Loading...
Loading...
Found 251 Skills
Automated penetration testing toolkit for security assessment, vulnerability scanning, and automated security reporting
Scan GitHub Actions workflow files for security vulnerabilities by reading the YAML and reporting findings directly — no external tools, no installation, no shell execution. Use this skill whenever the user shares a `.github/workflows/` file, pastes workflow YAML, asks for a CI/CD security review, mentions `pull_request_target`, `workflow_run`, action pinning, `GITHUB_TOKEN` permissions, pwn requests, template injection, cache poisoning, secret exfiltration, supply chain risk, or any GitHub Actions hardening topic. Also trigger when the user is hardening an OSS repo, doing a CI/CD red team assessment, evaluating a target for supply-chain scanning, or writing publicly about CI/CD security. Bias toward triggering this skill rather than answering from memory — CI/CD security defaults are wrong almost everywhere and the rules are unintuitive.
Delegate menial, well-scoped coding tasks to a cheap Qwen-backed subagent via the `claude-9arm` command instead of burning Claude tokens/quota. Use when the work is mechanical and low-risk — bulk renames, formatting, boilerplate, find-replace, grep-style search & summarization, reading/condensing logs or files, test/docstring/comment scaffolding, or running builds/linters/tests and reporting pass-fail. Also use when the user says "use qwen", "delegate this", "send it to 9arm/qwen", or "do this cheaply". Do NOT use for architecture, design, debugging judgment, security-sensitive edits, or anything needing this conversation's context.
This skill should be used when the user asks to "create report", "dashboard", "chart", "visualization", "analytics", "scheduled report", "export data", or any ServiceNow reporting and dashboard development.
Check and configure code coverage thresholds and reporting
Calculate influencer campaign ROI and build a leadership-ready narrative summary from raw performance data. This skill should be used when calculating ROI for a creator campaign, building a campaign performance report for leadership, turning raw influencer metrics into an executive summary, computing CPM CPE ROAS and EMV for a creator program, summarizing campaign spend versus revenue for a stakeholder meeting, proving influencer marketing ROI to a CMO or VP, creating a campaign wrap report with financial metrics, or comparing influencer channel efficiency against paid social. For setting KPI targets before a campaign launches, see performance-benchmark-setter. For tracking creator posting compliance, see creator-posting-compliance-tracker. For full end-of-campaign reporting with qualitative analysis, see post-campaign-creator-scorecard. For building UTM links to enable attribution, see utm-parameter-builder.
Access Red Rover absence management data for PSD staff attendance tracking and reporting
Guides QA engineers through daily testing activities—morning review, test case creation, automation, exploratory testing, bug reporting, and end-of-day wrap-up. Use when planning or executing day-to-day testing or when the user asks about daily testing workflow.
Use this skill when you need to generate test reports with summary, metrics, defect analysis, and risk assessment; triggers include test reporting and QA status report.
Build professional financial services data packs from various sources including CIMs, offering memorandums, SEC filings, web search, or MCP servers. Extract, normalize, and standardize financial data into investment committee-ready Excel workbooks with consistent structure, proper formatting, and documented assumptions. Use for M&A due diligence, private equity analysis, investment committee materials, and standardizing financial reporting across portfolio companies. Do not use for simple financial calculations or working with already-completed data packs.
Use when creating data reports on Xiaohongshu performance, summarizing analytics findings, presenting insights to stakeholders, documenting marketing results, or building reporting templates
Read-only exploration, status checks, and reporting without modifications. Use when user asks to check status, find files, search code, show state, or explicitly requests read-only investigation. Do NOT use when user wants changes, fixes, refactoring, or any write operation.