Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add XRenSiu/claude-code-forgenpx agentmods add plugins/xrensiu/claude-code-forge/done-when-pipelinegit clone --depth 1 https://github.com/XRenSiu/claude-code-forgeGrade A, and why
done-when-pipeline scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 36 lines — stays where its author put it; the contents beside it link to each section on GitHub.
{
"name": "done-when-pipeline",
"description": "Done_When Pipeline v1.0 — turn fuzzy natural-language requirements into machine-verifiable completion contracts, then run a multi-agent acceptance loop against an implementation. Nine skills in a two-layer topology (per HTML v2 architecture). Layer 1: TWO contract producers + SIX independently-invocable review skills — `/acceptance-spec` (NL → EARS spec + done_when.yaml with existence/behavior/rules schema + spec-robustness.md anti-gaming companion), `/test-suite-generator` (EARS → 5-layer test pyramid: existence/unit/integration/e2e/mutation; the v0.x fitness rubric layer was retired per HTML v2 §3.5 fitness-check dissolution), and six review skills each user-invocable on their own: `/code-reviewer` (diff → findings, focus-driven: security/logic/perf/style/all; Detective Loop not flowchart; 5-finding cap; cross-vendor adversarial mode), `/qa-reviewer` (actually runs tests, classifies maintenance-vs-genuine failures, emits go/no-go), `/pm-reviewer` (Agent-as-Judge: LOCATE/READ/RETRIEVE atoms; requirements normalized from EARS/Jira/Linear/PRD/issue; 4-state TicketCompliance verdict where requires_human_verification is the formal home for genuinely-unautomatable evaluation), `/spec-drift-detector` (code archaeologist: detects spec/code factual divergence without judging which is correct; git_blame traces commit_introducing_drift; 3 divergence types: timing/behavior/contract), `/spec-gaming-detector` (assumes author is gaming; 6 RHD patterns absolute + diff mode; outputs spec_robustness_gaps for contract hardening), `/meta-judge` (synthesizes findings via 4 actions: dedupe/weight/arbitrate/classify; HARD WALL — does NOT re-review code; pluggable rules source). Layer 2: `/acceptance-fleet` is pure orchestrator — dispatches the 6 review skills in parallel against an impl, hands findings to /meta-judge, decodes verdict into four-state ratchet (DONE/FIX/SPEC_DRIFT/GAMING_RISK), persists every iteration to ratchet-log/iterWhat this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 36 lines scan A 40d84ffa608c
done-when-pipeline is a plugin published in the GitHub repository XRenSiu/claude-code-forge (2 stars, last pushed 1mo ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other plugins, from other repositories
humanizer
Rewrite AI-sounding text so it reads naturally without changing what it says.
nextjs
Official Next.js skills: adopt and optimize Cache Components, adopt Partial Prefetching, and verify runtime behavior against a running dev server.
claude-plugins-official marketplace
Directory of popular Claude Code extensions including development tools, productivity plugins, and MCP integrations.
knowledge-work-plugins marketplace
Plugin marketplace listing 97 plugins: noibu, productivity, enterprise-search, cowork-plugin-management, sales.
ecc
Harness-native ECC plugin for engineering teams - 68 agents, 286 skills, 94 legacy command shims, reusable hooks, rules, MCP conventions, and operator workflows for Claude Code plus adjacent agent harnesses.
ui-ux-pro-max
UI/UX design intelligence. Searchable local database with 84 styles, 192 palettes, 74 font pairings, 25 charts, and 22 stacks (React, Next.js, Vue, Nuxt.js, Nuxt UI, Svelte, Astro, SwiftUI, React Native, Flutter, Tailwind, shadcn/ui, Jetpack Compose, Angular, Laravel, JavaFX, WPF, WinUI, Avalonia, Uno Platform, UWP…