Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add synaptiai/synapti-marketplacenpx agentmods add plugins/synaptiai/synapti-marketplace/flowgit clone --depth 1 https://github.com/synaptiai/synapti-marketplaceWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/plugins/synaptiai/synapti-marketplace/flow)<a href="https://agentmods.dev/plugins/synaptiai/synapti-marketplace/flow"><img src="https://agentmods.dev/badge/plugins/synaptiai/synapti-marketplace/flow.svg" alt="Measured on agentmods" height="20"></a>Grade A, and why
flow scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "flow",
"version": "3.2.2",
"description": "Skill-driven workflow plugin for GitHub development with excellence-by-default quality gates. Encodes team knowledge as composable skills, enforces safety through hooks, and compounds learning across sessions. Strict TDD, Stranger Test, holdout validation, and evidence-based verification built in. Durable goals, workflows, triggers, and runs at .flow/.",
"author": {
"name": "Synapti AI",
"url": "https://github.com/synaptiai"
},
"license": "Apache-2.0",
"keywords": [
"github",
"workflow",
"skills",
"autonomous",
"agent-teams",
"hooks",
"learning",
"development"
],
"repository": "https://github.com/synaptiai/synapti-marketplace",
"homepage": "https://github.com/synaptiai/synapti-marketplace/tree/main/plugins/flow"
}
What it installs
The manifest is a name and a version. 31 skills, 21 commands, 9 agents travel with it, and installing the plugin installs all of them — 4,427 tokens a session between them. Each is measured on its own page, and each can be installed alone.
- Skill holdout-validation A 120 tokens
- Skill runtime-verification A 116 tokens
- Skill specification-capture A 121 tokens
- Skill team-coordination A 80 tokens
- Skill visual-verification A 137 tokens
- Skill architecture-patterns A 66 tokens
- Skill code-review-methodology A 90 tokens
- Skill criterion-verification-map A 105 tokens
- Skill goal-evaluator A 143 tokens
- Skill goal-lifecycle A 167 tokens
- Skill feedback-resolution A 103 tokens
- Skill goal-contract-capture A 147 tokens
- Skill goal-evidence-ledger A 142 tokens
- Skill run-state-management A 151 tokens
- Skill tdd-patterns A 114 tokens
- Skill brainstorming A 60 tokens
- Skill capability-discovery A 77 tokens
- Skill debugging-patterns A 90 tokens
- Skill merge-conflict-resolution A 114 tokens
- Skill trigger-policy A 145 tokens
- Skill branch-and-task-management A 60 tokens
- Skill change-classification A 86 tokens
- Skill convention-enforcement A 80 tokens
- Skill issue-crafting A 64 tokens
- Skill autonomous-workflow A 83 tokens
- Skill llm-operator-principles A 155 tokens
- Skill code-quality-principles A 83 tokens
- Skill merge-and-release A 82 tokens
- Skill pr-lifecycle A 73 tokens
- Skill evidence-based-development A 80 tokens
- Skill preflight-checks A 64 tokens
- Command start A 29 tokens
- Command address A 23 tokens
- Command pr A 27 tokens
- Command goal A 71 tokens
- Command brainstorm A 22 tokens
- Command debug A 20 tokens
- Command design A 24 tokens
- Command learn A 29 tokens
- Command resolve A 38 tokens
- Command resume A 63 tokens
- Command commit A 24 tokens
- Command flow A 56 tokens
- Command release A 27 tokens
- Command workflow A 31 tokens
- Command issue A 28 tokens
- Command watch A 60 tokens
- Command explain A 38 tokens
- Command run A 21 tokens
- Command trigger A 49 tokens
- Command review B 23 tokens
- Command merge B 32 tokens
- Agent goal-evaluator-judge A 161 tokens
- Agent verdict-judge A 49 tokens
- Agent integration-verifier A 34 tokens
- Agent code-reviewer A 61 tokens
- Agent error-handler-inspector A 38 tokens
- Agent security-reviewer A 45 tokens
- Agent implementation-planner A 33 tokens
- Agent test-runner A 45 tokens
- Agent convention-checker A 28 tokens
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 23 lines scan A 9bc318cd2890
flow is a plugin published in the GitHub repository synaptiai/synapti-marketplace (6 stars, last pushed 1mo ago), licensed Apache-2.0. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other plugins, from other repositories
lead-dev-os
Spec & context-driven framework for Claude Code development. Structured skills for product planning, spec writing, task scoping, and context-aware implementation.
atdd
Acceptance Test Driven Development for Claude Code. Enforces the ATDD methodology: write Given/When/Then specs first, generate a project-specific test pipeline, maintain two test streams (acceptance + unit). Inspired by Robert C. Martin's acceptance test approach from empire-2025.
swarms
Launch agent teams for any kind of work — coding, writing, diagnosis, and more.
bad_plugin
bad-plugin. Turn human SOPs into deterministic, gated agentic workflows — a Claude Code plugin.
loop-kit
A session-based working method for coding agents: plan an epic into thin complete slices, build one at a time, verify by observing real behaviour, and hand off so the next session starts where the last one stopped.
rageatc-code-oss
Scale-adaptive software development — TDD, verification, perspective-based review, interface design, and tool capabilities (browser automation, PDFs, YouTube transcripts, local-LLM and Codex delegation).