Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add SienkLogic/plan-build-runnpx agentmods add plugins/sienklogic/plan-build-run/pbrgit clone --depth 1 https://github.com/SienkLogic/plan-build-runGrade A, and why
pbr scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "pbr",
"version": "2.22.0",
"description": "Plan-Build-Run — Structured development workflow for Claude Code. Solves context rot through disciplined subagent delegation, structured planning, atomic execution, and goal-backward verification.",
"author": {
"name": "SienkLogic",
"email": "[email protected]"
},
"homepage": "https://github.com/SienkLogic/plan-build-run",
"repository": "https://github.com/SienkLogic/plan-build-run",
"license": "MIT",
"keywords": [
"claude-code",
"context-engineering",
"development-workflow",
"subagent-delegation"
],
"userConfig": {
"default_mode": {
"title": "Default Mode",
"description": "Default workflow mode: autonomous (hands-free) or interactive (pause at gates)",
"type": "string",
"sensitive": false
},
"context_window": {
"title": "Context Window",
"description": "Your model's context window size in tokens (e.g., 200000 or 1000000)",
"type": "string",
"sensitive": false
},
"default_depth": {
"title": "Default Depth",
"description": "Default research/planning depth: quick, standard, or comprehensive",
"type": "string",
"sensitive": false
}
}
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 39 lines scan A 76e30c6f4c70
pbr is a plugin published in the GitHub repository SienkLogic/plan-build-run (17 stars, last pushed 5mo ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other plugins, from other repositories
connector-claude-code
Join the Cotal mesh — coordinate with other AI agents as lateral peers (presence, messaging, role requests) over NATS.
ensemble-ai
AI SDK skills for OpenAI, and other AI providers for Claude Code.
brana
AI development system — skills, agents, and hooks for systematic software engineering with Claude Code.
claude-md-management-hames
Hames-aware fork of claude-md-management. Audits and revises CLAUDE.md files while honoring the v5.5 kernel + .cursor/rules/ module separation, workspace boundaries, defense-line signatures, and isolated domains.
8-habit-ai-dev
Anti-Vibe-Coding plugin — 7-step workflow discipline + 8-Habit cross-verification for AI-assisted development.
vibe-flow
Orchestration skills for Vibe Kanban: plan → ship → link → review → merge with wave-based dispatch, executor routing (T0-T4), and autonomous fix loops.