Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add skillscake/use-skillscakenpx agentmods add plugins/skillscake/use-skillscake/marketplacegit clone --depth 1 https://github.com/skillscake/use-skillscakeGrade A, and why
skillscake scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "skillscake",
"owner": { "name": "SkillsCake", "url": "https://skillscake.com" },
"plugins": [
{
"name": "skillscake",
"source": "./plugins/claude-code",
"displayName": "SkillsCake",
"description": "Create or improve agent skills (SKILL.md) with SkillsCake — skill creation and optimization for prompt engineers on Claude Code, Codex, and Cursor.",
"category": "Developer Tools",
"tags": ["agent-skills", "skill", "prompt-engineering", "skill-creator", "skill-optimizer", "secure-skills", "claude-code", "codex", "cursor", "skillscake"],
"keywords": ["agent-skills", "skill", "prompt-engineering", "skill-creator", "skill-optimizer", "secure-skills", "skillscake"]
}
]
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 16 lines scan A 4e69a527d715
skillscake is a plugin published in the GitHub repository skillscake/use-skillscake (2 stars, last pushed 1mo ago), licensed Apache-2.0. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other plugins, from other repositories
slopsec
Security tooling for vibe-coded SaaS apps.
slopsec
Security audit and hardening for vibe-coded SaaS apps. Walks the 50 most common ways AI-generated apps get owned and produces a prioritized fix list.
hf-paper-publisher
Publish and manage research papers on Hugging Face Hub. Supports creating paper pages, linking papers to models/datasets, claiming authorship, and generating professional markdown-based research articles.
npi-registry
The NPI Registry Connector gives Claude access to the US National Provider Identifier (NPI) Registry, containing information about all HIPAA-covered healthcare providers in the United States.
pubmed
Provides access to PubMed's biomedical citations and PubMed Central's full-text archive. Search articles, retrieve metadata and abstracts, access full-text content (when available in PMC), find related research, and more.
swift-focusengine-pro
Plugin marketplace listing 1 plugin: swift-focusengine-pro.