Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add onehorizonai/skillsnpx agentmods add plugins/onehorizonai/skills/one-horizongit clone --depth 1 https://github.com/onehorizonai/skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/plugins/onehorizonai/skills/one-horizon)<a href="https://agentmods.dev/plugins/onehorizonai/skills/one-horizon"><img src="https://agentmods.dev/badge/plugins/onehorizonai/skills/one-horizon.svg" alt="Measured on agentmods" height="20"></a>Grade A, and why
one-horizon scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "one-horizon",
"source": ".",
"description": "Plan what matters, send tasks and initiatives to AI agents, and keep every task, commit, and PR tied back to the roadmap automatically.",
"version": "2.3.1",
"author": {
"name": "One Horizon"
},
"homepage": "https://onehorizon.ai",
"repository": "https://github.com/onehorizonai/skills",
"license": "MIT",
"keywords": [
"one-horizon",
"tasks",
"productivity",
"work-log",
"blockers",
"standup",
"retro",
"team"
]
}What it installs
The manifest is a name and a version. 21 skills, 1 hook, 1 MCP server travel with it, and installing the plugin installs all of them — 1,338 tokens a session between them. Each is measured on its own page, and each can be installed alone.
- Skill one-release-notes A 81 tokens
- Skill one-initiative-brief A 50 tokens
- Skill one-retro A 70 tokens
- Skill one-task-management A 97 tokens
- Skill one-work-item-delivery-loop A 82 tokens
- Skill one-report-issue A 51 tokens
- Skill one-update-task A 57 tokens
- Skill one-bug-triage-prep A 47 tokens
- Skill one-manage-documents A 76 tokens
- Skill one-create-task A 57 tokens
- Skill one-list-work A 77 tokens
- Skill one-find-team A 77 tokens
- Skill one-search-tasks A 58 tokens
- Skill one-get-task-details A 51 tokens
- Skill one-list-taxonomy A 61 tokens
- Skill one-standup-prep A 67 tokens
- Skill one-work-recap A 59 tokens
- Skill one-work-summarizer A 64 tokens
- Skill one-handoff-notes A 46 tokens
- Skill one-initiative-summary A 42 tokens
- Skill one-roadmap-suggestions A 68 tokens
- Hook UserPromptSubmit A not measured
- MCP server onehorizon A not measured
What ships with it
1 file beside marketplace.json#one-horizon in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 22 lines scan A 51f6c235d667
one-horizon is a plugin published in the GitHub repository onehorizonai/skills (2 stars, last pushed 1mo ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other plugins, from other repositories
aidd-vcs
External artifacts: repo-init, commit, pull-request, release-tag, issue-create.
comfyui-plugin
ComfyUI custom-node pack lifecycle - scaffold a pack, create + seed the repo, open the gitops adoption PR, publish to the Comfy Registry, and add README screenshots.
sdlc
SDLC — the complete software development lifecycle as gaps the engine cannot fill on its own (skillwise four-atom discipline: Knowledge / Capability / Judgment / Control, no step-marches). Twenty-seven skills organised as nine rings + a spine (docs/ARCHITECTURE.md). Delivery spine (original): /sdlc (lifecycle orchest.
release-conductor
Owns everything around the diff: craft Conventional Commits and PR descriptions, recommend the right semver bump by reasoning about behavioral breaking changes, assemble changelogs from messy history, and guide merge-conflict resolution, rebase planning, and git-history archaeology.
obsidian-tracker
Project tracking, task management with kanban boards, bug logging, decision records (ADR), session management, and engineering traceability via Obsidian. Auto-tracks sessions, actions, bugs, and commits via hooks.
bitwarden-delivery-tools
Delivery lifecycle skills for Bitwarden initiatives — initiative funnel navigation, work transitions, architectural judgment, commits, pull requests, preflight checks, change labeling, and Jira ticket filing.