Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add karlarao/afknpx agentmods add plugins/karlarao/afk/matt-latestgit clone --depth 1 https://github.com/karlarao/afkWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/plugins/karlarao/afk/matt-latest)<a href="https://agentmods.dev/plugins/karlarao/afk/matt-latest"><img src="https://agentmods.dev/badge/plugins/karlarao/afk/matt-latest.svg" alt="Measured on agentmods" height="20"></a>Grade A, and why
mattpocock-skills scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
94% identical to mattpocock-skills — 1 line differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
What it actually says
{
"name": "mattpocock-skills",
"skills": [
"./skills/engineering/diagnose",
"./skills/engineering/grill-with-docs",
"./skills/engineering/triage",
"./skills/engineering/improve-codebase-architecture",
"./skills/engineering/setup-matt-pocock-skills",
"./skills/engineering/tdd",
"./skills/engineering/to-issues",
"./skills/engineering/to-prd",
"./skills/engineering/zoom-out",
"./skills/engineering/prototype",
"./skills/productivity/caveman",
"./skills/productivity/grill-me",
"./skills/productivity/write-a-skill"
]
}
What it installs
The manifest is a name and a version. 13 skills travel with it, and installing the plugin installs all of them — 836 tokens a session between them. Each is measured on its own page, and each can be installed alone.
- Skill writing-beats A 78 tokens
- Skill writing-fragments A 80 tokens
- Skill triage A 49 tokens
- Skill diagnose A 66 tokens
- Skill setup-matt-pocock-skills A 124 tokens
- Skill to-prd A 36 tokens
- Skill prototype A 90 tokens
- Skill grill-with-docs A 57 tokens
- Skill caveman A 68 tokens
- Skill writing-shape A 76 tokens
- Skill to-issues A 53 tokens
- Skill handoff A 19 tokens
- Skill zoom-out A 40 tokens
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 19 lines scan A b7ab2ed7eb7e
mattpocock-skills is a plugin published in the GitHub repository karlarao/afk (2 stars, last pushed 3mo ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. It is 94% identical to mattpocock-skills, differing in 1 line, and is treated as a copy.
Other plugins, from other repositories
metaswarm
Multi-agent orchestration framework for Claude Code, Gemini CLI, and Codex CLI — 19 agents, 14 skills, 16 commands, quality gates, TDD enforcement.
flow
Unified toolkit for Context-Driven Development with spec-first planning, TDD workflow, and OKF knowledge bundles.
harnessay
Profile your Claude Code transcripts: context budget report, skill-promotion candidates, and a skill regression test harness. Local-only, stdlib-only.
superpowers-deepseek-v4
Superpowers DeepSeek v4: composable agent skills for TDD, debugging, and collaboration. Independently maintained; not identical to obra/superpowers.
whetstone
Engineering-craft skills that sharpen the edge: red-green TDD, flaky-test audit, pre-decision doubt review, merge-conflict resolution, skill linting, and a column budget computed from the staged diff. Each carries a deterministic self-verify.
next-todo
Land one TODO.md PR slice: choose the next slice, review the plan to consensus, implement with red-green TDD, open a draft pull request, and drain review comments until CI is green.