Data & Analytics
Data agent skills make AI agents useful for data work: writing SQL, cleaning datasets, building pipelines, working with spreadsheets, and producing analyses. Each skill is a reviewed SKILL.md file that teaches the agent one workflow well, ready to install in seconds.
-
aibot88 Bundle Endor SastStatic application security testing for code-level vulnerabilities. Use when the user says "SAST scan", "find SQL injection", "check for XSS", "static analysis", "endor sast", "code security scan", or wants to find injection flaws, hardcoded credentials, and insecure patterns in source code. Do NOT use for dependency vulnerabilities (/endor-sca), secrets scanning (/endor-secrets), or viewing pre-computed AI SAST findings (/endor-ai-sast).
3 -
aibot88 Bundle Flowstudio Power Automate Monitoring**Pro+ subscription required.** Tenant-wide Power Automate flow health monitoring, failure rate analytics, and asset inventory using the FlowStudio MCP cached store. Load this skill ONLY for tenant-wide aggregated views — not for listing flows in a single environment or debugging a specific run (use power-automate-mcp or power-automate-debug for those). Not the same as the server's `monitor-flow` tool bundle (`tool_search query: "skill:monitor-flow"`) — that bundle is for runtime control of a single flow (start/stop/trigger/ cancel/resubmit); this skill is for tenant-wide health analytics over the cached store. Load when asked to: monitor tenant health, get aggregated failure rates over a time window, review tenant-wide error trends, find inactive makers across the tenant, inventory all Power Apps in the tenant, compute governance scores, generate a compliance report, or run a tenant-wide health overview. Requires a FlowStudio for Teams or MCP Pro+ subscription — see https://mcp.flowstudio.app
3 -
aibot88 Bundle Input Validation Sanitization AuditorIdentifies and fixes XSS, SQL injection, and command injection vulnerabilities with validation schemas, sanitization libraries, and safe coding patterns. Use for "input validation", "XSS prevention", "SQL injection", or "sanitization".
3 -
aibot88 Bundle Designing Privacy Preserving AnalyticsDesign privacy-preserving analytics systems using differential privacy, k-anonymity, l-diversity, and t-closeness. Covers privacy budget allocation with epsilon tracking, references Google DP library, OpenDP, and Apple PPML. Includes Python differential privacy implementation for GDPR-compliant statistical analysis.
3 -
aibot88 Bundle Detecting SQL Injection VulnerabilitiesDetect and analyze SQL injection vulnerabilities in application code and database queries. Use when you need to scan code for SQL injection risks, review query construction, validate input sanitization, or implement secure query patterns. Trigger with phrases like "detect SQL injection", "scan for SQLi vulnerabilities", "review database queries", or "check SQL security".
3 -
aibot88 Bundle Implementing Secure Multi Party ComputationImplementation guide for secure multi-party computation enabling privacy-preserving analytics across organizations. Covers secret sharing, garbled circuits, reference frameworks MP-SPDZ and CrypTen, practical deployment patterns, and GDPR alignment for joint controller analytics without revealing individual party inputs.
3 -
aibot88 Bundle Lookalike Audience Upload Compliance ReviewUse this skill when reviewing custom-audience and lookalike-audience upload specifications for hashing adequacy, PII field scope, consent-basis validity, and platform data-sharing restrictions before the upload is submitted to Meta, Google, LinkedIn, or TikTok. Trigger when a user provides an audience upload field-mapping specification (CSV schema or platform upload template), declared hashing method, consent-basis documentation, or originating list segment metadata — or when they ask whether their customer list upload or lookalike seed list is compliant with GDPR, CCPA/CPRA, or platform terms before uploading.
3 -
aibot88 Bundle Cybersecurityplaybooks24 ATT&CK-mapped offensive security playbooks for penetration testing, red teaming, and security assessments. USE WHEN user mentions kerberoasting, bloodhound, active directory attacks, nmap scanning, SQL injection, privilege escalation, lateral movement, C2 infrastructure, metasploit, credential access, SSRF, SMB exploitation, memory forensics, or any specific offensive security technique. Provides step-by-step operator-grade playbooks with actual tool commands, detection indicators, and MITRE ATT&CK mappings. Designed for use with Talon (Kali Linux MCP) and Ehud (penetration testing agent).
3 -
infometa Bundle Minimax XLSXOpen, create, read, analyze, edit, or validate Excel/spreadsheet files (.xlsx, .xlsm, .csv, .tsv). Use when the user asks to create, build, modify, analyze, read, validate, or format any Excel spreadsheet, financial model, pivot table, or tabular data file. Covers: creating new xlsx from scratch, reading and analyzing existing files, editing existing xlsx with zero format loss, formula recalculation and validation, and applying professional financial formatting standards. Triggers on 'spreadsheet', 'Excel', '.xlsx', '.csv', 'pivot table', 'financial model', 'formula', or any request to produce tabular data in Excel format.
228 -
infometa Bundle Tencentcloud Cos腾讯云对象存储(COS)和数据万象(CI)集成技能。覆盖文件存储管理、AI处理和知识库三大核心场景。 存储场景:上传文件到云端、下载云端文件、批量管理存储桶文件、获取文件签名链接分享、查看文件元信息。 图片处理场景:图片质量评估打分、AI超分辨率放大、AI智能裁剪、二维码/条形码识别、添加文字水印、获取图片EXIF信息、 缩放、裁剪、旋转、格式转换。 文档处理场景:Word/Excel/PPT等办公文档转PDF、文档预览。 媒体处理场景:视频智能封面提取、视频转码、视频截帧、获取媒体信息。 内容审核场景:图片/视频/音频/文本/文档内容审核,检测违规内容。 智能语音场景:语音识别(音频转文字)、语音合成(文字转语音)、音频降噪、人声分离。 文件处理场景:文件哈希计算、文件压缩打包、文件解压。 内容识别场景:图片标签识别、OCR文字识别。 知识库场景:一键创建知识库、上传文档到知识库、从知识库检索内容片段。 智能检索场景:MetaInsight以图搜图、以文搜图、人脸搜索、元数据检索、多模态文档检索。 当用户提到以下关键词或口语化表述时应触发此技能: 上传到COS、腾讯云存储、对象存储、云存储、存储桶、Bucket、 图片处理、图片压缩、图片放大、超分辨率、抠图、裁剪、二维码识别、水印、 文档转换、转PDF、视频封面、智能封面、以图搜图、图片搜索、MetaInsight、 COS上传、COS下载、签名URL、腾讯云文件、数据万象、CI处理、 内容审核、图片审核、视频审核、文本审核、语音识别、语音合成、降噪、人声分离、 OCR、文字识别、图片标签、 创建知识库、建一个知识库、上传到知识库、往知识库里加文件、查询知识库、 从知识库找、搜索知识库、知识库检索、文档检索、文档搜索。 即使用户没有明确提到COS或腾讯云,只要涉及"把文件传到云上"、"生成下载链接"、 "处理云端图片"、"帮我建个知识库"、"把文档放进知识库"、"从知识库里搜一下"、 "加密COS凭证"、"COS密钥不安全"、"加密一下COS密钥"、"保护COS密钥"等意图,也应该触发此技能。
228 -
infometa Bundle ReviewPre-landing PR code review with 7 specialist sub-reviewers. Analyzes diff for SQL safety, LLM trust boundary violations, conditional side effects, and structural issues. Triggers: code review, PR review, pre-landing review, diff review. Specialists: api-contract, data-migration, maintainability, performance, red-team, security, testing.
228 -
infometa Bundle LovrabetLovrabet 运行态 CLI — 面向业务场景的 AI 操作套件,通过 lovrabet 命令管理应用目录、Service Tree 业务命令、API 文档发现、数据集查询、Instant API 数据操作、Custom SQL/Backend Function、personal BFF、文件上传、OCR 识别、定时任务、Skill、知识库与运行态 app-config key 状态检查。触发词:云图、lovrabet、lovrabet-cli、service tree、业务服务树、api-doc、dataset、data filter、file upload、file query-url、ocr recognize、发票识别、图片识别、附件上传、personal-bff、schedule、定时任务、cron、kb、skill、sql exec、bff exec、app-config、accessKey、compress、jq。
228 -
infometa Bundle AI Shifu Course CreatorUse when the user works with AI-Shifu (AI师傅) courses in any capacity of creating, writing, editing, rewriting, optimizing, reordering, deploying, publishing, previewing, or managing Teaching Prompts (per-lesson) and Course Prompts (course-level) — both written in MarkdownFlow (MDF). Covers the full course lifecycle — from converting raw material into structured lessons, to scripting interactions (single-select, multi-select, input, branching), adding variables, images, and course prompts, to deploying and managing live courses on the AI-Shifu platform. Also covers post-deployment analytics on those courses — learner count, completion rate, stuck lessons, orders, revenue, ratings, credit consumption, audience profiles, and individual learner tracking. Trigger on any mention of AI-Shifu, AI师傅, MarkdownFlow, Teaching Prompt, Course Prompt authoring, course analytics, creator analytics, 学习人数, 完成率, 卡课节, 订单收入, 积分消耗, or learner progress.
228 -
infometa Bundle Lark Sheets飞书电子表格:创建和操作电子表格。支持创建表格、管理工作表与行列结构(增删/合并/调整尺寸/隐藏/冻结)、读写单元格(值/公式/样式/批注/单元格图片)、查找替换、多操作批量更新,以及图表、透视表、条件格式、筛选器、迷你图、浮动图片等对象的创建与维护。当用户需要创建电子表格、管理工作表、批量读写或编辑数据、统计汇总与可视化、表格美化、公式计算(含 Excel 公式迁移)、金融/财务建模(DCF、三张表、预算、Sensitivity 等)等任务时使用。若用户是想按名称或关键词搜索云空间(云盘/云存储)里的表格文件,请改用 lark-drive 的 drive +search 先定位资源。当用户给出 doubao.com 的 /sheets/ URL/token 时,也应直接使用本 skill,不要因为域名不是飞书而回退到 WebFetch;路由依据是 URL 路径模式和 token,而不是域名。
228 -
infometa Skill Audit XlsAudit a spreadsheet for formula accuracy, errors, and common mistakes. Scopes to a selected range, a single sheet, or the entire model (including financial-model integrity checks like BS balance, cash tie-out, and logic sanity). Triggers on "audit this sheet", "check my formulas", "find formula errors", "QA this spreadsheet", "sanity check this", "debug model", "model check", "model won't balance", "something's off in my model", "model review".
228 -
infometa Skill Lbo ModelThis skill should be used when completing LBO (Leveraged Buyout) model templates in Excel for private equity transactions, deal materials, or investment committee presentations. The skill fills in formulas, validates calculations, and ensures professional formatting standards that adapt to any template structure.
228 -
infometa Bundle Wecomcli Sheet企业微信在线表格(sheet)管理技能。提供在线表格的新建、内容读取、内容修改、追加行数据,以及子工作表的增删管理。适用场景:(1) 新建空白在线表格 (2) 读取表格完整内容(Markdown)(3) 读取基础信息与子表列表 (4) 读取表格子表数据 (5) 修改指定区域内容 (6) 末尾追加一行数据 (7) 添加/删除子工作表。当用户提到「企业微信表格」「企业微信在线表格」「企微 Excel 表格」,或链接形如 `https://doc.weixin.qq.com/sheet/xxx` 时触发该技能。注意:智能表格(`/smartsheet/*`)请用 `wecomcli-smartsheet`;普通文档(`/doc/*`)请用 `wecomcli-doc`;智能文档/智能主页(`/smartpage/*`)请用 `wecomcli-smartpage`。
228 -
infometa Skill Comps AnalysisBuild institutional-grade comparable company analyses with operating metrics, valuation multiples, and statistical benchmarking in Excel/spreadsheet format. **Perfect for:** - Public company valuation (M&A, investment analysis) - Benchmarking performance vs. industry peers - Pricing IPOs or funding rounds - Identifying valuation outliers (over/under-valued) - Supporting investment committee presentations - Creating sector overview reports **Not ideal for:** - Private companies without comparable public peers - Highly diversified conglomerates - Distressed/bankrupt companies - Pre-revenue startups - Companies with unique business models
228 -
infometa Skill Model AuditAudit and tie-out financial models for accuracy, consistency, and best practices. Checks formula integrity, circular references, hardcodes, balance sheet balance, and cross-statement linkages. Triggers on "模型审计", "模型检查", "model audit", "model review", "tie-out", "模型核对", "公式检查", "model QA", "spreadsheet audit".
228 -
infometa Bundle Deck Design交付物生成工具:以假设驱动、证据分级和 Title Storyboard 为上游,使用统一 DeckSpec 与双引擎 Fusion 管线生成可审计的专业咨询 PPT;同时支持 Excel 测算底稿排版。 触发词:把这份分析做成PPT、出一份能直接汇报的演示文稿、产出ppt、帮我把测算结果整理成Excel、生成幻灯片。
228 -
infometa Bundle Tencentcloud Ocr Recognizetableaccurate腾讯云表格识别v3(RecognizeTableAccurateOCR)接口调用技能。当用户需要从表格图片或PDF中识别常规表格、无线表格、多表格的内容,提取每个单元格的文字信息,或将表格图片识别结果导出为Excel文件时,应使用此技能。支持中英文表格图片、旋转表格图片、嵌套表格图片等复杂场景,识别效果优于表格识别V2。
228 -
infometa Skill Data Model CreationOptional advanced tool for complex data modeling. For simple table creation, use relational-database-tool directly with SQL statements.
228 -
infometa Skill Indicator Query通过预置指标API查询HR数据。当用户需要查询涉及计算逻辑的数据(如比率、占比、平均值、人均、趋势对比、流入流出率等)时优先使用本Skill。指标口径经过业务验证,比手写SQL更准确。
228 -
infometa Skill Kpi DesignDesign KPI frameworks, set targets, develop measurement plans, and estimate market/opportunity sizes (TAM/SAM/SOM). Use when success metrics, drivers, guardrails, targets, or measurement approach need to be defined or improved, or when a market or opportunity size estimate is needed.
228 -
infometa Bundle Jinshuju Form通过金数据(Jinshuju,jinshuju.net)MCP 操作用户托管在金数据平台上的在线表单:创建 / 复制 / 编辑表单与主题,含自动判分的考试表单、选项计分的测评表单;查询、新增(单条或批量)、更新、删除、批量修改数据;用上传凭证上传本地图片或文件;查询账户套餐额度与团队成员。仅在用户操作其金数据平台数据时使用——触发信号:提到 金数据 / Jinshuju / jinshuju.net、给出 form_token,或要操作一张已托管在金数据上的表单或数据。不要用于:用代码开发表单 / 问卷系统、处理本地文件或表格(Excel / CSV)、图片 / 票据 OCR、物流或监控等与平台无关的自动化,以及与金数据平台无关的通用数据处理。
228 -
infometa Bundle Jinshuju Table通过金数据(Jinshuju,jinshuju.net)MCP 操作用户托管在金数据平台上的数据表格:创建 / 编辑数据表与列(含自动计算的公式列);查询、新增(单条或批量)、更新、批量更新、删除行数据;用上传凭证把本地文件写入附件列;查询账户套餐额度与团队成员。仅在用户操作其金数据数据表时使用——触发信号:提到 金数据表格 / Jinshuju 表格 / 数据表,或要在金数据上建表、加改列、批量维护行数据。不要用于:用代码开发表格系统、处理本地文件或表格(Excel / CSV)、搭建对外收集的表单 / 问卷、图片 / 票据 OCR,以及与金数据平台无关的通用数据处理。
228 -
infometa Skill Hr Data SQL Builder生成HR数仓StarRocks查询SQL。覆盖员工信息/人员异动/绩效/梯队等查询,含术语映射、业务规则和SQL模板。表结构从MCP resources动态获取。用户提出数据查询需求时必须使用本Skill。指标类查询(涉及率/比/占比/平均值/趋势等计算指标)必须使用indicator-query Skill。
228 -
infometa Skill Relational Database MCP CloudbaseThis is the required documentation for agents operating on the CloudBase Relational Database through MCP. It defines the canonical SQL management flow with `querySqlDatabase`, `manageSqlDatabase`, `readSecurityRule`, and `writeSecurityRule`, including MySQL provisioning, destroy flow, async status checks, safe query execution, schema initialization, and security rule updates.
228 -
infometa Bundle Contract Review EngineReview contracts for risk (scenarios C5/C6) — background assessment before signing (counterparty qualification, transaction-mode legality, contract-form fit, special procedures) and clause-by-clause review of a provided contract. Use this skill after the user's standpoint (Party A/B/neutral, strong/weak) is confirmed via intake. Runs an eight-step per-rule action (locate→extract→compare→judge→self-check→grade→legal-basis→suggest), grades risk via an impact×probability matrix into three tiers (high/medium/hint), and applies built-in Formal-Review and General-Substantive playbooks (or the user's playbook with priority). Produces a structured risk list (risk level, description, legal basis, remediation suggestion); optionally a redlined .docx, a review opinion, or — in professional review mode — three deliverables (Excel + Markdown report + Word annotations).
228 -
infometa Bundle AI Shifu Course Creator AIUse when the user works with AI-Shifu (AI师傅) courses in any capacity of creating, writing, editing, rewriting, optimizing, reordering, deploying, publishing, previewing, or managing Teaching Prompts (per-lesson) and Course Prompts (course-level) — both written in MarkdownFlow (MDF). Covers the full course lifecycle — from converting raw material into structured lessons, to scripting interactions (single-select, multi-select, input, branching), adding variables, images, and course prompts, to deploying and managing live courses on the AI-Shifu platform. Also covers post-deployment analytics on those courses — learner count, completion rate, stuck lessons, orders, revenue, ratings, credit consumption, audience profiles, and individual learner tracking. Trigger on any mention of AI-Shifu, AI师傅, MarkdownFlow, Teaching Prompt, Course Prompt authoring, course analytics, creator analytics, 学习人数, 完成率, 卡课节, 订单收入, 积分消耗, or learner progress.
228 -
infometa Bundle Databrain IntelligenceDataBrain intelligence data query assistant. Translates natural language questions into executable BigQuery SQL for the intelligence domain: market data (Sensortower, Alinea Analytics [Steam raw default], MScience, GSD, Ampere, NPD; Gamalytic legacy), streaming data (Streamhatchet), Steam live CCU (fetch_steam_ccu.py + warehouse spider/Alinea), Roblox CCU rankings & anomaly detection, mini game rankings (微信/抖音/Facebook小游戏榜单), report metadata (external & internal research reports), platform coverage statistics, MobyGames credits, news data, upcoming/未上线 game queries (Alinea live signals + combined_detail.release_date fuzzy-date normalization), game ID lookups (unified_id / combined_id), benchmark / 对标 queries (industry median, top 1%, peer ranking from benchmark.benchmark_detail), and mobile game audience overlap / affinity queries (Sensortower App Overlap). Trigger keywords: intelligence, 情报游戏数据, overlap, affinity, 受众重叠, 重叠度, 亲和力, 亲密度, 共同用户
228 -
infometa Skill Hr Analytics Dashboard轻流图表与门户深度集成——在轻流中搭建人力分析看板,覆盖人员结构、流失率、招聘漏斗、培训完成率等核心HR指标。 触发词:人力看板、流失率、招聘漏斗、培训完成率、人员结构
228 -
infometa Skill Data VisualizationDesign, specify, implement, revise, and QA quantitative visuals and chart choices. Use when an analytical answer needs visual judgment—comparing values, showing composition, reading concentration, understanding movement over time, or building chart specifications for reports and dashboards.
228 -
infometa Skill Metric DiagnosticsDiagnose why a metric changed or differs from expectation, and produce leadership-ready KPI updates. Use when the user needs to understand what drove a metric movement, anomaly, or discrepancy, or when producing WBR/MBR/QBR summaries, scorecards, target pacing readouts, or performance updates.
228 -
infometa Skill Analytics ReportingBuild polished analytical reports, dashboards, and product/business analyses. Use when the user needs a durable report (executive or technical), an analytical dashboard with clear metrics, or a data-backed product/business analysis to inform decisions. Covers report building, dashboard construction, and decision-oriented quantitative analysis.
228 -
infometa Bundle Data Warehouse API Codegen提供标准化的数仓 HTTP 查询接口调用能力。当用户需要从数据仓库获取数据时,根据接口规范生成正确的前端调用代码。⚠️严格限制:数仓接口只能在前端页面(浏览器端)中调用,严禁在任何后端代码(Node.js、Python、Go、Java等后端服务)中调用,因为后端环境没有用户的SSO身份信息,调用会报错。使用场景:1.用户需要在前端页面调用数据仓库接口查询数据。2.用户需要生成前端访问数仓的 HTTP 请求代码。3.用户需要在前端编写数据获取逻辑。4.用户提到"查数据"、"调接口"、"获取数据"、"数据仓库"等关键词
228
Frequently asked questions
What are Data & Analytics agent skills?
Data agent skills make AI agents useful for data work: writing SQL, cleaning datasets, building pipelines, working with spreadsheets, and producing analyses. Each skill is a reviewed SKILL.md file that teaches the agent one workflow well, ready to install in seconds.
Which Data & Analytics skills are most installed?
Popular Data & Analytics skills on SkillMD right now include endor-sast, flowstudio-power-automate-monitoring, input-validation-sanitization-auditor. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Data & Analytics skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.