Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add OneWave-AI/open-agent-stacknpx agentmods add plugins/onewave-ai/open-agent-stack/market-deskgit clone --depth 1 https://github.com/OneWave-AI/open-agent-stackGrade A, and why
market-desk scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "market-desk",
"description": "A personal equity-research desk: one-page ticker briefs, portfolio risk reviews, and earnings-season prep. Research and analysis only -- not financial advice.",
"version": "0.1.0",
"author": {
"name": "OneWave AI",
"url": "https://www.onewave-ai.com"
}
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 10 lines scan A 31d6879fef4b
market-desk is a plugin published in the GitHub repository OneWave-AI/open-agent-stack (2 stars, last pushed 22d ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other plugins, from other repositories
moai-accountant
재무·세무 전담 AI 코워커 — 재무제표 분석·결산 관리·차이 분석·IR, 개인 세금 절약·가계 예산·투자 입문·보험 적합성 스킬 11종. OpenDART 전자공시 MCP 연동. 이런 분께 추천: 사업자·재무 담당자·개인 재테크 입문자. ※ 세무사·회계사 자문 대체가 아닌 참고 자료입니다.
alternative-payments
Claude plugins for Alternative Payments - customers, invoices, payment requests, transactions, payouts, and webhooks.
hive
One OAuth-ready connection for evidence-backed crypto due diligence, with sources, freshness, and a runtime receipt on every Hive call.
vivid-mcp
Open a Vivid Business account from your AI chat via MCP.
kite
Power-user MCP + Skills for Indian retail traders on Zerodha Kite. Order placement (local build), portfolio analysis, FII/DII flow, concall summarizer, peer comparison, Telegram integration.
mem0
Cross-session memory and token savings for coding agents.