Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/TimboGP/timbogp-marketplaceWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/plugins/timbogp/timbogp-marketplace/lean-coach)<a href="https://agentmods.dev/plugins/timbogp/timbogp-marketplace/lean-coach"><img src="https://agentmods.dev/badge/plugins/timbogp/timbogp-marketplace/lean-coach/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/plugins/timbogp/timbogp-marketplace/lean-coach"><img src="https://agentmods.dev/badge/plugins/timbogp/timbogp-marketplace/lean-coach.svg" alt="Reviewed on agentmods" width="80" height="20"></a>Grade A, and why
lean-coach scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "lean-coach",
"version": "0.1.0",
"description": "A Lean business-development coach: guide a venture through Running Lean — Lean Canvas, riskiest-assumption testing, customer interviews, experiments, and product/market fit — and role-play the customers, investors, and advisors you test it with.",
"author": {
"name": "TimboGP"
},
"homepage": "https://github.com/TimboGP/timbogp-marketplace",
"repository": "https://github.com/TimboGP/timbogp-marketplace",
"license": "MIT",
"keywords": [
"lean",
"lean-startup",
"running-lean",
"lean-canvas",
"startup",
"business-model",
"customer-development",
"product-market-fit",
"entrepreneurship"
]
}
What it installs
The manifest is a name and a version. 8 skills, 5 commands, 1 agent travel with it, and installing the plugin installs all of them — 1,696 tokens a session between them. Each is measured on its own page, and each can be installed alone.
- Skill customer-interview A 159 tokens
- Skill investor-pitch A 143 tokens
- Skill lean-canvas A 142 tokens
- Skill lean-coach A 160 tokens
- Skill lean-roles A 156 tokens
- Skill prioritize-risks A 156 tokens
- Skill measure-fit A 145 tokens
- Skill run-experiment A 150 tokens
- Command lean-role A 23 tokens
- Command lean-canvas A 22 tokens
- Command lean-coach A 24 tokens
- Command lean-help A 27 tokens
- Command lean-interview A 29 tokens
- Agent lean-mentor A 360 tokens
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 23 lines scan A ffe7b560dbd6
lean-coach is a plugin published in the GitHub repository TimboGP/timbogp-marketplace (3 stars, last pushed 2mo ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other plugins, from other repositories
rails-consultant marketplace
Plugin marketplace listing 1 plugin: rails-consultant.
gan-zhong-xue
A learning add-on that turns AI-made code changes into guided, explainable understanding. It uses a question-and-answer process so developers can restate the reasoning and apply it elsewhere.
dev-pipeline
A 5-phase development pipeline (requirement engineering, system architecture, task generation, verified implementation, code review) with an optional QA gate (plan-qa + execute-qa) for changes that have a running surface worth driving — independent of /review, run sequentially or in parallel at the developer's…
agent-based-development
Full async multi-agent development workflow: Planning → Design → Dev → Security/Tech Review loop with file-based handoffs and release-branch Git model.
architecture-design
Guides system and feature architecture design with C4 diagrams, service boundaries, API contracts, failure analysis, and design artifacts.
architecture-review
Audits existing system architecture for anti-patterns, scalability risks, and reliability gaps. Produces graded findings with migration roadmap.