Official agent skill

Auditing External Claude Plugins

by bitwarden in bitwarden/ai-plugins

Audits an external (third-party) Claude Code plugin pinned in this marketplace for security risk before it is vendored, and writes the report to a file for downstream posting.

OfficialCustom licenceAuto-check passedSecurity

Install Auditing External Claude Plugins

skills CLI
$ npx skills add bitwarden/ai-plugins --skill auditing-external-claude-plugins -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install bitwarden/ai-plugins auditing-external-claude-plugins --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/bitwarden/ai-plugins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/bitwarden-security-engineer/skills/auditing-external-claude-plugins .claude/skills/auditing-external-claude-plugins && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
auditing-external-claude-plugins
GitHub stars
154
Token cost
~1.8k tokens
SKILL.md length
618 words
Files
5 (incl. scripts)
Skills in repo
33
Repo updated
First seen
Licence
Custom licence

At a glance

Audits an external (third-party) Claude Code plugin pinned in this marketplace for security risk before it is vendored, and writes the report to a file for downstream posting.

  • Works in 6 steps: Run… → Invoke… → Audit each of the following. Two are… → …
  • Asked to audit an external plugin
  • Runs Shell scripts from its folder; calls gh and go
  • Audit a vendored plugin

What it does

Auditing External Claude Plugins is an agent skill from bitwarden/ai-plugins, published by the product's own GitHub organization. Audits an external (third-party) Claude Code plugin pinned in this marketplace for security risk before it is vendored, and writes the report to a file for downstream posting. Use when asked to "audit an external plugin", "audit a vendored plugin", "run a plugin security audit", or when a new or updated external plugin pin needs a pre-merge security review.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts (for example `scripts/beautify.sh`, `scripts/gather-evidence.sh` and `scripts/package-lock.json`).

It sits in Security, covering Security review and Hooks and plugins. The repository describes itself as: AI plugin marketplace.

When your agent uses it

  • Asked to audit an external plugin
  • Audit a vendored plugin
  • Run a plugin security audit
  • Updated external plugin pin needs a pre-merge security review

Example prompts

  • “audit an external plugin”
  • “audit a vendored plugin”
  • “run a plugin security audit”
  • “/auditing-external-claude-plugins”

Requirements

  • A Bash shell
  • Pre-approved tools (allowed-tools): Bash(${CLAUDE_SKILL_DIR}/scripts/gather-evidence.sh *), Bash(${CLAUDE_SKILL_DIR}/scripts/beautify.sh *), Bash(grep *), Bash(jq *), Bash(file *), Bash(go version *), Bash(strings *), Bash(shasum *), Read, Write, Skill

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Run ${CLAUDE_SKILL_DIR}/scripts/gather-evidence.sh $plugin-repo-url $commit-sha. It ends with an inventory of what it gathered…
  2. Invoke Skill(bitwarden-security-context), Skill(detecting-secrets), Skill(analyzing-code-security), and Skill(reviewing-dependencies) to…
  3. Audit each of the following. Two are required regardless of what else is found; resolve each to a numbered finding or an explicit clean…
  4. Resolve OUTPUT_FILE: use $output-file if given, otherwise ${CLAUDE_PLUGIN_DATA}/plugin-audits/{plugin}-{short-sha}-{date}.md, where…
  5. Write the report to OUTPUT_FILE using this exact structure. Every section is required, in this order
  6. Confirm OUTPUT_FILE as your final line. Do not post to GitHub or run any gh pr comment/gh api mutation.

What it can do on your machine

Read from SKILL.md and the folder at commit 53e22a3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash(${CLAUDE_SKILL_DIR}/scripts/gather-evidence.sh *)
    • Bash(${CLAUDE_SKILL_DIR}/scripts/beautify.sh *)
    • Bash(grep *)
    • Bash(jq *)
    • Bash(file *)
    • Bash(go version *)
    • Bash(strings *)
    • Bash(shasum *)
    • Read
    • Write

    …and 1 more on the same allowed-tools line.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 4 files in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • gh
    • go

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Auditing External Claude Plugins loads about 1.8k tokens when it runs. Until then it costs about 98 tokens; SKILL.md has 618 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~98
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 618 words (~1,752 tokens).

“Audit the external Claude Code plugin at $plugin-repo-url, commit $commit-sha, for security risk before it is vendored into this marketplace.”

— opening of SKILL.md by bitwarden, Custom licence
name
auditing-external-claude-plugins
allowed-tools
Bash(${CLAUDE_SKILL_DIR}/scripts/gather-evidence.sh *), Bash(${CLAUDE_SKILL_DIR}/scripts/beautify.sh *), Bash(grep *), Bash(jq *), Bash(file *), Bash(go version *), Bash(strings *), Bash(shasum *), Read, Write, Skill
argument-hint
<plugin-repo-url> <commit-sha> [output-file]
arguments
plugin-repo-url, commit-sha, output-file
context
fork
agent
bitwarden-security-engineer:bitwarden-security-engineer
model
fable
background
false

Read the full SKILL.md on GitHub

Files

SKILL.md and 4 other files (scripts) in plugins/bitwarden-security-engineer/skills/auditing-external-claude-plugins of bitwarden/ai-plugins.

  • SKILL.md
  • scripts/beautify.sh
  • scripts/gather-evidence.sh
  • scripts/package-lock.json
  • scripts/package.json

Open the folder on GitHubat commit 53e22a3

Compare with similar skills

Auditing External Claude Plugins next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Auditing External Claude Plugins compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Auditing External Claude Plugins this skillbitwarden/ai-plugins154—~1.8kAutomated safety check: PassCustom licence
Plugin Auditorjeremylongshore/tons-of-skills-marketplace2.8k—~1.5kAutomated safety check: NotesMIT
Performing Security Code Reviewjeremylongshore/tons-of-skills-marketplace2.8k2 repos~1.3kAutomated safety check: NotesMIT
Openiap Workflowshyodotdev/openiap154—~766Automated safety check: PassMIT
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Kubernetes Network Security Auditkubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0

Similar skills

  • Plugin Auditor

    jeremylongshore/tons-of-skills-marketplace

    Audit automatically audits AI assistant code plugins for security vulnerabilities, best practices, AI assistant.md compliance, and quality standards when user mentions audit plugin, security review…

    2.8k GitHub stars~1.5k tokensUpdated today
    SecurityAuto-check: notes
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    SecurityAuto-check: notes
  • Openiap Workflows

    hyodotdev/openiap

    A skill your agent uses for OpenIAP monorepo work that should follow the repository's slash-command workflows when the user asks in natural language instead of typing a slash command, including…

    154 GitHub stars~766 tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 9 days ago
    SecurityAuto-check passed
  • Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

    12k GitHub stars~7.3k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Agentlas Security Scan

    agentlas-ai/Agentlas-OS

    A skill your agent uses when an agent folder must pass the Agentlas Cloud 2-stage security scan (static rules + BYOK LLM judgment) before private sync or public publish, or when asked to…

    1.6k GitHub starsUsed in 1 repo~822 tokens
    SecurityAuto-check passed

More from bitwarden/ai-plugins

All 33 skills in this repo
  • Reviewing Claude Config

    bitwarden/ai-plugins

    Official

    Reviews Claude configuration files for security, structure, and prompt engineering quality.

    154 GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Managing Workflow Secrets

    bitwarden/ai-plugins

    Official

    Bitwarden's canonical pattern for using a secret inside a GitHub Actions job: authenticate to Azure with the OIDC triad, pull the secret from an Azure Key Vault via the bitwarden/gh-actions…

    154 GitHub stars~4k tokensUpdated today
    Auto-check passed
  • Official

    This skill should be used when the user asks to "review the security architecture", "check authentication patterns", "evaluate trust boundaries", "review encryption implementation", "assess…

    154 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Action Audit

    bitwarden/ai-plugins

    Official

    Audit GitHub Actions action usage across an org. An agent skill from bitwarden/ai-plugins.

    154 GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • Action Remediate

    bitwarden/ai-plugins

    Official

    Remediate GitHub Actions action findings identified by the action-audit skill.

    154 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Official

    A skill your agent uses when the user is addressing pull request review comments locally and asks for help evaluating, implementing, or drafting responses to reviewer feedback - requires technical…

    154 GitHub stars~1.9k tokensUpdated today
    Auto-check passed

Categories

Questions about Auditing External Claude Plugins

What does Auditing External Claude Plugins do?

Audits an external (third-party) Claude Code plugin pinned in this marketplace for security risk before it is vendored, and writes the report to a file for downstream posting. Auditing External Claude Plugins is an agent skill from bitwarden/ai-plugins, published by the product's own GitHub organization. Audits an external (third-party) Claude Code plugin pinned in this marketplace for security risk before it is vendored, and writes the report to a file for downstream posting.

When should I use Auditing External Claude Plugins?

Auditing External Claude Plugins fits situations like: asked to audit an external plugin; audit a vendored plugin; run a plugin security audit; updated external plugin pin needs a pre-merge security review.

How do I install Auditing External Claude Plugins in Claude Code?

Run `npx skills add bitwarden/ai-plugins --skill auditing-external-claude-plugins -a claude-code`. Or copy the skill folder (plugins/bitwarden-security-engineer/skills/auditing-external-claude-plugins in bitwarden/ai-plugins) into .claude/skills/auditing-external-claude-plugins in your project. Claude Code loads it when a task matches its description.

How do I install Auditing External Claude Plugins in Codex?

Run `npx skills add bitwarden/ai-plugins --skill auditing-external-claude-plugins -a codex`. Or copy the skill folder (plugins/bitwarden-security-engineer/skills/auditing-external-claude-plugins in bitwarden/ai-plugins) into .agents/skills/auditing-external-claude-plugins in your project. Codex loads it when a task matches its description.

Can I use Auditing External Claude Plugins in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add bitwarden/ai-plugins --skill auditing-external-claude-plugins -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/auditing-external-claude-plugins, .gemini/skills/auditing-external-claude-plugins, .github/skills/auditing-external-claude-plugins and .opencode/skills/auditing-external-claude-plugins in your project.

What does Auditing External Claude Plugins need to run?

Going by SKILL.md and its folder, Auditing External Claude Plugins needs a shell for the scripts in its folder and the command-line tools its instructions call (gh and go). Our summary lists: A Bash shell. Its frontmatter pre-approves these tools: Bash(${CLAUDE_SKILL_DIR}/scripts/gather-evidence.sh *), Bash(${CLAUDE_SKILL_DIR}/scripts/beautify.sh *), Bash(grep *), Bash(jq *), Bash(file *), Bash(go version *), Bash(strings *), Bash(shasum *), Read, Write, Skill.

Does Auditing External Claude Plugins access the network?

SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Auditing External Claude Plugins safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Auditing External Claude Plugins use?

Auditing External Claude Plugins has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Auditing External Claude Plugins use?

About 1.8k tokens (SKILL.md is roughly 7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Auditing External Claude Plugins?

Skills that share tags, products or a category with Auditing External Claude Plugins: Plugin Auditor (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Performing Security Code Review (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Openiap Workflows (hyodotdev/openiap, 154 stars) and Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Auditing External Claude Plugins?

bitwarden (a GitHub organization, an official publisher) maintains it in bitwarden/ai-plugins, which has 154 GitHub stars. The repository holds 33 skills in this directory. The repository was last updated on October 8, 2026.

Source: bitwarden/ai-plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.