Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add toBzh30/Claude-Project-Bootstrapnpx agentmods add plugins/tobzh30/claude-project-bootstrap/engineering-craftgit clone --depth 1 https://github.com/toBzh30/Claude-Project-BootstrapGrade A, and why
engineering-craft scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "engineering-craft",
"description": "Engineering & Claude-coding craft skills (diagnose, tdd, prototype, zoom-out, grill-with-docs, improve-codebase-architecture, to-issues, to-prd) adapted from mattpocock/skills (MIT) to the bootstrap conventions and the AFK/HITL model, plus homegrown skills (checkpoint).",
"author": {
"name": "toBzh30"
}
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 8 lines scan A 068612cd771b
engineering-craft is a plugin published in the GitHub repository toBzh30/Claude-Project-Bootstrap (3 stars, last pushed 1mo ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other plugins, from other repositories
tdd-guard
Automated Test-Driven Development enforcement.
superpowers-deepseek-v4
Superpowers DeepSeek v4: composable agent skills for TDD, debugging, and collaboration. Independently maintained; not identical to obra/superpowers.
cantrips
The core engineering loop for coding agents (Claude Code, Codex CLI): grill, spec, tickets, implement with TDD at agreed seams, review, commit, plus a user-gated compound step that turns session learnings into durable project memory. Basic spells a caster always has prepared.
otter-skills
Portable software-craft skills for thin delivery, TDD, safe change, naming, refactoring, and trustworthy commits.
devflow
Full-lifecycle AI development workflow — fuses grill-with-docs (Matt Pocock) + OpenSpec (Fission-AI) + superpowers (obra) into one disciplined pipeline. Three modes: Design (quick-grill → spec-lite), Build (grill → spec → plan → isolate → enhanced-apply → review → archive), Fix (diagnose → apply → verify → archive).
pr-trains
Batch operators for GitHub queues: review-train reviews every open PR, fix-train applies requested changes, fix-ci-train turns red CI green, merge-train fixes and merges in dependency order, issue-train triages and builds one PR per actionable issue — all with parallel sub-agents and one grouped confirmation.