Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add EngDawood/emdash-claude-pluginnpx agentmods add plugins/engdawood/emdash-claude-plugin/emdash-claude-plugingit clone --depth 1 https://github.com/EngDawood/emdash-claude-pluginWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/plugins/engdawood/emdash-claude-plugin/emdash-claude-plugin)<a href="https://agentmods.dev/plugins/engdawood/emdash-claude-plugin/emdash-claude-plugin"><img src="https://agentmods.dev/badge/plugins/engdawood/emdash-claude-plugin/emdash-claude-plugin.svg" alt="Measured on agentmods" height="20"></a>Grade A, and why
emdash scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
The source is not reproduced here
No licence file
A repository with no LICENSE is all rights reserved by default, so the body is not copied here. The metadata, the measurements and the link are.
What it installs
The manifest is a name and a version. 8 skills, 7 agents, 3 MCP servers travel with it, and installing the plugin installs all of them — 884 tokens a session between them. Each is measured on its own page, and each can be installed alone.
- Skill wordpress-plugin-to-emdash A 52 tokens
- Skill emdash-cli A 56 tokens
- Skill building-emdash-site A 70 tokens
- Skill emdash-github-actions A 234 tokens
- Skill adversarial-reviewer A 71 tokens
- Skill agent-browser A 32 tokens
- Skill wordpress-theme-to-emdash A 72 tokens
- Skill creating-plugins B 62 tokens
- Agent _INVESTIGATE A 0 tokens
- Agent diagnose A 29 tokens
- Agent fix A 39 tokens
- Agent repro-admin A 44 tokens
- Agent repro-api A 48 tokens
- Agent repro-public A 45 tokens
- Agent verify A 30 tokens
- MCP server emdash-admin-local A not measured
- MCP server Astro docs A not measured
- MCP server emdash-docs A not measured
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 11 lines scan A 0d9119c927bb
emdash is a plugin published in the GitHub repository EngDawood/emdash-claude-plugin (3 stars, last pushed 2mo ago), with no licence file. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other plugins, from other repositories
skills
Skills for the Cloudflare developer platform: Workers, Durable Objects, Agents SDK, MCP servers, Wrangler CLI, and web performance.
alibabacloud-ecs-ops
Alibaba Cloud ECS 全生命周期运维管理插件,覆盖实例管理、诊断排障、磁盘快照、安全组网络及场景化运维,集成操作前成本评估能力.
alibabacloud-spec-ops
Alibaba Cloud AI Ops Plugin - Infrastructure operations workflow with intelligent planning, validation, and execution powered by MCP tooling.
rudder-terraform
Workflows for managing RudderStack workspaces with the Terraform provider: provider setup, resource and data-source usage, init/plan/apply cycles, module structure, and state management.
website-deploy
Deploy static websites to simple-host.app from your coding agent (inline JSON or tar.gz/zip). Each site gets a per-site backend (shared JSON state with atomic ops, append-only collections, drop-in comments/feedback widgets, templates), built-in server-side visitor analytics, and can be connected to your own custom…
cybrix-deploy
Deploy the current static site to a live HTTPS URL via Cybrix. Detects Next.js export, Astro, Vite, Hugo, Eleventy, and plain HTML. Returns a live URL on .cbrx.cc in under 60 seconds.