Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add PrabhdeepSingh/claude-pluginsnpx agentmods add plugins/prabhdeepsingh/claude-plugins/sonugit clone --depth 1 https://github.com/PrabhdeepSingh/claude-pluginsGrade A, and why
sonu scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
89% identical to prabhdeep-tools — 150 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 78 lines — stays where its author put it; the contents beside it link to each section on GitHub.
{
"name": "sonu",
"version": "4.6.0",
"description": "Make your coding agent work like a senior teammate instead of an eager intern. /sonu:build writes every change in your style and test-first, then hands it back with the riskiest parts flagged before you review. /sonu:ship takes it from working tree to merged PR on its own — collecting every AI reviewer bot enabled on the repo, fixing or answering each finding, looping until clean. Once you trust that loop, /sonu:factory turns your issue tracker into the queue: label a ticket in GitHub Issues, Jira, Linear, or a dependency-free local Markdown store, and the agent specs it, builds it in its own git worktree so several tickets can run in parallel, and — once you review the diff and apply the ship label — takes it through review to a merged PR, reporting plan, progress, and risks back to the ticket the whole way. Run a pass per label, or let /sonu:factory poll watch the queue for you. You approve the spec, the diff, and the ship — nothing merges without your label. It also knows what a good interface looks like: /sonu:interface-review audits a whole screen or flow across accessibility, layout, typography, color, motion, and copy, and those same bars fire automatically while it builds. The discipline lives in 26 skills that auto-apply as it works, and that you can read and edit like any other file: code-standards, tdd, debugging, security, performance, intent-interview, design-tree, model-tiering, self-review, blast-radius, pr-conventions, safe-migrations, infra-standards, observability, seo, interface-review, accessibility, layout, ui-polish, typography, colors, ux-writing, ticket-lifecycle, ticket-triage, classify-tickets, bug-finder. Every skill is plain Markdown you can read, fork, and edit — no runtime, no service to sign up for. Works in Claude Code and Cursor. The local tracker needs nothing but git; GitHub Issues uses the gh CLI, and Jira and Linear use their MCP servers or your own API credentials.",
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 78 lines scan A 30688e1a8f6d
sonu is a plugin published in the GitHub repository PrabhdeepSingh/claude-plugins (3 stars, last pushed 2d ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. It is 89% identical to prabhdeep-tools, differing in 150 lines, and is treated as a copy.
Other plugins, from other repositories
rodrigopg
Personal Claude Code plugins by Rodrigo Gonçalves.
pm-skills
Structured AI workflows for better product decisions. 68 domain-specific skills and 42 chained workflows across 9 PM plugins — from discovery to strategy, execution, launch, growth, and shipping AI-built software.
handbook-agent-spec-kit
Spec-driven development workflow system with structured phases: Requirements → Design → Tasks → Implementation.
handbook-discover
Discover and audit all plugins in a Claude Code marketplace with installation status, versions, and component breakdown.
all-skills
Every BenAI skill in one install. All 116 skills across marketing, sales, SEO, ads, design, YouTube, creative, operations, second-brain OS, Baalda OS, Marketing OS, and general productivity. Add this one plugin to get the complete library.
atera
Claude Code plugin for Atera RMM/PSA - tickets, agents, customers, alerts.