Explore skills
4,856 skills found
Category alert
Get new DevOps e Infra skills every Monday
package-search
Search for packages and assess security risk before adding as dependencies
github-automation
Automate GitHub repositories, issues, pull requests, branches, CI/CD, and permissions via Rube MCP (Composio). Manage code workflows, review PRs, search code, and handle deployments programmatically.
tweetclaw
Use TweetClaw as an OpenClaw plugin for X/Twitter automation: search tweets, search tweet replies, post tweets/replies, export followers, look up users, handle media, monitor tweets, deliver webhooks, run giveaway draws, and manage approval-gated visible actions.
ops-deploy
Deploy status across all projects. Shows ECS service versions, Vercel deployments, recent deploys, pending deploys, and CI/CD pipeline state.
financial-model
Run deterministic financial models for startup valuation and SaaS health analysis. Triggered by: "/venture-capital-intelligence:financial-model", "run a financial model on X", "DCF this company", "model the financials", "calculate runway", "what is the valuation", "SaaS metrics model", "LTV CAC analysis", "unit economics", "burn rate analysis", "comparable valuation", "how long is my runway", "wha
hard-screening-startup
Deterministic Python-scored startup screening with full audit trail. Use when you need a reproducible, weighted-score verdict on a startup — not just a qualitative opinion. Triggered by: "/venture-capital-intelligence:hard-screening-startup", "hard screen this startup", "run a hard screen on X", "score this startup with Python", "give me an auditable screen", "run a scored evaluation on X", "give
browser-cdp
Use this skill to control a Chrome browser via CDP (Chrome DevTools Protocol) for reusing existing login sessions. It covers launching Chrome in debug mode, opening URLs, waiting for page load, evaluating JavaScript, taking snapshots, and extracting authentication tokens.
evidence-hygiene
Evidence-capture and PoC-redaction discipline for bug-bounty submissions, covering cookie redaction protocols, PII black-bar discipline, and HAR file sanitization.
hunt-aspnet
Hunts ASP.NET-specific vulnerabilities like ViewState deserialization, machineKey recovery, MAC-bypass anti-patterns, and request-validator bypass. It also targets information disclosure, load-balanced ViewState failures, and classic Webforms attack surfaces.
hunt-cache-poison
Hunting skill for cache poison vulnerabilities. Built from 10 public bug bounty reports including X-Forwarded-Host poisoning, X-HTTP-Method-Override / GCS cache, reflected→stored XSS via cache, classic Omer-Gil Web Cache Deception, Cloudflare Cache Deception Armor bypass, session-token cache deception, Akamai hop-by-hop smuggling → server-side edge poisoning, and Kettle's 2024 path-normalization W.
hunt-ssti
Detects server-side template injection (SSTI) across various engines like Jinja2, Twig, and Freemarker. It uses server-side evaluated math expressions for detection and escalates to RCE via engine-specific patterns once identified.
okta-attack
An Okta-as-IdP red-team attack chain, encompassing tenant discovery, user and MFA enumeration, authentication flow analysis, password spraying, Okta-specific phishing, and post-compromise admin API surface exploitation.