Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add LukeRenton/explore-claude-codenpx agentmods add plugins/lukerenton/explore-claude-code/marketplacegit clone --depth 1 https://github.com/LukeRenton/explore-claude-codeGrade A, and why
explore-claude-code marketplace scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 92 lines — stays where its author put it; the contents beside it link to each section on GitHub.
{
// .claude-plugin/marketplace.json — Marketplace Catalogue
//
// This file defines a plugin marketplace: a catalogue that lists
// plugins and tells Claude Code where to fetch them. Host this
// in a git repo and share it with your team or community.
//
// Users add your marketplace:
// /plugin marketplace add owner/repo
//
// Then install individual plugins:
// /plugin install review-plugin@my-marketplace
// ── Marketplace identity ───────────────────────────────────────
// Public-facing name (kebab-case). Users see this when installing:
// /plugin install <plugin>@my-marketplace
"name": "my-marketplace",
// Who maintains this marketplace
"owner": {
"name": "Your Team",
"email": "[email protected]"
},
// ── Optional metadata ──────────────────────────────────────────
"metadata": {
"description": "A starter marketplace showing the catalogue format",
"version": "1.0.0",
// Base directory for relative plugin sources.
// With this set, "source": "review-plugin" resolves to "./plugins/review-plugin"
"pluginRoot": "./plugins"
},
// ── Plugin catalogue ───────────────────────────────────────────
//
// Each entry needs at minimum a name and source.
// You can also include any field from the plugin.json schema.
"plugins": [
// ── Relative path source ─────────────────────────────────────
// Plugin lives in the same repo as the marketplace.
// The simplest option for self-contained marketplaces.
{
"name": "review-plugin",
"source": "./plugins/review-plugin",
"description": "Adds a /review skill for quick code reviews",
"version": "1.0.0"
},
// ── GitHub source ────────────────────────────────────────────
// Plugin lives in a separate GitHub repo.
// Supports ref (branch/tag) and sha (exact commit) pinning.
{
"name": "deploy-tools",
"source": {
"source": "github",
"repo": "your-org/deploy-pluginWhat this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 92 lines scan A ba9bee0ceb60
explore-claude-code marketplace is a plugin published in the GitHub repository LukeRenton/explore-claude-code (309 stars, last pushed 21d ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other plugins, from other repositories
edulab
教育类技能集合:把学科问题转成可交互的教学网页。edu-solid-geometry 立体几何解题(建系+向量法,3D Three.js + MathJax);edu-analytic-geometry 解析几何/圆锥曲线解题(sympy 精确计算 + 实时交互 2D 画板 + KaTeX);edu-chem-reaction 化学反应微观 3D 演示(sympy 自动配平 + 原子守恒,morph/mechanism 双引擎,Three.js + KaTeX)。.
Master-skill
FoJin-powered Buddhist AI persona framework — source-grounded, boundary-aware, fidelity-tested, runtime-ready. 15 prebuilt masters across 印度/汉传/藏传/南传 plus compare, debate, and curriculum meta-skills.
swe-interview-coach
SWE interview prep — behavioral (STAR story bank, company-tailored mocks, delivery drills, debriefs), system design (canonical walkthroughs, graded mocks on a shared local Excalidraw canvas, practice sessions, real-interview debriefs), and coding (DSA pattern walkthroughs, guided practice, graded mocks with a local…
eli5
Build an interactive, self-contained HTML explainer that makes a hard idea genuinely click - a thing you operate, not a document you read. Lets the mechanism pick the shape of the page from eight that recur (Machine, Field, Solid, Ladder, Fork, Trace, Assembly, Reveal) rather than giving every topic the same tabs, and.
no-vibe
Tutor mode for AI coding assistants. AI shows code in chat and reviews your work, but never writes to your project files.
college-scorecard-mcp-server
Search, compare, and analyze U.S. college data — costs, earnings, programs, and outcomes — via MCP. STDIO or Streamable HTTP.