Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add natthasath/natthasath-marketplacenpx agentmods add plugins/natthasath/natthasath-marketplace/projectsgit clone --depth 1 https://github.com/natthasath/natthasath-marketplaceWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/plugins/natthasath/natthasath-marketplace/projects)<a href="https://agentmods.dev/plugins/natthasath/natthasath-marketplace/projects"><img src="https://agentmods.dev/badge/plugins/natthasath/natthasath-marketplace/projects.svg" alt="Measured on agentmods" height="20"></a>Grade A, and why
projects scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "projects",
"version": "0.3.2",
"description": "Plugin สำหรับ setup และจัดการ development project — scaffold โครงสร้าง context/, rules, config พร้อม skills ครบ workflow ตั้งแต่ setup จนถึง ship",
"author": {
"name": "natthasath"
},
"keywords": [
"project",
"setup",
"workflow",
"tasks",
"phases",
"checkpoint",
"implement",
"ship",
"debug",
"status"
],
"skills": [
"setup",
"checkpoint",
"add-phase",
"add-task",
"start-task",
"implement",
"ship",
"done-task",
"done-phase",
"debug",
"status",
"today",
"list-task",
"list-phase",
"set-stack"
]
}What it installs
The manifest is a name and a version. 8 skills travel with it, and installing the plugin installs all of them — 449 tokens a session between them. Each is measured on its own page, and each can be installed alone.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 37 lines scan A 1dd732c53fac
projects is a plugin published in the GitHub repository natthasath/natthasath-marketplace (1 stars, last pushed 4d ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other plugins, from other repositories
weft
Deterministic workflow tracking with event-sourced logs for Claude Code.
rook-maintainer
Maintainer-grade skills for rook (github.com/rook/): code review, backlog triage, systemic-PR campaigns, and the rook house conventions they enforce.
bugscribe
A single skill that files one already-identified bug as a new GitHub issue: verifies the defect against the source code, checks the backlog for duplicates, posts a short report pointing to a file and line, and pings the repository owner exactly once — it reports a known finding rather than searching for one.
telegram-topics
Telegram channel for Claude Code — 1 project = 1 forum topic, with a live working/idle status badge on each topic. Run multiple projects concurrently, get notifications, and drive or approve sessions remotely from your phone. Configure with /telegram-topics:configure.
pureinn-product-development
AI-native product development framework. 51 active skills covering the full product lifecycle. FDD+SDD hybrid: 4 living registers, JIT design per feature, atomic commit protocol. Three playbooks: Greenfield, Feature Implementation, Rebuild. From zero to launch.
axiomcore
Dedicated project management agent for professional and personal use. Enforced structure (numbered folders, task IDs, wiki memory), disciplined plan-approve-execute workflow, agile or WBS-based project creation, modular: voice, brand, todos (optional Notion board), software dev planning. Run /axiom start in a new…