Skills
18,283 skills, most installed first.
Browse
supabase-audit-buckets-readyoanbernabeuAttempt to list and read files from storage buckets to verify access controls.supabase-audit-functionsyoanbernabeuDiscover and test Supabase Edge Functions for security vulnerabilities and misconfigurations.supabase-audit-realtimeyoanbernabeuTest Supabase Realtime WebSocket channels for unauthorized subscriptions and data exposure.supabase-audit-rlsyoanbernabeuTest Row Level Security (RLS) policies for common bypass vulnerabilities and misconfigurations.supabase-audit-rpcyoanbernabeuList and test exposed PostgreSQL RPC functions for security issues and potential RLS bypass.supabase-audit-tables-listyoanbernabeuList all tables exposed via the Supabase PostgREST API to identify the attack surface.supabase-audit-tables-readyoanbernabeuAttempt to read data from exposed tables to verify actual data exposure and RLS effectiveness.supabase-detectyoanbernabeuDetect if a web application uses Supabase by analyzing client-side code, network patterns, and API endpoints.supabase-extract-anon-keyyoanbernabeuExtract the Supabase anon/public API key from client-side code. This key is expected in client apps but important for RLS testing.supabase-extract-db-stringyoanbernabeuCRITICAL - Detect exposed PostgreSQL database connection strings in client-side code. Direct DB access is a P0 issue.supabase-extract-jwtyoanbernabeuExtract and decode Supabase-related JWTs from client-side code, cookies, and local storage patterns.supabase-extract-service-keyyoanbernabeuCRITICAL - Detect if the Supabase service_role key is leaked in client-side code. This is a P0 severity issue.supabase-extract-urlyoanbernabeuExtract the Supabase project URL from client-side JavaScript code, environment variables, and configuration files.supabase-helpyoanbernabeuQuick reference for all Supabase security audit skills with usage examples and command overview.supabase-pentestyoanbernabeuOrchestrate a complete Supabase security audit with guided step-by-step execution and ownership confirmation.supabase-reportyoanbernabeuGenerate a comprehensive Markdown security audit report with executive summary, findings, and remediation guidance.supabase-report-compareyoanbernabeuCompare two security audit reports to track remediation progress and identify new vulnerabilities.blueprinteryofineGenerate technical diagrams using HTML/CSS in Flat Engineering Blueprint style. Use when the user wants to create architecture diagrams, system diagrams, flowcharts, or technical specification sheets that look like engineering blueprints. Triggers on requests for flat diagrams, blueprint-style visualizations, or technical drawings.memoryyonatangrossRead-side memory operations on the knowledge graph: search past decisions and patterns, load session context, view decision timelines, render Mermaid graph visualizations. Subcommands: search, load, history, viz, status. Use when finding or reviewing what memory already holds. For storing new knowledge instead, invoke remember; for retrieval internals, memory-fabric; for cleanup, dream.security-patternsyonatangrossSecurity patterns for authentication, defense-in-depth, input validation, OWASP Top 10, LLM safety, and PII masking. Use when implementing auth flows, security layers, input sanitization, vulnerability prevention, prompt injection defense, or data redaction.arxiv-searchyorkeccakSearch arXiv physics, math, and computer science preprints using natural language queries. Powered by Valyu semantic search.biomedical-searchyorkeccakComplete biomedical information search combining PubMed, preprints, clinical trials, and FDA drug labels. Powered by Valyu semantic search.literature-searchyorkeccakComprehensive scientific literature search across PubMed, arXiv, bioRxiv, medRxiv. Natural language queries powered by Valyu semantic search.patents-searchyorkeccakSearch global patents with natural language queries. Prior art, patent landscapes, and innovation tracking via Valyu.pubmed-searchyorkeccakSearch PubMed biomedical literature with natural language queries powered by Valyu semantic search. Full-text access, integrate into your AI projects.ai-image-prompts-skillyoumind-openlabRecommend curated prompts from a 10,000+ real-world image generation prompt library. Works with ANY AI image model — Nano Banana Pro, Nano Banana 2, Seedream 5.0, GPT Image 1.5, Midjourney, DALL-E 3, Flux, Stable Diffusion, and more. Use this skill when users want to: - Find proven image generation prompts (any model) - Get prompt inspiration for portraits, products, social media, posters, etc. - Create illustrations for articles, videos, podcasts, or marketing content - Browse categorized prompyoumindyoumind-openlabUse this skill when the task is clearly connected to the user's YouMind workspace, YouMind APIs, or the youmind CLI. It helps agents search, inspect, and call YouMind OpenAPI endpoints to work with boards, groups, YouMind files, picks, chats, and YouMind skills.youmind-wechat-articleyoumind-openlabWrite and publish WeChat Official Account articles end-to-end with AI, or take an existing draft straight into the skill's built-in formatting + direct-send capability. Supports full pipeline from topic, plus ready-article direct send when the article is already written. Use when user says "写公众号文章" / "微信推文" / "发布到草稿箱" / "微信排版" / "WeChat publish". Do NOT trigger for: generic blogs, newsletters, PPT, short-video scripts, non-WeChat SEO work.searxng-searchyparesEnhanced web and package repository search using local SearXNG instancearxiv-paper-translatoryromTranslate academic papers from arXiv to Chinese. Use when users want to (1) translate arXiv papers from English to Chinese, or (2) create technical reports summarizing academic papers. Works with arXiv paper IDs like "2206.04655".x-tweet-fetcherythx-101Fetch tweets, replies, timelines, search results, X Lists, and X Articles from X/Twitter without login or API keys. Single tweets: zero dependencies (FxTwitter). Timelines/search/replies: a Nitter instance (XTF_NITTER). Lists/Articles: a browser driver (Camofox or Playwright). Unified JSON schema across all backends; machine-readable error_code for agent branching. Field reports and agent-use questions: Agent Waystation #22 Teahouse: https://github.com/ythx-101/openclaw-qa/discussions/22yuque-personal-knowledge-connectyuqueDiscover connections between documents, build knowledge networks, and establish bidirectional links across your personal Yuque knowledge base. For personal/individual use — operates on your own docs.skill-builderyusufkaraaslanAutomatically detect source types and build AI skills using Skill Seekers. Use when the user wants to create skills from documentation, repos, PDFs, videos, or other knowledge sources.axyusukebeUse the ax CLI instead of curl + throwaway parsing scripts whenever you fetch a URL, explore an unknown web page, or extract structured data from HTML. Trigger whenever you are about to write an inline script (python3 heredoc, node -e, regex over HTML) or a bare curl for one-off web fetching, scraping, or page exploration.repo-analyzeryzddmr6Use when the user mentions "分析项目"、"分析仓库"、"分析 GitHub"、"项目分析"、"源码分析"、"架构分析"、"代码分析"、"学习这个项目"、"研究这个框架"、"看看这个库怎么实现的"、"对比两个项目"、"项目评测"、"框架评测humanizer-cnz0gsh1u识别并消除中文文本中的 AI 生成痕迹,使文章更自然、更像人类创作。 基于中文语境的 AI 写作特征检测,包括套话、过度修饰、机械结构等。 参考 Wikipedia "Signs of AI writing" 指南,并针对中文进行本地化。xiaohongshu-converterz0gsh1u将通用写作 Skill 产出的内容转换为适合小红书平台发布的格式和风格。 小红书偏好生活化、亲切感、有颜值的内容风格,Emoji 适度使用不过密。workflows-doctorzapierDiagnose Zapier Workflows skill and SDK CLI compatibility. Use when a workflow skill asks for a compatibility check, when SDK commands or flags are missing, when a workflow skill may be stale, or when updating workflow skills after an SDK CLI change.zapier-sdkzapierZapier SDK for TypeScript. Programmatic access to 9,000+ apps on a user's behalf via Zapier's OAuth and audit layer. Use when writing code that needs to run actions in third-party apps (send an email, upsert a CRM record, look up a spreadsheet row, post to a chat) without managing per-app OAuth or vendor SDKs. Triggers: "zapier sdk", "zapier-sdk", "@zapier/zapier-sdk", "runAction", "run zapier action", "connect to app via zapier", "zapier connection", "zapier tables", "list actions for zapier apfrontend-slideszarazhangruiCreate stunning, animation-rich HTML presentations from scratch or by converting PowerPoint files. Use when the user wants to build a presentation, convert a PPT/PPTX to web, or create slides for a talk/pitch. Helps non-designers discover their aesthetic through visual exploration rather than abstract choices.godot-optimizationzateExpert knowledge of Godot performance optimization, profiling, bottleneck identification, and optimization techniques. Use when helping improve game performance or analyzing performance issues.brand-writerzed-industriesWrite clear, developer-first copy for Zed — leading with facts, grounded in craft.humanizerzed-industriesRemove signs of AI-generated writing from text. Use after drafting to make copy sound more natural and human-written. Based on Wikipedia's "Signs of AI writing" guide.scenes-gathered-zine-v1-3zeejay0Transform a user-supplied photo into a vertical 3:5 Gathered Scenes Zine poster that anchors truthful photography inside a spacious source-derived abstract illustration field, aggressively compresses dense foliage and other micro-detail into a few large quiet forms, integrates one high-chroma hue as compositional structure, and preserves a visibly hand-torn fibrous photo-to-paper edge. Use when the user wants a tactile minimal paper collage with simplified illustration, active negative space, reswiss-designzekeApply a Swiss International Style design system using Tailwind CSS. Use when asked to style a webpage, clean up a UI, apply a design system, make something look great, or when the user references Swiss design, grotesque fonts, Helvetica, grid systems, modernist typography, or 1960s/1950s design aesthetics. Implements IBM Plex Sans typography, stone color palette, opacity-based hierarchy, generous whitespace, and structured grid layouts.short-dramazenstory-ai基于文件系统初始化和继续短剧或漫剧项目,提供 creator-first 五文档路由、本地 Dashboard、制作形态与 Look Development 决策。用户提出“创建/继续短剧项目”“看进度/下一步”“做 Look Development”“打开 dashboard/短剧创作台”“导出制作资料”,或任务跨多个创作阶段时使用;明确的写作、资产、提示词、分镜、剪辑或审查请求由对应子 skill 直接处理。short-drama-assetszenstory-ai从短剧剧本拆出人物/造型、地点/视图、道具/状态和跨场连续性,写成创作者可读的视觉设定。用户说“拆角色/场景/道具”“做资产设定”“判断复用还是新变体”“更新造型/道具状态”,或拿现成剧本直接做视觉资产准备时使用;不写图片提示词,不生成媒体。short-drama-developzenstory-ai将中文小说、短剧或漫剧想法、梗概、改编材料、已有系列笔记或多集完整剧本发展成可追溯的改编方案、戏剧方向、创作简报、导演阐述、故事引擎与分集地图,并按题材与制作形态(画风)选择写法。用户提出“导入小说做短剧”“从多集整稿生成/补分集地图”“开发短剧/漫剧”“做故事设定/系列大纲/分集规划”“写导演阐述”“这个题材怎么写”“定画风/制作形态”“把这个点子变成短剧”或需要梳理人物冲突与集间交接时使用;已有单集剧本可直接进入写作、资产或审查流程,不强制补开发文件。short-drama-image-promptszenstory-ai为短剧人物、造型、地点、道具和状态编写或修改可直接复制的图片提示词 Markdown。用户提到角色设定图、三视图、参考图、场景板、道具图、风格帧、Look Development、状态变体或局部编辑提示词时使用;不生成图片,也不调用供应商。short-drama-novel-analyzezenstory-ai把长篇小说、连载网文或多集散稿拆成可追溯的原著分析:章节索引、改编价值快评、逐章功能提取、剧情单元与节奏聚合、人物与设定归并,最后给出改编价值判定与分集候选,交给 $short-drama-develop 立契约。用户说“导入这本小说”“拆这本书”“分析原著”“这本书能不能改短剧”“先看看值不值得拆”“把长篇拆成分集候选”,或直接给出小说文件路径时使用。只做只读的结构化分析,不写剧本、不建资产、不生成媒体,也不替创作者决定改编方案。
