Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add jszmajda/lidnpx agentmods add plugins/jszmajda/lid/arrow-maintenancegit clone --depth 1 https://github.com/jszmajda/lidGrade A, and why
arrow-maintenance scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "arrow-maintenance",
"description": "Scaling layer for linked-intent-dev. Tracks spec-to-code coherence across large projects via docs/arrows/ index. Includes brownfield bootstrap for mapping existing codebases.",
"version": "1.2.0",
"author": {
"name": "Jess Szmajda"
},
"repository": "https://github.com/jszmajda/lid",
"license": "MIT"
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 11 lines scan A 7f7ae32af46a
arrow-maintenance is a plugin published in the GitHub repository jszmajda/lid (100 stars, last pushed 21d ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other plugins, from other repositories
lane-stack
Solo PM conveyor for Claude Code: orchestrator agents, lane playbooks, onboard and resume commands.
catalyst marketplace
Research-driven development workflow with Linear integration, PM tools, and infrastructure research agents.
catalyst-dev
Complete development workflow: research → plan → implement → validate → ship. Includes research agents, planning tools, handoff system, Linear integration, and PM commands.
specmanager
Lifecycle kanban for Claude Code projects (PRD → architecture → plan → tasks → walkthroughs).
commander-hub marketplace
Plugin marketplace listing 1 plugin: commander.
the-loop
An opinionated product-development-lifecycle harness that lets coding agents deliver work items end-to-end, with minimal human intervention, through a predictable loop of plan, execute, self-review, critic-review and escalate.