Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add webmaxru/ai-native-devnpx agentmods add plugins/webmaxru/ai-native-dev/marketplacegit clone --depth 1 https://github.com/webmaxru/ai-native-devGrade A, and why
webmaxru-ai-native-dev scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
The source is not reproduced here
No licence file
A repository with no LICENSE is all rights reserved by default, so the body is not copied here. The metadata, the measurements and the link are.
What ships with it
1 file beside marketplace.json in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 36 lines scan A 8bac37763ef6
webmaxru-ai-native-dev is a plugin published in the GitHub repository webmaxru/ai-native-dev (1 stars, last pushed 8d ago), with no licence file. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other plugins, from other repositories
estregenesis-plugins
Plugin marketplace listing 8 plugins: estregenesis, constellation, superscalar, hyperbrief, greatpractice.
constellation
Live multi-agent orchestration: WebSocket server + A2A messaging + dashboard + Stop hook helper + MCP server (full Phase 2 impl: WS proxy + 5 tools incl. a2awaitack 3-tier + session-lifecycle + §13.13.2 dedup + chunked transfer reassembly). v0.3.29 / Constellation v2.4.57 — room artifacts + board state schema: the re.
superscalar
Execution-scheduling discipline for parallel sub-agent dispatch. v0.5.0 / Superscalar v0.14.0 adds the /speculation toggle (§4 speculation authorization) — four modes plus a read-back (off default / auto asks per speculation with the four-element trade-off / on pre-authorizes low-downstream-sensitivity lanes while…
compendium
Concept-anchored dual-register vocabulary substrate. Wraps Compendium.md v0.2.4 (runtime — content store + lint/pointer-resolution + the §10 8-tool MCP server; dashboard surfaces deferred v0.2.x) — EstreGenesis's 6th module and the purest expression of north-star axis-2 (vocabulary survival > code survival): a…
corporate
Durable-role agent organization. Wraps Corporate.md v0.1.5 (design draft — runtime deferred as named prunable units) — EstreGenesis's 7th module and the third orchestration axis: Superscalar decides how many lanes and at which tier (anonymous, one fan-out), Constellation decides how agent processes talk, and Corporate.
estregenesis
The EG kit plugin — the entry point to EstreGenesis itself, as skills instead of a copy-pasted URL. 13 skills over 8 canonical procedures: eg-bootstrap (/egboot — new project: pick the seed tier, install it as .agent/seedprompt.md, run the seed's Bootstrap mode) · eg-migration (/egmig — existing project with its own r.