Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add aannoo/hcomnpx agentmods add plugins/aannoo/hcom/marketplacegit clone --depth 1 https://github.com/aannoo/hcomGrade A, and why
hcom scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"$schema": "https://anthropic.com/claude-code/marketplace.schema.json",
"name": "hcom",
"version": "1.0.0",
"description": "Let AI agents message, watch, and spawn each other across terminals. Claude Code, Gemini CLI, Codex, OpenCode, Kilo Code, Pi, Oh My Pi, Antigravity, Cursor, Kimi, Copilot.",
"metadata": {
"description": "Let AI agents message, watch, and spawn each other across terminals. Claude Code, Gemini CLI, Codex, OpenCode, Kilo Code, Pi, Oh My Pi, Antigravity, Cursor, Kimi, Copilot."
},
"owner": {
"name": "aannoo"
},
"plugins": [
{
"name": "hcom",
"source": "./plugin/hcom",
"description": "Let AI agents message, watch, and spawn each other across terminals. Claude Code, Gemini CLI, Codex, OpenCode, Kilo Code, Pi, Oh My Pi, Antigravity, Cursor, Kimi, Copilot.",
"category": "productivity",
"homepage": "https://github.com/aannoo/hcom"
}
]
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 22 lines scan A cc62c4491fdf
hcom is a plugin published in the GitHub repository aannoo/hcom (469 stars, last pushed 22d ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other plugins, from other repositories
overnight-keep-alive
Blocks the agent from stopping overnight. When a Stop event fires before the configured end-hour (default 06:00 local time), the hook emits a block decision that forces Claude to keep iterating on the current task until morning. Intended for long-running overnight builds (e.g. the cycle-tracker port) where the user…
app-mockup-kit
Deterministic app screenshot mockups for agents via a standalone TypeScript CLI and reusable SKILL.md workflow.
stfu
Minimal response mode for AI agents with automatic prompt injection.
safety-net
Block destructive git and filesystem commands before execution.
methodology-skills
Plugin marketplace listing 1 plugin: methodology-skills.
agent-skills
Plugin marketplace listing 8 plugins: elastic-search-logs, german-elster-tax-filing, prompt-template-wizard, read-only-gh-pr-review, read-only-postgres.