Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add aoreshkov/oracle-forms-mcpnpx agentmods add plugins/aoreshkov/oracle-forms-mcp/oracle-formsgit clone --depth 1 https://github.com/aoreshkov/oracle-forms-mcpGrade A, and why
oracle-forms scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 45 lines — stays where its author put it; the contents beside it link to each section on GitHub.
{
"$schema": "https://json.schemastore.org/claude-code-plugin-manifest.json",
"name": "oracle-forms",
"displayName": "Oracle Forms",
"version": "1.0.0",
"description": "Read Oracle Forms modules (.fmb/.mmb/.pll/.olb) from a directory — blocks, items, triggers, program units, PL/SQL, and durable annotations. Needs a JDK 21+ on PATH.",
"author": {
"name": "Atanas Oreshkov",
"url": "https://github.com/aoreshkov"
},
"homepage": "https://github.com/aoreshkov/oracle-forms-mcp#readme",
"repository": "https://github.com/aoreshkov/oracle-forms-mcp",
"license": "Apache-2.0",
"keywords": ["oracle", "forms", "fmb", "plsql", "legacy", "modernization"],
"userConfig": {
"forms_dir": {
"type": "directory",
"title": "Forms directory",
"description": "Directory containing the Oracle Forms modules to serve. Scanned non-recursively; in copy-mode the pre-converted *_fmb.xml / *.pld files are read from here too.",
"required": true
},
"convert_command": {
"type": "string",
"title": "Custom converter command",
"description": "Optional. Command run instead of Oracle's frmf2xml, with its arguments — quote any part containing spaces (\"C:\\tools\\my conv.bat\" -xml), or give a JSON array ([\"wine\",\"f2x.exe\",\"-xml\"]). It is spawned directly, never through a shell. The module's path replaces {}, or is appended when {} is absent; the working directory is the converted XML directory below, or the module's cache directory when that is empty, and the command must write the text form there. Leave empty to use an ORACLE_HOME installation, or pre-converted files next to the modules.",
"default": "",
"required": false
},
"converted_dir": {
"type": "directory",
"title": "Converted XML directory",
"description": "Optional. Directory the converted XML / .pld text forms are written into — the converter writes here directly, one flat directory for all modules, each file named afteWhat this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 45 lines scan A 173f5918b97b
oracle-forms is a plugin published in the GitHub repository aoreshkov/oracle-forms-mcp (3 stars, last pushed 2d ago), licensed Apache-2.0. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other plugins, from other repositories
chrisbanes-skills
Plugin marketplace listing 1 plugin: chrisbanes-skills.
Kotlin
Plugin marketplace listing 1 plugin: kotlin-agent-skills.
fixture-monkey
Claude Code plugins for Fixture Monkey.
ksafe
Agent skills for the KSafe Kotlin Multiplatform encrypted persistence library.
KSafe
Agent skill for the KSafe Kotlin Multiplatform encrypted persistence library — setup, usage patterns, anti-patterns, and debugging.
opentaint
OpenTaint skills extend built-in security rules and code models for your dependencies and frameworks, then find vulnerabilities with whole-program static taint analysis.