Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add juntossomosmais/pommelnpx agentmods add plugins/juntossomosmais/pommel/backend-csharp-plugingit clone --depth 1 https://github.com/juntossomosmais/pommelGrade A, and why
backend-csharp-plugin scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "backend-csharp-plugin",
"description": "Conditional rules for backend development in C# / .NET.",
"version": "0.1.0",
"author": { "name": "Juntos Somos Mais", "url": "https://github.com/juntossomosmais" },
"repository": "https://github.com/juntossomosmais/pommel",
"license": "MIT",
"keywords": ["csharp", "dotnet", "aspnetcore", "cap", "hangfire", "conditional-rules"],
"dependencies": [
{ "name": "conditional-rules-plugin", "version": ">=0.1.0" }
]
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 13 lines scan A 19533bc164d3
backend-csharp-plugin is a plugin published in the GitHub repository juntossomosmais/pommel (5 stars, last pushed 14d ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other plugins, from other repositories
koshi
Koshi MCP — retrieval, context engineering, persistent memory, and quality scoring for AI agents. 100% offline.
handoff
handoff: portable per-project context & state management for coding agents. A hook-driven memory spine — STATUS, RULES, MAP, durable tasks, and folder-level CONTEXT.md — that loads the right context at the right moment instead of bloating every session.
handoff
Portable project memory + development workflow for coding agents: auto-loads STATUS+RULES each session, enforces folder-level CONTEXT.md on edit, nudges durable state updates at turn end, scaffolds the system into any repo via guided discovery, and ships a tiered 6-phase workflow skill set covering every phase (brief.
amber
Zero-dependency context survival kit for Claude Code. Auto-checkpoints your session state to plain Markdown before compaction, restores it after — plus focus skills that keep Claude lean and on-task. No database, no background process, no AI compression. Just files you can read.
claude-amber
Amber — zero-dependency context survival kit for Claude Code.
ballast
Builds up to a goal in a field you have no expertise in — learns the foundations it needs and keeps every solved path for the next goal.