trailofbits/skills-curated

Curated, community-vetted Claude Code plugin marketplace

494Stars on the repository
66Mods indexed here, across every type
1mo agoLast push, which is what freshness is scored on
CC-BY-SA-4.0Licence, which decides whether bodies are shown

security-awareness

01

trailofbits/skills-curated

Skill Claude CodeCodex

Teaches agents to recognize and avoid security threats during normal activity. Covers phishing detection, credential protection, domain verification, and social engineering defense. Use when building or operating agents that access email, credential vaults, web browsers, or sensitive data.

not rated 494 1mo ago A 52 tokens CC-BY-SA-4.0

skill-extractor

02

trailofbits/skills-curated

Skill Claude CodeCodex

Extracts reusable skills from work sessions. Use when: (1) a non-obvious problem was solved worth preserving, (2) a pattern was discovered that would help future sessions, (3) a workaround or debugging technique needs documentation. Manual invocation only via /skill-extractor command - no automatic triggers or hooks.

not rated 494 1mo ago B 68 tokens CC-BY-SA-4.0

wooyun-legacy

03

trailofbits/skills-curated

Skill Claude CodeCodex

Provides web vulnerability testing methodology distilled from 88,636 real-world cases from the WooYun vulnerability database (2010-2016). Use when performing penetration testing, security audits, code reviews for security flaws, or vulnerability research. Covers SQL injection, XSS, command execution, file upload, path…

not rated 494 1mo ago B 80 tokens CC-BY-SA-4.0

x-research

04

trailofbits/skills-curated

Skill Claude CodeCodex

Searches X/Twitter for real-time perspectives, dev discussions, product feedback, breaking news, and expert opinions using the X API v2. Provides search with engagement sorting, user profiles, thread fetching, watchlists, and result caching. Use when: (1) user says "x research", "search x for", "search twitter for"…

not rated 494 1mo ago A 148 tokens CC-BY-SA-4.0

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: