Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/seancrecord/scvd-general-store-repoWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/plugins/seancrecord/scvd-general-store-repo/gemini-extension)<a href="https://agentmods.dev/plugins/seancrecord/scvd-general-store-repo/gemini-extension"><img src="https://agentmods.dev/badge/plugins/seancrecord/scvd-general-store-repo/gemini-extension/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/plugins/seancrecord/scvd-general-store-repo/gemini-extension"><img src="https://agentmods.dev/badge/plugins/seancrecord/scvd-general-store-repo/gemini-extension.svg" alt="Reviewed on agentmods" width="80" height="20"></a>Grade A, and why
scvd-general-store scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "scvd-general-store",
"version": "0.2.3",
"description": "Evidence observatory for agentic commerce: x402 preflight, receipt checks, settlement attestations.",
"mcpServers": {
"scvd-store": {
"httpUrl": "https://scvd.store/mcp"
}
},
"contextFileName": "AGENTS.md"
}
What ships with it
60 files beside gemini-extension.json in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- assets/fonts/IBMPlexSerif-Bold.ttf 160 KB
- assets/fonts/IBMPlexSerif-Italic.ttf 169 KB
- assets/fonts/IBMPlexSerif-Regular.ttf 159 KB
- assets/fonts/OFL.txt 4.4 KB
- examples/autogen/agent.py 1.9 KB runs code
- examples/claude-code/SKILL.md 3.0 KB
- examples/claude-code/x402-before-you-pay.mdc 1.2 KB
- examples/copilot/copilot-instructions.md 2.0 KB
- examples/corpus-recompute.ipynb 4.0 KB
- examples/crewai/agent.py 2.0 KB runs code
- examples/fixtures/accepts-empty.json 15 KB
- examples/fixtures/expected.json 3.7 KB
- examples/fixtures/over-cap.json 18 KB
- examples/fixtures/ready-would-sign.json 18 KB
- examples/fixtures/testnet-network.json 19 KB
- examples/fixtures/unreachable.json 14 KB
- examples/langgraph/agent.mjs 1.9 KB runs code
- examples/openai-agents/agent.mjs 2.4 KB runs code
- examples/pydantic-ai/agent.py 1.7 KB runs code
- examples/README.md 5.2 KB
- examples/shared/decide.mjs 11 KB runs code
- examples/shared/decide.py 10 KB runs code
- examples/shared/decide.test.mjs 3.9 KB runs code
- examples/shared/test_decide.py 2.1 KB runs code
- examples/vercel-ai-sdk/agent.mjs 1.7 KB runs code
- examples/x402-preflight-on-deploy.yml 1.1 KB
- scripts/a2a-live.mjs 5.6 KB runs code
- scripts/a2a-live.test.mjs 2.9 KB runs code
- scripts/a2a-runner-build.mjs 824 B runs code
- scripts/a2a-runner-entry.ts 1.0 KB runs code
- scripts/a2a-runner.test.mjs 1.8 KB runs code
- scripts/a2a-validation-build.mjs 1.3 KB runs code
- scripts/agentfinder-check.test.mjs 8.7 KB runs code
- scripts/agentic-market-check.mjs 7.9 KB runs code
- scripts/audit.mjs 17 KB runs code
- scripts/bazaar-check.mjs 20 KB runs code
- scripts/bazaar-regex-check.go 727 B
- scripts/bazaar-regex-check.mjs 1.1 KB runs code
- scripts/bazaar-validate.mjs 3.5 KB runs code
- scripts/bazaar-validate.test.mjs 2.0 KB runs code
- scripts/bazaar-validation-resources.test.mjs 2.1 KB runs code
- scripts/blindness-audit.mjs 6.3 KB runs code
- scripts/build-scorers-outreach.mjs 1.1 KB runs code
- scripts/buyer-cold-isolated.mjs 2.7 KB runs code
- scripts/buyer-deployment-collect.mjs 3.9 KB runs code
- scripts/buyer-deployment-live.mjs 10 KB runs code
- scripts/buyer-deployment-local.mjs 5.5 KB runs code
- scripts/buyer-deployment-score.mjs 5.3 KB runs code
- scripts/buyer-deployment-score.test.mjs 2.8 KB runs code
- scripts/buyer-link-check.mjs 3.3 KB runs code
- scripts/buyer-run-evidence.test.mjs 5.5 KB runs code
- scripts/buyer-wave-one.mjs 7.0 KB runs code
- scripts/buyer-wave-one.test.mjs 11 KB runs code
- scripts/buyer-wave-score.mjs 8.9 KB runs code
- scripts/buyer-wave-snapshot.mjs 1.5 KB runs code
- scripts/capture-evidence-inventory.mjs 3.5 KB runs code
- scripts/capture-retained-evidence.mjs 5.9 KB runs code
- scripts/catalog-evidence.mjs 3.0 KB runs code
- scripts/catalog-evidence.test.mjs 6.6 KB runs code
- scripts/catalog-review-smoke.mjs 5.1 KB runs code
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 12 lines scan A 51677cbc43c9
scvd-general-store is a plugin published in the GitHub repository seancrecord/scvd-general-store-repo (3 stars, last pushed today), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-12.
Other plugins, from other repositories
samedaydesk-extract
Self-contained Claude Code plugin that binds the canonical SameDayDesk MCP, one web-extract skill for single-page GET or bounded 1–5 URL batch POST, and one offline explicit-record skill. Unpaid discovery only. Mapping does not fetch or pay. No wallet, no second paywall, no installer.
merchant-context
Resolve sourced merchant facts before agent commerce actions.
actuarial-scientist
Reasons from mortality tables (qx, period/cohort, select/ultimate) and Chain-Ladder/Mack reserving through GLM/GAM frequency–severity and Tweedie pricing, limited-fluctuation and Bühlhmann-Straub credibility, Solvency II SCR standard formula, and IFRS 17 CSM/RA while treating triangle truncation, overfitting, and tail.
saleor-commerce
Expert subagent and skills for Saleor commerce development — GraphQL-only API with Graphene-Django, App development with Next.js SDK, webhooks (async/sync with subscription payloads), Dashboard extensions with App Bridge and MacawUI, Next.js storefronts, channels, catalog with typed attributes, transaction payment…
shopify-commerce
Expert subagent and skills for Shopify development — GraphQL Admin and Storefront APIs, Liquid templating, Online Store 2.0 themes, Hydrogen/Remix headless storefronts, Shopify Functions, checkout UI extensions, Polaris components, app development with App Bridge, webhooks, and JavaScript/TypeScript/React patterns.
magento2-commerce
Expert subagent and skills for Magento 2 Open Source development — module creation, DI, plugins, EAV, APIs, checkout, catalog, admin UI, testing, deployment, and PHP 8.x patterns.