Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add flintt-dev/boardrepo-pluginnpx agentmods add plugins/flintt-dev/boardrepo-plugin/boardrepo-plugingit clone --depth 1 https://github.com/flintt-dev/boardrepo-pluginGrade A, and why
boardrepo scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "boardrepo",
"version": "1.0.0",
"description": "Search and review real PCB projects with BoardRepo. Inspect schematic connectivity, BOMs and source files, run KiCad checks, compare fabrication limits, and review boards you own.",
"author": {
"name": "Flintt, Inc.",
"email": "[email protected]",
"url": "https://boardrepo.com"
},
"homepage": "https://boardrepo.com/connect",
"repository": "https://github.com/flintt-dev/boardrepo-plugin",
"license": "MIT",
"skills": "./skills/",
"mcpServers": {
"boardrepo": {
"type": "http",
"url": "https://boardrepo.com/mcp"
}
},
"keywords": [
"electronics",
"eda",
"kicad",
"pcb-design",
"hardware-design",
"design-review",
"schematic-analysis",
"bom",
"drc"
]
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 32 lines scan A 6e3ab3d6f52b
boardrepo is a plugin published in the GitHub repository flintt-dev/boardrepo-plugin (0 stars, last pushed 8d ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other plugins, from other repositories
auvik
Every Auvik endpoint as a command, plus the cross-client answers the Auvik UI and API cannot give you.
domotz
Every Domotz endpoint, plus a local SQLite fleet mirror that answers cross-site questions.
kicad
Design, inspect, validate, and export KiCad schematics and PCBs from natural-language prompts.
kicad-pro
KiCad MCP Pro plugin for schematic review, PCB design assistance, DRC/ERC validation, DFM checks, and manufacturing release workflows.
kiln
AI agent infrastructure for 3D printing — design, slice, print, monitor, and recover on real printers (Bambu Lab, Creality, Prusa, Elegoo, OctoPrint, Moonraker/Klipper, Direct USB). Bundles the full Kiln MCP server. Requires uv.
superb
Personal skill collection. Skills are invoked as superb: . craft turns a vague product idea into a decision-rich CRAFT.md brief — it questions, challenges and records, and deliberately stops short of planning. pipeline takes a settled idea to a finished branch, composing the superpowers skills with a zero-assumpt.