Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add pbvcity/supathinknpx agentmods add plugins/pbvcity/supathink/stgit clone --depth 1 https://github.com/pbvcity/supathinkGrade A, and why
st scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "st",
"version": "1.1.5",
"description": "让 AI 真正思考——思考方法(声明即契约)× 多模型合议(panel/debate/delphi/redblue)× 交付前双轴校验(Critic 正确性 × Navigator 对齐)× playbook 学习。本插件是入口壳(命令+引导);首次用 /st:init 让 AI 带你完成 daemon 安装与配置。",
"author": {
"name": "pbvcity"
},
"homepage": "https://github.com/pbvcity/supathink",
"license": "Apache-2.0"
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 11 lines scan A cae8b307900f
st is a plugin published in the GitHub repository pbvcity/supathink (5 stars, last pushed 1mo ago), licensed Apache-2.0. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other plugins, from other repositories
claude-skills-journalism
Agent skills and Claude Code plugins for journalism, research, and media organizations.
journalism-core
Fifteen core journalism skills for reporting, verification, publishing, and digital investigations: AP-style writing, AI-slop detox, source verification, FOIA/OPRA and Brazilian LAI requests, fact-checking, interview prep and transcription, story pitches, editorial workflow, crisis comms, newsletter publishing, data…
dev-toolkit
Thirteen development skills for newsroom and research dev teams: accessibility, context management, directed multi-agent execution, Electron, mobile debugging, Python pipelines, test-first bug fixing, ethical scraping, no-build frontends, web UI craft, and CLAUDE.md maintenance.
project-templates-toolkit
Three skills for starting and closing out journalism projects: a CLAUDE.md project-memory writer, a LESSONS.md retrospective writer, and a template-selector decision tree for editorial tools, events, publications, research, pipelines, and archives.
autocontext
Accumulates project knowledge across sessions and developers through structured lessons and hooks.
pdf-design
PDF report and proposal design system with interactive editing.