The library
Everything we index — ranked by what works, never by stars.
forSalesMarketingHRFinanceLegalOpsProductEngineeringDataProductivitySupportsetup≤ plug & play≤ + a key≤ multi-tool
● works · ● untested / no effect · ● hurts — every rank is measured against a no-skill baseline
untested★381→untested★1,791→untested★1,791→untested★82→untested★1,791→untested★46→untested★0→untested★1,791→untested★0→untested★1,791→untested★1,791→untested★1→untested★143→untested★1→untested★1,791→untested★1,791→untested★135→untested★1,791→untested★61→untested★1→untested★1,791→untested★1→untested★1,791→untested★27→untested★1,791→untested★1,791→untested★381→untested★1,791→untested★381→untested★1,791→untested★0→untested★1,791→untested★30→untested★1→untested★28→untested★0→untested★2→untested★1,791→untested★45→untested★1→untested★1,791→untested★10→untested★0→untested★1,791→untested★1,791→untested★147→untested★0→untested★1,758→untested★1,758→untested★17→
Build RAG pipeline for knowledge extractionskillEngineeringDataL2
llm-pipeline · Extracting structured knowledge from unstructured messaging with high-signal batching.
Detect SQL injection vulnerabilitiesskillLegalOpsL1
hunt-sqli · Discovering sqli vulnerabilities when generic scanners miss domain-specific chains.
Identify SSRF attack vectorsskillLegalOpsL1
hunt-ssrf · Discovering ssrf vulnerabilities when generic scanners miss domain-specific chains.
Upgrade dependencies safelyskillEngineeringOpsL1
upgrade-deps · Implementing upgrade deps workflows that require automation.
Hunt server-side template injectionskillLegalOpsL1
hunt-ssti · Discovering ssti vulnerabilities when generic scanners miss domain-specific chains.
Build industrial control protocolsskillEngineeringOpsL2
industrial · Implementing industrial workflows that require automation.
Sync delta specs to main specsskillProductEngineeringL1
openspec-sync-specs · Implementing openspec sync specs workflows that require automation.
Detect subdomain takeover risksskillLegalOpsL1
hunt-subdomain · Discovering subdomain vulnerabilities when generic scanners miss domain-specific chains.
Build MCP servers with TypeScriptskillEngineeringL3
mcp-server-patterns · Implementing mcp server patterns workflows that require automation.
Audit TLS and DNS misconfigurationsskillLegalOpsL1
hunt-tls-network · Discovering tls network vulnerabilities when generic scanners miss domain-specific chains.
Find WebSocket security gapsskillLegalOpsL1
hunt-websocket · Discovering websocket vulnerabilities when generic scanners miss domain-specific chains.
Isolate feature work with git worktreesskillEngineeringOpsL1
using-git-worktrees · When feature work requires complete isolation from current workspace without branch switching.
Classify structural genome variantsskillDataL2
genomics-sv-detection · When you have SV VCF output from Manta/Delly/Sniffles and need aggregated counts and size bins.
Search Unity built-in assetsskillProductEngineeringL1
assets-find-built-in · When searching Unity built-in resources by name without needing GUIDs or exact paths.
Hunt XML external entity attacksskillLegalOpsL1
hunt-xxe · When hunting XXE on XML-heavy endpoints, file parsers, or SAML flows where file-read or SSRF payoff is high.
Red-team Microsoft 365 EntraskillLegalOpsL2
m365-entra-attack · When testing M365 credential attacks with locked-down attempt budgets and needing AADSTS code interpretation.
Use assistant-ui library componentsskillProductEngineeringL2
assistant-ui · When building AI chat interfaces with composable primitives and streaming backends, versus monolithic UI libraries.
Detect meme coin security risksskillFinanceL2
meme-coin-audit · When doing pre-investment due diligence on meme coins or auditing token contracts for rug-pull mechanisms.
Set up Effect services architectureskillEngineeringL2
effect-services · When defining services in Effect v4 with compile-time type safety and explicit dependency wiring.
Build production Discord botsskillEngineeringL2
discord-bot-architect · When building production Discord bots with modern slash commands rather than legacy prefix-based bots.
Detect active security threatsskillOpsL3
mid-engagement-ir-detection · When running active testing against monitored targets and needing to separate your activity from external attacker activity.
Search the web with AIskillL2
tavily-search · When needing semantic search over current web with ranking, versus full-text grep search.
Map attack surface externallyskillOpsL3
offensive-osint · When conducting reconnaissance from attacker perspective with only public information.
Automate GitHub issue routingskillEngineeringL2
github-triage · When triaging large GitHub backlogs systematically rather than manual browser review.
Test Okta authentication defensesskillOpsL3
okta-attack · When testing Okta for credential attacks or session manipulation during authorized assessments.
Execute comprehensive security reconskillOpsL3
osint-methodology · When reconnaissance needs repeatable structure and documentation versus ad-hoc browsing.
Convert agents to Skills formatskillEngineeringL2
migrate-to-skills · When converting one-off scripts into reusable components for team collaboration.
Master red-team operator disciplineskillOpsL1
redteam-mindset · When planning red-team engagements with structured threat modeling versus vulnerability checklist testing.
Generate complete software specskillEngineeringL2
project-specification-writer · When clarifying project scope and objectives before development begins.
Format red-team findings reportskillOpsL1
redteam-report-template · When documenting red-team findings with proper impact quantification and evidence chain.
Analyze frontend task risksskillEngineeringL2
frontend-task-analysis · When decomposing frontend work into concrete, parallelizable subtasks with clear acceptance criteria.
Write bug bounty reports fastskillOpsL1
report-writing · Ensures reports pass triage by enforcing impact-first writing and exact reproduction over theoretical claims.
Update project dependenciesskillEngineeringL2
update-deps · Keeps dependencies current while catching regressions through automated post-update checks.
Create or update C# scriptsskillEngineeringL2
script-update-or-create · Programmatically generates and verifies Unity C# scripts without manual IDE interaction.
Send and read WhatsApp messagesskillL2
WhatsApp Assistant · Monitors WhatsApp archives without opening the app, extracting and actionifying conversation data.
Build Databricks AI agentsskillDataL3
databricks-agent-bricks · Reduces AI app deployment time by assembling pre-built conversational components without code.
Optimize cloud infrastructure costsskillFinanceL2
cloud-cost-models · Reduces cloud spend 30-70% through instance selection, savings plans, and per-environment scheduling formulas.
Validate security findingsskillOpsL1
triage-validation · Filters ineligible findings early (out-of-scope, known, theoretical) saving submission time and maintaining validity ratio.
Review QA test coverage gapsskillEngineeringL2
tc-review · Identifies test coverage gaps by comparing written cases to learned codebase, reducing manual test discovery.
Manage Windows filesskillProductivityL2
windows-file-management · Hybrid API+GUI approach combines speed with interactive shell features for complex file migrations.
Exploit VMware vSphere vulnerabilitiesskillOpsL3
vmware-vcenter-attack · Rapidly identifies critical CVE chains (file upload → RCE) in exposed VMware infrastructure for impact assessment.
Access Ableton Live control APIskillL1
ableton-lom · Enables real-time hardware parameter control through Python event listeners without boilerplate.
Archive completed OpenSpec changesskillOpsL1
openspec-archive-change · Automates spec change documentation to ensure migration guides are accurate and complete.
Enumerate web infrastructure and monitor changesskillOpsL3
web2-recon · Maps external attack surface comprehensively faster than manual DNS/port scanning.
Audit smart contracts for security bugsskillOpsL3
web3-audit · Identifies on-chain vulnerabilities (reentrancy, overflow, access control) before mainnet deployment.
Analyze protein sequences and structureskillEngineeringL3
full_protein_analysis · Rapidly characterizes unknown proteins by identifying homologs, domains, and predicted 3D structure.
Verify geographic and location dataskillOpsDataL2
geoint_web_search · Enables remote site assessment and change detection over time without travel, useful for infrastructure planning.
Design PostGIS spatial database tablesskillEngineeringL1
design-postgis-tables · Enables sub-second spatial queries on millions of geometries through proper index design and CRS handling.
Design PostgreSQL table schemasskillEngineeringL1
design-postgres-tables · Prevents common schema mistakes (N+1 queries, missing constraints) by enforcing normalization upfront.
Generate and edit images automaticallyskillMarketingL2
generate-images · Rapidly prototypes visual assets without hiring artists, useful for mockups, thumbnails, and design exploration.