factory-ai factory-plugins
COMMUNITYLABSCO SUMMARY
The eight are core (PR review and a parallel simplify pass, pre-installed with the CLI), droid-control (ten skills that drive terminals, browsers, and desktop apps for demos, QA, and computer-use tasks), security-engineer (STRIDE threat modeling, a commit/PR security scan, and vulnerability validation), typescript (banning as casts, banning useEffect, and fixing knip's unused-export violations), debugging (HTTP Toolkit interception), code-review (opening and following up on a PR), droid-evolved (session search, an AI-writing editor, skill creation, and image/presentation and frontend design), and autoresearch (a standalone experiment loop that tries a change, measures it, and reverts what regresses).
This is Factory AI's own marketplace for its droid CLI, published from factory-ai/factory-plugins: every install instruction in the README goes through droid plugin marketplace add and droid plugin install. It does not document a Claude Code or Cursor install path the way other skill repositories on this site do, so treat it as built for droid first.
READ THE FULL ANALYSIS
Three skills the README never names. desktop-control, init, and wiki are live in the repository but do not appear anywhere in the README's plugin-by-plugin skill lists. init's own description says what it does — sets up a new repository with an AGENTS.md file — but desktop-control and wiki ship no description at all, so beyond their names we cannot tell you what they do.
One more mismatch: the review skill's own description is create-pr's. The README says review should "review code changes and identify high-confidence, actionable bugs." What is actually live in the database is the identical trigger text used for create-pr, describing pull-request creation, word for word. Whatever causes this skill to fire in practice, it is not a request to review a diff.
WHAT'S INSIDE
27 showing · 27 totalNothing else to set up — install it and go.
autoresearch
Sets a machine loose on improving one number -- how long the tests take, how big the finished app is -- by trying an idea, measuring it, keeping it only if it really helped, then going again.
ban-type-assertions
Bans the shortcut where code simply tells the compiler to trust it about what a piece of data is, and replaces every one of them with something that is actually checked.
browser-navigation
Everything a browser can be made to do without a person sitting at it: open pages, fill in forms, grab screenshots, watch what the page sends over the network, even pretend to be a phone.
capture
Films an app while it is put through its paces -- the terminal, the browser window, screenshots, every keystroke -- so the raw footage is there to cut into a demo video afterwards.
commit-security-scan
Someone has to read a batch of code changes looking for the ways they could be attacked — this does that reading, and writes up each weakness with how serious it is and how someone would exploit it.
compose
The editing stage that comes after a screen recording: the raw clips go in and one finished video comes out, with a title card, transitions and polish on top.
create-pr
Opens a pull request that is ready for someone to review: the checks have already been run on your own machine, the title follows the house format, and the description is actually filled in.
droid-cli
A crib sheet for making Factory's own Droid command-line tool run unattended: which keys do what, which typed commands exist, and how to start it against a particular copy of a repository.
droid-control
The traffic controller for having a machine operate an app for you: it decides whether the job needs a terminal, a browser or a desktop window, and what has to be recorded to prove it worked.
fix-knip-unused-exports
Clears out the leftovers a codebase has stopped using: a checker called knip lists them, and each one is then deleted, hidden away, or moved to the one place that still needs it.
follow-up-on-pr
Takes a pull request that has been sitting open and gets it over the line: brought up to date with the branch it will merge into, every reviewer comment answered, and pushed back up ready to go in.
frontend-design
How to make a web page look like someone designed it: settle on the mood first, then on a small set of sizes, spaces and colours, and stick to them instead of drifting into the generic look.
http-toolkit-intercept
Puts a recorder in between your program and the internet, so you can see exactly what it sent to a remote service and exactly what came back.
human-writing
A list of the tells that give AI-written text away — the stock phrases, the hedging, the everything-in-threes rhythm — and what to write instead so it sounds like a person.
init
Writes your project a short handbook -- how to build it, how to run its tests, how the pieces fit together -- so the next AI assistant that works on the code isn't starting from zero.
no-use-effect
A team rule for React code: don't reach for the useEffect hook -- this lists the five things to write instead, and the single exception where it is still allowed.
pty-capture
When someone presses a key, the terminal window sends a small code to the program behind it — this is how you find out what that code really is, on Linux, Windows or macOS.
security-review
A security read of a codebase that reports a weakness only once it has been shown that an attacker could actually pull it off.
session-navigation
Every conversation with Droid, Factory's coding assistant, is kept as a file on your own computer — this is how you go back and find the one you half-remember among them.
showcase
Six ready-made looks for a demo or product video -- pick one by name and the frame around the recording, the background, the colour treatment and the transitions all come set.
simplify
A second look at the code you just wrote: what quietly repeats something the project already had, what was done the hacky way, and what is doing more work than it needs to.
skill-creation
What you work out in one session normally dies with it -- this is how you write it down as a reusable instruction file, decide what is even worth keeping, and improve the ones that are not landing.
threat-model-generation
A written map of how your system could be attacked -- which parts strangers can reach, what sensitive data sits where, and the risks that follow from both.
true-input
Types into a real terminal the way a physical keyboard does, so a demo or a test shows what that terminal genuinely does with a keystroke rather than what a simulated one would.
verify
The last check before work is handed over — everything promised at the start is matched against what actually came out, and what could not be checked is labelled as such rather than passed.
visual-design
Pictures and slide decks made from the command line: logos, icons, diagrams and photo touch-ups on one side, plain written notes turned into a presentation on the other.
vulnerability-validation
Takes the warnings a security scan threw up and works out which ones an attacker could really use -- the real ones come back with a worked example of the attack and a severity score, the rest marked as false alarms.
HOW TO GET IT
npx skills add factory-ai/factory-pluginsnpx skills add factory-ai/factory-plugins --skill <name> --full-depthPick the skill name from the Skills tab — each entry there installs independently.