Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add racecraft-lab/racecraft-plugins-publicnpx agentmods add plugins/racecraft-lab/racecraft-plugins-public/speckit-progit clone --depth 1 https://github.com/racecraft-lab/racecraft-plugins-publicWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/plugins/racecraft-lab/racecraft-plugins-public/speckit-pro)<a href="https://agentmods.dev/plugins/racecraft-lab/racecraft-plugins-public/speckit-pro"><img src="https://agentmods.dev/badge/plugins/racecraft-lab/racecraft-plugins-public/speckit-pro.svg" alt="Measured on agentmods" height="20"></a>Grade A, and why
speckit-pro scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "speckit-pro",
"description": "Autonomous Spec-Driven Development powered by GitHub SpecKit. Includes archive-aware autopilot startup, SDD coaching, multi-spec project management, and a fully autonomous workflow executor with multi-agent clarification consensus.",
"version": "2.30.0",
"author": {
"name": "Racecraft Lab"
},
"homepage": "https://github.com/racecraft-lab/racecraft-plugins-public/tree/main/speckit-pro",
"license": "MIT",
"keywords": [
"speckit",
"sdd",
"spec-driven-development",
"specification",
"planning",
"autopilot",
"autonomous",
"workflow"
],
"repository": "https://github.com/racecraft-lab/racecraft-plugins-public"
}
What it installs
The manifest is a name and a version. 11 skills, 13 agents, 3 hooks, 1 MCP server travel with it, and installing the plugin installs all of them — 2,637 tokens a session between them. Each is measured on its own page, and each can be installed alone.
- Skill speckit-scaffold-spec A 244 tokens
- Skill speckit-coach A 213 tokens
- Skill install A 54 tokens
- Skill speckit-prd A 259 tokens
- Skill speckit-upgrade A 199 tokens
- Skill speckit-install A 188 tokens
- Skill speckit-status A 45 tokens
- Skill grill-me A 127 tokens
- Skill speckit-archive-cleanup A 35 tokens
- Skill speckit-resolve-pr A 48 tokens
- Skill speckit-autopilot C 212 tokens
- Agent artifact-author A 108 tokens
- Agent clarify-executor A 66 tokens
- Agent codebase-analyst A 84 tokens
- Agent consensus-synthesizer A 85 tokens
- Agent domain-researcher A 57 tokens
- Agent implement-executor A 74 tokens
- Agent analyze-executor A 85 tokens
- Agent checklist-executor A 80 tokens
- Agent sweep-analyst A 36 tokens
- Agent phase-executor A 123 tokens
- Agent sweep-classifier A 36 tokens
- Agent uat-runbook-author A 114 tokens
- Agent spec-context-analyst A 65 tokens
- Hook PreToolUse A not measured
- Hook SessionStart A not measured
- Hook SubagentStop A not measured
- MCP server sweep-broker A not measured
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today Changed 9e024d5bb98f
- 4d ago First seen · 22 lines scan A c4932c188a03
speckit-pro is a plugin published in the GitHub repository racecraft-lab/racecraft-plugins-public (5 stars, last pushed yesterday), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other plugins, from other repositories
produck-skills
Pull real in-context user feedback into your coding agent and ship aligned fixes. Bundles the produck MCP (searchfeedback, getfeedback), a feedback-to-fix guide skill, and the user-alignment PRD skill.
personal-corp-os
Personal Corp framework: run your business with AI agents through GitHub, department repos, safe public releases, Telegram, agent gateways, html-draft diagrams, and media/art-direction workflows.
dev-workflow
Plan features with structured PRDs, checkpoint progress, and resume across sessions.
manager
Product and project management discipline for the NVZver marketplace. Agents: product-manager — shapes vague ideas into structured draft pitches and returns their full content + pending human gates (writes no files); project-manager — stewards the roadmap, recommends what to build next with dependency/risk/value…
agents-virtuoso
19 agents, 3 pre-composed teams, 7 role skills, and agent workflow skills — delegation patterns, team library, team dispatcher, subagent-driven development, verification discipline, plus all specialist and role agents.
code-to-content
Transform codebases into developer content. 6-phase gated workflow, 3 parallel agents, 9 content formats (blog, tutorial, Twitter, LinkedIn, README, newsletter, video script, conference talk, product launch).