Data & Analytics
Data agent skills make AI agents useful for data work: writing SQL, cleaning datasets, building pipelines, working with spreadsheets, and producing analyses. Each skill is a reviewed SKILL.md file that teaches the agent one workflow well, ready to install in seconds.
-
fdu-ins Skill Postgres Schema ExpertInstructions for managing the PostgreSQL schema, writing SQL queries, and maintaining data integrity for the insurance analytics project.
-
fdu-ins Bundle CommonCross-product infrastructure for HealthSim — persistence (cohort save/load), identity correlation (SSN-based cross-product linking), and DuckDB database operations. Use when saving/loading cohorts, linking entities across products, or querying the database directly.
-
tonone-ai Skill Apex StatsSpawn-count analytics for the tonone roster — which agents this project actually uses, from local session transcripts. Use when "which agents do we actually use", "show tonone stats", "prune the roster", or before running apex-profile.
-
pramoddutta Skill Test Observability AnalyticsImplementing test observability with execution analytics, failure trend analysis, coverage gap detection, and test suite health dashboards.
-
tonone-ai Skill Flux QueryOptimize slow database queries — analyze execution plans, add indexes, rewrite queries. Use when asked about "slow query", "optimize SQL", "query performance", or "explain this query".
-
tonone-ai Skill Lens AuditReview existing analytics — find all dashboards and reports, check who uses them, whether metrics are defined, and whether they drive decisions. Recommend what to keep, kill, or add. Use when asked "are our dashboards useful", "analytics review", or "metrics audit".
-
tonone-ai Skill Lens ChartUse when asked to select chart types for analytics dashboards, choose BI visualizations, or design data displays. Examples: "best chart for sales data", "dashboard visualization for metrics", "analytics chart selection"
-
fdu-ins Bundle Insurance Agent Customer Crm帮助保险代理人将pdf、Excel、Word、PPT等各类客户资料转化为个人客户信息资料库,方便小龙虾调用和使用,回答下列问题:"帮我为下个月生日的客户撰写个性化的生日祝福"、"帮我为每个保单客户撰写一份个性化的理财活动邀约",等等。
-
fdu-ins Bundle PopulationsimPopulationSim provides population-level intelligence using public data sources. Use this skill for ANY request involving: (1) population demographics or profiles, (2) geographic health patterns or disparities, (3) social determinants of health (SDOH), (4) SVI or ADI analysis, (5) cohort definition or specification, (6) clinical trial feasibility, site selection, or enrollment projection, (7) service area analysis, (8) health equity assessment, (9) census data or ACS variables, (10) CDC PLACES health indicators.
-
tonone-ai Skill Lens ReconAnalytics reconnaissance for takeover — find all analytics tools, inventory what's tracked and dashboarded, assess data freshness and metric definitions, and present a coverage map. Use when asked "what analytics exist", "BI assessment", or "what do we track".
-
pramoddutta Skill SQL Injection TestingComprehensive SQL injection testing patterns including blind SQLi, time-based, union-based, and parameterized query validation techniques.
-
fdu-ins Bundle Hcls Provider Claims Data AnalysisAnalyze healthcare claims data for real-world evidence (RWE) studies. Use when working with medical/pharmacy claims (837/835), calculating utilization metrics, building patient cohorts, or analyzing treatment patterns. Triggers include claims data, RWE, real-world evidence, 837, 835, medical claims, pharmacy claims, utilization, treatment patterns, HEDIS, healthcare analytics.
-
outlinedriven-odin-claude-plugin Bundle Dataflow DiagramUse when asked to visualize data movement, ETL or ELT, lineage, transformations, custody, governance, stores, sources, or consumers.
-
tonone-ai Skill Lumen ReconAnalytics reconnaissance — scan existing event tracking, metric definitions, dashboards, and analytics configuration to understand what is currently being measured. Use when asked to "what are we tracking", "audit our analytics", "what metrics exist", "analytics inventory", or before designing new metrics or instrumentation.
-
pramoddutta Bundle Secure Test Data EngineerGenerate test data from the schemas you already have. Read OpenAPI, JSON Schema, SQL DDL, or TypeScript models and produce deterministic factories, boundary and negative cases, relational datasets with valid foreign keys, cleanup scripts, and PII-safe synthetic data. Production records never leave the machine.
-
pramoddutta Skill Mobile Performance TestingMobile application performance testing including app launch time, frame rendering, memory profiling, battery consumption, network throttling, and crash analytics using Appium, XCTest, and Espresso with real device testing.
-
tonone-ai Skill Echo SegmentUser segmentation and persona creation from mixed data sources — analytics, CRM, support tickets, reviews, or any combination. Use when asked to "build personas", "who are our users", "segment our users", "create user profiles", "define user archetypes", or "who is the target user".
-
tonone-ai Skill Flux MigrateBuild zero-downtime database migrations — forward SQL, rollback SQL, deployment sequence. Use when asked to "write migration", "schema change", "add column", "rename table", "drop column", or "migrate safely".
-
pramoddutta Skill Test Metrics Kpis And DashboardsDefine and build QA metrics that drive decisions, escape rate, flake rate, coverage of risk, MTTR for test failures, release readiness scorecards, anti-gaming rules, and dashboard layouts with SQL and query examples.
-
tryboy869 Bundle Duckdb[Applies to: **/*] This guide provides opinionated, actionable best practices for writing high-performance, maintainable, and robust DuckDB SQL queries and scripts, focusing on modern analytical workloads.
-
tonone-ai Skill Lens DashboardDesign and spec an analytical dashboard — define the question each chart answers, write the SQL queries, spec the layout and refresh cadence. Produces a complete dashboard spec ready to implement. Use when asked to "build a dashboard", "analytics dashboard", "BI dashboard", "weekly product health", or "visualize this data".
-
tonone-ai Skill Lumen InstrumentInstrumentation plan — design event taxonomy, property schema, and tracking plan for analytics tools. Use when asked to "what should we track", "instrumentation plan", "set up analytics events", "analytics event schema", "tracking plan", or "instrument this feature".
-
abelrguezr Bundle Document SteganographyAnalyze documents for hidden steganographic content. Use this skill whenever the user needs to extract hidden data from PDFs, Office files (.docx/.xlsx/.pptx), or other document formats. Trigger on requests to find hidden files, extract embedded content, analyze document structures, or investigate suspicious documents in CTFs, forensics, or security research.
-
abelrguezr Bundle Sqlmap PentestSQL injection testing with sqlmap. Use this skill whenever the user needs to test for SQL injection vulnerabilities, enumerate databases, extract data from vulnerable applications, or bypass WAFs with sqlmap. Trigger on any mention of SQL injection testing, sqlmap commands, database enumeration, WAF bypass, or web application security testing involving SQL. Don't wait for explicit "use sqlmap" - if they're testing SQLi or need database extraction, this skill applies.
-
abelrguezr Bundle Splunkd PentestHow to pentest Splunkd services (port 8089) for vulnerability assessment and exploitation. Use this skill whenever the user mentions Splunk, port 8089, Splunkd, log analytics security testing, or needs to assess Splunk installations for vulnerabilities including RCE, credential weaknesses, and free version exploitation. Trigger for any Splunk security assessment, penetration testing, or vulnerability research tasks.
-
abelrguezr Bundle Login BypassHow to systematically test and bypass web login mechanisms. Use this skill whenever the user mentions login pages, authentication bypass, web security testing, pentesting login forms, credential testing, or any scenario involving web application authentication. This includes SQL injection login bypass, NoSQL injection, XPath injection, LDAP injection, parameter manipulation, and remember me functionality abuse. Trigger this skill for any web security assessment involving authentication.
-
abelrguezr Bundle SQL Injection TestingSQL injection vulnerability testing and exploitation guide. Use this skill whenever the user mentions SQL injection, SQLi, database injection, SQL vulnerability testing, penetration testing of web applications, authentication bypass, WAF bypass, or any security testing involving database queries. This skill provides detection methods, exploitation techniques, and payloads for MySQL, PostgreSQL, MSSQL, Oracle, SQLite, and other databases. Trigger this skill for any SQL injection related security assessment, even if the user doesn't explicitly say "SQL injection" but describes symptoms like unusual database behavior, query manipulation, or database exfiltration.
-
abelrguezr Bundle Sqlmap AssistantSQLMap automation and SQL injection testing assistant. Use this skill whenever the user needs to test for SQL injection vulnerabilities, run SQLMap commands, extract database information, or perform web application security testing. Trigger on mentions of SQLMap, SQL injection, database exploitation, web security testing, penetration testing, or any request to audit web applications for database vulnerabilities.
-
abelrguezr Bundle Dcom Lateral MovementUse DCOM objects for Windows lateral movement in authorized security assessments. Use this skill whenever you need to move laterally between Windows systems, execute commands remotely via DCOM, or enumerate DCOM applications. Trigger this skill for any Windows penetration testing task involving remote code execution, DCOM exploitation, MMC20.Application, ShellWindows, Excel DCOM objects, or when you have admin credentials and need to pivot to other systems.
-
abelrguezr Bundle SQL Login BypassSQL injection payloads for testing login form vulnerabilities. Use this skill when you need to test for SQL injection vulnerabilities in authentication forms, when analyzing login bypass techniques, or when conducting authorized penetration testing on web applications. This skill provides a comprehensive collection of SQL injection payloads for XPath, LDAP, and SQL injection attacks. Make sure to use this skill whenever the user mentions SQL injection, login bypass, authentication testing, web security testing, or penetration testing on login forms.
-
abelrguezr Bundle Mssql InjectionMSSQL SQL injection exploitation techniques including Active Directory enumeration, SSRF via MSSQL functions, WAF bypass methods, and data exfiltration. Use this skill whenever the user mentions MSSQL, Microsoft SQL Server, SQL injection against MSSQL databases, or needs to enumerate domain users, bypass WAFs, or exfiltrate data from MSSQL servers. Trigger for any MSSQL-specific injection scenarios, not just generic SQL injection.
-
abelrguezr Bundle Oracle SQL InjectionOracle SQL injection exploitation techniques for SSRF, OOB exfiltration, and internal reconnaissance. Use this skill whenever the user mentions Oracle databases, SQL injection against Oracle, DBMS packages, UTL_HTTP, UTL_TCP, DBMS_CLOUD, or needs to perform out-of-band attacks, port scanning, or metadata extraction from Oracle databases. Make sure to use this skill for any Oracle-specific injection scenarios, even if the user doesn't explicitly mention 'Oracle' but describes symptoms like ORA- error codes or PL/SQL packages.
-
abelrguezr Bundle Postgresql PentestingPostgreSQL database penetration testing and exploitation. Use this skill whenever the user needs to enumerate, exploit, or escalate privileges in PostgreSQL databases. Trigger on mentions of PostgreSQL, pgsql, port 5432, database pentesting, SQL injection against PostgreSQL, privilege escalation in databases, or any PostgreSQL security assessment tasks. This skill covers connection enumeration, privilege analysis, file system access, RCE techniques, and post-exploitation.
-
abelrguezr Bundle Grafana PentestPentest Grafana instances for misconfigurations and CVE-2024-9264 SQL Expressions RCE/LFI vulnerability. Use this skill whenever you need to assess Grafana security, check for exposed credentials in config files, enumerate data sources, or test for the CVE-2024-9264 vulnerability that allows authenticated users to execute arbitrary commands via DuckDB shellfs extension. Trigger this skill for any Grafana security assessment, penetration test, or vulnerability scan.
-
abelrguezr Bundle Cypher Injection Neo4jHow to identify, test for, and exploit Cypher injection vulnerabilities in Neo4j graph databases. Use this skill whenever the user mentions Neo4j, graph databases, Cypher queries, database injection testing, or needs to assess graph database security. This skill covers reconnaissance, vulnerability identification, payload crafting, and exploitation techniques for Cypher injection attacks. Make sure to use this skill for any Neo4j security assessment, penetration testing, or when analyzing applications that interact with graph databases.
-
abelrguezr Bundle Ms Access SqliUse this skill whenever testing for SQL injection vulnerabilities in MS Access databases, including Jet/ACE database engines. Trigger on any mention of MS Access, .mdb files, Access database, or SQL injection testing against legacy ASP applications. This skill covers enumeration, data extraction, and advanced exploitation techniques specific to MS Access.
Frequently asked questions
What are Data & Analytics agent skills?
Data agent skills make AI agents useful for data work: writing SQL, cleaning datasets, building pipelines, working with spreadsheets, and producing analyses. Each skill is a reviewed SKILL.md file that teaches the agent one workflow well, ready to install in seconds.
Which Data & Analytics skills are most installed?
Popular Data & Analytics skills on SkillMD right now include document-steganography, sqlmap-pentest, splunkd-pentest. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Data & Analytics skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.