Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add RoxyAPI/claude-pluginnpx agentmods add plugins/roxyapi/claude-plugin/marketplacegit clone --depth 1 https://github.com/RoxyAPI/claude-pluginGrade A, and why
roxyapi scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "roxyapi",
"owner": {
"name": "RoxyAPI"
},
"description": "RoxyAPI: the multi domain spiritual intelligence API and Remote MCP. One plugin connects Claude Code to verified astrology, Vedic, forecast, human design, Chinese astrology, feng shui, numerology, tarot, and more.",
"plugins": [
{
"name": "roxyapi",
"source": "./",
"description": "Connects Claude Code to RoxyAPI: a keyless Docs MCP for live endpoint lookup plus a skill that teaches Claude how to build on every RoxyAPI domain under one key.",
"category": "api",
"keywords": [
"roxyapi",
"mcp",
"remote-mcp",
"claude-code",
"agent-skill",
"astrology-api",
"spiritual",
"divination",
"natal-chart",
"kundli",
"horoscope",
"astrology",
"vedic-astrology",
"forecast",
"human-design",
"chinese-astrology",
"feng-shui",
"numerology",
"tarot",
"biorhythm",
"iching",
"crystals",
"dreams",
"angel-numbers",
"location"
],
"homepage": "https://roxyapi.com",
"repository": "https://github.com/RoxyAPI/claude-plugin",
"license": "MIT"
}
]
}
What ships with it
1 file beside marketplace.json in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 46 lines scan A 22949d8b4a4e
roxyapi is a plugin published in the GitHub repository RoxyAPI/claude-plugin (1 stars, last pushed 3d ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other plugins, from other repositories
aurora
Plugin marketplace listing 9 plugins: aurora-agent, aurora-backend, aurora-context, aurora-missions, aurora-integrate.
aurora-agent
The AURORA Agent in one plugin: the bioprism MCP server (264 tools) wired into every session, FIBER decision-context commands (compile / explain / compare / validate / verify), mission preflight, an ops-auditor subagent, and skills for setup, the FIBER workflow, missions, and SDK integration. Requires a built…
aurora-science
The measurement-science methodology from the AURORA Agent workspace, packaged for any evaluation or benchmarking effort: equal-engineering baselines, discriminating experiment design, certificate-audited analysis, metamorphic evaluation, honest figures, and research-dossier discipline.
aurora-backend
Wires the AURORA Agent (bioprism) MCP server into Claude Code: 259 tools for decision-context compilation (FIBER), missions, evaluation, capability routing, and the autonomous-brain control plane. Requires a built aurora-agent checkout (AURORAAGENTROOT or /aurora-agent).
aurora-context
Drive the FIBER decision-context compiler from any project: compile, explain, compare against baselines, validate worlds, and verify certificates, with the 10-exit-code retryability matrix interpreted for you. Requires a built aurora-agent checkout.
aurora-honesty
The honest-labelling engineering discipline from the AURORA Agent workspace, packaged for any codebase: never collapse an error into a benign default, make invariants unrepresentable, prove your scanners fire, and recognise Windows test-runner lies.