AI Guides › Step-by-step guides

Five Claude Code Add-Ons, Installed in Order of Risk

By Nigel Guy · 6 min read

Most people install Claude Code add-ons the way they collect browser extensions: paste whatever a post lists, in whatever order it lists them, and find out later which one rewired something. The five tools here are not equal. One is read-only and made by Anthropic; one points Claude Code at a local gateway; one runs an AI that actively attacks software. Installing them as a flat list hides that difference.

The rule: install in order of how much each one can change or touch, read what it will do before you run it, and stop at the first one that already solves your problem.

Only the first of the five is a Claude Code plugin in the strict sense. The others are separate command-line tools or skills. That distinction matters, so it gets named at each step.

Before you start

Step 1 — Claude Code Setup (read-only, official)

This is Anthropic's claude-code-setup plugin, in the claude-plugins-official repository. It reads your codebase and recommends automations: MCP servers, skills, hooks, subagents and slash commands, one or two per category. Its README describes it as read-only.

  1. In a Claude Code session, run: /plugin install claude-code-setup@claude-plugins-official
  2. Claude Code opens the plugin's details panel. Read the "Will install" list, then choose a scope: you (user), everyone on the repository (project), or you in this repo only (local).
  3. Anthropic's docs say the official marketplace is added automatically the first time you start an interactive terminal session. If the command says the marketplace is unknown, run /plugin marketplace add anthropics/claude-plugins-official first.
  4. Ask for the recommendations in plain language:
You are reviewing my project to suggest Claude Code automations.
Project: [PROJECT_NAME], mainly built with [LANGUAGES_AND_FRAMEWORKS].
My biggest annoyance right now: [REPEATED_CHORE_OR_PROBLEM].
Scan the repository, then recommend at most two options each for MCP servers, skills, hooks, subagents and slash commands.
For each: name, what it does for this codebase, and what it would change on my machine.
Do not install or edit anything. If you cannot tell something from the code, ask me instead of assuming.
Before answering, check that every recommendation is tied to something you actually saw in the repo.

Fill in the three square-bracket items.

Step 2 — find-skills (installs instructions, not software)

find-skills is a skill from Vercel Labs that helps your agent search the skills.sh ecosystem and recommend skills by install count, source reputation and GitHub stars.

  1. Run: npx skills add https://github.com/vercel-labs/skills --skill find-skills
  2. Follow the prompts on which agent and scope to install to.
  3. In Claude Code, describe a job: "Is there a skill for [TASK]?" It should suggest candidates rather than install them silently.

The same CLI can also search directly, for example npx skills find typescript.

Step 3 — Agent Reach (reads the internet, with caveats)

Agent Reach is an open-source (MIT) layer that sets up and health-checks tools for reading web pages, YouTube, RSS, GitHub and more. Its README says most channels need no API key. Several social platforms (Twitter/X, Reddit, Facebook, Instagram, Xiaohongshu) need your own cookies or credentials.

Its documented install is to give your agent a link to its install guide. Write the request so the agent shows you the plan first:

Set up Agent Reach using the instructions at
https://raw.githubusercontent.com/Panniantong/agent-reach/main/docs/install.md
Before running anything, list every command you plan to run and every package it installs, and wait for my go-ahead.
Only configure channels that work without logins: [CHANNELS_I_WANT, e.g. web, RSS, YouTube].
Do not ask for or store my personal account cookies. When finished, run its health check and report what works.

Fill in the channels you actually need.

Step 4 — OmniRoute (a gateway that sits in front of your model)

OmniRoute is an MIT-licensed local gateway that routes requests across many providers and falls back when one runs out of quota. It starts at http://localhost:20128/v1.

  1. Install: npm install -g omniroute
  2. Configure Claude Code. The article this guide draws on gives omniroute setup-claude-code; the project's README instead describes omniroute configure claude. I could not confirm which is current, so run omniroute --help and use whichever the tool lists.
  3. Manual fallback from the README: base URL http://localhost:20128/v1, API key from the dashboard's Endpoints page, model auto.

Step 5 — Strix (attacks software; the riskiest)

Strix is an Apache 2.0 licensed AI penetration-testing tool. It runs agents that probe a target and try to prove a flaw with a working exploit. It needs Docker and an LLM provider key.

  1. Start Docker.
  2. Install: curl -sSL https://strix.ai/install | bash. Piping a script to bash runs it unread; open the URL first if you want to see it.
  3. Set STRIX_LLM to your provider/model string and LLM_API_KEY to your key.
  4. Run strix --target ./your-app-directory, on code or a deployment you own.

Strix's own README says to test only systems you own or have explicit written permission to test.

Check it worked

What to skip

Guardrails

Sources

All 751 AI guides · JulieMango plans from £17/mo