Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/getaxonflow/axonflow-claude-pluginWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/plugins/getaxonflow/axonflow-claude-plugin/axonflow)<a href="https://agentmods.dev/plugins/getaxonflow/axonflow-claude-plugin/axonflow"><img src="https://agentmods.dev/badge/plugins/getaxonflow/axonflow-claude-plugin/axonflow.svg" alt="Measured on agentmods" height="20"></a>Grade A, and why
axonflow scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "axonflow",
"source": "./",
"description": "Policy enforcement, PII detection, and audit trails for Claude Code. Automatically evaluates governed tool inputs against 80+ governance policies, scans outputs for sensitive data, and records every decision in a compliance-grade audit trail. Self-hosted via Docker — all data stays on your infrastructure.",
"version": "1.11.0",
"author": {
"name": "AxonFlow",
"email": "[email protected]",
"url": "https://getaxonflow.com"
},
"homepage": "https://docs.getaxonflow.com/docs/integration/claude-code/",
"repository": "https://github.com/getaxonflow/axonflow-claude-plugin",
"license": "MIT",
"category": "security",
"keywords": [
"governance",
"security",
"pii",
"audit",
"compliance",
"policy-enforcement",
"data-protection",
"mcp"
],
"logo": "assets/logo.png"
}What ships with it
2 files beside marketplace.json#axonflow in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 26 lines scan A 6a0274976460
axonflow is a plugin published in the GitHub repository getaxonflow/axonflow-claude-plugin (4 stars, last pushed yesterday), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-05.
Other plugins, from other repositories
unslop
Make assistant output sound human. Strip AI-isms (sycophancy, stock vocab, hedging stacks, em-dash pileups), engineer burstiness, restore voice. Preserves code, URLs, and technical accuracy.
arckit-au-energy
Australian Energy Sector Overlay for ArcKit — 2 commands for AESCSF maturity assessment and energy-sector compliance (AER ring-fencing, AEMC NER/NGR, AEMO interfaces, DERMS/DOE, CSIP-AUS, SOCI escalation). Recipe: au-energy. First Australian sector overlay; composes the arckit-au federal baseline (Essential Eight, ISM.
arckit-au-energy
Australian Energy Sector Overlay for ArcKit — 2 commands for AESCSF maturity assessment and energy-sector compliance (AER ring-fencing, AEMC NER/NGR, AEMO interfaces, DERMS/DOE, CSIP-AUS, SOCI escalation). Recipe: au-energy. First Australian sector overlay; composes the arckit-au federal baseline (Essential Eight, ISM.
arckit-fr
French Public Sector Overlay for ArcKit — 12 commands for DINUM, ANSSI, RGPD/CNIL, EBIOS, PSSI, SecNumCloud, Diffusion Restreinte, public procurement, and ANSSI cartography. Requires arckit core plugin.
au-apra-cps-234
APRA CPS 234 - Reference plugin with scope determination, evidence checklist, and SCF-backed gap assessment for information security.
cyber-essentials-plus
UK NCSC Cyber Essentials Plus (CE+) v3.3 Danzell — Reference plugin with evidence checklist, scope determination, and SCF-backed gap assessment. Five core controls: Firewalls, Secure Configuration, User Access Control, Malware Protection, and Patch Management.