Data & Analytics Agent Skills

Data agent skills make AI agents useful for data work: writing SQL, cleaning datasets, building pipelines, working with spreadsheets, and producing analyses. Each skill is a reviewed SKILL.md file that teaches the agent one workflow well, ready to install in seconds.

Data & Analytics

1,725 skills
mukul975
performing-linux-log-forensics-investigation
Analyze Linux system logs including auth.log, syslog, systemd journal, and auditd to reconstruct user activity, detect unauthorized access, and establish event timelines on compromised systems.
24.6k · bundle
mukul975
performing-memory-forensics-with-volatility3
Analyze volatile memory dumps using Volatility 3 to extract running processes, network connections, loaded modules, and evidence of malicious activity.
24.6k · bundle
mukul975
building-vulnerability-aging-and-sla-tracking
Track vulnerability aging and SLA compliance with severity-based remediation timelines, automated escalations, and compliance metrics.
24.6k · bundle
mukul975
detecting-entra-offensive-tools-in-graph-logs
Hunt AADGraphActivityLogs and MicrosoftGraphActivityLogs in Microsoft Sentinel/Log Analytics for fingerprints of offensive Entra ID tools such as ROADtools, AADInternals, and AzureHound.
24.6k · bundle
mukul975
hunting-for-beaconing-with-frequency-analysis
Identify command-and-control beaconing patterns in network traffic by applying statistical frequency analysis, jitter calculation, and coefficient of variation scoring to detect periodic callbacks from compromised endpoints.
24.6k · bundle
mukul975
performing-timeline-reconstruction-with-plaso
Build comprehensive forensic super-timelines using Plaso (log2timeline) to correlate events across file systems, logs, and artifacts into a unified chronological view.
24.6k · bundle
mukul975
analyzing-malware-behavior-with-cuckoo-sandbox
Executes malware samples in Cuckoo Sandbox to observe runtime behavior including process creation, file system modifications, registry changes, network communications, and API calls. Generates comprehensive behavioral reports for malware classification and IOC extraction.
24.6k · bundle
mukul975
analyzing-prefetch-files-for-execution-history
Parse Windows Prefetch files to determine program execution history including run counts, timestamps, and referenced files for forensic investigation.
24.6k · bundle
mukul975
performing-asset-criticality-scoring-for-vulns
Build a multi-factor asset criticality scoring model to weight vulnerability prioritization based on business impact, data sensitivity, and operational importance.
24.6k · bundle
mukul975
analyzing-certificate-transparency-for-phishing
Monitor Certificate Transparency logs using crt.sh and Certstream to detect phishing domains, lookalike certificates, and unauthorized certificate issuance targeting your organization.
24.6k · bundle
mukul975
performing-network-traffic-analysis-with-tshark
Automates packet capture analysis using tshark and pyshark to extract protocol statistics, detect suspicious flows, identify IOCs, and analyze DNS anomalies from PCAP files.
24.6k · bundle
mukul975
detecting-golden-ticket-attacks-in-kerberos-logs
Detect Golden Ticket attacks in Active Directory by analyzing Kerberos TGT anomalies including mismatched encryption types, impossible ticket lifetimes, non-existent accounts, and forged PAC signatures in domain controller event logs.
24.6k · bundle
mukul975
detecting-anomalies-in-industrial-control-systems
Deploys anomaly detection for industrial control environments using machine learning models trained on OT network baselines, physics-based process models, and behavioral analysis of industrial protocol communications.
24.6k · bundle
mukul975
performing-cloud-asset-inventory-with-cartography
Map cloud infrastructure assets and relationships into a Neo4j graph using Cartography to discover attack paths, IAM permission chains, and security gaps across AWS, GCP, and Azure.
24.6k · bundle
mukul975
performing-static-malware-analysis-with-pe-studio
Performs static analysis of Windows PE malware samples using PEStudio to examine file headers, imports, strings, resources, and indicators without executing the binary.
24.6k · bundle
mukul975
analyzing-email-headers-for-phishing-investigation
Parse and analyze email headers to trace the origin of phishing emails, verify sender authenticity, and identify spoofing through SPF, DKIM, and DMARC validation.
24.6k · bundle
mukul975
detecting-dns-exfiltration-with-dns-query-analysis
Detect data exfiltration through DNS tunneling by analyzing query entropy, subdomain length, query volume, TXT record abuse, and response payload sizes using passive DNS monitoring.
24.6k · bundle
mukul975
performing-mobile-device-forensics-with-cellebrite
Acquire and analyze mobile device data using Cellebrite UFED and open-source tools to extract communications, location data, and application artifacts.
24.6k · bundle
mukul975
analyzing-memory-forensics-with-lime-and-volatility
Acquires Linux memory using the LiME kernel module and analyzes the image with Volatility 3 to extract processes, network connections, bash history, kernel modules, and injected code for incident response.
24.6k · bundle
mukul975
performing-memory-forensics-with-volatility3-plugins
Analyze memory dumps using Volatility3 plugins to detect injected code, rootkits, credential theft, and malware artifacts in Windows, Linux, and macOS memory images.
24.6k · bundle
mukul975
performing-windows-artifact-analysis-with-eric-zimmerman-too
Parse and analyze Windows forensic artifacts including MFT, registry hives, prefetch files, event logs, LNK files, and jump lists using Eric Zimmerman's EZ Tools suite and KAPE.
24.6k · bundle
wondelai
ddia-systems
Design reliable, scalable, and maintainable data systems by applying principles from storage engines, replication, partitioning, transactions, and consistency models.
1.6k · bundle
wondelai
lean-analytics
Choose and audit startup metrics using the Lean Analytics framework: separate actionable metrics from vanity metrics, identify the One Metric That Matters for your business model and stage, set targets, and plan instrumentation.
1.6k · bundle
wondelai
improve-retention
Diagnose and fix retention problems using the Fogg Behavior Model (B=MAP), covering motivation, ability, prompts, and tiny habits.
1.6k · bundle
alphagbm
alphagbm-compare
Compares 2-5 stocks or options across GBM Five Pillars scores, options metrics, technicals, and valuations, highlighting winners per category and providing an overall recommendation.
1.2k
alphagbm
alphagbm-iv-rank
Calculates IV Rank and IV Percentile for any ticker to determine whether implied volatility is high or low relative to its 252-day history, and provides trading signals based on IV zones.
1.2k
alphagbm
alphagbm-vol-smile
Analyzes the volatility smile and skew for a single options expiration, providing implied volatility curves, skew metrics, and shape classification to reveal market pricing of tail risk and directional fear.
1.2k
alphagbm
alphagbm-watchlist
Monitor a list of tickers for key changes in price, IV rank, unusual activity, earnings dates, and score changes. Supports custom watchlists and a default hot options list.
1.2k
alphagbm
alphagbm-fear-score
Calculates a per-ticker panic index (0-100) from six weighted signals including VIX, IV Rank, RSI-14, volume anomaly, put/call ratio, and consecutive down days, triggering Bull Put Spread entry signals at scores ≥60.
1.2k
alphagbm
alphagbm-macro-view
Track key macro indicators (VIX, US10Y, DXY, gold, oil, BTC) and get AI-generated impact analysis linked to your portfolio holdings.
1.2k
alphagbm
alphagbm-polymarket
Compares prediction market probabilities from Polymarket with options-implied probabilities to identify mispricing signals and potential arbitrage opportunities.
1.2k
alphagbm
alphagbm-vol-surface
Builds a 3D volatility surface for any optionable ticker, mapping implied volatility across strike price and time to expiration to identify cheap, expensive, or anomalous options.
1.2k
alphagbm
alphagbm-bps-backtest
Runs a side-by-side walk-forward backtest of a Bull Put Spread strategy with and without a FearScore entry signal, comparing performance metrics over ~8 years of daily data.
1.2k
alphagbm
alphagbm-tepper-signal
Detects whether current market conditions match David Tepper's historic panic-buy signal by combining VIX, FearScore, and a quality filter.
1.2k
alphagbm
alphagbm-earnings-crush
Analyzes earnings-season implied volatility: historical IV crush, implied move forecast, IV Rank strategy tag, and a priced Iron Condor quote ready to trade.
1.2k
alphagbm
alphagbm-stock-analysis
Analyzes stocks using the AlphaGBM Five Pillars framework, returning a composite score, risk assessment, target price, and AI-generated report from real market data.
1.2k

Frequently asked questions

What are Data & Analytics agent skills?

Data agent skills make AI agents useful for data work: writing SQL, cleaning datasets, building pipelines, working with spreadsheets, and producing analyses. Each skill is a reviewed SKILL.md file that teaches the agent one workflow well, ready to install in seconds.

Which Data & Analytics skills are most installed?

Popular Data & Analytics skills on SkillMD right now include hunting-for-beaconing-with-frequency-analysis, performing-timeline-reconstruction-with-plaso, lean-analytics. Rankings shift as installs change; sort this page by "Most downloaded" for the live list.

Do Data & Analytics skills work with Claude Code and Cursor?

Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds add <owner>/<name>, or copy the file into your agent's skills directory.