Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/modu-ai/moai-coworkWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/plugins/modu-ai/moai-cowork/moai-accountant)<a href="https://agentmods.dev/plugins/modu-ai/moai-cowork/moai-accountant"><img src="https://agentmods.dev/badge/plugins/modu-ai/moai-cowork/moai-accountant/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/plugins/modu-ai/moai-cowork/moai-accountant"><img src="https://agentmods.dev/badge/plugins/modu-ai/moai-cowork/moai-accountant.svg" alt="Reviewed on agentmods" width="80" height="20"></a>Grade A, and why
moai-accountant scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "moai-accountant",
"displayName": "💰 재무·세무 담당",
"version": "1.2.0",
"description": "재무·세무 전담 AI 코워커 — 재무제표 분석·결산 관리·차이 분석·IR, 개인 세금 절약·가계 예산·투자 입문·보험 적합성 스킬 11종. OpenDART 전자공시 MCP 연동. 이런 분께 추천: 사업자·재무 담당자·개인 재테크 입문자. ※ 세무사·회계사 자문 대체가 아닌 참고 자료입니다.",
"author": {
"name": "모두의 AI",
"email": "[email protected]"
},
"license": "Apache-2.0",
"userConfig": {
"DART_API_KEY": {
"type": "string",
"title": "OpenDART 인증키",
"description": "opendart.fss.or.kr 회원가입 후 인증키 신청 — 이메일로 즉시 발급되는 40자 키입니다. 하루 20,000건 무료.",
"sensitive": true
}
}
}
What it installs
The manifest is a name and a version. 11 skills, 2 agents, 1 MCP server travel with it, and installing the plugin installs all of them — 1,541 tokens a session between them. Each is measured on its own page, and each can be installed alone.
- Skill finance-investor-relations A 180 tokens
- Skill finance-financial-statements A 108 tokens
- Skill finance-tax-helper A 95 tokens
- Skill finance-close-management A 104 tokens
- Skill finance-variance-analysis A 87 tokens
- Skill finance-econ-literacy A 128 tokens
- Skill finance-household-budget A 119 tokens
- Skill finance-insurance-fit A 119 tokens
- Skill finance-invest-primer A 134 tokens
- Skill finance-personal-tax-saver A 132 tokens
- Skill finance-wealth-roadmap A 129 tokens
- Agent finance-analyst A 121 tokens
- Agent close-auditor A 85 tokens
- MCP server dart A not measured
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago Changed · +8 lines c3628fcc5fca
- 9d ago First seen · 12 lines scan A 9249097edef9
moai-accountant is a plugin published in the GitHub repository modu-ai/moai-cowork (298 stars, last pushed 6d ago), licensed Apache-2.0. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other plugins, from other repositories
market-desk
A personal equity-research desk: one-page ticker briefs, portfolio risk reviews, and earnings-season prep. Research and analysis only -- not financial advice.
dev-tooling
Three MCP servers for PHP and JavaScript operations plus an optional PHP language server. PHP (php-tooling): PHPStan, ECS, Rector, PHPUnit, PHPUnit coverage gap analysis, Symfony Console. Administration (js-admin-tooling): ESLint, Stylelint, Prettier, Jest, TypeScript, Vite builds. Storefront (js-storefront-tooling)…
fakoli-speak
Multi-provider text-to-speech with owned playback, opt-in autospeak, and local cost estimates.
gamedev
revenantworks-gamedev — game-development skills on the -smith motif. First member: pixelsmith, art direction for pixel art that must read at several zoom scales at once.
nextjs
Official Next.js skills: adopt and optimize Cache Components, adopt Partial Prefetching, and verify runtime behavior against a running dev server.
themes-example
themes-example. An open-source AI agent that brings the power of Gemini directly into your terminal.