Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add alicicek/tale-modenpx agentmods add plugins/alicicek/tale-mode/tale-modegit clone --depth 1 https://github.com/alicicek/tale-modeGrade A, and why
tale-mode scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"$schema": "https://json.schemastore.org/claude-code-plugin-manifest.json",
"name": "tale-mode",
"displayName": "Tale Mode",
"version": "2.6.1",
"description": "A discipline mode for complex/high-stakes work: staged planning, decisions-with-receipts, verify-against-source, parallel delegation, adversarial review. Always-on core disciplines via a SessionStart hook, plus a self-armed autonomous loop (a deterministic Stop gate) that can also arm itself from a committed, content-hash-trusted .claude/tale-mode.json during a kickoff phase. Plan-mode investigation runs without a wall of permission dialogs: a fail-closed PreToolUse hook auto-approves provably read-only shell in plan mode only (kill switch TALE_PLAN_APPROVE=0; see SECURITY.md). Cross-platform: the skill + autonomous loop run on both Claude Code and OpenAI Codex (on Codex the loop needs the one-time `touch ~/.tale-mode-allow-cwd-root` opt-in \u2014 its hook subprocesses don't receive env config). Helper skills: trust (the two user-only opt-in files), seed-gates (suggest committed gates), end-phase (clear the phase marker). The optional read-only stuck-loop governor (one advisory model call per stuck goal) ships as the companion plugin tale-mode-governor.",
"author": {
"name": "Ali Cicek",
"url": "https://github.com/alicicek"
},
"homepage": "https://github.com/alicicek/tale-mode",
"repository": "https://github.com/alicicek/tale-mode",
"license": "MIT",
"keywords": [
"workflow",
"planning",
"discipline",
"stop-hook",
"autonomous-loop",
"review"
],
"defaultEnabled": true
}What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 23 lines scan A 0d53152e0e93
tale-mode is a plugin published in the GitHub repository alicicek/tale-mode (36 stars, last pushed 2mo ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other plugins, from other repositories
codeeraser
Plugin marketplace listing 1 plugin: codeeraser.
logic-lens-marketplace
Plugin marketplace listing 1 plugin: logic-lens.
craftsman-marketplace
Practical, opinionated craft skills for Claude Code and Codex: engineering-readiness audits for AI-built apps, and CPA-grade US tax and accounting workpapers.
bullpen
The senior dev, unbundled. A cast of opinionated skills that make an AI agent push back on bad ideas, verify before it claims done, attack its own code, and finish like a senior engineer.
dynos-work
Autonomous Software Foundry. Human-directed, tool-grounded, self-improving. Plans, executes, audits, repairs — calibrates to your project over time.
raysense-marketplace
Raysense — architectural X-ray for your codebase, exposed to AI coding agents through MCP.