mirror of
https://github.com/trailofbits/skills-curated
synced 2026-06-21 14:12:04 +00:00
ed9c0b71a0
* Add OpenAI skills converter and 16 converted plugins Add scripts/convert_openai_skills.py, a PEP 723 script that fetches curated skills from openai/skills and converts them to Claude Code plugin format. The script rewrites Codex-specific paths, frontmatter, sandbox instructions, and branch naming conventions. 16 portable skills converted. Skipped 14 (MCP-dependent, OpenAI API, or Codex-hosted infrastructure like vercel-deploy's deploy endpoint). Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * Fix CI lint failures in imported OpenAI scripts - Add --unsafe-fixes to ruff in lint_plugin() for auto-fixable errors - Add per-file ruff ignores for unfixable vendor code issues (B023, B904, E501, SIM105, SIM117) - Regenerate all plugins with lint fixes applied Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Security Threat Model
Repository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, and writes a concise Markdown threat model. Trigger only when the user explicitly asks to threat model a codebase or path, enumerate threats/abuse paths, or perform AppSec threat modeling. Do not trigger for general architecture summaries, code review, or non-security design work.
Installation
/plugin install trailofbits/skills-curated/plugins/openai-security-threat-model
What It Covers
- Quick start
- Workflow
- Risk prioritization guidance (illustrative, not exhaustive)
- References
Credits
Originally from OpenAI's curated skills catalog. Converted to Claude Code plugin format for the Trail of Bits curated skills marketplace.