Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add mozilla-ai/cqnpx agentmods add plugins/mozilla-ai/cq/marketplacegit clone --depth 1 https://github.com/mozilla-ai/cqGrade A, and why
cq scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "cq",
"owner": {
"name": "Mozilla AI"
},
"metadata": {
"description": "Shared knowledge commons for AI agents; find, share, and confirm collective knowledge to stop rediscovering the same failures."
},
"plugins": [
{
"name": "cq",
"source": "./plugins/cq",
"description": "Shared knowledge commons for AI agents; find, share, and confirm collective knowledge to stop rediscovering the same failures.",
"category": "knowledge",
"tags": ["knowledge-sharing", "agent-learning", "agent-commons","mcp", "pitfall-avoidance", "team-knowledge", "api-quirks"]
}
]
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 19 lines scan A 72767943919b
cq is a plugin published in the GitHub repository mozilla-ai/cq (1,258 stars, last pushed 18d ago), licensed Apache-2.0. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other plugins, from other repositories
cloudshipai-station
Plugin marketplace listing 2 plugins: station, station-agent.
claude-code-plugin-agent
Station AI agent orchestration with a pre-configured subagent - full MCP integration for power users.
agent-teams
Orchestrate multi-agent teams for parallel code review, hypothesis-driven debugging, and coordinated feature development using Claude Code's Agent Teams.
agent-orchestration
Multi-agent system optimization, agent improvement workflows, and context management.
entire-dev-tools
Plugin marketplace listing 2 plugins: e2e, agent-integration.
microsoft-agents-sdk
Plugin marketplace listing 4 plugins: agents-sdk-common, agents-for-js, agents-for-net, agents-for-python.