Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add corezoid/simulator-ai-pluginnpx agentmods add plugins/corezoid/simulator-ai-plugin/simulatorgit clone --depth 1 https://github.com/corezoid/simulator-ai-pluginGrade A, and why
simulator scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "simulator",
"version": "2.8.0",
"description": "Simulator.Company platform assistant. Exposes the Simulator REST API as an MCP server and provides skills for managing actors, forms, graph structures, and financial accounts.",
"author": {
"name": "Simulator.Company",
"url": "https://simulator.company"
},
"homepage": "https://doc.simulator.company",
"license": "MIT",
"keywords": [
"simulator",
"bpm",
"business-process",
"graph",
"financial",
"actors",
"forms",
"mcp"
],
"skills": "./skills/",
"mcpServers": "./.mcp.json",
"interface": {
"displayName": "Simulator.Company",
"shortDescription": "BPM and financial tracking via Simulator.Company API",
"longDescription": "Manage actors, graph-based business processes, form templates, financial accounts, transactions and transfers via the Simulator.Company REST API.",
"developerName": "Simulator.Company",
"category": "Productivity",
"capabilities": [
"Graph-based business process management",
"Actor and form template management",
"Financial accounts and transaction tracking",
"Multi-layer visual graph organization",
"Dashboard charts and time-series visualisation on graph layers"
],
"websiteURL": "https://simulator.company",
"defaultPrompt": [
"Create a business process graph for customer onboarding",
"Show me all actors in my workspace",
"Create a financial account to track expenses"
]
}
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 44 lines scan A 9249e6c30cf5
simulator is a plugin published in the GitHub repository corezoid/simulator-ai-plugin (60 stars, last pushed 4d ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other plugins, from other repositories
unslop-marketplace
Plugins that make model-assisted text sound natural and human: clearer voice, less robotic phrasing, better burstiness, no AI fingerprint.
unslop
Make assistant output sound human. Strip AI-isms (sycophancy, stock vocab, hedging stacks, em-dash pileups), engineer burstiness, restore voice. Preserves code, URLs, and technical accuracy.
claude-code-dev-workflow
An opinionated spec-to-ship workflow for Claude Code — grill a vague idea into a real PRD, then drive it through plan → TDD → review. | 从模糊想法锻造出 PRD,再驱动完整研发流程.
dev-flow-lite
简版研发流程插件:读 PRD → 提问对齐 → 编码 → Code Review,不写 MD、不做断点续传.
forge-prd
从任何原料(粗略想法、图片、PDF、HTML、MD)通过强势拷问锻造出一份清晰可用的 PRD,输出 MD 文件。.
axonflow
Plugin marketplace listing 1 plugin: axonflow.