Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add carloshpdoc/ios-workflow-claudenpx agentmods add plugins/carloshpdoc/ios-workflow-claude/ios-workflowgit clone --depth 1 https://github.com/carloshpdoc/ios-workflow-claudeGrade A, and why
ios-workflow scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "ios-workflow",
"version": "0.2.0",
"description": "iOS workflow automation: Swift 6 migration, Apollo to native SDK removal, stacked PRs via gh CLI, Jira-driven PR opener, feature-flag cleanup, perf playbook, SwiftLint fixer. Project-specific values are auto-detected or asked at runtime - no setup required.",
"author": {
"name": "Carloshperc",
"email": "[email protected]"
},
"homepage": "https://github.com/carloshpdoc/ios-workflow-claude",
"repository": "https://github.com/carloshpdoc/ios-workflow-claude",
"license": "Apache-2.0",
"keywords": ["ios", "swift", "swift6", "apollo", "jira", "pr-workflow", "github-cli", "stacked-prs", "swiftlint"]
}
What it installs
The manifest is a name and a version. 22 commands, 3 agents travel with it, and installing the plugin installs all of them — 1,356 tokens a session between them. Each is measured on its own page, and each can be installed alone.
- Command apollo-migrate A 0 tokens
- Command swift6-fix A 0 tokens
- Command apollo-check A 0 tokens
- Command open-pr A 0 tokens
- Command perf-investigate A 0 tokens
- Command verified-pr A 104 tokens
- Command apollo-review A 0 tokens
- Command bump A 0 tokens
- Command code-review A 18 tokens
- Command stacked-prs A 19 tokens
- Command apollo-tasks A 0 tokens
- Command feature-flag-check A 0 tokens
- Command request-review A 0 tokens
- Command review-pr A 0 tokens
- Command swift6-check A 0 tokens
- Command create-pr-from-staged-changes A 0 tokens
- Command feature-flag-completed A 0 tokens
- Command swift6-status A 0 tokens
- Command apollo-status A 0 tokens
- Command feature-flag-status A 0 tokens
- Command update-jira A 0 tokens
- Command feature-flag-remove C 0 tokens
- Agent ios-test-writer A 436 tokens
- Agent ios-code-reviewer A 409 tokens
- Agent swiftlint-fixer A 370 tokens
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 14 lines scan A cb4be81dd7e5
ios-workflow is a plugin published in the GitHub repository carloshpdoc/ios-workflow-claude (7 stars, last pushed 2mo ago), licensed Apache-2.0. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other plugins, from other repositories
grovs
Create tracking links for your mobile app and see exactly how much traffic, installs, and app opens each link drives. Set up iOS Universal Links and Android App Links, manage deep links with custom metadata, and get real-time analytics — all from your editor.
agent-toolkit-agents
18 AI agent personas: 11 holistic (planner, architect, designer, implementer, reviewer, qa-engineer, security-engineer, platform-engineer, researcher, data-engineer) + orchestrator (assistant, client-workflow-bootstrap) + 5 specialists (code-reviewer, agentic-security-reviewer, security-reviewer, e2e-runner, tdd-guide.
tray-api
Plugin completo para integração com as APIs da Tray. Acelera o desenvolvimento de aplicativos e-commerce por parceiros e comunidade na plataforma Tray, fornecendo documentação detalhada de todos os endpoints, fluxos de autenticação OAuth, webhooks e boas práticas de integração.
app-intents-pro
App Intents: AppIntent, parameters, entities, App Shortcuts, Siri and Spotlight.
swift-performance-pro
Performance: Instruments, SwiftUI render cost, memory and retain cycles, launch time, lists.
timelinesai-whatsapp
Drive your real WhatsApp inbox from Claude via TimelinesAI — 18 tools across chat discovery, messaging, and triage.