Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add queelius/claude-anvilnpx agentmods add plugins/queelius/claude-anvil/mfgit clone --depth 1 https://github.com/queelius/claude-anvilGrade A, and why
mf scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "mf",
"description": "Metafunctor site management: blog architecture, content workflows, and mf CLI",
"version": "1.3.0",
"repository": "https://github.com/queelius/claude-anvil",
"license": "MIT",
"author": {
"name": "Alexander Towell",
"email": "[email protected]",
"url": "https://metafunctor.com"
},
"keywords": [
"hugo",
"metafunctor",
"site-management",
"blog",
"static-site"
]
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 20 lines scan A 7628b97d0c74
mf is a plugin published in the GitHub repository queelius/claude-anvil (2 stars, last pushed 1mo ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other plugins, from other repositories
requesthunt
Generate user demand research reports from real user feedback. Scrape and analyze feature requests, complaints, and questions from Reddit, X, and GitHub.
content-studio
Content studio for managing thought leadership content with a visual editor, Claude Code skills, and utility scripts.
mcp-gsc
Connect Claude Code to Google Search Console for organic-search analytics, URL inspection, sitemap management, indexing requests, and SEO insights.
facebook-mcp
Local-first TypeScript MCP server for the Meta Graph API that lets an MCP client publish, read and moderate Facebook Pages through your own Meta developer app, with least-privilege tokens, plan-and-apply write safety and no telemetry.
search-visibility
Two halves of getting found: a-seo-gsc turns a Google Search Console export into a prioritized action plan backed by your own data, and a-geo-optimizer checks whether AI assistants can fetch, parse, and cite a site, then recommends the technical and content fixes. One diagnoses from data, the other covers the newer…
claude-utilities
Cross-stack utilities: turn recent technical work into LinkedIn/Twitter drafts (content), federated knowledge-base search across /Desktop/knowledge + repo + memory dir (knowledge), turn meeting notes into Jira tasks (create-tasks).