Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/popjam-io/skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/plugins/popjam-io/skills/popjam-skills)<a href="https://agentmods.dev/plugins/popjam-io/skills/popjam-skills"><img src="https://agentmods.dev/badge/plugins/popjam-io/skills/popjam-skills/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/plugins/popjam-io/skills/popjam-skills"><img src="https://agentmods.dev/badge/plugins/popjam-io/skills/popjam-skills.svg" alt="Reviewed on agentmods" width="80" height="20"></a>Grade A, and why
popjam-skills scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "popjam-skills",
"version": "1.3.1",
"description": "Marketing, ads & creative skills: generate ad creatives, segment target audiences, simulate reactions with synthetic personas, build landing pages that convert, reverse-engineer brand guidelines and voice, validate ad-platform safe zones, and avoid Remotion render pitfalls.",
"source": "./",
"strict": false,
"license": "MIT",
"author": {
"name": "POPJAM",
"url": "https://popjam.io"
},
"keywords": [
"marketing",
"ads",
"creatives",
"landing-pages",
"branding",
"personas",
"safe-zones",
"remotion",
"brand-voice",
"copywriting"
],
"category": "marketing",
"skills": [
"./skills/popjam-growth-engine",
"./skills/award-landing-page",
"./skills/brand-guideline-extraction",
"./skills/writing-style-extraction",
"./skills/ad-platform-safe-zones",
"./skills/remotion-render-pitfalls"
],
"mcpServers": {
"popjam": {
"type": "http",
"url": "https://api.popjam.io/mcp/"
}
}
}What it installs
The manifest is a name and a version. 6 skills travel with it, and installing the plugin installs all of them — 940 tokens a session between them. Each is measured on its own page, and each can be installed alone.
What ships with it
1 file beside marketplace.json#popjam-skills in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago Changed · +1 lines 4cba7ad3a2ed
- 3d ago Changed c609510d9660
- 7d ago Changed · +3 lines a2c3d95d0fbd
- 8d ago First seen · 35 lines scan A 35b19b814142
popjam-skills is a plugin published in the GitHub repository popjam-io/skills (3 stars, last pushed today), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other plugins, from other repositories
instagram-skills
9 Claude Code and Codex skills for Instagram marketing: caption writing with a first-125-char hook, slide-by-slide carousel planning, viral Reel and carousel hook extraction, 2026 hashtag sizing, an AI-tell humanizer with pre-publish audit, cross-platform repurposing, profile optimization, niche and profile audience…
claude-content-skills
13 free Claude skills that run your whole reel factory — idea to leads. Content Factory (one-command orchestrator) + Going Viral (strategy), AI Brain memory, Agent Reach (scrape Reddit/web + download reels), Reel Analyzer, Viral Hook Writer, Reel Scripter, Reel Builder, Caption & Hashtags, Content Repurposer, Content…
visual-gen
Generate blog cover images, architecture diagrams, and process infographics as PNG files using HTML+CSS rendered via Chrome headless.
apple-creator-studio-skills
Apple Creator Studio workflows for production and delivery.
jina-image-search
Find and scrape web images via Jina AI (search + reader). Bring your own free JINAAPIKEY; Reader also works keyless.
example-skills
Example skills from Anthropic demonstrating various capabilities including skill creation, MCP building, visual design, algorithmic art, internal communications, web testing, artifact building, Slack GIFs, and theme styling.