AI Guides › Workbench
By Nigel Guy · 8 min read
The usual mistake with a fresh Claude Code install is to copy a list of "must-have" plugins off social media, paste every install command, and assume more add-ons means a better setup. It feels productive because each command succeeds. What you actually get is a slower start-up, a context window quietly filled by skills you never call, and at least one tool running code on your machine that you never read.
The rule: install one add-on at a time, know what each one runs on your machine, and keep only the ones you have used within a fortnight.
Below are five gaps a new install tends to have. Two add-ons are low-risk, two need care, and one most readers should skip.
| Term | What it means here |
|---|---|
| Plugin | A bundle that can add skills, agents, hooks and MCP servers to Claude Code. Installed with /plugin. |
| Marketplace | A catalogue of plugins. Anthropic's official one is claude-plugins-official. |
| Skill | A folder of instructions (a SKILL.md file) Claude loads when a task matches. |
| MCP server | A program that gives Claude extra tools, such as a scraper. |
| Scope | Who gets the plugin: you everywhere (user), everyone on the repo (project), or you in this repo only (local). |
| Add-on | What it does | Cost at time of writing | Best for | The catch |
|---|---|---|---|---|
claude-code-setup (official plugin) |
Reads your codebase and recommends the top one or two hooks, skills, MCP servers, subagents and commands per category | Free; uses your normal Claude Code usage | Anyone who doesn't know what to add | Read-only. It recommends; it does not install or remove anything |
find-skills (skill from the open skills CLI) |
Searches the public skills directory and installs matches | Free | Finding skills for a specific project | Community skills are unvetted text that steers Claude |
| Strix (open-source pentest tool plus agent skills) | Runs AI agents that actively attack an app and report findings | Free licence (Apache 2.0); you pay your own LLM API usage | Testing an app you own before launch | Needs Docker; only legal against systems you own or have written permission to test |
firecrawl (official-marketplace plugin) |
Scrapes, crawls and maps sites with JavaScript rendering and anti-bot handling | Free plan of 1,000 credits a month; Hobby is US$19 a month billed monthly (roughly £14, plus any VAT) | Pulling clean text from JavaScript-heavy pages | Third-party service; "blocked" sites often block for a reason |
| OmniRoute (third-party npm router) | A local proxy that routes requests across many AI providers, including free tiers | Free (MIT licence) | Tinkerers experimenting with other tools | Anthropic doesn't support routing Claude Code to non-Claude models through any gateway |
You need Claude Code on a plan that includes it. Anthropic's pricing page lists Pro, Max, Team and Enterprise; Free does not include it. Pro is listed at US$20 a month in dollars there. Check the price in pounds at checkout, because the page doesn't show sterling prices.
Claude Code adds the official marketplace for you the first time you open an interactive terminal session. So you can usually skip /plugin marketplace add anthropics/claude-plugins-official and go straight to:
/plugin install claude-code-setup@claude-plugins-official
This opens the plugin's details pane rather than installing straight away. Read Will install and, for official plugins, Context cost, then pick a scope. Choose Install for you (user scope) for this one. If the summary says Run /reload-plugins to activate., let it reload.
Then ask for an audit, with constraints so it doesn't hand you a shopping list:
You are reviewing my Claude Code setup for this repository.
Context: the project is [ONE_LINE_PROJECT_DESCRIPTION]. I mostly use Claude Code for [MAIN_TASKS, e.g. bug fixes, tests, writing docs].
Goal: a short, prioritised list of automations worth adding, plus anything I already have installed that I should remove.
Steps:
1. Inspect the codebase and my current plugins, skills, hooks and MCP servers.
2. Recommend at most five additions in total, ranked by how much time each saves for the tasks above.
3. List any installed plugin or skill that doesn't match those tasks as a removal candidate.
Output: a table with columns Item | Add or remove | Why | What it runs on my machine (hooks, servers, none).
Rules: don't install or change anything. If you can't tell what I use Claude Code for, ask me before recommending.
Before answering, check that every recommendation maps to one of my stated tasks.
Fill in your project description and main tasks. To act on removals, open /plugin, go to the Installed tab, and look under the Not used recently header.
find-skills is a skill from Vercel's open skills CLI, which supports Claude Code among many other agents. Install it globally from your normal terminal, not inside Claude Code:
npx skills add https://github.com/vercel-labs/skills --skill find-skills -g
The -g flag installs to your user folder (for Claude Code, ~/.claude/skills/) instead of the current project. Leave off -y the first time so you see each prompt. Then, inside Claude Code:
Use the find-skills skill to look for skills that would help with this project.
Project: [ONE_LINE_PROJECT_DESCRIPTION]. Stack: [LANGUAGES_AND_FRAMEWORKS].
Goal: no more than three skills that cover gaps Claude can't already handle well.
For each candidate, show: name, source repository, what it does, and whether it comes from an official vendor or an individual.
Prefer official vendor sources and widely installed skills. Don't install anything until I reply with the names I want.
If my description is too vague to search on, ask me one question first.
Check before answering: have you shown the source of every skill?
Fill in the project line and your stack.
Strix runs agents that probe a target for real vulnerabilities and validate them. Its README requires Docker running and an LLM API key, and warns plainly that it is for authorised use only. Install the agent skills with:
npx skills add usestrix/strix -g
The Strix README says this adds a set of skills so a coding agent can run tests and fix findings. Point it at a local or staging copy, never production, and never at anything you don't own.
You are helping me security-test an application I own.
Target: [LOCAL_OR_STAGING_URL_OR_REPO_PATH]. I confirm I own this system or have written permission to test it: [YES/NO].
If the answer is not YES, stop and say so.
Goal: find exploitable issues before launch and fix the ones that matter.
Steps: 1) confirm the target isn't a production URL; 2) run the Strix scan; 3) list findings ranked by severity with evidence; 4) propose a fix for each high or critical finding as a diff, without applying it.
Output: a findings table (Severity | Issue | Evidence | Proposed fix), then the diffs.
Before answering, check that nothing outside the stated target was touched.
Fill in the target and your permission answer.
Claude Code's built-in fetch struggles with pages that build their content in JavaScript. The firecrawl plugin is listed in Anthropic's official marketplace, although it comes from Firecrawl's own repository:
/plugin install firecrawl@claude-plugins-official
You'll need a Firecrawl account and API key. A local alternative is Scrapling (pip install "scrapling[ai]" for its MCP server, BSD-3 licence), which asks you to respect each site's terms of service and robots.txt.
Using the Firecrawl tools, collect [WHAT_DATA, e.g. product names and prices] from [URL_OR_LIST_OF_URLS].
Before scraping, check the site's robots.txt and tell me if the pages are disallowed; if they are, stop.
Scrape only the listed pages, not the whole site, unless I say [CRAWL: YES].
Output: a table with columns [COLUMN_NAMES], plus the source URL for each row.
Flag any row where a value was missing rather than guessing it.
Fill in the data you want, the URLs and the columns.
OmniRoute is a real MIT-licensed npm package (npm install -g omniroute) that runs a local router on port 20128 with a provider catalogue and free-tier tracking. I couldn't confirm a bare omniroute setup command; its README shows tool-specific omniroute setup-<tool> commands. Its own README flags providers whose terms make them risky, and warns about account bans from shared or OAuth credentials.
The bigger issue is Claude Code itself. Anthropic's gateway documentation says it doesn't endorse or audit third-party gateways and doesn't support routing Claude Code to non-Claude models through any of them. If you hit limits, waiting for the reset or moving to API billing is the supported route.
claude-code-setup, then act on its removal list.find-skills, capped at three skills.-y on any npx skills add until you have read what it installs.