Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add hmans/beansnpx agentmods add plugins/hmans/beans/beans-primegit clone --depth 1 https://github.com/hmans/beansGrade A, and why
beans-prime scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "beans-prime",
"version": "1.0.0",
"description": "Configure Claude Code to track work using Beans.",
"author": {
"name": "Hendrik Mans",
"email": "[email protected]"
}
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 10 lines scan A 84233822bcda
beans-prime is a plugin published in the GitHub repository hmans/beans (909 stars, last pushed 4mo ago), licensed Apache-2.0. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other plugins, from other repositories
design-ops
Streamline design operations with critique frameworks, handoff specs, sprint planning, review processes, and team workflows.
beads_rust
Official marketplace for beadsrust (br), the agent-first issue tracker.
elnora-linear
Linear workspace for Claude Code — single-plugin marketplace.
linear-workspace
Linear issue management for Claude Code — search, bulk operations, intelligent agents, config-driven curator. Backed by the elnora-linear CLI.
aria-knowledge
ARIA — Applied Reasoning and Insight Architecture. Persistent human-governed knowledge for Claude Code via a five-phase lifecycle: capture → govern → promote → apply → refresh. Stages session insights/decisions/feedback into review backlogs, promotes approved items to a tag-indexed markdown base, and applies them via…
g-forge
Educated, enforced project management for AI development - a PM layer, parallel implementation waves, and a git-hook commit gate that can't be skipped. Make any model ship like a senior team.