Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add natthasath/natthasath-marketplacenpx agentmods add plugins/natthasath/natthasath-marketplace/githubgit clone --depth 1 https://github.com/natthasath/natthasath-marketplaceGrade A, and why
github scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "github",
"version": "0.2.0",
"description": "Plugin รวม Skills สำหรับงาน GitHub repo — เลือกและติดตั้ง License ให้โปรเจกต์ (interview แบบภาษาชาวบ้าน) และแนะนำ Tag สำหรับบันทึก repo ลง Capacities จาก GitHub topics และ README",
"author": {
"name": "natthasath"
},
"keywords": [
"github",
"repo",
"readme",
"topics",
"tech-stack",
"tags",
"license",
"licensing",
"copyright",
"patent",
"open-source",
"mit",
"apache",
"gpl",
"agpl",
"lgpl",
"mpl",
"bsd",
"creative-commons",
"spdx",
"busl",
"source-available",
"dual-licensing",
"compliance"
]
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 35 lines scan A b836adbd347d
github is a plugin published in the GitHub repository natthasath/natthasath-marketplace (1 stars, last pushed 2d ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other plugins, from other repositories
dokumenty
Operacje na dokumentach: konwersja PDF/Office do Markdown (markitdown, opendataloader-pdf), redlining .docx z Track Changes (redline-docx-pl), anonimizacja i pseudonimizacja PII (let-it-be), terminy procesowe (terminy-procesowe-pl), klauzule umowne (klauzule-kontraktowe-pl), kalkulatory procesowe…
fundament-weryfikacyjny
Rdzeń weryfikacyjny instaluj-zawsze: routing zadania, ocena wejścia, grounding cytatu, czerwony zespół, wierność deliverable, paczka audytowa AI Act. Neutralny jurysdykcyjnie, bez konektorów, nic nie wysyła na zewnątrz.
governance-kancelarii
Governance AI dla kancelarii: Konstytucja AI (matematic-konstytucja-ai), warsztat decyzyjny Expert Panel, szyfrowany backup Google Workspace (matematic-workspace-backup, RODO art. 32). Generatory dokumentow, bez konektorow.
multi-jurysdykcja-ue
Dziewiec konektorow prawa krajowego UE jedna komenda (DE, AT, ES, FI, IE, NL, SE, FR, LU) - ustawodawstwo i orzecznictwo wprost ze zrodel urzedowych, z identyfikatorami ELI/ECLI. Wymaga uv/uvx; Francja wymaga darmowych danych PISTE.
ochrona-danych
Operacje RODO dla kancelarii i IOD (6 skilli): ocena skutkow DPIA (art. 35-36), obsluga naruszenia w 72h (art. 33-34), zadania osob DSAR (art. 12, 15-22), rejestr czynnosci RoPA i przeglad umow powierzenia DPA (art. 30, 28). Ugruntowane w artykulach RODO i wytycznych EROD/UODO. Bez konektorow, bez wlasnych polaczen…
orzecznictwo-zrodla
Wyszukiwanie i pobieranie źródeł prawa PL/UE: SAOS, EUR-Lex, katalog źródeł krajowych. Niesie konektory MCP saos/krs/eu-sparql (read-only, publiczne API). Wymaga node/npx.