Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add Samqra/auto-reader-ocrnpx agentmods add plugins/samqra/auto-reader-ocr/marketplacegit clone --depth 1 https://github.com/Samqra/auto-reader-ocrGrade A, and why
auto-reader-ocr scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "auto-reader-ocr",
"owner": {
"name": "Auto-Reader OCR",
"url": "https://ocr.auto-reader.com"
},
"plugins": [
{
"name": "auto-reader-ocr",
"source": "./",
"description": "Arabic-first OCR, translation and document extraction as MCP tools - keyless, a free trial key auto-provisions on first call."
}
],
"description": "Arabic-first OCR, translation and document extraction for agents: OCR images/PDFs (Arabic, manga-Japanese, 13+ languages), extract invoice/receipt/ID fields with ZATCA validation, RAG-ready markdown and chunks. Keyless: first call mints a free trial key."
}
What ships with it
1 file beside marketplace.json in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 16 lines scan A bea6aecf7aa7
auto-reader-ocr is a plugin published in the GitHub repository Samqra/auto-reader-ocr (0 stars, last pushed 1mo ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other plugins, from other repositories
well
Plugin marketplace listing 1 plugin: well.
well
Connect Claude to your Well financial data — invoices, companies, contacts, transactions, and the accounting ledger — over a hosted OAuth MCP, with skills for real financial workflows. Installing the plugin auto-configures the MCP server; run /well:connect to authenticate.
intlayer
Intlayer plugins for Claude Code — LSP-powered i18n intelligence for TypeScript, JavaScript, Vue, and Svelte projects.
tray-api
Plugin completo para integração com as APIs da Tray. Acelera o desenvolvimento de aplicativos e-commerce por parceiros e comunidade na plataforma Tray, fornecendo documentação detalhada de todos os endpoints, fluxos de autenticação OAuth, webhooks e boas práticas de integração.
unabatedpm-business-building
AI coaching skills for PM business acumen — metrics design, unit economics, P&L translation, business models, and ROI modeling. Each skill coaches you through the thinking with scoring rubrics, real coaching exchanges, and pushback on weak reasoning.
academic-pdf-translation
Translate academic PDFs into readable, searchable PDFs while preserving document structure and research meaning.