Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/synaptiai/synapti-marketplaceWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/plugins/synaptiai/synapti-marketplace/dossier)<a href="https://agentmods.dev/plugins/synaptiai/synapti-marketplace/dossier"><img src="https://agentmods.dev/badge/plugins/synaptiai/synapti-marketplace/dossier/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/plugins/synaptiai/synapti-marketplace/dossier"><img src="https://agentmods.dev/badge/plugins/synaptiai/synapti-marketplace/dossier.svg" alt="Reviewed on agentmods" width="80" height="20"></a>Grade A, and why
dossier scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "dossier",
"version": "1.1.0",
"description": "Evidence-first project documentation system. Produces an audit-ready 23-file package for technical due diligence, engineering and product onboarding, and partner or customer communication — every material claim traced to a ledger row and a claim state, three context-isolated verification passes, and a binary release gate. Ships a post-merge GitHub Actions job that keeps the package current by opening a documentation PR.",
"author": {
"name": "Synapti AI",
"url": "https://github.com/synaptiai"
},
"repository": "https://github.com/synaptiai/synapti-marketplace",
"homepage": "https://github.com/synaptiai/synapti-marketplace/tree/main/plugins/dossier",
"license": "Apache-2.0",
"keywords": [
"documentation",
"due-diligence",
"onboarding",
"evidence-based",
"audit",
"verification",
"disclosure",
"architecture",
"compliance",
"automation"
]
}
What it installs
The manifest is a name and a version. 10 skills, 9 commands, 6 agents, 2 hooks travel with it, and installing the plugin installs all of them — 2,218 tokens a session between them. Each is measured on its own page, and each can be installed alone.
- Skill evidence-ledger A 137 tokens
- Skill disclosure-gating A 127 tokens
- Skill engagement-scoping A 135 tokens
- Skill finding-reconciliation A 150 tokens
- Skill gap-and-contradiction-register A 144 tokens
- Skill project-modeling A 123 tokens
- Skill scoring-and-release-gate A 149 tokens
- Skill verification-protocol A 136 tokens
- Skill prose-clarity A 146 tokens
- Skill doc-package-contract C 119 tokens
- Command audit A 50 tokens
- Command baseline A 42 tokens
- Command reconcile A 46 tokens
- Command status A 43 tokens
- Command claim A 44 tokens
- Command gate A 45 tokens
- Command setup B 41 tokens
- Command init B 43 tokens
- Command refresh C 58 tokens
- Agent dossier-pass-a-evidence A 72 tokens
- Agent dossier-pass-c-audience A 86 tokens
- Agent dossier-doc-drafter A 69 tokens
- Agent dossier-pass-b-falsification A 80 tokens
- Agent dossier-evidence-collector A 59 tokens
- Agent dossier-scorer A 74 tokens
- Hook PreToolUse A not measured
- Hook PostToolUse A not measured
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 25 lines scan A 4b916391daff
dossier is a plugin published in the GitHub repository synaptiai/synapti-marketplace (6 stars, last pushed 1mo ago), licensed Apache-2.0. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other plugins, from other repositories
lead-dev-os
Spec & context-driven framework for Claude Code development. Structured skills for product planning, spec writing, task scoping, and context-aware implementation.
swarms
Launch agent teams for any kind of work — coding, writing, diagnosis, and more.
paper-trail
Plugin Claude Code anti-hallucination pour la recherche scientifique. Cree des SOTAs (etats de l'art) garantis sans fabrication, audite les SOTAs/articles existants (purge ou warnings), avec un moteur de validation strict (FSM 8 etats + cascade d'acquisition PDF + page 1 anti-homonymie + 19 invariants de coherence).…
bergant-workflow
Engineering workflow plugin: spec-to-docs (project-init) and feature lifecycle orchestration (lifecycle) with compact/gate-enforcement hooks.
loop-kit
A session-based working method for coding agents: plan an epic into thin complete slices, build one at a time, verify by observing real behaviour, and hand off so the next session starts where the last one stopped.
riven-analyst
Agent-led Warframe Riven advice, reroll targets, and complete builds using shared reviewed knowledge.