plugin-gardener — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited plugin-gardener (Plugin) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A public Claude Code plugin marketplace — installable skills and agents for AI coding agents.
Add the marketplace, then install a plugin:
/plugin marketplace add theagenticguy/agentic-plugins
/plugin install agentic-skills@agentic-plugins
/plugin install plugin-gardener@agentic-pluginsFlagship skills for AI coding agents.
| Skill | What it does |
|---|---|
workbench-builder | Builds disposable localhost workbenches — Flask + sqlite3 + htmx + Server-Sent Events apps that give an agentic coding/eval/PR/data session a live UI with no build step, no npm install, and no deploy. The signature move is a two-way human↔agent loop over one SQLite file: the human acts in the browser (htmx POST → SQLite → fragment + SSE invalidation), the agent acts from the terminal (httpx → SQLite → SSE), both seeing the same state update live with no reload. Ships recipes for eval viewers, PR review rooms, document-redline surfaces, trace replays, and refactor cockpits. |
Bundled MCP servers (plugins/agentic-skills/.mcp.json) — research and documentation tools that back the skills. Each reads its key from an environment variable; the marketplace entry is strict: false, so a missing key never blocks install — the server is simply skipped.
| Server | Purpose | Env var |
|---|---|---|
| context7 | Up-to-date library/API docs | CONTEXT7_API_KEY |
| deepwiki | GitHub repo Q&A | (none) |
| brave-search | Web search | BRAVE_API_KEY |
| tavily | Web search + extraction | TAVILY_API_KEY |
| exa | Neural web search | EXA_API_KEY |
| you | You.com search + research | YDC_API_KEY |
| awsknowledge | AWS documentation | (none) |
Catalog hygiene for Claude Code skill/agent plugins. Runs audits — inventory, per-skill scoring, embedding-based collision detection, and HDBSCAN taxonomy checks — and proposes PR-style resolutions without auto-applying.
.claude-plugin/marketplace.json # marketplace registry — lists every plugin
plugins/
agentic-skills/ # flagship plugin
.claude-plugin/plugin.json
.mcp.json # bundled MCP servers
skills/
plugin-gardener/ # catalog-hygiene plugin
.claude-plugin/plugin.json
skills/ references/ scripts/
tools/ # repo-wide validators and scaffoldingmise install # node, markdownlint-cli2, dprint
mise run fmt # format all markdown and JSON
mise run fmt:check # check formatting (CI-friendly)
mise run lint # lint all markdown
mise run lint:md:fix # lint with auto-fix
mise run validate # frontmatter + size + refs + freshness + versions
mise run build # full gate: lint + fmt:check + validate
mise run bump -- <plugin> patch # bump one plugin's version
mise run init:skill -- <plugin> <name> 'Description. Use when...' # scaffold a skillCI runs mise run build on every push and pull request.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.