GPTsApp PluginsCodex Reset
Menu

Hosted preview

WORKFLOW PACKAGES · FREE DISCOVERY

Find the right plugin.

Know what it includes, what it needs, and where to install it.

47 packages

Review security · Page 2 of 4

Coverage & limits
Claude Codev2.0.1 · manifest

Insecure Defaults

Inspect a workflow for reviewing default configuration choices and candidate failure cases.

Source: trailofbits/skills
plugins/insecure-defaults · Independent maintainer marketplace

Includes Composition not yet established — not zero components

Manifest observed; full component inventory, installed tools, provider access and task permissions remain unverified.

Matches this task · Manifest fields inspected · Not a runtime test
Claude Codev1.1.0 · manifest

Rust Review

Review Rust safety boundaries and concurrency concerns using a separately maintained package.

Source: trailofbits/skills
plugins/rust-review · Independent maintainer marketplace

Includes Composition not yet established — not zero components

Manifest observed; full component inventory, installed tools, provider access and task permissions remain unverified.

Matches this task · Manifest fields inspected · Not a runtime test
Claude Codev1.2.4 · manifest

Semgrep Rule Creator

Draft and test Semgrep detection rules for a stated code pattern.

Source: trailofbits/skills
plugins/semgrep-rule-creator · Independent maintainer marketplace

Includes Composition not yet established — not zero components

Manifest observed; full component inventory, installed tools, provider access and task permissions remain unverified.

Matches this task · Manifest fields inspected · Not a runtime test
Claude Codev1.1.1 · manifest

Semgrep Rule Variant Creator

Assess how a detection rule should change for another programming language.

Source: trailofbits/skills
plugins/semgrep-rule-variant-creator · Independent maintainer marketplace

Includes Composition not yet established — not zero components

Manifest observed; full component inventory, installed tools, provider access and task permissions remain unverified.

Matches this task · Manifest fields inspected · Not a runtime test
Claude Codev1.1.1 · manifest

Sharp Edges

Review API and configuration choices that are easy to misuse.

Source: trailofbits/skills
plugins/sharp-edges · Independent maintainer marketplace

Includes Composition not yet established — not zero components

Manifest observed; full component inventory, installed tools, provider access and task permissions remain unverified.

Matches this task · Manifest fields inspected · Not a runtime test
Claude Codev1.4.3 · manifest

Static Analysis

Find source-listed CodeQL, Semgrep and SARIF review workflows without assuming the tools are present.

Source: trailofbits/skills
plugins/static-analysis · Independent maintainer marketplace

Includes Composition not yet established — not zero components

Manifest observed; full component inventory, installed tools, provider access and task permissions remain unverified.

Matches this task · Manifest fields inspected · Not a runtime test
Claude Codev2.0.2 · manifest

Supply Chain Risk Auditor

Inspect dependency-review guidance for package advisories, maintainers and install-script exposure.

Source: trailofbits/skills
plugins/supply-chain-risk-auditor · Independent maintainer marketplace

Includes Composition not yet established — not zero components

Manifest observed; full component inventory, installed tools, provider access and task permissions remain unverified.

Matches this task · Manifest fields inspected · Not a runtime test
Claude Codev1.2.0 · manifest

Testing Handbook Skills

Explore application-testing handbook workflows; the full bundled inventory has not been enumerated.

Source: trailofbits/skills
plugins/testing-handbook-skills · Independent maintainer marketplace

Includes Composition not yet established — not zero components

Manifest observed; full component inventory, installed tools, provider access and task permissions remain unverified.

Matches this task · Manifest fields inspected · Not a runtime test
Claude Codev0.11.2 · manifest

Trailmark

Inspect code-graph analysis workflows for call paths, source context and review scoping.

Source: trailofbits/skills
plugins/trailmark · Independent maintainer marketplace

Includes Composition not yet established — not zero components

Manifest observed; full component inventory, installed tools, provider access and task permissions remain unverified.

Matches this task · Manifest fields inspected · Not a runtime test
Claude Codev2.0.2 · manifest

Variant Analysis

Look for a workflow that checks related code patterns after a candidate finding.

Source: trailofbits/skills
plugins/variant-analysis · Independent maintainer marketplace

Includes Composition not yet established — not zero components

Manifest observed; full component inventory, installed tools, provider access and task permissions remain unverified.

Matches this task · Manifest fields inspected · Not a runtime test
Claude Codev0.1.1 · manifest

Vulnerability Triage Brocards

Find structured guidance for triaging submitted security findings before deeper review.

Source: trailofbits/skills
plugins/vulnerability-triage-brocards · Independent maintainer marketplace

Includes Composition not yet established — not zero components

Manifest observed; full component inventory, installed tools, provider access and task permissions remain unverified.

Matches this task · Manifest fields inspected · Not a runtime test
Claude Codev2.1.1 · manifest

Yara Authoring

Inspect YARA-X rule-writing and validation guidance for defensive detection work.

Source: trailofbits/skills
plugins/yara-authoring · Independent maintainer marketplace

Includes Composition not yet established — not zero components

Manifest observed; full component inventory, installed tools, provider access and task permissions remain unverified.

Matches this task · Manifest fields inspected · Not a runtime test
Compare packages for the same taskSelect 2–4 candidates. No winner or score.
A directory you can inspect.

Snapshot assembled 2026-09-12; each package retains its actual observation date. Component lists can be partial; account access and task success remain unknown until you verify them in your own environment.