Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add nullorder/agenthubnpx agentmods add plugins/nullorder/agenthub/marketplacegit clone --depth 1 https://github.com/nullorder/agenthubGrade A, and why
agenthub scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
"description": "Intercepts GitHub URL fetches and curl/wget commands, redirecting to the authenticated gh CLI.", How it starts
The opening of the file, as written. The whole thing — 5,904 lines — stays where its author put it; the contents beside it link to each section on GitHub.
{
"$schema": "https://anthropic.com/claude-code/marketplace.schema.json",
"name": "agenthub",
"version": "1.0.0",
"metadata": {
"description": "A community-driven marketplace for Claude Code plugins. Open to all contributors."
},
"owner": {
"name": "nullorder"
},
"plugins": [
{
"name": "a11y-audit",
"source": {
"source": "git-subdir",
"url": "https://github.com/alirezarezvani/claude-skills.git",
"path": "engineering-team/a11y-audit"
},
"description": "WCAG 2.2 accessibility audit and fix for React, Next.js, Vue, Angular, Svelte, and HTML. Static scanner detecting 20+ violation types, contrast checker with suggest mode, framework-specific fix patterns, /a11y-audit slash command.",
"version": "2.2.0",
"author": {
"username": "alirezarezvani",
"name": "Alireza Rezvani"
},
"category": "development",
"tags": [
"skills"
],
"license": "MIT"
},
{
"name": "abstract",
"source": {
"source": "git-subdir",
"url": "https://github.com/athola/claude-night-market.git",
"path": "plugins/abstract"
},
"description": "Skill authoring, hook development, evaluation frameworks, and escalation governance for the Claude Code plugin ecosystem",
"version": "1.8.1",
"author": {
"username": "athola",
"name": "athola"
},
"category": "security",
"tags": [
"skills"
],
"license": "MIT"
},
{
"name": "adversarial-spec",
"source": {
"source": "github",
"repo": "zscole/adversarial-spec"
},
"description": "Iteratively refines product specs through multi-model debate until consensus",
"version": "1.0.0",
"author": {
"username": "zscole"
},
"category": "development",
"tags": [
"skills"
],
"license": "MIT"
},
{
"name": "agent-teamWhat this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 5,904 lines scan A c65a451e3875
agenthub is a plugin published in the GitHub repository nullorder/agenthub (3 stars, last pushed 2d ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other plugins, from other repositories
umputun-cc-thingz
Plugin marketplace listing 7 plugins: brainstorm, review, planning, release-tools, thinking-tools.
review
PR review, interactive git diff annotation review, and writing style guide.
context-guard
Per-session context-window observability plus the first shipped consumer: a statusline wrapper tees each session's contextwindow fields to a per-session snapshot file, a zone resolver classifies usage into smart/acceptable/dumb bands (percentage bands plus window-class token bands, conservative-min combination, zones.
ai-briefing
Build source-backed AI-industry briefings from official vendor publications, configured RSS/Atom feeds, GitHub releases, reputable secondary reporting, and user-supplied URLs. Deduplicate, rank, and present results as markdown or optional HTML/PPTX decks, with repository-owned profile, audience, and brand…
context-budget
Measure a Claude Code session's fixed startup context payload per item, on the consumer's machine at a pinned, version-stamped binary — including per-tool attribution of the built-in tool pools that /context reports only as lump sums, derived live by A/B bare-name-deny differencing with enforced comparability rules…
claude-memory
Keeps a repo's Claude Code memory layer healthy and under your control, against criteria derived from official Claude Code documentation. The audit skill checks the instruction/memory layer (CLAUDE.md, CLAUDE.local.md, .claude/rules/, auto-memory) with a deterministic script-backed spine plus judgment-tier checks. The.