Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/nikeyes/stepwise-devWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/plugins/nikeyes/stepwise-dev/diagrams)<a href="https://agentmods.dev/plugins/nikeyes/stepwise-dev/diagrams"><img src="https://agentmods.dev/badge/plugins/nikeyes/stepwise-dev/diagrams/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/plugins/nikeyes/stepwise-dev/diagrams"><img src="https://agentmods.dev/badge/plugins/nikeyes/stepwise-dev/diagrams.svg" alt="Reviewed on agentmods" width="80" height="20"></a>Grade A, and why
diagram-design scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
94% identical to diagram-design — 0 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
What it actually says
{
"name": "diagram-design",
"description": "Create branded architecture, IT current-state, flowchart, sequence, state machine, ER/data model, timeline, swimlane, quadrant, radar/spider, polar chart (polar/radial lollipop), loop/flywheel, nested, tree, org chart, layer stack, Venn, pyramid/funnel, treemap, bar, line, Gantt and scatter charts, high-level, process, medallion, data flow, DP integration, DP security matrix, sankey, fishbone, Wardley map, kanban, user journey, deployment, dependency graph, UML class, story map, or database schema diagrams as standalone HTML/SVG/PNG. Redraw .drawio/.drawio.png/.drawio.svg or Mermaid .mmd sources at a chosen size/detail; onboard brand tokens from a website; add semantic patterns, callouts, accessible motion, or sketchy/hand-drawn styling.",
"version": "2.6.17",
"author": {
"name": "Cathryn Lavery",
"url": "https://github.com/cathrynlavery"
},
"homepage": "https://github.com/cathrynlavery/diagram-design",
"repository": "https://github.com/cathrynlavery/diagram-design",
"license": "MIT",
"keywords": [
"diagrams",
"svg",
"architecture",
"flowchart",
"visualization",
"editorial",
"drawio",
"mermaid",
"import",
"animation",
"semantic-patterns"
]
}
What it installs
The manifest is a name and a version. 1 skill, 5 commands travel with it, and installing the plugin installs all of them — 266 tokens a session between them. Each is measured on its own page, and each can be installed alone.
What ships with it
1 file beside plugin.json in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today First seen · 26 lines scan A ed23938af16b
diagram-design is a plugin published in the GitHub repository nikeyes/stepwise-dev (24 stars, last pushed yesterday), licensed Apache-2.0. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. It is 94% identical to diagram-design, differing in 0 lines, and is treated as a copy.
Other plugins, from other repositories
raven-mcp
Design-intelligence MCP server: audits pages, screens, and diffs for contrast, layout, tap targets, and consistency; carries a design system and a taste profile an agent can consult before writing UI code.
aio-visual-diff
Verify AI-built UI against design via measurement-driven diff — extracts computed CSS and bounding boxes through Chrome DevTools MCP, diffs against Figma reference or a frozen baseline, and feeds numerical deltas back to the agent. No screenshot eyeballing.
motion-design-skills
Motion design fundamentals, engines, and brand elements as installable skills for AI coding agents — timing, typography, color, composition, After Effects, Remotion, logos, and backgrounds.
ui-input-skills
Form systems, search, and filter components for user input and data collection.
hyperstack
Disciplined MCP server + skill system. 16 plugins and 121 tools covering designer (6 personalities, 13 page templates, 9 presets), shadcn/ui, design tokens, ui/ux, React Flow v12, Motion v12, Lenis, React 19, Echo, Go, Rust, product-manager, marketing, reflect, and optimizer. 29 skills with adversarial enforcement…
stark-figma-drive
Exporta frames do Figma e faz upload automatico para o Google Drive do cliente.