Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add SoliEstre/EstreGenesisnpx agentmods add plugins/soliestre/estregenesis/ultrasafegit clone --depth 1 https://github.com/SoliEstre/EstreGenesisWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/plugins/soliestre/estregenesis/ultrasafe)<a href="https://agentmods.dev/plugins/soliestre/estregenesis/ultrasafe"><img src="https://agentmods.dev/badge/plugins/soliestre/estregenesis/ultrasafe.svg" alt="Measured on agentmods" height="20"></a>Grade A, and why
ultrasafe scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 21 lines — stays where its author put it; the contents beside it link to each section on GitHub.
{
"name": "ultrasafe",
"version": "0.2.16",
"description": "Pre-release / pre-update simulated penetration testing discipline — v0.2.x runtime activation cut (advisory mode; v0.2.1 = ship-surface alignment doc patch). Wraps Ultrasafe.md v0.2.1 substantive spec (~3522 lines, +978 since v0.1.0) with the runtime layer: 8 attacker SKILL.md (ultrasafe-ai-llm-redteam · ultrasafe-web-api-attacker · ultrasafe-supply-chain-auditor · ultrasafe-crypto-reviewer · ultrasafe-social-engineer · ultrasafe-methodology-compliance · ultrasafe-threat-model-lifecycle · ultrasafe-synthesizer) implementing the v0.1.0-spec 8-agent parallel red-team fan-out; 2 hooks (PreToolUse `ultrasafe-trigger.cjs` matcher=Bash detects publish-equivalent commands and emits ULTRASAFE_RELEASE_GATE advisory; Stop `ultrasafe-clean-signal.cjs` evaluates 4-condition AND-gate at cycle-end and emits ULTRASAFE_ITERATION_BOUNDARY); MCP server `server.cjs` exposing 5 stdio JSON-RPC tools (ultrasafe_run_fanout · ultrasafe_finding_aggregate · ultrasafe_clean_signal_check · ultrasafe_report_generate · ultrasafe_release_gate); 5 new Constellation A2A intents integrated per Constellation v2.4.3 §13.16.13 wire-spec (ULTRASAFE_FINDING per-attacker emit + ULTRASAFE_ITERATION_BOUNDARY ≥3-iteration boundary marker + ULTRASAFE_RELEASE_GATE publish-time gate state + SECURITY_DISCLOSURE_INTAKE external disclosure entry + MPCVD_COORDINATION Multi-Party Coordinated Vulnerability Disclosure; ack_tier dual-mode mapping advisory v0.2.x → blocking v0.3+; cross-module integration with Hyperbrief paired DECISION_REQUEST on severity ≥ high + Greatpractice macro/mezzo entry candidate flow for ratified findings + Superscalar retire-barrier composition at iteration boundaries). v0.2 advisory invariant: all outputs (skill recommendations / hook emissions / MCP tool returns) carry `advisory` flag — NEVER block publish in v0.2.x. Blocking mode (v0.3+) introduces user gate via paired Hyperbrief DECISION_REQUEST. 3-layer synthesis report (What it installs
The manifest is a name and a version. 8 skills travel with it, and installing the plugin installs all of them — 1,580 tokens a session between them. Each is measured on its own page, and each can be installed alone.
- Skill ultrasafe-crypto-reviewer A 186 tokens
- Skill ultrasafe-methodology-compliance A 208 tokens
- Skill ultrasafe-supply-chain-auditor A 228 tokens
- Skill ultrasafe-synthesizer A 210 tokens
- Skill ultrasafe-threat-model-lifecycle A 199 tokens
- Skill ultrasafe-web-api-attacker A 169 tokens
- Skill ultrasafe-social-engineer A 217 tokens
- Skill ultrasafe-ai-llm-redteam C 163 tokens
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today Changed ca28152999de
- 6d ago First seen · 21 lines scan A 3130e13a20bf
ultrasafe is a plugin published in the GitHub repository SoliEstre/EstreGenesis (8 stars, last pushed today), licensed Apache-2.0. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other plugins, from other repositories
offstage-qa
Background QA for macOS apps via the offstage harness: AX perception, semantic port actuation, canonical pixel goldens, ground-truth verification.
ppgp
Portable continuity protocol for long-running coding agents.
flow
Skill-driven workflow plugin for GitHub development with excellence-by-default quality gates. Encodes team knowledge as composable skills, enforces safety through hooks, and compounds learning across sessions. Strict TDD, Stranger Test, holdout validation, and evidence-based verification built in. Durable goals…
webmaxru-ai-native-dev marketplace
Plugin marketplace listing 3 plugins: ai-native-dev-skills, web-ai-skills, enonic-skills.
superpowers
Core skills library for Claude Code: TDD, debugging, collaboration patterns, and proven techniques.
nextjs
Official Next.js skills: adopt and optimize Cache Components, adopt Partial Prefetching, and verify runtime behavior against a running dev server.