Plugin · Claude Code · Security

Trilwu Secskills

trilwu-secskills is a Claude Code plugin for the Ship phase that adds specialized penetration-testing skills and security subagents to the agent.

by trilwu · github.com/trilwu/secskills

Equip Claude Code with offensive-security workflows—recon, testing, and auditing—without leaving the agent.

13
GitHub stars
0
Installs
0
Community votes
One vote per signed-in builder - it helps surface the tools the community actually relies on.
Install

Add it to Claude Code

Install the plugin in Claude Code. One command, paste-ready.

Install the plugin
/plugin install trilwu-secskills@trilwu/secskills
Add to ClaudeUse the Agent APISkillselion is itself an MCP server - your agent can fetch this config directly.
Agent API

Built to be called by your agent

Skillselion is itself an MCP server. Your agent can pull this entry and a paste-ready install config straight from the API - no copy-paste.

Retrieve this entry with skillselion.get_details("plugin:trilwu/secskills") and the paste-ready config with skillselion.get_install_config("plugin:trilwu/secskills").

About

What it does

trilwu-secskills is a Claude Code plugin that turns the agent into a penetration-testing and security-auditing copilot. Solo builders and small teams who ship web, API, or cloud products can register it when they need structured recon, mobile and cloud checks, and offensive testing playbooks without assembling prompts from scratch. The repository advertises specialized security skills and AI subagents that mirror how security consultants divide work—useful during Ship-phase review, before launch, and when operating production systems that need recurring audits. It is not a replacement for certified pentests or compliance programs; it accelerates how you drive Claude through repeatable security tasks inside the editor. Install via the plugin marketplace, then invoke security-oriented skills when validating auth, APIs, infra, or client surfaces. Complexity is advanced because misuse or sloppy scope can harm systems you do not own.

Highlights

  • Bundles specialized security skills plus expert subagents for teaming-style offensive testing
  • Covers reconnaissance, mobile, cloud, and comprehensive auditing keywords from the toolkit
  • Positions Claude Code as a penetration-testing assistant rather than a generic coder
  • Community plugin (1 plugin in repo) aimed at production-ready security workflows
  • Offensive and defensive testing patterns in one installable Claude Code plugin

Why builders use it

Security testing from a coding agent usually means ad-hoc prompts that miss recon, cloud, and mobile coverage and do not scale across releases.

After install, Claude Code can run coordinated security skills and subagent workflows for auditing and offensive testing aligned to your stack.

At a glance

  • Type - Plugin in Security.
  • Adoption - 0 installs, 13 stars, 0 votes.

FAQ

Who is trilwu-secskills for?

It is for Claude Code users doing hands-on security work—recon, testing, and audits—on products they build or operate.

When should I use trilwu-secskills?

Use it during security review before ship, after large refactors, or when validating cloud and API exposure in staging or production-like environments.

How do I add trilwu-secskills to my agent?

Install the plugin from the trilwu/secskills repository in Claude Code's plugin flow, then invoke the bundled security skills from your session.

Discussion

Comments

Share how you use trilwu-secskills, gotchas, or tips for other indie builders.

No comments yet - be the first to share how you use it.

This week for builders

Five minutes, every Monday — the tools, releases and tactics for shipping solo.

unsubscribe anytime.