Official agent skill

Skill Extractor

by trailofbits in trailofbits/skills-curated

Extracts reusable skills from work sessions. An agent skill from trailofbits/skills-curated.

OfficialCC-BY-SA-4.0Auto-check passedDevelopment

Install Skill Extractor

skills CLI
$ npx skills add trailofbits/skills-curated --skill skill-extractor -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trailofbits/skills-curated skill-extractor --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trailofbits/skills-curated.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/skill-extractor/skills/skill-extractor .claude/skills/skill-extractor && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
skill-extractor
GitHub stars
512
Token cost
~1.9k tokens
SKILL.md length
883 words
Files
4 (incl. references)
Skills in repo
24
Repo updated
First seen
Licence
CC-BY-SA-4.0

At a glance

Extracts reusable skills from work sessions. An agent skill from trailofbits/skills-curated.

  • Works in 8 steps: Check for Existing Skills → Identify the Learning → Quality Assessment → …
  • A non-obvious problem was solved worth preserving
  • SKILL.md covers When to Use, When NOT to Use, Finding Extraction Candidates and Command, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Skill Extractor is an agent skill from trailofbits/skills-curated, published by the product's own GitHub organization. Extracts reusable skills from work sessions. Use when: (1) a non-obvious problem was solved worth preserving, (2) a pattern was discovered that would help future sessions, (3) a workaround or debugging technique needs documentation. Manual invocation only via /skill-extractor command - no automatic triggers or hooks.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/quality-guide.md`, `references/skill-lifecycle.md` and `references/skill-template.md`).

It sits in Development. The repository describes itself as: Curated, community-vetted Claude Code plugin marketplace. The licence is CC-BY-SA-4.0.

When your agent uses it

  • A non-obvious problem was solved worth preserving
  • A pattern was discovered that would help future sessions
  • Debugging technique needs documentation

Example prompts

  • “Use the skill-extractor skill to extract reusable skills from work sessions. An agent skill from trailofbits/skills-curated”
  • “/skill-extractor”

Requirements

  • Pre-approved tools (allowed-tools): Read, Write, Glob, Grep, WebSearch, AskUserQuestion

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Check for Existing Skills
  2. Identify the Learning
  3. Quality Assessment
  4. Gather Details
  5. Optional Research
  6. Generate the Skill
  7. Validate Before Saving
  8. Save the Skill

What it can do on your machine

Read from SKILL.md and the folder at commit 6d05be4. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Glob
    • Grep
    • WebSearch
    • AskUserQuestion

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Skill Extractor loads about 1.9k tokens when it runs, and up to ~3.9k if it reads all its reference files. Until then it costs about 84 tokens; SKILL.md has 883 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~84
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trailofbits/skills-curated at commit 6d05be4, republished under its CC-BY-SA-4.0 licence (© trailofbits). 883 words, ~1,926 tokens.

Download SKILL.mdSave it as .claude/skills/skill-extractor/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
skill-extractor
description
Extracts reusable skills from work sessions. Use when: (1) a non-obvious problem was solved worth preserving, (2) a pattern was discovered that would help future sessions, (3) a workaround or debugging technique needs documentation. Manual invocation only via /skill-extractor command - no automatic triggers or hooks.
allowed-tools
Read, Write, Glob, Grep, WebSearch, AskUserQuestion

Skill Extractor

Extracts reusable knowledge from work sessions and saves it as a Claude Code skill.

When to Use

  • Just solved a non-obvious problem through investigation
  • Discovered a workaround that required trial-and-error
  • Found a debugging technique that would help in similar situations
  • Learned a project-specific pattern worth preserving
  • Fixed an error where the root cause wasn't immediately apparent

When NOT to Use

  • Simple documentation lookups (just bookmark the docs)
  • Trivial fixes (typos, obvious errors)
  • One-off project-specific configurations
  • Knowledge that's already well-documented elsewhere
  • Unverified solutions (wait until it actually works)

Finding Extraction Candidates

Use these prompts to identify knowledge worth extracting:

  • "What did I just learn that wasn't obvious before starting?"
  • "If I faced this exact problem again, what would I wish I knew?"
  • "What error message or symptom led me here, and what was the actual cause?"
  • "Is this pattern specific to this project, or would it help in similar projects?"
  • "What would I tell a colleague who hits this same issue?"

If you can't answer at least two of these with something non-trivial, it's probably not worth extracting.

Command

/skill-extractor [--project] [context hint]
  • Default: saves to ~/.claude/skills/[name]/SKILL.md
  • --project: saves to .claude/skills/[name]/SKILL.md
  • Context hint helps focus extraction (e.g., /skill-extractor the cyclic data DoS fix)

Extraction Process

Step 0: Check for Existing Skills

Before creating a new skill, search for existing ones that might cover the same ground:

bash
# Check user skills
ls ~/.claude/skills/

# Check project skills
ls .claude/skills/

# Search by keyword
grep -r "keyword" ~/.claude/skills/ .claude/skills/ 2>/dev/null

If a related skill exists, consider updating it instead of creating a new one. See skill-lifecycle.md for guidance on when to update vs create.

Step 1: Identify the Learning

If $ARGUMENTS contains a context hint (e.g., "the cyclic data DoS fix"), use it to focus the extraction on that specific topic.

Analyze the conversation to identify:

  • What problem was solved?
  • What made the solution non-obvious?
  • What would someone need to know to solve this faster next time?
  • What are the exact trigger conditions (error messages, symptoms)?

Present a brief summary to the user:

I identified this potential skill:

**Problem:** [Brief description]
**Key insight:** [What made it non-obvious]
**Triggers:** [Error messages or symptoms]
Step 2: Quality Assessment

Evaluate the candidate skill against these criteria:

CriterionPass?Evidence
Reusable - Helps future tasks, not just this instance[Why]
Non-trivial - Required discovery, not docs lookup[Why]
Verified - Solution actually worked[Evidence]
Specific triggers - Exact error messages or scenarios[What they are]
Explains WHY - Trade-offs and judgment, not just steps[How]
Value-add - Teaches judgment, not just facts Claude could look up[How]

Present assessment to user and ask: "Proceed with extraction? [yes/no]"

The user decides whether to proceed regardless of how many criteria pass. Respect their judgment - if they say yes, extract; if no, skip.

Step 3: Gather Details

Ask the user:

  1. Skill name - Suggest a kebab-case name based on context, let them override
  2. Scope - User-level (default) or project-level (--project)
Step 4: Optional Research

If the topic involves a specific library or framework:

  • Use web search to find current best practices
  • Use Context7 MCP (if available) for official documentation
  • Include relevant sources in the References section

Skip research for:

  • Project-specific internal patterns
  • Generic programming concepts
  • Time-sensitive extractions
Step 5: Generate the Skill

Use the template from skill-template.md.

Quality standards: Follow quality-guide.md to ensure the skill provides lasting value. Key points:

  • Behavioral guidance over reference dumps
  • Explain WHY, not just WHAT
  • Specific triggers that compete well against other skills
Show full SKILL.md (354 more words)Show less
Step 6: Validate Before Saving

Run through the validation checklist in skill-template.md. If validation fails, fix the issues before saving.

Step 7: Save the Skill

Create the directory and save:

  • User-level: ~/.claude/skills/[name]/SKILL.md
  • Project-level: .claude/skills/[name]/SKILL.md

Report success:

Skill saved to: [path]

The skill will be available in future sessions when the context matches:
"[first line of description]"

Memory Consolidation

When extracting, consider how the new knowledge relates to existing skills:

Combine or separate?

  • Combine if the new knowledge is a variation or edge case of an existing skill
  • Separate if it has distinct trigger conditions or solves a fundamentally different problem
  • When in doubt, start separate - you can always merge later

Update vs create:

  • Update an existing skill when you've discovered additional edge cases, better solutions, or corrections
  • Create a new skill when the knowledge has different trigger conditions, even if the domain is related

Cross-referencing:

  • If skills are related but separate, add a "See also" section linking them
  • Example: A skill for "debugging connection pool exhaustion" might link to "serverless cold start optimization"

Skill Lifecycle

Skills aren't permanent. See skill-lifecycle.md for guidance on:

  • Updating skills with new discoveries
  • Deprecating skills when tools or patterns change
  • Archiving skills that are no longer relevant

Rationalizations to Reject

If you catch yourself thinking any of these, do NOT extract:

  • "This might be useful someday" - Only extract verified, reusable knowledge
  • "Let me just save everything" - Quality over quantity
  • "The user didn't confirm but it seems valuable" - Always get explicit confirmation
  • "I'll skip the 'When NOT to Use' section" - It's mandatory for good skills
  • "The description can be vague" - Specific triggers are essential for discovery

Example Extraction

Scenario: User discovered that an AST visitor crashes with RecursionError when analyzing serialized files containing cyclic references (e.g., a list that contains itself).

Identified learning:

  • Cyclic data structures create cyclic ASTs
  • Visitor pattern without cycle tracking causes infinite recursion
  • Need to track visited nodes or enforce depth limits

Generated skill name: cyclic-ast-visitor-hardening

Key sections:

  • When to Use: "RecursionError in AST visitor", "analyzing untrusted serialized input"
  • When NOT to Use: "Recursion from deeply nested (but acyclic) structures"
  • Problem: Visitor doesn't track visited nodes, enters infinite loop on cycles
  • Solution: Add visited: set parameter, check before recursing
  • Verification: Cyclic test case completes without RecursionError

© trailofbits, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in plugins/skill-extractor/skills/skill-extractor of trailofbits/skills-curated.

  • SKILL.md
  • references/quality-guide.md
  • references/skill-lifecycle.md
  • references/skill-template.md

Open the folder on GitHubat commit 6d05be4

Compare with similar skills

Skill Extractor next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Skill Extractor compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Skill Extractor this skilltrailofbits/skills-curated512—~1.9kAutomated safety check: PassCC-BY-SA-4.0
Vercel Composition Patternssupabase/supabase111k59 repos~726Automated safety check: PassMIT
Finishing a Development Branchobra/superpowers296k5 repos~1.9kAutomated safety check: PassMIT
Typescript Advanced Typesrolling-scopes/rsschool-app10k25 repos~4.2kAutomated safety check: PassMPL-2.0
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT

Similar skills

  • Official

    React composition patterns that scale. An agent skill from supabase/supabase.

    111k GitHub starsUsed in 59 repos~726 tokens
    DevelopmentAuto-check passed
  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    296k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Typescript Advanced Types

    rolling-scopes/rsschool-app

    Master TypeScript's advanced type system including generics, conditional types, mapped types, template literals, and utility types for building type-safe applications.

    10k GitHub starsUsed in 25 repos~4.2k tokens
    DevelopmentAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed

More from trailofbits/skills-curated

All 24 skills in this repo
  • Openai Security Ownership Map

    trailofbits/skills-curated

    Official

    Analyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensitive-code ownership, and export CSV/JSON for graph databases and visualization.

    512 GitHub starsUsed in 5 repos~2.2k tokens
    Auto-check: notes
  • Openai Doc

    trailofbits/skills-curated

    Official

    A skill your agent uses when the task involves reading, creating, or editing .docx documents, especially when formatting or layout fidelity matters; prefer python-docx plus the bundled…

    512 GitHub starsUsed in 5 repos~786 tokens
    Auto-check: notes
  • Openai Develop Web Game

    trailofbits/skills-curated

    Official

    A skill your agent uses when the agent is building or iterating on a web game (HTML/JS) and needs a reliable development + testing loop: implement small changes, run a Playwright-based test script…

    512 GitHub stars~2.3k tokensUpdated 2 mo ago
    Auto-check: notes
  • Openai Jupyter Notebook

    trailofbits/skills-curated

    Official

    A skill your agent uses when the user asks to create, scaffold, or edit Jupyter notebooks (.ipynb) for experiments, explorations, or tutorials; prefer the bundled templates and run the helper script…

    512 GitHub stars~1k tokensUpdated 2 mo ago
    Auto-check: notes
  • Openai Playwright

    trailofbits/skills-curated

    Official

    A skill your agent uses when the task requires automating a real browser from the terminal (navigation, form filling, snapshots, screenshots, data extraction, UI-flow debugging) via playwright-cli…

    512 GitHub stars~945 tokensUpdated 2 mo ago
    Auto-check: notes
  • X Research

    trailofbits/skills-curated

    Official

    Searches X/Twitter for real-time perspectives, dev discussions, product feedback, breaking news, and expert opinions using the X API v2.

    512 GitHub stars~1.9k tokensUpdated 2 mo ago
    Auto-check: notes

Categories

Questions about Skill Extractor

What does Skill Extractor do?

Extracts reusable skills from work sessions. An agent skill from trailofbits/skills-curated. Skill Extractor is an agent skill from trailofbits/skills-curated, published by the product's own GitHub organization. Extracts reusable skills from work sessions.

When should I use Skill Extractor?

Skill Extractor fits situations like: A non-obvious problem was solved worth preserving; A pattern was discovered that would help future sessions; debugging technique needs documentation.

How do I install Skill Extractor in Claude Code?

Run `npx skills add trailofbits/skills-curated --skill skill-extractor -a claude-code`. Or copy the skill folder (plugins/skill-extractor/skills/skill-extractor in trailofbits/skills-curated) into .claude/skills/skill-extractor in your project. Claude Code loads it when a task matches its description.

How do I install Skill Extractor in Codex?

Run `npx skills add trailofbits/skills-curated --skill skill-extractor -a codex`. Or copy the skill folder (plugins/skill-extractor/skills/skill-extractor in trailofbits/skills-curated) into .agents/skills/skill-extractor in your project. Codex loads it when a task matches its description.

Can I use Skill Extractor in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trailofbits/skills-curated --skill skill-extractor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/skill-extractor, .gemini/skills/skill-extractor, .github/skills/skill-extractor and .opencode/skills/skill-extractor in your project.

What does Skill Extractor need to run?

SKILL.md names no scripts, command-line tools or credentials: Skill Extractor is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Write, Glob, Grep, WebSearch, AskUserQuestion.

Does Skill Extractor access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Skill Extractor safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Skill Extractor use?

Skill Extractor is published under the CC-BY-SA-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Skill Extractor use?

About 1.9k tokens (SKILL.md is roughly 7.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2k tokens, read only when the agent opens those files.

What are the alternatives to Skill Extractor?

Skills that share tags, products or a category with Skill Extractor: Vercel Composition Patterns (supabase/supabase, 111k stars), Finishing a Development Branch (obra/superpowers, 296k stars), Typescript Advanced Types (rolling-scopes/rsschool-app, 10k stars) and PR Babysitter (openinterpreter/openinterpreter, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Skill Extractor?

trailofbits (a GitHub organization, an official publisher) maintains it in trailofbits/skills-curated, which has 512 GitHub stars. The repository holds 24 skills in this directory. The repository was last updated on July 14, 2026.

Source: trailofbits/skills-curated on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.