Security
ClawSecCheck — OpenClaw Security Self-Audit
Free, local security self-audit for your own OpenClaw agent. Reads your OpenClaw config, bootstrap files, log files, agent session logs, and installed skills...
Security
Vmware Policy
Unified audit logging, policy enforcement, and input sanitization for the entire VMware MCP skill family. Use when querying audit logs, managing policy rules...
Testing
quality-playbook
Explore any codebase from scratch and generate six quality artifacts: a quality constitution (QUALITY.md), spec-traced functional tests, a code review protocol with regression test…
Design
ui-ergonomics
Use when auditing whether a view/screen is correctly built against usability & ergonomic dimensions. Checks a UI against 18 usability dimensions — prompting, grouping by location/f…
Security
solana-auditor
Audit and research Solana smart contracts for security vulnerabilities and exploits. Use this skill whenever the user asks to audit, review, analyze, or security-test any Solana pr…
Productivity
skill-reviewer
Skill 质量审查与规范脚手架。审查 Claude/Cursor Agent Skill 是否符合高质量规范(渐进式加载、description 关键词、工作流 checklist、确认节点、脚本封装、参数系统、references 组织、Pre-Delivery、CLI+Skill 模式、反 Slop),并按 P0–P3 分级输出报告;也能 --temp…
Productivity
grading-claude-agents-md
Grades and improves CLAUDE.md (Claude Code) and AGENTS.md (Codex/OpenCode) configuration files. Use when asked to grade, score, evaluate, audit, review, improve, fix, optimize, or …
Security
skill-security-reviewer
Security review and threat analysis for agent skills. Use when reviewing, auditing, or validating skills for security issues including prompt injection, code execution risks, data …
Security
ovhcloud-live-kms-key-destruction-guard
Gate and audit OVHcloud KMS key version destruction requests by enforcing five mandatory checks: confirmed key ID and KMS service URN, named approving identity, usage audit confirm…
Security
forter-agentic-readiness-audit
Audit a website against the Forter Agentic Readiness Guide. Loads the 25 weighted rubrics in `audit/`, probes the target site (and optional source code), scores each guideline Pass…
DevOps
ssh-command-screenshot
Run SSH commands in Windows Terminal and capture per-command screenshot evidence into a new folder. Use early whenever a task involves Linux/Unix system inspection, troubleshooting…
Security
hipaa-review
Performs a HIPAA Security Rule compliance review across all Administrative, Physical, and Technical Safeguards in 45 CFR Part 164, Subpart C. Auto-invoked for healthcare data secur…
DevOps
playbook-cli-audit
Audit all packmind-* skills for CLI compatibility issues: deprecated commands, invalid options, wrong file formats, missing flags, and version mismatches against the locally instal…
Design
design-review
Web / iOS / Android の UI を multi-axis でスコアリングし、フォント/余白/画像密度/モダン度の「ダサさ」シグナルを機械的に拾って md+html レポート化する design audit skill。general (一般フィードバック) と diff (目標デザインとの差分) の 2 モード × strict/norma…
Security
auditing-skills
Scans AI agent skill directories for dangerous bash patterns, prompt injection, supply chain risks, and SKILL.md structure violations. Use when reviewing, validating, or security-a…
Security
dependa-audit
Supply-chain audit of a Dependabot PR. For every dependency the PR bumps, diff the current vs target version (install hooks, new deps, publisher/provenance, network endpoints, code…
Security
defi-risk-analysis
Analyze a DeFi protocol's risk profile across smart contract, off-chain, and track-record dimensions. Use when the user wants a risk analysis of a DeFi project, to check protocol s…
Engineering
complete-codebase-review
Use when asked to review, audit, assess, or evaluate an entire codebase holistically — not a PR diff. Covers architecture, security, tech debt, test health, deps, docs, CI, standar…
Automation
goal-evidence-ledger
Maintains append-only evidence ledgers as sidecar files under `.flow/runs/<run-id>/evidence/`, storing structured metadata in `.evidence.yaml` and raw outputs in matching `.txt` fi…
Business
fz-personalkosten-und-stundennachweis
Defines eligible personnel costs for the research tax credit: gross wages plus employer contributions, 70-euro hourly flat rate for owner-managers, and 60 percent (70 percent for S…
Security
sap-audit-evidence-packaging
Packages SAP audit evidence for Segregation of Duties, change management, access, and financial controls. Defines evidence taxonomy, maps controls to artifacts, enforces chain-of-c…
Research
ontology-review
Audits ontologies, knowledge graphs, and schemas for structural integrity using a seven-axis review covering orthogonality, granularity, taxonomic hygiene, identity, relationship s…
Productivity
rz-quarterly-review
Triggers on first Sunday of January/April/July/October or explicit quarterly review commands. Runs an 80-100 minute process: pulls metrics, re-scores channels on a 5-criteria frame…
Documentation
ara-report-writer
Create, review, and refine standalone annual reports or audit syntheses styled after institutional oversight bodies. Use for drafting, restructuring, quality assurance, or guidance…
Business
auditar-mis-libros
Audits accounting records for uncategorized entries, reconciliation gaps, overdue accruals, cutoff candidates, draft journals, missing opening balances, and duplicate vendors. Rank…
Engineering
audit-deep
Composite skill — full project health check across testing, config, hooks, performance, security, MCP, and plugins. Runs audit skills in parallel and reconciles into one severity-r…
Productivity
skill-explorer
Manages the skill ecosystem: audits existing skills for duplicates or consolidation opportunities, researches web sources for new capabilities, and installs lightweight modular sub…
Testing
audit-accessibility
Automated WCAG 2.2 accessibility audit that crawls every page, runs axe-core checks, validates keyboard navigation, color contrast, ARIA labels, heading hierarchy, form labels, and…
DevOps
eks-operation-review
Audits live EKS clusters across ten operational domains—networking, autoscaling, observability, identity, add-ons, workloads, deployments, lifecycle, IaC, and processes—delivering …
Research
research-to-paper-write
End-to-end academic manuscript drafting and revision in Build-From-Materials or Rewrite modes across journals, conferences, reports, reviews, and competitions; plans per-unit ratio…
Data
amazon-catalog-auditor
Audit Amazon Category Listing Reports (CLRs) for catalog health issues. Use when analyzing CLR files (.xlsx/.xlsm), checking for missing attributes, RUFUS bullet optimization, titl…
Automation
schedule-effective-dated-changes
Schedule future-dated changes (plan, tier, price, deactivation) via a pending-changes table holding the payload, effective date, and status. A scheduled job applies due rows transa…
Productivity
utility-pm-critic
Runs adversarial review on a PM artifact via the pm-critic sub-agent. Dispatches natively on Claude Code with the pm-skills plugin; on other clients reads agents/pm-critic.md and e…
Engineering
db-naming
Audit naming conventions — inconsistent table/column casing and pluralization, ambiguous or reserved-word identifiers, untyped/opaque columns, inconsistent FK and boolean naming, a…
Business
pm-progress-auditor
Audit a status update, exec review, board email, all-hands talking point, or dashboard callout for credibility leaks before sending. Flags overstated claims, cherry-picked windows,…
Automation
fan-out-work
Scouts a large list of independent items, then executes each through its workflow stages concurrently with concurrency limits, isolation for file-mutating work, and full reporting …
Design
dx-audit
Audits an existing developer-experience surface for friction and scores it. Covers APIs, SDKs, CLIs, developer docs, examples, errors, setup, local inner-loop, migrations, package …
Productivity
skill-streamlining-audit
Audit a single skill directory (SKILL.md, references, templates) to detect redundant, contradictory, or outdated content and generate a severity-classified report recommending remo…
Business
stb-drv-sozialversicherungspruefung
DRV social security audit support. Four-year review cycle under § 28p SGB IV. Focuses on status determination, managing directors, bogus self-employment, mini/midijobs, phantom wag…
Productivity
story-analyze
Audits alignment between story.md, design.md, and implementation artifacts (testcases.md or tasks.md) before coding. Requires at least one of testcases.md or tasks.md; rejects if b…
Security
resume-watchdog-audit
Validates the resume watchdog layer: reads live registry ledgers, scheduled-task exit codes, and Principal.LogonType to confirm active revival of productive sessions rather than st…
Engineering
SPM
Production-grade software project development skill for OpenClaw. Structured event auditing, pluggable skill system, security gate, WBS hash attestation, auto context injection. 生产…
Testing
agenttrace
Local-first TUI/CLI for post-run agent session audits — cost/token spikes, tool failures, retry loops, latency gaps, health scores, anomalies, session-to-session diffs. No upload, …
Business
the-support-machine
Converts The Support Machine book into an executable field guide for planning, auditing, or operating AI customer support on B2B or technical products. Diagnose friction, evaluate …
DevOps
observabilityaudit
Comprehensive observability audit scoring 18 dimensions: logging, tracing (OpenTelemetry), metrics (RED/USE), dashboards, alerts, SLOs, error tracking, retention, sampling, probes,…
Documentation
shipping-artifacts
Documents the minimal durable set needed to review and audit an AI-built app before release: architecture, user flows, permissions, secrets, test coverage, plus conditional topics …
Documentation
refresh-cachedoc-numbers
Refreshes cached operational numbers in guarded docs by re-deriving snapshots from live telemetry, reconciling rendered values and dates, and re-running the hermetic audit until cl…
Security
hipaa-security-rule
Implements HIPAA Security Rule technical safeguards under 45 CFR §164.312 for electronic protected health information. Covers access controls with unique user identification, emerg…
Business
legal-design-assessment-mirza-chiragov
Audits legal documents against design principles across language clarity, readability, structure, hidden obligations, statutory duplication, and visual hierarchy. Scores on six pil…
Productivity
utility-pm-skill-auditor
Runs a repo-wide governance audit via the pm-skill-auditor sub-agent. Dispatches natively on Claude Code with the pm-skills plugin; on other clients reads agents/pm-skill-auditor.m…
DevOps
veda-cto
CTO-level infrastructure and operations for VEDA Platform. Handles security hardening, incident response, operational hygiene, and class audits. Use for /cto or requests like "chec…
Security
audit-consumers
Audits all GitHub consumers of a codebase against a user-defined check spec. Discovers repositories via search, runs named checks (grep patterns on SDK symbols), and generates a ma…
Engineering
entity-mapper-expert
Implement JPA Entity Long FK strategy with BaseAuditEntity/SoftDeletableEntity inheritance and EntityMapper Domain⇄Entity conversion. Prohibits JPA relationship annotations and Lom…
Security
auditing-python-dependencies
Scans Python dependency trees for known CVEs using pip-audit, covering direct and transitive packages across requirements.txt, pyproject.toml, Pipfile.lock, and poetry.lock. Output…
Security
secknowledge-skill
Security audit skill for web and AI systems. Draws on 88k+ real-world cases and established methodologies (L1-L4, GAARM, OWASP) to perform penetration testing, vulnerability discov…
Security
l5-red-team-auditor
Performs an uncompromising L5 Enterprise Red Team Audit on a given plugin against the 39-point architectural maturity matrix. Trigger when the user requests a security audit, red t…
Security
owasp-mobile-security-checker
Perform security audits, vulnerability assessments, or compliance checks on Flutter or mobile applications. Covers OWASP Mobile Top 10 (2024) — hardcoded secrets, insecure storage,…
Data
leaks
Comprehensive audit of money leaving accounts through untracked subscriptions, hidden fees, interest charges, predatory products, gambling patterns, duplicate charges, and billing …
Security
Agent Compliance & Security Assessment
Delivers a 14-point compliance and security audit for AI agents, generating a structured threat model and RED/AMBER/GREEN ratings across governance, EU AI Act readiness, oversight,…
Automation
autoforge
Production-grade autonomous optimization framework that replaces subjective reflection with rigorous convergence loops, tracking iterations in TSV and stopping only on measurable p…
Showing the top 60 of 2,853. See the full list →