Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/wenhaochai/claude-pluginsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/plugins/wenhaochai/claude-plugins/anti-autoresearch)<a href="https://agentmods.dev/plugins/wenhaochai/claude-plugins/anti-autoresearch"><img src="https://agentmods.dev/badge/plugins/wenhaochai/claude-plugins/anti-autoresearch.svg" alt="Measured on agentmods" height="20"></a>Grade A, and why
anti-autoresearch scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "anti-autoresearch",
"version": "0.5.0",
"description": "Reviewer-side integrity forensics for autoresearch / AI-generated papers, used here as the ADVERSARIAL SELF-AUDIT gate on my own paper output (draft → /anti-autoresearch → fix verdict-bearing findings → re-run until CLEAN_GIVEN_EVIDENCE). 61 signals: 46 integrity hack-patterns in 8 families (numeric self-consistency, method/scope drift, baseline integrity, experiment integrity, citation integrity, presentation, proof/derivation, eval design incl. leakage + LLM-judge validity) + 13 zero-verdict-weight AI writing-style impressions + 2 advisory. Span-anchored evidence ledger, auditors propose / deterministic adjudicator decides (GRIM, GRIMMER, statcheck gates). 12 skills: the /anti-autoresearch orchestrator + evidence-ledger, consistency-audit, citation-forensics, baseline-comparison-audit, experiment-forensics, eval-design-forensics, proof-derivation-forensics, presentation-signals, ai-style-impressions, adversarial-case-builder, novelty-duplication-advisory. Vendored from wanshuiyin/Anti-Autoresearch (MIT, LICENSE.upstream) with one patch: repo-root resolution ($(git rev-parse --show-toplevel)) replaced by ${CLAUDE_PLUGIN_ROOT} so the bundled tools/ + references/ resolve inside the plugin.",
"author": {
"name": "Wenhao Chai",
"url": "https://wenhaochai.com"
}
}
What it installs
The manifest is a name and a version. 12 skills travel with it, and installing the plugin installs all of them — 3,057 tokens a session between them. Each is measured on its own page, and each can be installed alone.
- Skill anti-autoresearch A 275 tokens
- Skill baseline-comparison-audit A 309 tokens
- Skill adversarial-case-builder A 195 tokens
- Skill eval-design-forensics A 457 tokens
- Skill experiment-forensics A 237 tokens
- Skill citation-forensics A 193 tokens
- Skill presentation-signals A 246 tokens
- Skill consistency-audit A 133 tokens
- Skill proof-derivation-forensics A 222 tokens
- Skill evidence-ledger A 221 tokens
- Skill novelty-duplication-advisory A 285 tokens
- Skill ai-style-impressions A 284 tokens
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 10 lines scan A 21eae2a1e0ed
anti-autoresearch is a plugin published in the GitHub repository wenhaochai/claude-plugins (16 stars, last pushed 8d ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other plugins, from other repositories
catalysis-scientist
Reasons from active-site structure, turnover frequency, selectivity, and the Sabatier principle through CO/H2 chemisorption site-counting, Weisz-Prater and Mears transport checks, Langmuir-Hinshelwood/Mars-van Krevelen kinetics, and operando DRIFTS/XAS while treating diffusion-limited apparent rates, DRIFTS spectator…
antimicrobial-resistance-scientist
Reasons from MIC distributions, ECOFFs, and phenotype–genotype concordance through EUCAST/CLSI AST, CARD/RGI and AMRFinderPlus resistomes, GLASS/WHONET/NARMS surveillance, carbapenemase/ESBL/MRSA mechanism panels, and heteroresistance PAP while treating breakpoint mixing, genotype-without-phenotype overclaim…
hypha
Hypha is the AI agent of the Mycelium ecosystem: a connecting filament between engineers and the SysML v2 specification. Provides skills and subagents for KerML/SysML v2 metamodel lookup, standard model library lookup, normative spec citation, and SysML v2 textual-notation validation.
r2g-skills
RTL-to-GDS-to-Graph skill collection. eda-install detects the machine and installs + verifies the open-source EDA toolchain (with a no-sudo conda path). signoff-loop drives an open-source EDA flow (Yosys + OpenROAD-flow-scripts + KLayout + Magic + Netgen + OpenRCX) from a spec or RTL to signed-off GDSII (DRC, LVS…
ar
ar — autoresearch: a skill-only autonomous experiment loop. Propose → measure → keep winners → repeat, against any numeric objective, with noise-floor gating so nothing is banked on noise. Five skills: /ar:start opens a run (dedicated branch + baseline noise floor), /ar:resume advances it, /ar:status prints read-only…
academic-research
Academic research toolkit for AI PhD researchers — literature survey, paper reviewing, citation management, and more.