Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add AppleCG/devflownpx agentmods add plugins/applecg/devflow/devflowgit clone --depth 1 https://github.com/AppleCG/devflowGrade A, and why
devflow scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "devflow",
"version": "1.0.0",
"description": "Full-lifecycle AI development workflow — fuses grill-with-docs (Matt Pocock) + OpenSpec (Fission-AI) + superpowers (obra) into one disciplined pipeline. Three modes: Design (quick-grill → spec-lite), Build (grill → spec → plan → isolate → enhanced-apply → review → archive), Fix (diagnose → apply → verify → archive).",
"author": "DevFlow",
"license": "MIT",
"repository": "https://github.com/user/devflow",
"keywords": ["devflow", "workflow", "spec-driven", "tdd", "grill", "design", "development"],
"skills": [
{
"name": "devflow",
"description": "Route to the right mode (design/build/fix) and enforce the full development pipeline. Auto-detects whether you're discussing design, building features, or fixing bugs.",
"path": "skills/devflow/SKILL.md"
}
],
"hooks": {
"SessionStart": [
{
"prompt": "DevFlow is active. Before any action, analyze the user's intent: Are they discussing/designing a solution (→ Design mode)? Are they building a feature or implementing a change (→ Build mode)? Are they reporting a bug or unexpected behavior (→ Fix mode)? Route to the devflow skill accordingly. All artifacts go to devwork/ directory. Templates are in skills/devflow/templates/.",
"skills": ["devflow"]
}
]
}
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 25 lines scan A 5a58cda6a37d
devflow is a plugin published in the GitHub repository AppleCG/devflow (8 stars, last pushed 1mo ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other plugins, from other repositories
disruptor
12 agent skills for AI-driven software development, stitched into one gated idea-to-ship pipeline: 7w3 design, build-ready spec, executable architecture guardrails, tracer-bullet slicing, an honest review loop, a parallel MVP worker fleet, demo-stand QA and safe server deploy. Cross-agent skills format (Claude Code…
ForgeDock
Autonomous AI development pipeline that uses GitHub as a structured knowledge graph for Claude Code agents. Adds /work-on, /review-pr, /quality-gate, /orchestrate, and 20+ pipeline commands.
acgm
ACGM (Agent Coding Governance Methodology) for Claude Code. ACGM(Agent 编码治理方法论)Claude Code 版。.
nextjs
Official Next.js skills: adopt and optimize Cache Components, adopt Partial Prefetching, and verify runtime behavior against a running dev server.
nextjs
Official Claude Code plugin marketplace for Next.js, serving the skills that ship in the vercel/next.js repository.
claude-plugins-official
Directory of popular Claude Code extensions including development tools, productivity plugins, and MCP integrations.