Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add niharya/skills-drawernpx agentmods add plugins/niharya/skills-drawer/lay-uigit clone --depth 1 https://github.com/niharya/skills-drawerGrade A, and why
lay-ui scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "lay-ui",
"version": "1.0.0",
"description": "Translates Figma designs into production-ready code using a three-station component-first workflow. Built for product designers and UI/UX designers. Requires the Figma MCP server.",
"author": {
"name": "Nihar Bhagat",
"email": "[email protected]"
},
"license": "MIT",
"repository": "https://github.com/niharya/skills-drawer",
"keywords": [
"figma",
"ui",
"design",
"frontend",
"code-generation",
"design-to-code",
"components"
]
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 21 lines scan A b0c606879f82
lay-ui is a plugin published in the GitHub repository niharya/skills-drawer (2 stars, last pushed 1mo ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other plugins, from other repositories
im-not-ai
Plugin marketplace listing 1 plugin: humanize-korean.
im-not-ai
AI가 쓴 한글 텍스트를 사람이 쓴 글처럼 윤문 — routehint 3경로(light 1콜 · standard 2콜 · heavy 3+콜). 10대 카테고리 70 AI 티 패턴 탐지·재작성.
create-retro-game-kr-patch
레트로 게임(게임보이·NES·SNES·메가드라이브·새턴·PS1·드림캐스트·PC엔진·PC-98·게임기어 등) 한글 패치 제작 전 과정을 다루는 Agent Skill. ROM/디스크 분석부터 폰트·인코딩 설계, PoC, 추출·번역·재삽입, 빌드, 에뮬레이터 검증까지.
kr-patch
레트로 게임 한글 패치 제작 방법론 Agent Skill.
mario-montanari-skills
Le skill pubbliche di Mario Montanari per Claude Code e Claude Cowork.
italiano-scrittura-anti-ai
Suite per la lingua italiana e sistema avanzato anti AI. Scrive secondo la norma, rivede testi già scritti, traduce senza calchi, misura la voce di un autore su un corpus e difende un testo umano segnalato da un rilevatore automatico.