natuleadan-skills marketplace

A marketplace listing for one plugin containing coding skills across areas such as Node.js, security, architecture, testing, and more.

In plain words
What is it for?
Finding add-ons that guide work with JavaScript packages, application architecture, security, databases, testing, and related topics.
Why use it?
It gives developers one place to discover a collection of skills instead of searching for each one separately.

Plugin for Claude Code

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Claude Code
/plugin marketplace add natuleadan/skills
agentmods
npx agentmods add plugins/natuleadan/skills/marketplace
Clone the repo
git clone --depth 1 https://github.com/natuleadan/skills

Made for: Claude Code.

Per session not measured What this adds to a session before it is invoked.
When invoked not measured Not applicable: nothing here is loaded into a session.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Security

Grade A, and why

natuleadan-skills marketplace scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.claude-plugin/marketplace.json · 130 lines

How it starts

The opening of the file, as written. The whole thing — 130 lines — stays where its author put it; the contents beside it link to each section on GitHub.

{
  "name": "natuleadan-skills",
  "owner": {
    "name": "natuleadan",
    "url": "https://github.com/natuleadan"
  },
  "metadata": {
    "description": "Agent skills collection spanning multiple domains",
    "version": "1.0.0",
    "pluginRoot": "./"
  },
  "plugins": [
    {
      "name": "natuleadan",
      "description": "Multi-domain agent skills for AI coding agents — programming, biology, cooking, and more",
      "version": "1.0.0",
      "source": "./",
      "author": {
        "name": "natuleadan"
      },
      "homepage": "https://github.com/natuleadan/skills",
      "repository": "https://github.com/natuleadan/skills",
      "license": "MIT",
      "keywords": [
        "nodejs",
        "package-management",
        "supply-chain-security",
        "crm",
        "contacts",
        "architecture",
        "caching",
        "docker",
        "security",
        "elysia",
        "clean-architecture",
        "zero-trust",
        "server-actions",
        "nextjs",
        "authentication",
        "react",
        "typescript",
        "testing",
        "accessibility",
        "coding-standards",
        "prisma",
        "multi-currency",
        "multi-language",
        "i18n",
        "git",
        "commits",
        "semantic-release",
        "ci-cd"
      ],
      "category": "Programming",
      "tags": [
        "node",
        "npm",
        "pnpm",
        "bun",
        "security",
        "crm",
        "contacts",
        "skills",
        "architecture",
        "caching",
        "docker",
        "elysia",
        "nextjs",
        "zero-trust",
        "clean-arch",
        "authentication",
        "auth",
        "react",
        "typescript",
        "testing",
        "a11y",
        "coding-standards",
        "prisma"
      ],
      "strict": false,
      "skills": [
        "./skills/010101-package-security",
        "./skills/010102-install-toolchain",
        "./skills/010103-package-operations",
        "./skills/01

Read the full file on GitHub · 130 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 130 lines scan A d3d8fe2ed5b9

Subscribe to this mod's changes

natuleadan-skills marketplace is a plugin published in the GitHub repository natuleadan/skills (2 stars, last pushed 3mo ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other plugins, from other repositories

actions

GitHub Actions skills — least-privilege workflow style with truthy/falsey expressions, security hardening (SHA-pinning, no pullrequesttarget), wiring the bitwise reusable-workflow library, and an actionlint/zizmor validation loop.

bitwise-media-group/skills · not measured

golang

Modern Go development — stdlib-first code style with cobra/viper CLIs, table-driven tests and native fuzzing, canonical project layout with pinned tooling, documentation conventions with LLM-ready CLI references, and GoReleaser-based release engineering.

bitwise-media-group/skills · not measured

python

Modern Python on the Astral toolchain — uv for project and dependency management with the uvbuild backend, ruff for formatting and linting, ty or pyright for type checking, pytest with Hypothesis property tests, Google-style docstrings with CLI reference generation, and trusted-publishing release engineering.

bitwise-media-group/skills · not measured

workflow

Developer-workflow commands and skills — sandbox-safe Conventional commits with a commit.sh handoff, immutable code-scanning triage reports with SHA-pinned permalinks, and generation of evolve evaluation suites (triggers + behavioral evals) for agent skills.

bitwise-media-group/skills · not measured

terraform

Terraform style conventions, module scaffolding, and fmt/validate/tflint workflows for authoring reusable modules.

bitwise-media-group/skills · not measured

jenkins-cli

GitHub CLI-style interface for Jenkins controllers - create multibranch jobs, inspect config.xml, and manage runs, logs, artifacts, credentials, nodes, and queues.

avivsinai/jenkins-cli · not measured