Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/neuromechanist/research-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/plugins/neuromechanist/research-skills/project)<a href="https://agentmods.dev/plugins/neuromechanist/research-skills/project"><img src="https://agentmods.dev/badge/plugins/neuromechanist/research-skills/project.svg" alt="Measured on agentmods" height="20"></a>Grade A, and why
project scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "project",
"version": "0.6.0",
"description": "Complete project lifecycle toolkit: initialization, cross-agent user-instruction setup, tiered model routing, epic/sprint workflow, PR review, onboarding, planning, debugging, engineering loop, agent fan-out, CI/CD, Docker, security, and document processing",
"author": {
"name": "Seyed Yahya Shirazi",
"email": "[email protected]"
},
"license": "BSD-3-Clause",
"commands": "./commands/",
"skills": "./skills/",
"keywords": [
"project",
"init",
"workflow",
"ci-cd",
"docker",
"security",
"scaffolding",
"epic",
"sprint",
"worktree",
"pr-review",
"code-review",
"document-processing",
"onboarding",
"planning",
"debugging",
"fan-out",
"model-routing",
"user-instructions"
]
}
What it installs
The manifest is a name and a version. 15 skills, 5 commands, 3 agents travel with it, and installing the plugin installs all of them — 1,620 tokens a session between them. Each is measured on its own page, and each can be installed alone.
- Skill epic-dev A 84 tokens
- Skill implementation-planning A 82 tokens
- Skill init-project A 136 tokens
- Skill workflow-reference A 75 tokens
- Skill codebase-onboarding A 94 tokens
- Skill security-audit A 83 tokens
- Skill ci-scaffolding A 126 tokens
- Skill docker-packaging A 75 tokens
- Skill pr-review-toolkit A 89 tokens
- Skill agent-fanout A 113 tokens
- Skill debugging A 90 tokens
- Skill engineering-loop A 82 tokens
- Skill update-rules A 114 tokens
- Skill document-processing B 94 tokens
- Skill install-user-instructions C 87 tokens
- Command epic-dev A 0 tokens
- Command release-prep A 13 tokens
- Command epic-status A 7 tokens
- Command update-rules A 16 tokens
- Command init-project A 11 tokens
- Agent dependency-auditor A 48 tokens
- Agent release-prep A 55 tokens
- Agent pr-review-toolkit A 46 tokens
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 34 lines scan A be60986b3ddb
project is a plugin published in the GitHub repository neuromechanist/research-skills (45 stars, last pushed 5d ago), licensed BSD-3-Clause. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other plugins, from other repositories
pm-skills
Product manager skill suite for Claude Code — PRD writing, competitor research, daily briefing, HTML prototyping, feature acceptance, UI walkthrough.
hr-automation
Help HR teams identify, design, and implement automation opportunities across HR processes including workflows, HRIS configuration, AI tools, and no-code solutions. Use when asked to automate HR processes, build HR workflows, reduce HR admin work, implement HRIS automation, use AI in HR, or similar HR automation tasks.
hr-change-management
Help HR leaders, change managers, and business partners design, lead, and sustain organizational change initiatives. Use when asked to design a change management plan, advise leadership on change communication, build a stakeholder engagement strategy, create a change readiness assessment, design training and…
hr-contingent-workforce
Help HR and procurement teams manage contractors, freelancers, and temporary staff, including classification, vendor management, and program design. Use when asked to set up a contingent workforce program, classify a worker as contractor or employee, manage a VMS/MSP program, draft a statement of work, or similar…
hr-performance-management
Help HR managers design, execute, and refine performance management systems. Use when asked to write performance reviews, create PIPs, design appraisal forms, set employee goals or OKRs, conduct 360-degree feedback, or build recognition and succession frameworks.
hr-product-management
Help HR and recruiting teams hire and assess product management candidates, including job descriptions, case-study interviews, and leveling frameworks. Use when asked to write a product manager job description, create a PM case study interview, assess product sense, build a PM leveling framework, or similar product…