Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add MostAshraf/ai-sdlc-harnessnpx agentmods add plugins/mostashraf/ai-sdlc-harness/marketplacegit clone --depth 1 https://github.com/MostAshraf/ai-sdlc-harnessWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/plugins/mostashraf/ai-sdlc-harness/marketplace)<a href="https://agentmods.dev/plugins/mostashraf/ai-sdlc-harness/marketplace"><img src="https://agentmods.dev/badge/plugins/mostashraf/ai-sdlc-harness/marketplace.svg" alt="Measured on agentmods" height="20"></a>Grade A, and why
ai-sdlc-harness marketplace scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "ai-sdlc-harness",
"description": "AI-driven SDLC workflow harness — multi-agent dev with plan → code → review → test → PR.",
"license": "MIT",
"owner": {
"name": "Mostafa Ashraf"
},
"plugins": [
{
"name": "ai-sdlc-harness",
"source": {
"source": "github",
"repo": "MostAshraf/ai-sdlc-harness"
},
"version": "3.9.0",
"description": "AI-driven SDLC workflow harness for multi-repo development. Provides story refinement, multi-agent development (plan → code → review → test → PR), and automated guardrails via hooks. Runs under Claude Code and Qwen Code. Supports Azure DevOps, Jira, GitLab, GitHub, Zoho, and local Markdown as work item providers; ADO, GitLab, GitHub, gh-cli, and glab-cli as git providers. Language-agnostic, discovery-driven; supports any language (frontend + backend).",
"author": {
"name": "Mostafa Ashraf"
},
"keywords": [
"claude-code",
"claude-plugin",
"sdlc",
"workflow",
"multi-agent",
"azure-devops",
"jira",
"gitlab",
"github",
"zoho",
"language-agnostic",
"discovery-driven",
"dev-workflow",
"tdd",
"code-review-automation",
"qwen-code"
]
}
]
}
The plugins it lists here
This marketplace lists 1 plugin kept in the same repository. Each has its own page, its own measurements and its own install command.
What ships with it
1 file beside marketplace.json in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 41 lines scan A bb24094aa893
ai-sdlc-harness marketplace is a plugin published in the GitHub repository MostAshraf/ai-sdlc-harness (18 stars, last pushed 8d ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other plugins, from other repositories
pbr
Plan-Build-Run — Structured development workflow for Claude Code. Solves context rot through disciplined subagent delegation, structured planning, atomic execution, and goal-backward verification.
supervisor
Strict multi-agent Supervisor for Claude Code: web-grounded anti-hallucination, expert coding/frontend implementation, independent judges, adversarial review, and final Stop release gate.
orchestrate
Multi-model orchestration for Claude Code: the session model leads as tech-lead orchestrator, routing work across model-pinned executors (deep-reasoner/Opus, fast-worker/Sonnet, scout/Haiku) and a cross-vendor Codex peer — with a first-match routing table, delegation contracts, budget modes, an escalation ladder, and…
suede-code
Code quality subset: one-pass review plus an A-F ship verdict (suede-code), deep findings with TypeScript, React, Next.js, OWASP, and database checklists (suede-code-review), a grade-only verdict with instant-F triggers and grade caps (suede-code-grader), and CI branch protection that gates the merge (suede-ci-gate).
nextjs
Official Next.js skills: adopt and optimize Cache Components, adopt Partial Prefetching, and verify runtime behavior against a running dev server.
claude-plugins-official marketplace
Directory of popular Claude Code extensions including development tools, productivity plugins, and MCP integrations.