Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add ShaftHQ/SHAFT_ENGINEnpx agentmods add plugins/shafthq/shaft_engine/shaft-skillsgit clone --depth 1 https://github.com/ShaftHQ/SHAFT_ENGINEWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/plugins/shafthq/shaft_engine/shaft-skills)<a href="https://agentmods.dev/plugins/shafthq/shaft_engine/shaft-skills"><img src="https://agentmods.dev/badge/plugins/shafthq/shaft_engine/shaft-skills.svg" alt="Measured on agentmods" height="20"></a>Grade A, and why
shaft-skills scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"author": {
"name": "ShaftHQ"
},
"category": "testing",
"description": "Official SHAFT agent skills: methodology router, locator strategy, test planning and authoring, MCP-driven recording, failure analysis, and change verification.",
"homepage": "https://shafthq.github.io/docs/start/overview",
"keywords": [
"shaft",
"test-automation",
"selenium",
"appium",
"rest-assured",
"java",
"testng",
"junit"
],
"license": "MIT",
"name": "shaft-skills",
"repository": "https://github.com/ShaftHQ/SHAFT_ENGINE",
"skills": [
"./shaft-accessibility-testing",
"./shaft-api-testing",
"./shaft-assertions",
"./shaft-automated-test-authoring",
"./shaft-change-verification",
"./shaft-cli",
"./shaft-database-testing",
"./shaft-defect-reporting",
"./shaft-developer",
"./shaft-execution-reporting",
"./shaft-failure-analysis",
"./shaft-flaky-test-analysis",
"./shaft-fluent-api",
"./shaft-guide-search",
"./shaft-locator-design",
"./shaft-mcp",
"./shaft-mobile-actions",
"./shaft-nonfunctional-test-design",
"./shaft-page-objects",
"./shaft-recording-codegen",
"./shaft-requirements-analysis",
"./shaft-stakeholder-reporting",
"./shaft-test-case-design",
"./shaft-test-data-design",
"./shaft-test-environment",
"./shaft-test-execution",
"./shaft-test-monitoring",
"./shaft-test-planning",
"./shaft-test-recording",
"./shaft-web-actions"
],
"source": "./shaft-skills",
"strict": false
}What it installs
The manifest is a name and a version. 30 skills travel with it, and installing the plugin installs all of them — 987 tokens a session between them. Each is measured on its own page, and each can be installed alone.
- Skill shaft-developer A 28 tokens
- Skill shaft-execution-reporting A 37 tokens
- Skill shaft-nonfunctional-test-design A 32 tokens
- Skill shaft-requirements-analysis A 32 tokens
- Skill shaft-accessibility-testing A 31 tokens
- Skill shaft-api-testing A 32 tokens
- Skill shaft-assertions A 35 tokens
- Skill shaft-automated-test-authoring A 40 tokens
- Skill shaft-change-verification A 34 tokens
- Skill shaft-cli A 31 tokens
- Skill shaft-database-testing A 32 tokens
- Skill shaft-defect-reporting A 34 tokens
- Skill shaft-failure-analysis A 27 tokens
- Skill shaft-flaky-test-analysis A 35 tokens
- Skill shaft-fluent-api A 28 tokens
- Skill shaft-guide-search A 29 tokens
- Skill shaft-locator-design A 35 tokens
- Skill shaft-mcp A 33 tokens
- Skill shaft-mobile-actions A 31 tokens
- Skill shaft-page-objects A 33 tokens
- Skill shaft-recording-codegen A 35 tokens
- Skill shaft-stakeholder-reporting A 31 tokens
- Skill shaft-test-case-design A 33 tokens
- Skill shaft-test-data-design A 35 tokens
- Skill shaft-test-environment A 31 tokens
- Skill shaft-test-execution A 31 tokens
- Skill shaft-test-monitoring A 34 tokens
- Skill shaft-test-planning A 36 tokens
- Skill shaft-test-recording A 36 tokens
- Skill shaft-web-actions A 36 tokens
What ships with it
1 file beside marketplace.json#shaft-skills in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 55 lines scan A f4b068582d30
shaft-skills is a plugin published in the GitHub repository ShaftHQ/SHAFT_ENGINE (407 stars, last pushed 2d ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other plugins, from other repositories
secedgar-mcp-server
Query SEC EDGAR filings, XBRL financials, and company data through MCP. STDIO & Streamable HTTP.
safe-android-reverser
Sandboxed Android reverse engineering with semantic program indexing, XREF/CFG queries and structured network evidence through MCP.
claude-webcache
Cross-session WebFetch cache for Claude Code. WebFetches disappear after 15 minutes — claude-webcache makes them persist.
wikimoth
Deterministic, token-minimal memory for Claude Code: capture each session as a [[wikilink]] note (edges computed by code, not a model) and recall connected notes at boot.
youtube-outlier-research
YouTube outlier finder and competitor research. Ranks a channel's recent uploads and Shorts by how far each beat that channel's own baseline views, compares channels, and sweeps a niche for video ideas that already worked. Runs on your own free YouTube Data API key, unmetered.
linkedctl
LinkedIn API toolkit — MCP server and workflow guidance for Claude Code.