Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add Zts0hg/codexspecnpx agentmods add plugins/zts0hg/codexspec/marketplacegit clone --depth 1 https://github.com/Zts0hg/codexspecGrade A, and why
codexspec-market scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"$schema": "https://anthropic.com/claude-code/marketplace.schema.json",
"name": "codexspec-market",
"description": "Requirements-First SDD toolkit for Claude Code - structured slash commands for AI-assisted software development",
"owner": {
"name": "Zts0hg"
},
"plugins": [
{
"name": "codexspec",
"description": "Complete Requirements-First SDD toolkit with constitution, requirements, specification, planning, and implementation commands. Includes a full suite of slash commands for requirements clarification and confirmation, spec generation, technical planning, task breakdown, code review, configuration management, and more.",
"source": {
"source": "github",
"repo": "Zts0hg/codexspec",
"ref": "v0.7.13",
"path": ".claude/commands/codexspec"
},
"version": "0.7.13",
"author": {
"name": "Zts0hg"
},
"homepage": "https://github.com/Zts0hg/codexspec",
"repository": "https://github.com/Zts0hg/codexspec",
"license": "MIT",
"category": "development",
"keywords": ["requirements-first", "spec-driven", "development", "ai", "claude", "sdd", "specification", "planning", "tdd"],
"strict": false
}
]
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 31 lines scan A 66d6ce90ce16
codexspec-market is a plugin published in the GitHub repository Zts0hg/codexspec (5 stars, last pushed 3d ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other plugins, from other repositories
intlayer
Intlayer plugins for Claude Code — LSP-powered i18n intelligence for TypeScript, JavaScript, Vue, and Svelte projects.
claude-code-zh-cn
为 Claude Code 提供简体中文界面、本地化提示和安全的渐进式 CLI patch.
product-playbook
MUST use when the user wants to plan, strategize, validate, or scope a product or feature. Composable product-thinking lenses (JTBD, PR-FAQ, positioning, pre-mortem, RICE, North Star, MVP, GTM, and more) that snap to the outcome and blend when the situation needs it, from raw idea to dev handoff.
product-playbook
Plugin marketplace listing 1 plugin: product-playbook.
claude-thai-skills
Plugin marketplace listing 13 plugins: claude-thai-skills, thai-translate, thai-social-caption, thai-customer-service, thai-resume.
claude-thai-skills
12 skills ภาษาไทยสำหรับ Claude Code — แปล, แคปชั่นโซเชียล, เรซูเม่, จดหมายราชการ, PDPA, ใบกำกับภาษี, PromptPay, เลขบัตร ปชช., วันที่ พ.ศ., ที่อยู่ไทย, และตอบลูกค้า.