Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/hmcts/agentic-plugins-marketplaceWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/plugins/hmcts/agentic-plugins-marketplace/hmcts-apim-sdlc-orchestrator)<a href="https://agentmods.dev/plugins/hmcts/agentic-plugins-marketplace/hmcts-apim-sdlc-orchestrator"><img src="https://agentmods.dev/badge/plugins/hmcts/agentic-plugins-marketplace/hmcts-apim-sdlc-orchestrator.svg" alt="Measured on agentmods" height="20"></a>Grade A, and why
hmcts-apim-sdlc-orchestrator scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "hmcts-apim-sdlc-orchestrator",
"version": "1.5.0",
"description": "HMCTS API-Marketplace SDLC orchestrator — a fully self-contained, contract-first pipeline for OpenAPI-first api-cp-* spec libraries and service-cp-* Spring Boot services. Bundles all pipeline agents (requirements-analyst, apim-architect, story-writer, contract-test-engineer, implementation, code-reviewer, amp-security, ci-orchestrator, deployer, catalog-publisher) plus two hub-and-spoke specialists (contract-compatibility-analyzer, feature-flag-auditor), the openapi-spec-reviewer, entra-token-validation, bootstrap-context, and release skills, the forked springboot-api-from-template / springboot-service-from-template repo-bootstrap skills (with git-access verification and README-hygiene trimming of template boilerplate), the wire-service-deployment CI-wiring skill now chained to a new exclude-db-from-priming-clear skill (protects any service-cp-*-owned database from the nonprod priming pipeline's quick_clear sweep), APIM context docs (including a standardized ClockService time-access pattern), and guard hooks. catalog-publisher runs a mandatory eligibility check and validates OpenAPI examples against their schemas before registering. Every pipeline stage now states an explicit signal/handoff to the next agent, implementation enforces a physical red-test gate before any code is written, and the Hard rules carry a broadened, enumerated ADR-trigger list. Targets GHA + ADO CI/CD, PMD, CodeQL, GHCR, and the cp-vp-aks-deploy GitOps repo.",
"author": {
"name": "HMCTS APIM"
},
"license": "MIT",
"keywords": [
"hmcts",
"apim",
"api-marketplace",
"sdlc",
"orchestrator",
"openapi",
"spring-boot",
"contract-first",
"agents",
"pipeline",
"jwt",
"entra",
"security"
]
}What it installs
The manifest is a name and a version. 9 skills, 12 agents, 3 hooks travel with it, and installing the plugin installs all of them — 3,638 tokens a session between them. Each is measured on its own page, and each can be installed alone.
- Skill springboot-service-from-template A 55 tokens
- Skill entra-token-validation A 92 tokens
- Skill publish-api-to-catalog A 114 tokens
- Skill springboot-api-from-template A 65 tokens
- Skill wire-service-deployment A 124 tokens
- Skill exclude-db-from-priming-clear A 141 tokens
- Skill release A 48 tokens
- Skill openapi-spec-reviewer A 78 tokens
- Skill bootstrap-context B 67 tokens
- Agent catalog-publisher A 356 tokens
- Agent amp-security A 356 tokens
- Agent apim-architect A 244 tokens
- Agent code-reviewer A 176 tokens
- Agent ci-orchestrator A 231 tokens
- Agent contract-compatibility-analyzer A 259 tokens
- Agent feature-flag-auditor A 326 tokens
- Agent implementation A 181 tokens
- Agent requirements-analyst A 185 tokens
- Agent deployer A 172 tokens
- Agent story-writer A 171 tokens
- Agent contract-test-engineer A 197 tokens
- Hook PreToolUse A not measured
- Hook UserPromptSubmit A not measured
- Hook SessionStart A not measured
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday Changed · +3 lines e22b0155706a
- 8d ago First seen · 21 lines scan A d935d9a815df
hmcts-apim-sdlc-orchestrator is a plugin published in the GitHub repository hmcts/agentic-plugins-marketplace (3 stars, last pushed yesterday), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other plugins, from other repositories
app-builder
Development, customization, testing, and deployment skills for Adobe App Builder projects, including the Workfront UI-extension suite (skills/appbuilder-workfront).
load-tester
Load and stress testing for APIs and web services.
rabbitmqadmin
Skill for inspecting RabbitMQ instances using the rabbitmqadmin CLI (rabbitmqadmin-ng).
jpm-payments-skills
Conversational agent skills that walk a merchant from J.P. Morgan Payments onboarding through a working API integration. Supports Checkout and Online Payments in the initial release. Generates language-specific OAuth modules (Node/TypeScript, Python, Java idiomatic; other languages via canonical algorithm).
rails-consultant marketplace
Plugin marketplace listing 1 plugin: rails-consultant.
rails-consultant
A collection of skills for Rails development and consulting, with an emphasis on learning, communication, and client success.