Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add AratKruglik/claude-sdlcnpx agentmods add plugins/aratkruglik/claude-sdlc/php-foundationgit clone --depth 1 https://github.com/AratKruglik/claude-sdlcWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/plugins/aratkruglik/claude-sdlc/php-foundation)<a href="https://agentmods.dev/plugins/aratkruglik/claude-sdlc/php-foundation"><img src="https://agentmods.dev/badge/plugins/aratkruglik/claude-sdlc/php-foundation.svg" alt="Measured on agentmods" height="20"></a>Grade A, and why
php-foundation scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "php-foundation",
"version": "1.3.0",
"description": "Shared PHP foundation skills for the SDLC marketplace. Contains stack-agnostic conventions: php-conventions (modern PHP 8.x idioms — readonly properties, enums, match, constructor promotion, strict_types, PSR-12), composer-tooling (PSR-4 autoloading, version constraints, scripts, platform requirements) and php-testing (PHPUnit + Pest, data providers, test doubles, fixtures, coverage). Referenced by laravel-plugin and symfony-plugin. No agent, no stack profile — pure shared library.",
"author": {
"name": "Oleksii Kruhlyk",
"url": "https://github.com/AratKruglik"
},
"license": "MIT",
"homepage": "https://github.com/AratKruglik/claude-sdlc",
"keywords": ["php", "composer", "phpunit", "pest", "psr-12", "shared", "foundation", "sdlc"],
"dependencies": ["sdlc"]
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today First seen · 14 lines scan A 8a0f68e77775
php-foundation is a plugin published in the GitHub repository AratKruglik/claude-sdlc (32 stars, last pushed 29d ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other plugins, from other repositories
php-style
PHP code conventions centred on object calisthenics: one level of indentation, no else, wrapped primitives, first-class collections, no train wrecks, no abbreviations, small entities, no getters or setters, plus the PHP specifics that support them.
superpowers-laravel
Laravel-focused skills for Claude Code: TDD (Pest/PHPUnit), migrations, queues, quality checks (Pint/Insights), and pragmatic architecture patterns — Sail and non-Sail compatible.
symfony-contribution-skills
AI agent skills for contributing to Symfony: PHP coding standards, naming conventions, the backward compatibility promise, and reStructuredText documentation standards.
lean
Dense answers, honest token accounting, Laravel/PHP aware.
phpstan-type-trace
See the full type-inference chain of any PHP value in PHPStan — every assignment, parameter binding, narrowing, and read up to the failing line. Lets Claude Code fix PHPStan errors with upstream type evidence instead of guesses.
laravel-claude-agents
Specialized Claude Code subagents and skills for Laravel development — architecture, Eloquent, API, testing, security, performance, debugging, and more.