Agent Plugins Marketplace

Recently added

Plugins grouped by the day they were added to the directory, newest first.

Sep 22, 2026

  1. Checks each shell command the assistant runs before it runs. Blocks force-pushes to protected branches (main and master by default), git hooks skipped with the no-verify flag, and staging or committing files or added lines that look like secrets; asks for confirmation before git commands that discard uncommitted work (Codex cannot ask from a hook, so there those commands are blocked with the reason). It reads the command text, so it catches ordinary and accidental commands, not deliberately hidden ones. A skill explains each rule and its settings.

    Claude Code1 skill
  2. Keeps the assistant's context small. A read guard hook refuses a whole-file read of a non-image file over 50KB with the reason, so the session reads a range or summarizes the file instead (enforced on Claude Code). A bounded session-start checklist hook, and a context-hygiene skill with the rules for large results, idle gaps, shell output (run checks through skilliton gate) and subagents. A separate, reversible setup script adds a status line that logs real quota; the config drift check is a manual diagnostic.

    Claude Code1 skill
  3. Splitting an oversized file without changing what it does: moving code rather than rewriting it, keeping every name and its callers, and ending in evidence a reader can check rather than a claim. Four cleanup skills were written for this pack and given an eval case each, run three times with the plugin and three times without it; this is the one whose runs beat their own baseline. The other three are recorded in docs/not-shipped with what was measured, because their cases could not tell the difference.

    Claude Code1 skill
  4. sidecrew0stars

    Local MLX worker models make behaviour-preserving code changes and write unit tests, behind a gate a machine can run. Claude plans and reviews; only survivors come back.

    Claude Code1 skill
  5. spec-trio2stars

    Spec-anchored ralph-trio: an external spec.md gates planner / coder / reviewer with allowlist scope checks + §-citation coverage. Planner can request pre-coding research (Antigravity). Uses ask-reviewer.sh + ask-researcher.sh from the dev-trio plugin on PATH.

    Claude Code2 skills
  6. Durable LangGraph control plane for the agent-team CLI registry: bounded retries, test gates, SQLite checkpoints, and human ship approval.

    Claude Code1 skill
  7. Ralph Wiggum loops — solo / trio / debate / meta variants. Iterative LLM-driven coder loop with planner+coder+reviewer (trio uses ask-reviewer.sh + ask-researcher.sh from dev-trio plugin; debate uses debate.sh from debate-conductor plugin). Planner can request pre-coding research (Antigravity). Optional Stop-hook in-session driver for solo.

    Claude Code3 skills
  8. dev-trio2stars

    Codex PM and coder coordinates CLI research and authenticated Claude Code review.

    CodexClaude Code
  9. Codex conducts Generator-vs-Critic debates with external CLI adapters and live transcript artifacts.

    CodexClaude Code
  10. Language-agnostic multi-agent pipeline for spec-driven development: orchestrates role sub-agents in parallel waves to produce grounded contract files under specs/<name>/ — spec.md, plan.md, task.md (the status holder), tech-spec.md, test.md — plus survey.md and research.md as evidence, all verified by scripts/check.py.

    Claude Code1 skill
  11. Multi-company GTM engine — prospect, write outreach, scan the market, track events, run the news-driven content pipeline (radar → plan → research → studio → human-gated LinkedIn publish), build carousels with AI visuals and motion teasers, prep for calls, research accounts into structured deck dossiers, build branded .pptx decks, produce a friendly forward-to-a-seller account + buyer dossier as a Word doc, plan accounts, run quarterly GTM planning, automate the weekly carousel pipeline, run the Solution Architect motion — technical discovery, solution design with diagrams, and a per-product setup runbook — turn a delivered or designed engagement into an evidence-tiered customer case study, run the partner motion — give-first briefs for consulting partners (map their published framework onto our products) and for peer product vendors (find the seam their own docs already name) — and run the market-intelligence motion as a capture/synthesis pair: `market-harvest` pulls the external signal (metered, watermarked, five lanes) and `market-intelligence` reads what it landed into an evidence-backed internal brief in which only VERIFIED customer-voice passages may back a demand claim, and run the short-form video motion in four lanes — script and render an idea into vertical/feed assets, repurpose a long-form YouTube video into clips, restyle real footage into an on-brand short, or capture a real screen recording into a Reap Video Studio clip — each scored for retention before a human approves the post, with brand identity (trained likeness, reference elements, cloned voice, restyle preset) resolved from the profile as config rather than prompt discipline, and any synthetic likeness or voice disclosed at the publish gate or the post will not stage. Adds a pre-sales motion beyond the design itself — a security questionnaire answered only from the profile's evidence pack (anything unbacked is refused with a named owner, never answered plausibly), a value case whose every number carries its source and an assumption register, a time-boxed POC plan with a named customer-side verifier per pass/fail criterion, a demo narrative that opens on the outcome and declares what is staged, and a competitor battlecard that states where the competitor genuinely wins. Adds a storyboard gate before video render spend and a front-door router that asks one question to route a 'make a video' request into the correct lane, plus a cross-modal format router that decides which formats and platforms to produce from an approved hook. Company facts, brand, voice, and product load from the active profile bundle (per-company); skills carry zero hardcoded company strings. 78 skills: setup, prospect, inbound-triage, draft-outreach, email-sequence, email-quality, market-scan, market-harvest, market-intelligence, events-tracker, content-radar, content-plan, content-research, content-studio, content-publish, content-outcomes-sync, format-router, creator-brief, video-script, video-render, video-avatar, video-finish, video-score, video-clip, video-restyle, video-router, video-storyboard, demo-capture, identity-kit, carousel-pdf, carousel-visuals, carousel-auto, call-prep, deck-research, build-deck, account-dossier, account-plan, gtm-planning, campaign-plan, case-study, consulting-partner-brief, product-partner-brief, solution-discovery, solution-design, solution-scope-check, gateway-runbook, infographic-data, infographic-handwritten, linkedin-engagers, linkedin-reply, reddit-reply, community-signal-analysis, airq-scan, builder-radar, builder-evidence, builder-studio, profile-onboard, knowledge-refresh, outcomes-sync, commercial-proposal, video-plan, video-preview, video-footage, crm-hygiene-check, deal-slip-scenario, diagram-design, metrics-review, seo-audit, seo-competitor-analysis, seo-keyword-clustering, seo-keyword-research, synthesize-research, team-pipeline, security-review, value-case, poc-plan, demo-narrative, battlecard.

    Claude Code50 skills2 MCP servers
  12. kit0stars

    A Claude Code kit with two roles that grade opposite halves of the same round. The MENTOR coaches how each request was framed before the work runs, then grades the ask — framing, leverage, learnings applied. The CRITIC judges, in fresh context and its own words, whether the thing you ASKED for actually happened, then grades the delivery — did it happen, was there evidence, did it stay in scope. Both write to one append-only ledger per repo, and the SCORECARD renders it as a published board where the human prompter and the model are scored side by side.

    Claude Code3 skills
  13. Skills that decide when a store should ask for a review, which products are short of proof, how to answer a falling rating, where proof belongs on the storefront, and where existing proof earns its place. Vendor-neutral reasoning; the TargetBay Reviews MCP supplies the capabilities.

    Claude Code5 skills
  14. Skills that turn a newly signed-up store into a store-specific programme across all three TargetBay products — auditing what the platform actually knows about this store, asking only what it cannot observe, setting up the onsite capture that must go in first, sequencing the first ninety days so the three products do not compete for the same customer, and provisioning the result behind explicit approval. Vendor-neutral reasoning; the TargetBay MCP supplies the capabilities.

    Claude Code10 skills
  15. Skills that decide whether a store should run a loyalty programme, what shape it takes, what points are worth, where tier thresholds go, how a referral programme should pay, and which members are quietly leaving. Vendor-neutral reasoning; the TargetBay Loyalty MCP supplies the capabilities.

    Claude Code6 skills
  16. 38 skills that decide how a store should plan, target, sequence and optimise its email and SMS marketing. Vendor-neutral reasoning; the TargetBay Email & SMS MCP supplies the capabilities.

    Claude Code38 skills
  17. A live checklist above the prompt of the conversation's loose ends: questions left unanswered, points made in passing, caveats and deferred work it moved past, kept up to date by a small model after each turn. Needs function hooks (early access) and an interactive terminal.

    Claude Code
  18. Persistent long-term memory for Claude Code via MCP — captures coding decisions, bugfixes, and context across sessions. Hybrid FTS5 + TF-IDF search with episode batching. Single SQLite DB, no external services. A lighter, lower-cost alternative to claude-mem (episode batching + a smaller model; cost savings are an internal estimate, not a measured benchmark).

    Claude Code1 MCP server
  19. Research current search trends, related demand, and trend-driven SEO opportunities.

    CodexClaude CodeAgent Plugins1 MCP server
  20. Build a trained, deployable RL policy from a verbal description of a dynamic decision-making problem: formalize it into an MDP-IR, generate a spec-conformant simulator domain, baselines, PPO training and tuning, and a policy-structure readback, with executable gates between stages.

    Claude Code9 skills
  21. tamheed0stars

    Turn a project description into a validated, traceable, execution-ready planning & handoff package for Claude Code to implement.

    Claude Code1 skill1 MCP server
  22. jev-guardrails31.7kstars

    Screens every prompt going into the conversation and every reply coming out of it with TypeSafe's Jev, a System One decision model, the way TypeSafe's guardrails cookbook does: one request per message asks a battery of hazard questions (jailbreak, harm or a crime, a diagnosis or a dosage, self-harm) and scores how much harm complying would do. The thresholds live here, in a named policy (strict or permissive), and turn the probabilities into pass, review (the user is asked), block (the prompt is dropped, or the reply withheld) or support. Falls back to the engine's built-in classifier when no key is set.

    Claude Code
  23. Persistent long-term memory for Claude Code — wiring for the Pseudolife-MCP daemon (session briefing + identity hooks + memory commands; MCP transport via the installer's stdio shim or claude mcp add). Requires the daemon stack: https://github.com/Pseudogiant-xr/Pseudolife-MCP#quickstart

    Claude Code
  24. accounts0stars

    Integra Foundathyon Accounts: signup, signin, refresh token, OAuth, magic link, webhooks, roles y behaviors — con las rutas, headers y formato de respuesta reales.

    Claude CodeAgent Plugins1 skill
  25. Software Design and Architecture Guidelines with lens-based review skills and Python scaffolding skills

    Claude Code21 skills
  26. 白盒 XXE 审计. Includes 1 skill.

    Claude Code1 skill
  27. 白盒 SSRF 审计. Includes 1 skill.

    Claude Code1 skill
  28. 白盒高危密钥与凭据暴露审计. Includes 1 skill.

    Claude Code1 skill
  29. 白盒远程代码执行审计. Includes 1 skill.

    Claude Code1 skill
  30. 白盒注入审计(SQL/命令/NoSQL/LDAP). Includes 1 skill.

    Claude Code1 skill
  31. 白盒任意文件读写与危险上传审计. Includes 1 skill.

    Claude Code1 skill
  32. 白盒不安全反序列化审计. Includes 1 skill.

    Claude Code1 skill
  33. 白盒鉴权与认证绕过审计. Includes 1 skill.

    Claude Code1 skill
  34. 漏洞评分模块:支持 CVSS v3.1 与 v4.0(按需加载),映射 DeepSonar 四级定级,并补充 EPSS/SSVC/KEV 优先级指引。

    Claude Code1 skill
  35. 漏洞定义模块:每类漏洞的定义,以及严重 / 高危 / 中危 / 无危害的判定标准。白盒与黑盒审计的共用语义基线。OpenHarmony 系统类加载 references/openharmony.md;Chrome / Chromium 浏览器加载 references/chromium.md;数据库(ClickHouse 等 DBMS / 数据库云平台)加载 references/database.md;移动端(Android / iOS App)加载 references/mobile.md(四档 + 调整/无效;项目规则见 vuln-definitions-mobile 的 google-android-devices-rules.md)。

    Claude Code1 skill
  36. OpenHarmony / Phone OS 系统漏洞定义:官方四档与调整/无效条款,外加移动 OS 通用漏洞类型(内核/HDF/IPC/沙箱/Ark/近场软总线/OTA 等,对齐 Android·iOS 形态)。

    Claude Code1 skill
  37. 移动端(Android App + iOS App)领域漏洞定义:形态主表(Deep Link / URL Scheme / WebView / Intent / 组件导出 / Content Provider / 广播 / 文件路径 / 认证逻辑 / 权限与 WIU / UI 覆盖与点按劫持 / 跨用户与 Private Space / 数据存储密钥 / SSL-TLS 证书 / 内存安全)与 HackerOne 移动端赏金惯例 → 四档映射;含调整/无效条款、Gate 门禁、Android·iOS 攻击面索引、历史漏洞模式库(案例归纳 + 定级校准 + 挖掘切入点),以及 Google Bug Hunters 的 Android 与 Google 设备项目规则(范围 / 资格 / PoC 与补丁要求 / 奖金与 SNR 纪律,不定级)。本地 DoS(杀进程 / 纯崩溃 / 资源耗尽)按 INV1 不报;破坏性远程 DoS 按 H8 报。入口面本身(exported / 自定义 scheme / 不校验调用方)按 INV26 不报。

    Claude Code
  38. 数据库领域漏洞定义:DBMS 通用形态(认证/RBAC/查询处理/存储引擎/外部访问/复制/云控制面/泄露/密钥/内存安全)与 Bugcrowd VRT P1–P5 → 四档映射;含 ClickHouse Bugcrowd 项目资产范围、合格条款、赏金资格(不定级)、历史漏洞模式库(定级校准 + 挖掘切入点)与 Langfuse Cloud 厂商文件(安全架构特征 + 挖掘候选)。

    Claude Code1 skill
  39. Chrome / Chromium 浏览器漏洞定义:官方四档(S0–S3)与缓解/非安全条款,外加进程沙箱、Site Isolation、浏览器形态与 Chrome VRP 资格(不定级)。

    Claude Code1 skill
  40. 移动客户端 App(Android APK / iOS IPA)安全审计方法论:静态解包与攻击面枚举、代码/数据流、混合栈与内嵌 SDK、真机动态验证、PoC 攻击者 App、证据包。不定级;定级配合 vuln-definitions 与 vuln-definitions-mobile。

    Claude Code1 skill
  41. 黑盒 XXE 挖掘. Includes 1 skill.

    Claude Code1 skill
  42. 黑盒 SSRF 挖掘. Includes 1 skill.

    Claude Code1 skill
  43. 黑盒高危密钥与凭据暴露挖掘. Includes 1 skill.

    Claude Code1 skill
  44. 黑盒远程代码执行挖掘. Includes 1 skill.

    Claude Code1 skill
  45. 黑盒注入挖掘(SQL/命令/NoSQL). Includes 1 skill.

    Claude Code1 skill
  46. 黑盒任意文件读写与危险上传挖掘. Includes 1 skill.

    Claude Code1 skill
  47. 黑盒不安全反序列化挖掘. Includes 1 skill.

    Claude Code1 skill
  48. 黑盒鉴权与认证绕过挖掘. Includes 1 skill.

    Claude Code1 skill
  49. Skills, subagent roles, slash commands and an output style from the Agent Harness checkout, installable on their own.

    Claude Code
  50. Turns a clinical document into a plain-language, fact-checked care plan. Every statement is anchored to a line of the original; interim files form an audit trail; output is JSON rendered to Markdown and a single self-contained HTML page.

    Claude Code1 skill