Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add rigour-labs/rigournpx agentmods add plugins/rigour-labs/rigour/rigour-mcpgit clone --depth 1 https://github.com/rigour-labs/rigourGrade A, and why
Rigour Quality Governance scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "Rigour Quality Governance",
"version": "2.14.0",
"description": "Meta-cognitive governance for AI agents. Monitor drift, manage agent teams, and enforce quality gates during long-running coworking tasks.",
"author": "Rigour Labs",
"capabilities": {
"mcp": {
"enabled": true
}
},
"entrypoint": "../dist/index.js",
"icon": "🛡️",
"categories": [
"Productivity",
"Developer Tools"
]
}What it installs
The manifest is a name and a version. 1 skill, 1 MCP server travel with it, and installing the plugin installs all of them — 0 tokens a session between them. Each is measured on its own page, and each can be installed alone.
What ships with it
2 files beside plugin.json in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 17 lines scan A f3011006d175
Rigour Quality Governance is a plugin published in the GitHub repository rigour-labs/rigour (26 stars, last pushed 12d ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other plugins, from other repositories
aura-frog
Planning-first LLM OS for software engineering. Hierarchical planning (T0-T4) survives session reset · forensic reasoning traces · L1+L2 conflict detection · self-healing safety gates · per-agent MCP security · durable project-context snapshots · cross-tool porter (Copilot/Codex/Cursor) · CLI dashboard. 15 agents…
rpi
RPI workflow: Research, Planning, Implementation. Context engineering system with structured agents and commands for AI-assisted development.
activerecord
ActiveRecord patterns for Rails models and queries.
dragonruby
DragonRuby Game Toolkit patterns for 2D game development.
ratatui-ruby
RatatuiRuby TUI development for terminal user interfaces.
draper
Draper decorator patterns for Rails view logic.