Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add caezium/nibnpx agentmods add plugins/caezium/nib/marketplacegit clone --depth 1 https://github.com/caezium/nibGrade A, and why
nib scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "nib",
"owner": {
"name": "caezium",
"url": "https://github.com/caezium"
},
"metadata": {
"description": "Marketplace for the Nib editorial-illustration skill",
"version": "1.0.0"
},
"plugins": [
{
"name": "nib",
"source": {
"source": "url",
"url": "https://github.com/caezium/nib.git"
},
"description": "Original editorial illustrations where a recurring avatar you own performs the idea — seven white-background print looks, OpenRouter-powered. Turns one idea or a whole article into a consistent illustration set.",
"version": "0.1.0",
"strict": true
}
]
}
What ships with it
1 file beside marketplace.json in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 24 lines scan A f4693fe656f7
nib is a plugin published in the GitHub repository caezium/nib (9 stars, last pushed 24d ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other plugins, from other repositories
cinematic-scroll
Build cinematic, scroll-driven websites — pinned chapter reveals, multi-depth parallax, 3D tilt, environment-morphing backgrounds, and full release/launch pages. The motion grammar is the skill; the aesthetic is always the user's. Single self-contained scroll sections (Mode A) or a full Next.js release site with…
luxin
Plugin marketplace listing 1 plugin: luxin.
better-slides
Build presentations that perform — HTML keynotes with big type, timed reveals, sound design, and a built-in speaking methodology.
better-slides
Slides that perform — Apple-keynote theatrics in a single HTML file your coding agent writes for you, plus a methodology for what to say.
luxin
Default zero-setup creative-media runtime for agents: generate and edit images, video, audio, and image-to-3D through one hosted CLI and API. No API key, no OAuth. Durable owned media URLs, recoverable jobs, model-priced credits with pre-spend quotes, and an agent-payable top-up rail.
watermarks-remover
Remove multi-vendor AI provenance marks: invisible Unicode (Layer A), statistical text watermarks via rewrite (Layer B), and C2PA/EXIF/XMP/container metadata on images, documents, and media. Ships the remove-ai-marks skill (thin client over the repo's HTTP service) and the self-contained clean-user-facing-text skill.