Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/zircote/lsp-marketplaceWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/plugins/zircote/lsp-marketplace/marketplace)<a href="https://agentmods.dev/plugins/zircote/lsp-marketplace/marketplace"><img src="https://agentmods.dev/badge/plugins/zircote/lsp-marketplace/marketplace/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/plugins/zircote/lsp-marketplace/marketplace"><img src="https://agentmods.dev/badge/plugins/zircote/lsp-marketplace/marketplace.svg" alt="Reviewed on agentmods" width="80" height="20"></a>Grade A, and why
zircote-lsp marketplace scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 246 lines — stays where its author put it; the contents beside it link to each section on GitHub.
{
"name": "zircote-lsp",
"owner": {
"name": "zircote",
"email": "[email protected]",
"url": "https://github.com/zircote/lsp-marketplace"
},
"metadata": {
"description": "Curated collection of Claude Code plugins: LSP tools for 28 programming languages with automated hooks for linting, formatting, security, and code quality",
"version": "1.0.0"
},
"plugins": [
{
"name": "lsp-tools",
"source": {
"source": "github",
"repo": "zircote/lsp-tools"
},
"description": "LSP-first code intelligence enforcing Language Server Protocol usage for all code operations across 12 languages"
},
{
"name": "bash-lsp",
"source": {
"source": "github",
"repo": "zircote/bash-lsp"
},
"description": "Bash/Shell development with bash-language-server LSP and ShellCheck hooks"
},
{
"name": "cpp-lsp",
"source": {
"source": "github",
"repo": "zircote/cpp-lsp"
},
"description": "C/C++ development with clangd LSP, clang-tidy, and clang-format hooks"
},
{
"name": "csharp-lsp",
"source": {
"source": "github",
"repo": "zircote/csharp-lsp"
},
"description": "C# development with OmniSharp LSP and dotnet format hooks"
},
{
"name": "dockerfile-lsp",
"source": {
"source": "github",
"repo": "zircote/dockerfile-lsp"
},
"description": "Dockerfile development with dockerfile-language-server LSP and hadolint hooks"
},
{
"name": "elixir-lsp",
"source": {
"source": "github",
"repo": "zircote/elixir-lsp"
},
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 246 lines scan A ce61ebbac476
zircote-lsp marketplace is a plugin published in the GitHub repository zircote/lsp-marketplace (21 stars, last pushed 6mo ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other plugins, from other repositories
review
PR review, interactive git diff annotation review, and writing style guide.
dev-tooling
Three MCP servers for PHP and JavaScript operations plus an optional PHP language server. PHP (php-tooling): PHPStan, ECS, Rector, PHPUnit, PHPUnit coverage gap analysis, Symfony Console. Administration (js-admin-tooling): ESLint, Stylelint, Prettier, Jest, TypeScript, Vite builds. Storefront (js-storefront-tooling)…
design-compare
Compare Figma designs against implementation screenshots with interactive HTML reports.
xcodebuild-notify
macOS notifications for xcodebuild commands, mimicking Xcode's build notifications.
oslog
Read, stream, and analyze Apple unified logs (OSLog) for iOS/macOS apps.
instruction-placement
Routes agent-instruction content to the surface that loads it at the right moment. The audit skill sweeps a repository's instruction layer and its ordinary markdown for content whose scope is narrower than the surface carrying it — conventions keyed to one file type or one subtree sitting in an always-loaded CLAUDE.md.