Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add miles990/claude-software-skillsnpx agentmods add plugins/miles990/claude-software-skills/java-kotlingit clone --depth 1 https://github.com/miles990/claude-software-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/plugins/miles990/claude-software-skills/java-kotlin)<a href="https://agentmods.dev/plugins/miles990/claude-software-skills/java-kotlin"><img src="https://agentmods.dev/badge/plugins/miles990/claude-software-skills/java-kotlin.svg" alt="Measured on agentmods" height="20"></a>Grade A, and why
java-kotlin scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "java-kotlin",
"description": "Java and Kotlin programming patterns",
"source": "./programming-languages/java-kotlin",
"version": "1.0.0",
"strict": true
}What ships with it
1 file beside marketplace.json#java-kotlin in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today First seen · 7 lines scan A 79812d5d880b
java-kotlin is a plugin published in the GitHub repository miles990/claude-software-skills (20 stars, last pushed 7mo ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other plugins, from other repositories
android-skills
Android and KMP development skills for Claude Code — architecture, Compose, coroutines, flows, networking (Retrofit, Ktor), persistent storage (Room, DataStore), pagination, dependency injection (Hilt, Koin), testing, debugging, Gradle, and Material Design 3.
t-tools
DDD-driven development skills, sub-agents and workflow commands for Rust, React, miniapp, and Flutter projects.
swift-engineer
Elite iOS and macOS development expertise with automatic skill activation for Swift, UIKit, AppKit, SwiftUI, Xcode, and Apple frameworks plus code formatting tools.
widgets
Reviews and writes Swift WidgetKit code: timeline providers, configurations, families, accented/tinted rendering, interactive widgets, Controls, Live Activities, Smart Stack relevance, push-updated widgets, data loading, deep links, animations, and SiriKit/ClockKit migration.
swift
Swift programming language utilities and migration tools for Claude Code.
everything-claude-code-ios
Comprehensive Claude Code configurations for iOS/Swift development with profile-based installation, Node.js hook infrastructure, session persistence, and continuous learning. Includes Xcode 26 system prompt insights, Liquid Glass, FoundationModels, and Swift 6.2 concurrency patterns.