Neels Plugins — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Neels Plugins (Plugin) and scored it 96/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 1 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
You run marketing for a single brand, an agency portfolio, or a content team — and you want the same depth across every brand, every article, every campaign, with no per-platform lock-in. You don't want to learn six different "AI marketing" SaaS UIs that all charge per-seat per-month.
Install three open-source plugins from one marketplace. Same skills, same agents, same outputs across Claude Code, Anthropic Cowork, OpenAI Codex, Cursor 2.5+, GitHub Copilot CLI, Google Antigravity 2.0, Hermes Agent, and OpenClaw + 35+ additional Agent Skills platforms — via the Agent Skills open standard. Zero global hooks, zero auto-connecting MCP servers, MIT-licensed, no telemetry, no seats.
🆕 June 9, 2026 — marketplace v3.13.1: Test-infra polish across the suite — CF v3.15.1 + SF v1.12.1 add release-consistency suites (+61 tests). Suite total 221 tests passing (DMP 114 + CF 53 + SF 54). Every cross-manifest version drift, broken anchor, stale install command, and missing critical section is now caught by python -m unittest discover -s tests before it ships. v3.13.0 (earlier today) brought CF + SF to native Hermes Agent + OpenClaw parity with DMP. All 3 plugins on all 8 native platforms + 35+ Agent Skills clients. Read what's new → · Full changelog →A custom plugin marketplace by Indranil Banerjee · LinkedIn · X. Agent Skills was donated to the Agentic AI Foundation December 2025; adopted by 41+ agent products by June 2026.
| Your job-to-be-done | Install | What's in the box |
|---|---|---|
| Run end-to-end brand-strategy engagements across a portfolio (agencies, in-house, consultants) | digital-marketing-pro | 158 skills · 25 agents · 12-Part Strategy Flow · 6-platform AEO/GEO · EU AI Act Article 50 · Cowork-team-persistent · multi-brand · multi-jurisdiction compliance |
| Produce publish-ready long-form content (blog posts, white papers, case studies, executive briefs) | contentforge | 21 skills · 13 agents · 11 quality gates · 29-pattern AI humanizer · fact-checker · real .docx output · C2PA signing |
| Produce social media assets at agency scale (carousels, single-image posts, AI image / video creatives) | socialforge | 16 skills · 25 commands · asset-first compositing · AI image (Vertex AI Nano Banana Pro) · AI video (Kling v3.0 Pro) · C2PA signing |
The three plugins are complementary, not overlapping. A typical agency workflow uses all three: DMP for strategy + campaign planning, ContentForge for the long-form articles a campaign produces, SocialForge for the social assets a campaign produces. All three share the same brand-state directory (~/.claude-marketing/<brand>/) so a brand profile created in DMP is immediately picked up by CF and SF.
| If you're a... | Why this matters |
|---|---|
| 🏢 Marketing agency (50–200 brands) | One toolchain across every client, audit-trail compliance, new-hire onboarding from 6 weeks → 6 hours, Cowork team persistence so your senior strategists work in browser-based Cowork while your team Drive has every artifact. |
| 👔 In-house marketing team | Single canonical strategy document underwriting every campaign + content piece. No more "the deck and the blog post say different things." |
| 🚀 Marketing automation builder (n8n / Zapier / Make / Pipedream) | DMP's connector-resolver + executor pattern. 8 verified HTTP connectors execute end-to-end; 25 more return manifest-ready specs for OAuth-mediated platforms. |
| 💼 Solo consultant / freelance marketer | Per-engagement billing model: 50–60 canonical files for $15–40 of API spend in ~60 minutes. Installs on Codex / Cursor / Copilot CLI / Antigravity for terminal-native or IDE-native workflows. |
| 📈 Growth team / product marketer | Funnel architecture, attribution, MMM, incrementality testing, retention, churn — all anchored to the strategy document. |
| 🛡 Compliance-led marketer (EU · UK · India · Brazil · California) | EU AI Act Article 50, C2PA content provenance, deepfake disclosure, GDPR + CCPA + DPDPA + LGPD + 12 more jurisdictions baked into every output. |
CF v3.15.0 → v3.15.1 + SF v1.12.0 → v1.12.1. DMP unchanged at v3.13.1. Mirrors DMP's v3.13.1 test-infra polish into the other two plugins.
tests/test_release_consistency.py, +30 tests; CF total 23 → 53)skills/ directory contents16 skills (was a generic feature list) — better marketplace search relevance + the new test enforces the count going forward#current-release-v182 re-pointed at the live Current Release sectionCF v3.14.0 → v3.15.0 + SF v1.11.0 → v1.12.0. DMP unchanged at v3.13.1. Brings ContentForge + SocialForge into native Hermes Agent + native OpenClaw parity with DMP. Now all 3 plugins ship plugin.yaml + __init__.py (Hermes adapter) + openclaw.plugin.json at their repo root, plus a stdlib-unittest suite.
DMP v3.13.0 → v3.13.1. CF + SF unchanged. Test suite expanded 70 → 114 with cross-manifest drift detection. New tests/test_release_consistency.py (25 tests) catches version drift, README badge staleness, CHANGELOG out-of-sync, install commands going missing, critical sections going missing, broken anchor links. New tests/test_hermes_edge_cases.py (10 tests) for adapter resilience. New README sections: "Get started in 5 minutes (non-developer path)" + "Troubleshooting" covering all 8 native platforms.
DMP v3.12.1 → v3.13.0. CF + SF unchanged. Native Hermes Agent plugin (plugin.yaml + Python adapter at repo root walking skills/ and registering via ctx.register_skill()). Native OpenClaw manifest (openclaw.plugin.json with skills: ["./skills"]). 35 additional Agent Skills platforms documented (Goose, OpenHands, OpenCode, Junie, Gemini CLI, Roo Code, Kiro, Letta, Amp, and 26 more). Test count 49 → 70.
DMP v3.12.0 → v3.12.1. CF + SF unchanged. README "Who this is for" audience table (agencies / in-house / automation builders / consultants / growth / compliance). "How does this compare?" table vs Anthropic Marketing, Composio Marketing, claude-seo. "Real workflows you'd actually run" with 6 copy-paste examples. Recent-release callout at top. 2 new FAQ entries (Cowork persistence + model freshness). GitHub repo descriptions + topics refreshed across all 4 repos for SEO.
DMP v3.11.0 → v3.12.0. CF + SF unchanged. Research-grounded hardening pass after web research confirmed ${CLAUDE_PLUGIN_DATA} is NOT persistent across Anthropic Cowork sessions (GitHub issue #51398). DMP now ships a new /digital-marketing-pro:cowork-setup skill that routes brand state through a Google Drive MCP. Plus fallbackModel chain in settings.json.example, requiredMinimumVersion: 2.1.157 in plugin.json, model-registry freshness check in /doctor, 49-test stdlib suite.
DMP bumped 3.10.1 → 3.11.0. CF + SF unchanged. Three new SEO skills (keyword-cluster / backlink-gap / seo-drift) + pattern upgrades across 10 existing SEO skills (Confirm-Then-Dispatch dispatcher, numbered intermediate-file output, quality scorecards). See DMP CHANGELOG.md for the full entry.
Coordinated platform-refresh release: DMP v3.10.0 + SF v1.11.0. Every claim verified against primary sources before code changes.
/digital-marketing-pro:gsc-ai-performance skill for the Google Search Console AI Performance Report rolled out 3 June 2026, plus a new skills/context-engine/eu-code-of-practice.md reference doc for EU AI Act Article 50 transparency. Updates to aeo-geo, aeo-audit, c2pa-metadata, paid-advertising (Google Ads API v24 breaking changes), analytics-insights + attribution-report (GA4 AI Assistant channel group added 13 May 2026).c2pa.ai-disclosure assertion for Article 50 deployer compliance./plugin marketplace add indranilbanerjee/neels-pluginsIn Cowork: Settings → Plugins → Add Marketplace → paste indranilbanerjee/neels-plugins.
/plugin list neels-plugins/plugin install contentforge@neels-plugins(Replace contentforge with digital-marketing-pro or socialforge as desired.)
Third-party marketplaces have auto-update OFF by default in Claude Code. When we ship a new ContentForge / DM Pro / SocialForge release, you will not be notified — you will keep running whatever version you installed first.
To get future updates automatically: open /plugin, go to the Marketplaces tab, find neels-plugins, and toggle Enable auto-update. After an auto-update fires you will be prompted to run /reload-plugins to pick up changes mid-session (no full Claude Code restart needed; conversation context preserved).
To update manually instead, see the Updating section below.
| Plugin | Version | What it does |
|---|---|---|
| [digital-marketing-pro](https://github.com/indranilbanerjee/digital-marketing-pro) | 3.8.0 | The most comprehensive open-source AI marketing plugin — 153 skills, 25 specialist agents, 12-Part Strategy Flow producing the Four Core Documents (61 explicit steps), Two-Views Model, Decision Matrix, Living Project Instruction File. Built for marketing agencies, in-house teams running 50–200 brands, and consultancies. EU AI Act Article 50 ready (C2PA content provenance signing). 6-platform AEO/GEO audit including Google AI Mode. 16 privacy-law jurisdictions. 14 HTTP MCP connectors, 77 Python scripts (optional), 167 reference knowledge files, 14 top-level slash commands. v3.7.11 closes the connector-resolver loop with a stdlib urllib HTTP executor that fires manifests against real APIs for 8 verified connectors. Test harnesses: 44/44 pass. v3.8.0 adds real native manifests for Codex / Antigravity / Cursor / Copilot CLI. |
| [contentforge](https://github.com/indranilbanerjee/contentforge) | 3.15.1 | Open-source enterprise content production pipeline — 21 skills, 13 specialist agents, 11 quality gates, 29-pattern AI-detection humanizer, fact-checker subagent, three-category internal linking (topical / commercial / authority), real .docx output with embedded SEO + Quality + Production + Internal-Link appendices. EU AI Act Article 50 ready via --c2pa-sign on scripts/generate-docx.py. 16 opt-in HTTP MCP connectors catalogued in .mcp.json.connectors-reference. v3.15.x ships real native manifests for Codex / Antigravity / Cursor / Copilot CLI / Hermes Agent / OpenClaw — installs on all 8 native platforms + 35+ Agent Skills clients. 53 tests passing (release-consistency suite added in v3.15.1). |
| [socialforge](https://github.com/indranilbanerjee/socialforge) | 1.12.1 | Open-source agency-grade social media production engine — calendar parsing, asset-first compositing, AI image generation (Vertex AI Nano Banana Pro), AI video generation (WaveSpeed Kling v3.0 Pro), multi-platform copy adaptation (Instagram, TikTok, LinkedIn, Threads, X, Facebook, YouTube Shorts), human-in-the-loop review galleries, C2PA signing for EU AI Act Article 50 compliance. 16 skills, 25 commands, 5 agents, 22 scripts, 10 HTTP MCP connectors (all Cowork-compatible), 0 global hooks. Four creative modes (ANCHOR_COMPOSE / ENHANCE_EXTEND / STYLE_REFERENCED / PURE_CREATIVE). v1.12.x ships real native manifests for Codex / Antigravity / Cursor / Copilot CLI / Hermes Agent / OpenClaw — installs on all 8 native platforms + 35+ Agent Skills clients. 54 tests passing (release-consistency suite added in v1.12.1). |
v3.7.0 (2026-05-27): real native manifests for 5 surfaces. Ships verified-real manifests for OpenAI Codex (.codex-plugin/plugin.jsonper the published OpenAI schema), Google Antigravity 2.0 (gemini-extension.jsonat repo root per Google'sgemini-cli-extensions/data-agent-kit-starter-packreference pattern), Cursor 2.5+ (.cursor-plugin/plugin.jsonper the verified Cursor JSON Schema), and GitHub Copilot CLI (.github/plugin/plugin.jsonper the verified GitHub schema). All three plugins ship matching native manifests in their own repos at the same version bump (DMP 3.8.0 / CF 3.13.0 / SF 1.9.0). Replaces the v3.5-v3.6 era invented manifests that were correctly removed in marketplace v3.6.0 on 2026-05-26. Pre-flight verified: all 190 skills across the 3 plugins pass the Codex[a-z0-9-]regex.
# Claude Code (CLI + IDE extensions)
/plugin marketplace add indranilbanerjee/neels-plugins
/plugin install <plugin-name>@neels-plugins
# Anthropic Cowork — UI only (no /plugin slash commands)
# Plugins panel → Add marketplace → paste indranilbanerjee/neels-plugins → Install
# OpenAI Codex (CLI + IDE + App)
codex plugin marketplace add indranilbanerjee/neels-plugins
codex plugin install <plugin-name>@neels-plugins
# Cursor 2.5+ (in any Agent chat — no marketplace add needed)
/add-plugin digital-marketing-pro@https://github.com/indranilbanerjee/digital-marketing-pro
/add-plugin contentforge@https://github.com/indranilbanerjee/contentforge
/add-plugin socialforge@https://github.com/indranilbanerjee/socialforge
# GitHub Copilot CLI
copilot plugin marketplace add indranilbanerjee/neels-plugins
copilot plugin install <plugin-name>@neels-plugins
# Google Antigravity 2.0 CLI (no marketplace concept — install per-plugin URL)
agy plugin install https://github.com/indranilbanerjee/digital-marketing-pro
agy plugin install https://github.com/indranilbanerjee/contentforge
agy plugin install https://github.com/indranilbanerjee/socialforge| Feature | Claude Code CLI | Anthropic Cowork |
|---|---|---|
| All 3 plugins install | ✓ | ✓ |
| Skills, agents, custom commands | ✓ | ✓ |
Persistent data via ${CLAUDE_PLUGIN_DATA} | ✓ | ✓ |
| Python scripts via Bash | ✓ | ✓ |
| HTTP MCP connectors (Notion, Canva, Webflow, Slack, Gmail, GCal, Figma, fal-ai, Replicate, Pipedream, Composio, Zapier, Make) | ✓ | ✓ |
stdio/npx MCP servers (in .mcp.json.example files) | ✓ | ✗ — use HTTP aggregators instead |
ContentForge v3.9.1's connectors reference catalog includes Pipedream, Composio, Zapier, and Make.com aggregator MCPs that cover Google Sheets/Drive and 1000+ other SaaS services — these are the recommended path for Cowork users.
All three plugins are designed to comply with the Anthropic Software Directory Policy:
All three plugins ship the same model-selection infrastructure under scripts/:
replacement_id for deprecated entries.latest-balanced-anthropic, latest-image-google, latest-video-wavespeed resolve to concrete ids at call time; deprecated ids passed via --model auto-fall-forward to their replacement with a stderr warning.Why it matters: frontier models change every ~6 weeks. Hardcoding claude-sonnet-4-5-20250929 or veo-2.0-generate-001 across dozens of scripts means a provider deprecation silently 404s. The curator prevents that. Each plugin documents the alias map at docs/MODEL-CURATOR.md.
.claude-plugin/plugin.json manifest (include $schema, name, version, description, author, homepage, repository, license, keywords)..claude-plugin/marketplace.json in this repo with the source: { source: "github", repo: "owner/repo" } format.metadata.version (semver: minor bump for a new plugin or feature release in an existing plugin; patch for hotfixes).neels-plugins/
├── .claude-plugin/
│ └── marketplace.json ← Plugin catalog (3 plugins)
├── CHANGELOG.md ← Release history
├── LICENSE ← MIT
└── README.md ← This fileAll three plugins follow a strict "no global side-effects" pattern as of May 2026:
hooks/hooks.json ships as {"hooks":{}}. Plugin hooks fire globally on every Claude Code operation regardless of working directory, so embedding compliance/verification logic in hooks pollutes unrelated work. The work lives instead in agent files (where it runs in proper context) and Quality Gate criteria..mcp.json ships as {"mcpServers":{}}. Plugin-bundled MCP servers auto-connect on plugin enable, which means shipping N servers triggers N connection attempts (and likely auth prompts) for users who only want some of them. Each plugin ships its full connector catalog as a .mcp.json.connectors-reference file with per-entry auth notes; users opt in via the plugin's connect skill.If you contribute a plugin to this marketplace, please follow the same pattern.
If you see "/plugin isn't available in this environment" — you're in the standard Claude chat app (browser OR installed desktop app). The/pluginslash command is only supported in two environments: Claude Code (the developer CLI / IDE at claude.com/code,npm install -g @anthropic-ai/claude-code) and Anthropic Cowork. Everywhere else —claude.aiweb chat, the Claude Desktop app, mobile — plugins are managed through the UI, not slash commands.
>
Plugins from this marketplace still install and run in those environments (skills auto-discover and work normally); only the /plugin management command is unavailable.>
Fix: 1. In the chat UI — click the Plugins button at the bottom of the chat → Manage plugins → find the plugin → look for Update / Refresh / Remove. If there's no Update button, Remove then Add plugin → re-install from indranilbanerjee/neels-plugins. The re-pull fetches the latest version. 2. For slash-command management — switch to Claude Code (CLI or IDE) or Cowork. All three plugins run identically across every Anthropic surface; you're choosing where to type management commands.>
The rest of this section assumes you're in Claude Code or Cowork.
There are two paths depending on whether you turned on auto-update during Quick Start step 4.
Claude Code refreshes the marketplace at startup and pulls the latest version automatically. After it fires, run /reload-plugins when prompted to pick up the new version mid-session.
/plugin marketplace update neels-plugins
/plugin uninstall <plugin-name>@neels-plugins
/plugin install <plugin-name>@neels-plugins
/reload-plugins/plugin marketplace update only refreshes the catalog — it does not bump installed plugin versions. The uninstall + reinstall is what actually pulls the new version.
Happens during fast-iteration debugging:
rm -rf ~/.claude/plugins/cache/neels-plugins
/plugin install <plugin-name>@neels-plugins
/reload-pluginsThere is currently no in-product update notification for third-party marketplaces — no banner, no badge. Either:
CHANGELOG.md in the individual plugin repos/plugin marketplace update neels-plugins periodicallyMIT © Indranil Banerjee. See LICENSE.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.