github.com/openai/plugins
| Skill | Added | Review |
|---|---|---|
triage-finding plugins/codex-security/skills/triage-finding/SKILL.md Use when the user supplies or imports existing security findings, vulnerability reports, or security/vulnerability Jira/Linear tickets from scanners, advisories, GitHub, Atlassian Rovo, Linear, or similar backlog sources and wants static repo-impact triage. Do not use for discovery, duplicate-bug triage, validation, or fixes. | 72 72 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 11c74d6 | |
track-findings plugins/codex-security/skills/track-findings/SKILL.md Track validated Codex Security findings in Linear, Jira, GitHub issues, or draft GitHub security advisories. Use it for one finding or an explicitly selected batch of up to 25 findings tracked as Linear, Jira, or GitHub issues. Includes duplicate checks, exact previews, approval-gated writes, and readback. Do not use it for scans or fixes. | 68 68 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 11c74d6 | |
threat-model plugins/codex-security/skills/threat-model/SKILL.md Use when Codex is already in the threat-modeling phase of a security scan, the user explicitly invokes $threat-model, or the user explicitly asks to create, update, or persist a repository threat model. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans. | 75 75 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 11c74d6 | |
security-scan plugins/codex-security/skills/security-scan/SKILL.md Use for a standard, single-pass security audit of an entire repository or a scoped path, package folder, or submodule with no diff to review. This is the default repository scan. Do not use for PR/commit/branch/working-tree diffs, or for deep, multi-pass, or variance-reducing scans. | 69 69 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 11c74d6 | |
security-diff-scan plugins/codex-security/skills/security-diff-scan/SKILL.md Use when the user asks for a security review of a pull request, commit, branch diff, working-tree patch, or other Git-backed change set. | 69 69 Impact — No eval scenarios have been run Securityby High Do not use without reviewing Version: 11c74d6 | |
propose-security-hardening plugins/codex-security/skills/propose-security-hardening/SKILL.md Develop evidence-backed structural and architectural security hardening proposals from vulnerability disclosures, supplied findings, incident or assessment documents, source code, or a completed Codex Security scan. Use when a user asks for systemic improvements, alternatives beyond per-finding patches, before-and-after security architecture views, engineering tradeoff analysis, or an implementation-ready plan for a selected hardening option. Also use automatically after a Codex Security scan with reportable findings when the top-level scan workflow requests final-report hardening guidance. | 75 75 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 11c74d6 | |
fix-finding plugins/codex-security/skills/fix-finding/SKILL.md Use when the user explicitly asks to fix and verify a validated or plausible security finding. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans. | 64 64 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 11c74d6 | |
finding-discovery plugins/codex-security/skills/finding-discovery/SKILL.md Use when Codex is already in the finding-discovery phase of a security scan or the user explicitly asks to discover candidate security findings in a repository or code change. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans. | 65 65 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 11c74d6 | |
deep-security-scan plugins/codex-security/skills/deep-security-scan/SKILL.md Use when the user asks for a deep, exhaustive, multi-pass, or variance-reducing repository-wide or scoped-path Codex Security scan. Run repeated independent discovery passes over one resolved scope with worker-specific threat models, semantically merge candidates, synthesize one canonical validation threat model, then run validation, attack-path analysis, canonical JSON completion, and generated reporting once. Do not use for PRs, commits, branch diffs, or working-tree diffs. | 61 61 Impact — No eval scenarios have been run Securityby High Do not use without reviewing Version: 11c74d6 | |
attack-path-analysis plugins/codex-security/skills/attack-path-analysis/SKILL.md Use when Codex is already in the attack-path-analysis phase of a security scan or the user explicitly asks to trace a security finding from source to sink and calibrate severity. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans. | 70 70 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 11c74d6 | |
code-review plugins/coderabbit/skills/coderabbit-review/SKILL.md Reviews code changes using CodeRabbit AI. Use when user asks for code review, PR feedback, code quality checks, security issues, or requests fix-review cycles. | 76 76 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 11c74d6 | |
wrangler plugins/cloudflare/skills/wrangler/SKILL.md Cloudflare Workers CLI for deploying, developing, and managing Workers, KV, R2, D1, Vectorize, Hyperdrive, Workers AI, Containers, Queues, Workflows, Pipelines, and Secrets Store. Load before running wrangler commands to ensure correct syntax and best practices. Biases towards retrieval from Cloudflare docs over pre-trained knowledge. | 68 68 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 11c74d6 | |
workers-best-practices plugins/cloudflare/skills/workers-best-practices/SKILL.md Reviews and authors Cloudflare Workers code against production best practices. Load when writing new Workers, reviewing Worker code, configuring wrangler.jsonc, or checking for common Workers anti-patterns (streaming, floating promises, global state, secrets, bindings, observability). Biases towards retrieval from Cloudflare docs over pre-trained knowledge. | 75 75 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 11c74d6 | |
web-perf plugins/cloudflare/skills/web-perf/SKILL.md Analyzes web performance using Chrome DevTools MCP. Measures Core Web Vitals (FCP, LCP, TBT, CLS, Speed Index), identifies render-blocking resources, network dependency chains, layout shifts, caching issues, and accessibility gaps. Use when asked to audit, profile, debug, or optimize page load performance, Lighthouse scores, or site speed. Biases towards retrieval from current documentation over pre-trained knowledge. | 99 99 1.15x Agent success vs baseline Impact 95% 1.15xAverage score across 3 eval scenarios Securityby Low Low-risk findings worth noting Reviewed: Version: 11c74d6 | |
sandbox-sdk plugins/cloudflare/skills/sandbox-sdk/SKILL.md Build sandboxed applications for secure code execution. Load when building AI code execution, code interpreters, CI/CD systems, interactive dev environments, or executing untrusted code. Covers Sandbox SDK lifecycle, commands, files, code interpreter, and preview URLs. Biases towards retrieval from Cloudflare docs over pre-trained knowledge. | 96 96 2.63x Agent success vs baseline Impact 100% 2.63xAverage score across 3 eval scenarios Securityby Passed No findings from the security scan Reviewed: Version: 11c74d6 | |
durable-objects plugins/cloudflare/skills/durable-objects/SKILL.md Create and review Cloudflare Durable Objects. Use when building stateful coordination (chat rooms, multiplayer games, booking systems), implementing RPC methods, SQLite storage, alarms, WebSockets, or reviewing DO code for best practices. Covers Workers integration, wrangler config, and testing with Vitest. Biases towards retrieval from Cloudflare docs over pre-trained knowledge. | 95 95 1.40x Agent success vs baseline Impact 98% 1.40xAverage score across 3 eval scenarios Securityby Passed No findings from the security scan Reviewed: Version: 11c74d6 | |
cloudflare plugins/cloudflare/skills/cloudflare/SKILL.md Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), networking (Tunnel, Spectrum), security (WAF, DDoS), and infrastructure-as-code (Terraform, Pulumi). Use for any Cloudflare development task. Biases towards retrieval from Cloudflare docs over pre-trained knowledge. | 79 79 Impact — No eval scenarios have been run Securityby — The risk profile of this skill Version: 11c74d6 | |
building-mcp-server-on-cloudflare plugins/cloudflare/skills/building-mcp-server-on-cloudflare/SKILL.md Builds remote MCP (Model Context Protocol) servers on Cloudflare Workers with tools, OAuth authentication, and production deployment. Generates server code, configures auth providers, and deploys to Workers. Use when: user wants to "build MCP server", "create MCP tools", "remote MCP", "deploy MCP", add "OAuth to MCP", or mentions Model Context Protocol on Cloudflare. Also triggers on "MCP authentication" or "MCP deployment". Biases towards retrieval from Cloudflare docs over pre-trained knowledge. | 80 80 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 11c74d6 | |
building-ai-agent-on-cloudflare plugins/cloudflare/skills/building-ai-agent-on-cloudflare/SKILL.md Builds AI agents on Cloudflare using the Agents SDK with state management, real-time WebSockets, scheduled tasks, tool integration, and chat capabilities. Generates production-ready agent code deployed to Workers. Use when: user wants to "build an agent", "AI agent", "chat agent", "stateful agent", mentions "Agents SDK", needs "real-time AI", "WebSocket AI", or asks about agent "state management", "scheduled tasks", or "tool calling". Biases towards retrieval from Cloudflare docs over pre-trained knowledge. | 90 90 1.00x No change in agent success vs baseline Impact 100% 1.00xAverage score across 3 eval scenarios Securityby Low Low-risk findings worth noting Reviewed: Version: 11c74d6 | |
agents-sdk plugins/cloudflare/skills/agents-sdk/SKILL.md Build AI agents on Cloudflare Workers using the Agents SDK. Load when creating stateful agents, durable workflows, real-time WebSocket apps, scheduled tasks, MCP servers, or chat applications. Covers Agent class, state management, callable RPC, Workflows integration, and React hooks. Biases towards retrieval from Cloudflare docs over pre-trained knowledge. | 95 95 2.20x Agent success vs baseline Impact 99% 2.20xAverage score across 3 eval scenarios Securityby Low Low-risk findings worth noting Reviewed: Version: 11c74d6 | |
circleci-config plugins/circleci/skills/config/SKILL.md Optimize CircleCI configuration for speed, reliability, and maintainability. Use when users ask to improve `.circleci/config.yml`, reduce CI runtime, tune caching/workspaces/parallelism, remove pipeline waste, or fix flaky pipeline behavior caused by configuration choices. | 70 70 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 11c74d6 | |
circleci-cli plugins/circleci/skills/cli/SKILL.md Operate and troubleshoot CircleCI using the CircleCI CLI. Use when users ask to authenticate CLI access, inspect pipeline/workflow/job status, validate configuration locally, rerun pipelines/jobs, trigger pipelines, or gather actionable diagnostics from CLI outputs. | 75 75 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 11c74d6 | |
chunk plugins/circleci/skills/chunk/SKILL.md Use CircleCI Chunk for AI-assisted CI/CD work through either the Chunk web UI or the chunk-cli. Trigger this skill when users ask to set up Chunk, troubleshoot or fix failing builds with Chunk, configure Chunk environments, schedule/proactively run Chunk tasks, or use chunk-cli commands such as init, validate, build-prompt, auth, sandbox, task, and skill install. | 75 75 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 11c74d6 | |
circleci-builds plugins/circleci/skills/builds/SKILL.md Diagnose and fix failing CircleCI builds quickly and safely. Use when users ask to investigate failed CircleCI jobs, triage flaky pipelines, identify root causes from logs, and implement minimal fixes in configuration, test setup, or build-related code paths. | 68 68 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 11c74d6 | |
chronograph-gp-meeting-prep plugins/chronograph-lp/skills/chronograph-gp-meeting-prep/SKILL.md Prepare an LP to meet with their fund manager (GP): review the fund's latest reporting, surface what changed since last period, and draft the questions worth raising. Use when someone is getting ready for a manager call, quarterly check-in, annual meeting, LPAC meeting, or a re-up decision — for example "I have my quarterly call with this manager next week, help me prep," "what changed in this fund this quarter," "what should I ask them about these marks," or "what are the red flags in this reporting package." Draws on Chronograph fund and portfolio data when connected — captured reporting such as fund performance, schedules of investments, and portfolio company KPI profiles — and asks the LP to provide anything else it needs, such as a capital account statement, investor letter, or AGM or board deck. | 75 75 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 11c74d6 |