Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add pactflow/pactflow-agent-skillsnpx agentmods add plugins/pactflow/pactflow-agent-skills/swagger-contract-testinggit clone --depth 1 https://github.com/pactflow/pactflow-agent-skillsGrade A, and why
swagger-contract-testing scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "swagger-contract-testing",
"description": "Expert assistant for PactFlow and Pact contract testing — consumer-driven contracts, provider verification, can-i-deploy, BDCT, Drift CLI, and OpenAPI spec parsing. Includes specialized agents for reviewing and generating pact tests.",
"version": "1.1.0",
"author": {
"name": "Kevin Rohan Vaz",
"email": "[email protected]"
},
"skills": "./skills/",
"agents": ["./agents/pact-generator.md", "./agents/pact-implementor.md", "./agents/pact-reviewer.md", "./agents/bdct-tester.md", "./agents/pact-maintainer.md"],
"mcpServers": "./.mcp.json",
"userConfig": {
"pact_broker_base_url": {
"title": "PactFlow Base URL",
"description": "Your PactFlow or Pact Broker URL (e.g. https://yourorg.pactflow.io)",
"type": "string",
"sensitive": false
},
"pact_broker_token": {
"title": "PactFlow API Token",
"description": "PactFlow API token — get it from app.pactflow.io/settings/api-tokens",
"type": "string",
"sensitive": true
}
}
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 27 lines scan A 2ad53303e437
swagger-contract-testing is a plugin published in the GitHub repository pactflow/pactflow-agent-skills (6 stars, last pushed 9d ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other plugins, from other repositories
google-plugins
Plugin marketplace listing 17 plugins: alloydb, alloydb-omni, bigtable, cloud-sql-mysql, cloud-sql-postgresql.
xcode-build-skills
A multi-skill plugin for benchmarking and optimizing Xcode builds, compile hotspots, project settings, and Swift Package Manager dependency overhead.
newsjack
Newsjack — PR-operator skills for coding agents.
produck
Plugin marketplace listing 1 plugin: produck.
liquid-glass
Apple-style liquid glass: frosted, refracting surfaces for web UI, with the rules that keep them from reading as gray boxes.
beautiful-mermaid
Render Mermaid diagrams as SVG and PNG using the Beautiful Mermaid library. Use when the user asks to render a Mermaid diagram.