Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add plugins/siva01c/claude-plugins/marketplace/plugin marketplace add siva01c/claude-pluginsgit clone --depth 1 https://github.com/siva01c/claude-pluginsGrade A, and why
dev-tools scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 87 lines — stays where its author put it; the contents beside it link to each section on GitHub.
{
"name": "dev-tools",
"owner": {
"name": "siva01",
"email": "[email protected]"
},
"metadata": {
"description": "Developer tools for Drupal development, security, and deployment — Drupal, Docker, CI/CD, git, and security workflows.",
"categories": [
"Development",
"Productivity"
],
"tags": [
"drupal",
"docker",
"ci-cd",
"git",
"security"
]
},
"plugins": [
{
"name": "drupal-dev-tools",
"source": "./drupal-dev-tools",
"description": "Drupal 11 toolkit — audit command and skills for module development and security review",
"version": "4.0.0",
"author": {
"name": "Ludek Kvapil - siva01"
}
},
{
"name": "ddev-tools",
"source": "./ddev-tools",
"description": "DDEV local environment skills — drupal-ddev agent and operational workflows for Drupal 11 projects in DDEV",
"version": "1.0.0",
"author": {
"name": "Ludek Kvapil - siva01"
}
},
{
"name": "git-tools",
"source": "./git-tools",
"description": "Git workflow skills — worktrees for parallel, conflict-free work on multiple branches",
"version": "1.0.0",
"author": {
"name": "Ludek Kvapil - siva01"
}
},
{
"name": "security-tools",
"source": "./security-tools",
"description": "Security verification skills — OWASP ASVS v5.0 checklist mapped to Drupal 11 APIs for security code reviews",
"version": "1.0.0",
"author": {
"name": "Ludek Kvapil - siva01"
}
},
{
"name": "docker-tools",
"source": "./docker-tools",
"description": "Docker skills for Drupal development — Compose stack authoring/operations and Docker Model Runner for local AI models",
"version": "1.0.0",
"author": {
"name": "Ludek Kvapil - siva01"
}
},
{
"name": "cicd-tools",
"source": "./cicd-tools",
"descriptWhat this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 87 lines scan A a2f168f06bbb
dev-tools is a plugin published in the GitHub repository siva01c/claude-plugins (16 stars, last pushed 1mo ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other plugins, from other repositories
slide-wright
Create beautiful, animated presentations — generate a custom theme and preview, then build the full deck once you confirm the direction.
drunkrhin0
Rami Tawil's self-hosted Claude Code plugin marketplace.
codealive-marketplace
Plugin marketplace listing 1 plugin: codealive.
evolution-skills
Home of the evolution plugin — eleven thinking skills, each a proven prompt rewritten as an agent workflow with a completion bar on every step.
famulor-assistants-history
Review Famulor assistants and read omnichannel call, messaging, and email history through an OAuth-secured, read-only 11-tool MCP profile.
pstack
poteto's engineering skills for rigorous AI-assisted development.