Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add handarbeit/fabriknpx agentmods add plugins/handarbeit/fabrik/marketplacegit clone --depth 1 https://github.com/handarbeit/fabrikWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/plugins/handarbeit/fabrik/marketplace)<a href="https://agentmods.dev/plugins/handarbeit/fabrik/marketplace"><img src="https://agentmods.dev/badge/plugins/handarbeit/fabrik/marketplace.svg" alt="Measured on agentmods" height="20"></a>Grade A, and why
fabrik marketplace scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 44 lines — stays where its author put it; the contents beside it link to each section on GitHub.
{
"$schema": "https://anthropic.com/claude-code/marketplace.schema.json",
"name": "fabrik",
"description": "The Fabrik plugin marketplace \u2014 ambient awareness of Fabrik (a GitHub-Project-driven SDLC pipeline orchestrator) for your interactive Claude Code session.",
"owner": {
"name": "handarbeit.io",
"url": "https://handarbeit.io"
},
"plugins": [
{
"name": "fabrik",
"description": "Ambient awareness of Fabrik for the human's interactive Claude Code session. Turns Claude into a product-management buddy and supervisor for projects that use Fabrik to automate issue processing through a configurable SDLC pipeline (Specify, Research, Plan, Implement, Review, Validate).",
"category": "development",
"source": {
"source": "git-subdir",
"url": "https://github.com/handarbeit/fabrik.git",
"path": "plugin/fabrik",
"ref": "main"
},
"homepage": "https://fabrik.handarbeit.io",
"author": {
"name": "handarbeit.io",
"url": "https://handarbeit.io"
}
},
{
"name": "entwurf",
"description": "Turn a project into buildable specifications, one expert role at a time. Guided interviews for the three people a project needs: the product owner (goals, scope, vocabulary, then feature specifications), the technical architect (constraints, shared domain model, contracts, then the architecture baseline), and the experience lead (conditions of use, states, components, content). Output is a standard GitHub Spec Kit specs/ folder ready to hand to a development team, or to Fabrik. The product-owner path needs no terminal, git, or technical background.",
"category": "productivity",
"source": {
"source": "git-subdir",
"url": "https://github.com/handarbeit/fabrik.git",
"path": "plugin/entwurf",
"ref": "main"
},
"homepage": "https://fabrik.handarbeit.io",
"author": {
"name": "handarbeit.io",
The plugins it lists here
This marketplace lists 3 plugins kept in the same repository. Each has its own page, its own measurements and its own install command.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 44 lines scan A 7ecacfd8d127
fabrik marketplace is a plugin published in the GitHub repository handarbeit/fabrik (22 stars, last pushed today), licensed Apache-2.0. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other plugins, from other repositories
dx
Developer experience essentials: GitHub Actions debugging, conversation half/quarter-cloning, context handoffs, research (Reddit and Hacker News), private GitHub search, and Claude Code version checks.
junior-flow
Helps junior developers create technical story markdown from a story tracker.
milestone-driver
Drives a GitHub milestone to completion: triages each issue for design gaps + dependency order up front, then for each buildable issue finds the root cause (or parks it), dispatches a TDD implementer subagent, runs unit + E2E tests + code review, opens a PR, and auto-merges issues on CI green. The whole loop sits…
context-optimization
Techniques for extending effective context capacity through compaction, observation masking, KV-cache optimization, and context partitioning. Double or triple effective context without larger models.
cc-research
Multi-agent deep research on Claude models: orchestrator -> parallel researcher subagents -> triangulate -> synthesize -> cite -> report. Built-in tools only (WebSearch, WebFetch, Read, Grep, Glob, Write, Task); no external research APIs or MCP servers.
sample-plugin
sample-plugin. Marketplace Framework AI-Driven Dev : Context Engineering, Plugins, Agents, Skills, Hooks, Templates, SDLC.