Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add ironwallet/ironwallet-agent-kitnpx agentmods add plugins/ironwallet/ironwallet-agent-kit/plugingit clone --depth 1 https://github.com/ironwallet/ironwallet-agent-kitGrade A, and why
ironwallet-mcp scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "ironwallet-mcp",
"version": "1.1.0",
"description": "The IronWallet MCP server gives AI agents a non-custodial hot wallet on the host machine. Seed phrases stay encrypted locally and never leave the host. Agents can check balances, transfer tokens, and swap across 10+ networks (EVM, Tron, Bitcoin, Litecoin, Dogecoin, Solana, XRP, TON).",
"author": {
"name": "IronWallet",
"email": "[email protected]",
"url": "https://ironwallet.io"
},
"homepage": "https://ironwallet.io/ai",
"repository": "https://github.com/ironwallet/ironwallet-agent-kit",
"license": "MIT",
"logo": "assets/logo.svg",
"keywords": ["wallet", "crypto", "mcp", "swap", "transfer", "web3"]
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 16 lines scan A b87518e55a28
ironwallet-mcp is a plugin published in the GitHub repository ironwallet/ironwallet-agent-kit (0 stars, last pushed 3d ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other plugins, from other repositories
claude-code
Deterministic harness-maturity audit for your repository: measures AGENTS.md, rules, skills, hooks, sensors, CI, and hygiene against a 5-level maturity model — without any LLM calls — and teaches the agent how to fix every gap.
harness-score
Deterministic AI coding harness-maturity plugins — audit AGENTS.md, rules, skills, hooks, sensors, CI, and hygiene, and fix every gap.
cursor-usage
Query and analyze your Cursor Enterprise team's AI usage, spending, and adoption metrics. Wraps the full Cursor Admin and Analytics APIs as MCP tools with expert data interpretation skills.
humanizer
Install Humanizer as a Claude plugin.
ainb-hooks
Emit every safely observable Claude Code lifecycle event into Hangar's durable provider log. User-facing events still reach ainb-notifyd over its Unix socket. The same notify.sh powers ATC structured control when installed with AINBMANAGED=atc. stallguard.py additionally blocks turn-end when a session would idle on i.
draft-plugins
Plugin marketplace listing 1 plugin: draft.