bitwarden ai-plugins
COMMUNITYLABSCO SUMMARY
The plugins split into two kinds. A minority is generic engineering tooling that would make sense in any codebase: multi-agent code review, security review, secret detection, dependency-risk review, GitHub Actions audit-and-remediate, and git commit conventions. The majority is Bitwarden's own process encoded as skills -- the Software Initiative Funnel (shepherd playbooks for research, proof-of-concept, scoping, implementation, and closure), the Technical Strategy Ideas backlog, product-design critique and Jira/Figma handoff workflows, a content style guide pinned to bitwarden.com/brand, and reference material for Bitwarden's own security principles (P01-P06) and a home-grown GitHub Actions linter (bwwl).
This is for someone on a Bitwarden engineering or design team, not an outside developer looking for reusable skills: reading the skill descriptions, several assume you already know what a "shepherd," a "TSI," or a "Primary-Owner" is inside Bitwarden's org chart, and the branding, content-style, and Jira-process skills are enforcing Bitwarden's own standards rather than teaching a transferable practice. If you don't work at Bitwarden, the handful of general code-review and security skills are the only part worth taking.
READ THE FULL ANALYSIS
What it costs to start. Thirteen of the fifty-five need a local tool the skill shells out to -- git, gh, or a linter binary -- rather than just producing guidance. Thirteen more are labeled unverified, meaning we could not confirm what they depend on from the material we have. Six need an MCP service, mostly Atlassian (Jira/Confluence) or Figma Dev Mode access. Two need an account key: perform-security-review and triaging-security-findings both reach an external scanning or bug-bounty service. Only the rest run as pure guidance with no extra access.
The repository has thinned since we first tracked it. Eight entries we recorded here previously are no longer live, among them a Jira/Confluence reader and several .NET-specific skills (Dapper queries, EF Core, writing client/server/database code) -- the README gives no reason, and we have not guessed at one.
Checked from the package's own README and its fifty-five live skill descriptions; we have not run any of these plugins against a real Bitwarden environment.
ALSO IN THIS PACKAGE
claude-retrospective
Comprehensive analysis of Claude Code sessions to identify successful patterns, problematic areas, and opportunities for improvement.
claude-config-validator
Validates Claude Code configuration files for security, structure, and quality. Routes CLAUDE.md, agents, commands, hooks, and settings to targeted review skills, reporting only what a changeset introduced.
bitwarden-code-review
Comprehensive code review system with organization-wide standards.
bitwarden-init
Initialize Claude Code configuration with Bitwarden's standardized template format
bitwarden-product-analyst
Product analyst agent for creating comprehensive Bitwarden requirements documents from multiple sources, and writing user-facing release notes
bitwarden-software-engineer
Software engineer agent for a Bitwarden product team. Implements stories, tasks, and bugs in the team's domain with code quality, performance, and security in mind.
bitwarden-atlassian-tools
Atlassian access via MCP server with deep Jira issue research skill, JQL search, Confluence pages, CQL search, attachments, and opt-in Jira write tools
bitwarden-security-engineer
Application security engineering assistant for vulnerability triage, threat modeling, and secure code analysis at Bitwarden.
bitwarden-devops-engineer
GitHub Actions workflow compliance, action security auditing, and org-wide CI/CD remediation.
bitwarden-tech-lead
Tech lead agent for a Bitwarden product team. The team's primary technical resource — architects solutions in the team's domain, partners with the EM on scoping and backlog, partners with peer tech leads on cross-team architecture, and serves as the team's conduit for cross-team technical decisions.
bitwarden-shepherd
Champion-of-a-technical-strategy agent for Bitwarden. Shepherds a Technical Strategy Idea through Architecture's evaluation into the Software Initiative Funnel, then drives the resulting initiative across all five funnel phases (Identification, Research, Proof of Concept, Scoping & Commitment, Implementation) to durable adoption.
bitwarden-delivery-tools
Delivery lifecycle skills for Bitwarden initiatives — initiative funnel navigation, work transitions, architectural judgment, commits, pull requests, preflight checks, change labeling, and Jira ticket filing.
bitwarden-designer
Product designer agent for Bitwarden. Holds the design team's Code of Conduct and the 30/60/90 critique framework, and dispatches into the bitwarden-design-tools toolkit for content style, Figma reads, brand application, handoff prep, Design System governance, and the Product and Design Jira workflow.
bitwarden-design-tools
Design toolkit for Bitwarden — non-persona skills for the design lifecycle. Content style guide reference, Figma Dev Mode MCP usage, Bitwarden brand application, design-to-engineering handoff prep, Design System governance, and the Product and Design Jira workflow.
bitwarden-ai-telemetry
Claude Code hooks that emit metadata-only AI-usage telemetry (identity, git-linkage, MCP) as OTLP logs. Fail-open.
bitwarden-testing-tools
Testing tools for Bitwarden — analyzing and improving test quality across its repositories.
bitwarden-designer
Bitwarden product designer. Holds the team's Code of Conduct and the 30/60/90 critique framework, and dispatches into the design toolkit for everything else — content style, Figma reads, brand application, handoff prep, Design System governance, and Jira choreography.
product-analyst
Use when analyzing requirements, synthesizing specifications from multiple sources, or conducting product research. Trigger phrases: "analyze requirements", "create specification", "create spec", "write spec", "spec out", "spec document", "create a requirements doc", "research feature", "document requirements", "gather requirements", "write requirements", "product spec", "turn this into a spec
bitwarden-security-engineer
Application security engineer specializing in vulnerability triage, threat modeling, and secure code analysis. Use for security findings remediation, threat model generation, dependency audits, and architecture security review.
bitwarden-shepherd
Champion of a Bitwarden technical strategy — a Staff+ engineer who shepherds a Technical Strategy Idea from inception, through Architecture's evaluation and into the Software Initiative Funnel, then carries the resulting initiative across all five funnel phases (Identification, Research, Proof of Concept, Scoping & Commitment, Implementation) to durable adoption. Holds the thesis; produces the Architectural Assessment, the PoC, the ADR, the High-Level Architecture Plan, and the child epics; coordinates cross-team consistency; reports to leadership — while teams own their own breakdown and execution.
bitwarden-software-engineer
Software engineer on a Bitwarden product team. Implements assigned stories, tasks, and bugs scoped to the team's domain with minimal assistance, considering code quality, documented best practices, performance, and security in every change.
bitwarden-tech-lead
Tech lead for a Bitwarden product team. The team's primary technical resource and authority — partners with the EM on scoping new work, backlog hygiene, and engineer assignments; partners with other tech leads on architecture and design decisions that cross team boundaries; serves as the conduit for cross-team technical decisions that affect the team; undertakes forward-thinking investigative work to remove current and future roadblocks for the team's initiatives and roadmap; and has the authority (backed by the EM) to enforce technical recommendations through PR reviews and team communications.
WHAT'S INSIDE
51 showing · 51 totalNothing else to set up — install it and go.
action-audit
Goes through every repository a GitHub organization owns and reports which of the ready-made build steps they pull in could change under you without warning.
action-remediate
Repairs the build steps an audit flagged, one repository at a time, and nothing is committed until you have seen the exact change.
addressing-code-review-comments
Every comment a reviewer leaves on your code gets checked against the code itself first, so a wrong suggestion gets an argument back instead of a silent fix.
analyzing-code-security
A hands-on security review that follows the data an outsider can send into your code all the way to the places it could do real damage.
analyzing-git-sessions
Tells you what actually changed in a project between two points in time — which files, how much, by whom, and the edits themselves on request.
applying-bitwarden-branding
Bitwarden's own rules for its logo, its colours and its type — which file to use, how much space to leave round it, and the capital B (never a capital W) that people keep getting wrong.
architecting-solutions
Designing a feature for a password manager carries constraints an ordinary app does not, and this is the set Bitwarden holds a new design to before anyone builds it.
auditing-hackerone-vulns
Checks each outstanding security bug report against how far its fix really got, and says which ones you can now update, close, or chase.
avoiding-false-positives
A filter for code-review complaints that drops anything you cannot actually prove is a bug — code that was already there, or something a tool will catch anyway.
bitwarden-security-context
Bitwarden's security rulebook in short form — the six promises it makes about user data, and what each protection term means inside the company.
bitwarden-workflow-linter-rules
What each of the ten checks Bitwarden runs over its build files is looking for, how to fix a failure, and which ones need a human to decide.
championing-a-strategy-idea
The step-by-step guide for the person carrying a big engineering proposal through Bitwarden's internal review, until leadership agrees to fund the work.
classifying-review-findings
How serious is it? Every remark left on someone's code gets one of five labels, from 'this will break' down to 'I just have a question' — and anything the reviewer cannot actually prove gets no label at all.
committing-changes
Puts a Bitwarden commit message in the expected format — ticket number and change type — and stops you committing onto the main branch.
content-style-guide
Settles how anything a Bitwarden user reads on screen should be worded — serious rather than jokey, and plain enough for a 12-year-old.
contributing-to-technical-strategy
How a problem your team keeps hitting becomes a company-wide proposal at Bitwarden, and how the work that comes back down stays tied to the reason it started.
coordinating-implementation-across-teams
The coordinator's side of a project several teams build at once — keeping them consistent, unblocking them, and calling it finished without writing any of the code.
creating-pull-request
The three things a Bitwarden pull request must get right are easy to forget and painful to fix later, so this settles each one before the request goes out.
curating-the-strategy-ideas-backlog
The second person on a proposal — the one who pushes back on it, keeps the wider list of proposals honestly ranked, and takes the shortlist to leadership each quarter.
design-review
How to give a designer feedback that helps: the big direction questions while the work is still a sketch, the fine detail only once it is nearly built, and always about the design rather than the designer.
detecting-secrets
Hunts for passwords and keys left sitting in code, and when one turns out to be real, starts the clean-up by rotating it rather than just deleting the line.
evolving-design-system-components
The approval route for adding a new reusable piece of interface to Bitwarden's shared library, or changing one that dozens of screens already use.
extracting-session-data
Claude Code leaves a log file behind after every session; this digs out the parts you want — what was asked, which tools ran, what failed — and hands them over without drawing any conclusions.
facilitating-design-critique
How to run a design feedback meeting at Bitwarden — who presents, who steers the room, and how to keep the comments about the work rather than the person.
labeling-changes
The title of a change has to name what kind of change it is, because an automated job reads that word and tags the work from it.
navigating-design-jira-process
Keeps design work visible inside the engineering ticket system instead of a tracker of its own — the file attached to the right ticket, moved at the right moment.
navigating-the-initiative-funnel
What a team lead owns, and what belongs to the person running the wider project, when their team gets pulled into it.
perform-preflight
A checklist to run before you hand a change in: the tests pass, the formatting is clean, no secret has ended up in a log, and the code follows the patterns the rest of the project uses.
perform-security-review
A security review run from several angles at once, where nothing counts as a finding until a second pass has confirmed it.
performing-multi-agent-code-review
A code review run by a team rather than one reader — each reviewer hunts a different kind of problem, and every complaint is double-checked and ranked by seriousness before it reaches the report.
posting-bitwarden-review-comments
Attaches each problem a review found to the exact line of code it is about — on GitHub or in a local file — marked for how serious it is, with the long explanation folded out of the way.
posting-review-summary
The closing note on a code review — one overall verdict, approve or changes needed, put where the team will actually see it, plus an honest no-verdict when the review never really ran.
preparing-design-handoff
Before finished designs go to the engineers who build them, someone has to confirm nothing is missing — the screens, the wording on them, and the ticket all in the state the team agreed on.
requirements-elicitation
Reads a written spec and turns it into a plain list of what the software has to do, how you would prove each part works, and which questions nobody has answered yet.
researching-jira-issues
A Jira ticket rarely stands alone — this reads the ticket plus everything hanging off it and explains the whole picture: what it is for, what has to be finished first, and which documents matter.
retrospecting
A write-up of what actually happened in a working session with Claude — what got done, what went smoothly, what slowed things down — built from the saved history and from answers you give.
reviewing-claude-config
The files that tell Claude how to behave are code too: this checks the ones a change touched for unsafe permissions, leaked passwords and risky instructions, and reports only what that change introduced.
reviewing-dependencies
Security warnings pile up about the outside code a project depends on; this works out which ones actually put you at risk, and whether to update, work around them, or just keep watching.
reviewing-dependency-changes
A check on the moment a project adds, upgrades or drops someone else's code — whether it was cleared first, whether the jump could break things, and whether the old one was really cleaned up.
reviewing-security-architecture
Goes through a system's design asking the security questions: how people are proved to be who they say, what each of them is allowed to touch, how the data is kept secret, and where an outsider could get in.
running-a-proof-of-concept
Before a change is committed to across the whole company, someone builds it for real in one small corner of the code to see where it breaks — and writes up whether it should go any further.
running-an-architectural-assessment
Interviews the people living with a problem, surveys how it is being handled today, then lays out two to four ways forward with a recommendation leadership can actually decide from.
running-work-transitions
Handing work from one team to another isn't finished when the meeting ends — it's finished when the new team can run it alone, and this is the six-step path to that point, from either side.
scoping-and-handing-off-to-teams
The point where a plan stops being one person's and becomes several teams' work: who builds which part, what it will cost, and a yes or no from leadership before anyone starts.
shepherding-an-initiative
Taking a big engineering change from first idea to finished rollout is a five-stage job, and this is the map of it — what to produce at each stage, who decides, and how long each usually takes.
threat-modeling
A written statement of what an attacker can and cannot do, what the system promises to hold against them, and an honest note on whether that promise actually holds today. It follows Bitwarden's own security review, from the first assessment through sign-off by the security team.
triaging-security-findings
Decides whether an automated security alert is a real problem, how serious it is and what should happen next, and writes that verdict up as a ticket — for findings raised by Aikido, Dependabot or GitHub's secret scanning.
using-figma
Reads a design out of Figma — its layers, the colours and spacing it uses, the words on screen, a picture of the frame — so it can be checked or discussed without anyone opening the file by hand.
work-breakdown
Splits a large feature into small tasks of a few hours each, ordered so nothing starts before the thing it depends on, and each one carrying a way to tell when it is really finished.
workflow-audit
Checks the automation files in one or more GitHub repositories against Bitwarden's own linter and lays out everything it objects to, split into what a machine can safely fix and what needs a person, changing nothing itself.
workflow-fix
Fixes what Bitwarden's workflow linter objected to in a repository's GitHub automation files: a branch of its own, the corrections that have only one right answer applied, a draft pull request opened, and a pause for your decision on anything else.
HOW TO GET IT
npx skills add bitwarden/ai-pluginsnpx skills add bitwarden/ai-plugins --skill <name> --full-depthPick the skill name from the Skills tab — each entry there installs independently.
/plugin marketplace add bitwarden/ai-plugins/plugin install claude-retrospective@bitwarden-marketplace/plugin install claude-config-validator@bitwarden-marketplace/plugin install bitwarden-code-review@bitwarden-marketplaceTyped inside the agent's own prompt, not in a terminal. The marketplace lists 16 plugins; three are shown. Every one installs the same way, with its own name before @bitwarden-marketplace.