Audit nonprofit mergers and governanceskillLegalL2
fusion-vereine · German association mergers need Vereinsrecht-specific compliance mapping.
Generate NestJS DTOs with validation decoratorsskillEngineeringL1
dto-generator · NestJS projects scaffold DTOs faster with auto-discovery than manual scaffolding.
Map competitor content gaps and missing topicsskillMarketingL1
content-gap-analysis · Editorial planning beats brainstorming when you compare against a specific competitor set.
Animate interfaces using Disney principles and GSAPskillProductL2
gsap-greensock · Web animations achieve principle polish faster with GSAP than pure CSS for tweens.
Discover high-value keywords and topic clustersskillMarketingL2
keyword-research · SEO planning systematizes keyword discovery better than intuition-driven topic selection.
Set up and manage Arena development containersskillEngineeringL3
dev-container · IsaacLab development runs faster with one shared image across parallel project clones.
Analyze search results layout and ranking factorsskillMarketingL2
serp-analysis · Ranking strategy beats guessing when you analyze live SERP composition and top-10 patterns.
Apply Next.js best practices to projectsskillEngineeringL1
next-best-practices · Next.js refactors avoid pitfalls when you follow file conventions and RSC boundaries.
Debug and optimize Terraform infrastructure codeskillEngineeringL3
terraform-skill · IaC refactors are safer when you diagnose risk categories before applying changes.
Consult ChatGPT for quick agent decisionsskillL2
consult-chatgpt · Multi-agent debugging beats solo guessing when you cache questions and budget calls.
Run metric-driven optimization experimentsskillDataL3
ce-optimize · Tuning converges faster with hard gates and parallel experiments than one-shot tweaks.
Fix tool-calling agent schema and behaviorskillEngineeringL1
tool-calling-tutor · Tool-calling agents work faster when you debug schema, invocation, and loop patterns.
Debug complex systems with multi-step reasoningskillEngineeringL1
sequential-think · Complex debugging beats quick answers when you systematize multi-layer reasoning.
Design products that work for everyoneskillProductL1
universal-design · Inclusive design reaches broader audiences than retrofitting accessibility later.
Red-team Android apps end-to-endskillEngineeringL4
apk-redteam-pipeline · Mobile security research runs faster with automated APK acquisition and decompilation.
Detect arbitrage opportunities across exchangesskillFinanceL3
finding-arbitrage-opportunities · Crypto arbitrage beats manual scanning when you monitor CEX/DEX spread in real-time.
Hunt vulnerabilities with complete bug bounty workflowskillEngineeringL3
bb-local-toolkit · Bug bounty hunting converges faster with systematic recon, learning, and triage.
Run static analysis scans with SemgrepskillEngineeringL2
semantic-grep · Security scanning is faster and more reliable when you use semantic rules vs regex.
Orchestrate bug bounty hunting methodologyskillEngineeringL1
bb-methodology · Bug bounty sessions gain focus when you apply systematic 5-phase methodology.
Track trends in session metrics and progressskillProductivityL2
session-trends · Progress tracking improves with aggregated deltas vs single-point observations.
Sharpen value propositions into powerful statementsskillSalesL1
value-prop-sharpener · Product positioning when weak generic messaging needs multi-dimensional resonance.
Report bugs to Bugcrowd with severity strategyskillEngineeringL1
bugcrowd-reporting · Bug bounty submissions when VRT defaults misalign with actual impact severity.
Create engaging LinkedIn posts for authorityskillMarketingL1
linkedin-post · Professional content distribution when personal voice, audience targeting, and engagement matter.
Analyze document library health and maintenanceskillOpsL1
content-analyst · Library governance when actual document state analysis informs feature prioritization.
Exploit cloud IAM misconfigurations across providersskillEngineeringL4
cloud-iam-deep · Red-team privilege analysis when a cloud credential surfaces and escalation vectors matter.
Evaluate street infrastructure drainage rightsskillLegalL1
strassenentwaesserung · German legal practice when street-drainage rights/obligations require statutory analysis.
Refine OpenSpec proposals for completenessskillOpsL1
linear-iterate-on-plan · Technical planning when proposal quality gates improve before approval.
Audit enterprise VPN attack surfaceskillLegalL1
enterprise-vpn-attack · Perimeter testing when SSL VPN appliances are initial-access points.
Predict metagenome function from 16S dataskillEngineeringL2
bio-microbiome-functional-prediction · Metagenomics when shotgun sequencing is unavailable and KEGG/MetaCyc function prediction suffices.
Redact evidence for bug bounty submissionsskillLegalL1
evidence-hygiene · Bug-bounty submissions when cookie leakage and unauthorized PII exposure risks matter.
Automate GitHub issue triage and labelingskillOpsL2
ai-assisted-operations · GitHub issue triage at scale when AI summarization and tagging reduce manual work.
Optimize MAUI app performance for iOSskillEngineeringL3
dotnet-maui-aot · Mobile performance when app size and startup time reductions (up to 50%) justify AOT setup.
Hunt API security misconfigurationsskillLegalL1
hunt-api-misconfig · API security testing when parameter-binding and object-serialization flaws enable escalation.
Hunt ASP.NET-specific vulnerabilitiesskillLegalL1
hunt-aspnet · Legacy ASP.NET pentesting when ViewState, machineKey, and trace endpoint disclosure matter.
Assemble deep research handoff bundlesskillOpsL3
research-handoff-oracle · Team collaboration when research handoff to another LLM agent preserves context.
Navigate Nx CLI workspace projectsskillEngineeringL2
nx-cli · Monorepo development when task discovery and affected-scope analysis speed up iteration.
Hunt account takeover vulnerabilitiesskillLegalL1
hunt-ato · Authentication testing when multiple ATO paths (password-reset, email-change, JWT, MFA-bypass) require systematic coverage.
Map regulatory compliance frameworkskillLegalL1
eu-ebene-und-better-regulation · German legal practice when proposed rules require EU compliance justification.
Create product feature specificationsskillProductL1
feature · Test-driven development when executable specifications guide implementation.
Hunt authentication bypass vulnerabilitiesskillLegalL1
hunt-auth-bypass · SSO security testing when SAML signature stripping and parser-differential attacks apply.
Hunt brute force and rate limiting gapsskillLegalL1
hunt-brute-force · Use for hunt missing/weak rate limiting — login brute force, otp/2fa brute force (10^6 keyspace), password-reset-token brute, credential stuffing, username/email enumeration via error-string / status-code / timing differences, weak password policy, missing captcha, ip-based rate-limit bypass via x-forwarded-for and friends, redos. distinguishes hard lockout vs soft ip-throttle vs captcha-injection vs silent shadow-throttling (avoids false-negative 'no rate limit' conclusions). medium to critical depending on what the brute reaches (otp→ato = critical).
Adapt planning depth to PRD complexityskillProductL1
pm-organization-scale-adaptive · Use for adjust planning depth and agent behavior based on prd complexity level
Generate code from UI specificationsskillEngineeringL2
codegen · Use for code generation utilities for json-render. use when generating code from ui specs, building custom code exporters, traversing specs, or serializing props for @json-render/codegen.
Hunt business logic vulnerabilitiesskillLegalL1
hunt-business-logic · Use for hunting skill for business logic vulnerabilities. built from 12 public bug bounty reports. covers coupon-race-stacking (instacart, stripe, reverb), negative-quantity-in-cart price tampering (upserve, eternal/zomato), decimal/fraction price-field overflow (shipt), client-side checkout amount trust on paypal redirect (wordpress.org), price-per-unit mass-assignment (krisp), and archived-price swap / cart-toctou (stripe). use when hunting business logic — heavy emphasis on financial-impact-demonstrated cases.
Add test infrastructure to .NET projectsskillEngineeringL2
dotnet-add-testing · Use for >-
Hunt cache poisoning vulnerabilitiesskillLegalL1
hunt-cache-poison · Use for hunting skill for cache poison vulnerabilities. built from 10 public bug bounty reports including x-forwarded-host poisoning, x-http-method-override / gcs cache, reflected→stored xss via cache, classic omer-gil web cache deception, cloudflare cache deception armor bypass, session-token cache deception, akamai hop-by-hop smuggling → server-side edge poisoning, and kettle's 2024 path-normalization wcd against cloudflare/fastly/gcp. use when hunting cache poisoning, web cache deception, cdn-fronted apps.