Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add OpenRaiser/PaperFitnpx agentmods add plugins/openraiser/paperfit/marketplacegit clone --depth 1 https://github.com/OpenRaiser/PaperFitGrade A, and why
paperfit-vto marketplace scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "paperfit-vto",
"owner": {
"name": "OpenRaiser"
},
"metadata": {
"description": "PaperFit marketplace — natural-language LaTeX visual typesetting agent for Claude Code",
"version": "1.0.5"
},
"plugins": [
{
"name": "paperfit",
"description": "Natural-language paper layout analysis, repair, migration, and visual acceptance for Claude Code",
"version": "1.0.5",
"author": {
"name": "OpenRaiser"
},
"homepage": "https://github.com/OpenRaiser/PaperFit",
"repository": "https://github.com/OpenRaiser/PaperFit",
"license": "MIT",
"category": "developer-tools",
"tags": [
"latex",
"typesetting",
"academic",
"pdf",
"vto",
"claude-code"
],
"keywords": [
"latex",
"typesetting",
"vto",
"pdf",
"agents",
"skills"
],
"source": {
"source": "github",
"repo": "OpenRaiser/PaperFit"
}
}
]
}
The plugins it lists here
This marketplace lists 1 plugin kept in the same repository. Each has its own page, its own measurements and its own install command.
What ships with it
2 files beside marketplace.json in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 45 lines scan A d7a8a0915cbf
paperfit-vto marketplace is a plugin published in the GitHub repository OpenRaiser/PaperFit (330 stars, last pushed 2mo ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other plugins, from other repositories
anthropic-office-skills
Official Anthropic skills for PDF, Word, PowerPoint, and Excel files.
agent-skills
Skills for knowledge-base research, PDF extraction, and slop-free writing.
nutrient-skills marketplace
Plugin marketplace listing 7 plugins: nutrient-dws, make-pdf, remediate-pdf, pdf-to-markdown, pdf-to-text.
make-pdf
Generate finished PDFs from Markdown or HTML — accessible PDF/UA, archival PDF/A, watermarks, batch — with built-in conformance verification.
remediate-pdf
Remediate existing PDFs: auto-tag with PDF/UA semantic structure via the Nutrient DWS Accessibility API, then check the result with the bundled verifier.
collate
历史论文 OCR 校对工作流:PDF 预处理去水印去角标、MinerU OCR、三类文献(繁体古籍 / 民国排印 / 现代简体)校对、公众号排版导出.