Repository files navigation

Agent Plugins Marketplace

Find open-source plugins for Codex, Claude Code, and Agent Plugins.

Search public plugins, compare their supported formats, skills, and MCP servers, and review the source before installing.

Browse the directory · API & MCP docs · OpenAPI 3.1 · Full agent-readable catalog

Sync GitHub pluginsLiveLicense: MIT

Agent Plugins Marketplace preview

What is this?

Agent Plugins Marketplace is a community index of open-source packages that follow one or more canonical plugin formats. It discovers repositories on GitHub, validates their manifests, merges cross-format variants into one entry, and exposes the result through a website, REST API, MCP server, and LLM-friendly text feeds.

It is an index, not a package host. Plugin code stays in its source repository, and the directory does not execute third-party plugins during indexing.

One index, five surfaces

SurfaceBest forURL
Web appBrowse, search, filter, and inspect pluginspluginsmp.com
REST APIApplications, scripts, and integrations/api/v1/*
MCPNative search from an agent sessionPOST /api/mcp
llms.txtA concise guide for agents/llms.txt
llms-full.txtRetrieval over the complete catalog/llms-full.txt

All five surfaces read from the same validated snapshot.

Try it

Search from a browser:

https://pluginsmp.com/plugins?q=github

Open any compatible listing and copy its Codex or Claude Code install command block. It adds and refreshes this repository as the agent-plugin-marketplace catalog, then installs the selected source plugin for the current user. The generated catalogs are refreshed alongside the SQLite snapshot.

Search from code:

curl "https://pluginsmp.com/api/v1/plugins?q=github&protocol=codex&protocol=claude-code&sort=stars&per_page=10"

Connect an MCP client:

{
"mcpServers": {
"agent-plugin-marketplace": {
"type": "streamable-http",
"url": "https://pluginsmp.com/api/mcp"
}
}
}

The MCP server is stateless and exposes three tools:

  • search_plugins — search and filter the index
  • get_plugin — retrieve a plugin, its manifests, skills, and MCP servers
  • get_stats — retrieve current directory totals

Plugin format compatibility

ClientPlugin manifestCatalog file
Codex.codex-plugin/plugin.json.agents/plugins/marketplace.json
Claude Code.claude-plugin/plugin.json.claude-plugin/marketplace.json
Agent Plugins v1plugin.json

A repository may support one plugin format or several. When Codex and Claude Code manifests describe the same plugin root, the index stores one logical plugin with multiple protocols instead of duplicate listings.

Shared components are discovered from skills/<name>/SKILL.md. MCP configuration is read from canonical or manifest-referenced configuration files and normalized to stdio, streamable-http, or sse for filtering.

How automatic discovery works

The index is refreshed by GitHub Actions every day at 00:17 and 12:17 UTC. It can also be started manually.

flowchart LR
A["GitHub repository search"] --> B["Inspect candidate Git trees"]
B --> C["Load canonical manifests"]
C --> D["Validate skills and MCP config"]
D --> E["Merge runtimes and upsert plugins"]
E --> F["Validate SQLite snapshot"]
F --> G["Commit snapshot to main"]
G --> H["Vercel production deploy"]
H --> I["Web · REST · MCP · llms.txt"]
Loading

Discovery combines repository metadata, topics, README signals, Git-tree inspection, and — when a dedicated token is configured — GitHub's legacy Code Search. It searches for all three supported manifest families instead of relying on a hand-maintained allowlist, so first-party and community repositories follow the same path.

Each sync:

  1. Discovers candidate repositories across the supported protocols.
  2. Inspects their trees for canonical manifests, including monorepos with multiple plugin roots.
  3. Validates manifest fields, skills, and MCP server declarations.
  4. Merges sibling runtime manifests and updates repository metadata and star counts.
  5. Runs database integrity checks, protocol tests, and linting.
  6. Commits a changed snapshot to main; Vercel deploys that snapshot automatically.

Unchanged repositories reuse their indexed components based on GitHub's pushed_at value. Sync is deliberately upsert-only: a plugin is not deleted merely because a bounded search fails to return it on a later run.

Coverage boundaries

GitHub search is broad but not mathematically exhaustive. Individual search queries are capped at 1,000 results, API quotas apply, repositories can be private or temporarily unavailable, and some projects do not publish a canonical manifest. The workflow uses multiple protocol-specific windows and safely commits completed transactions when a run becomes quota-limited, but it does not claim to enumerate every repository on GitHub.

REST API

The API is read-only, requires no authentication, and allows cross-origin requests.

EndpointDescription
GET /api/v1/pluginsSearch and paginate plugins
GET /api/v1/plugins/:slugRetrieve one plugin with manifests and components
GET /api/v1/statsRetrieve live directory totals
GET /api/v1/categoriesList manifest-keyword tags with counts

Useful list parameters include q, category, type, transport, sort, page, and per_page. Repeat protocol to match any selected plugin format:

/api/v1/plugins?protocol=codex&protocol=claude-code&type=mcp&sort=stars

See the interactive documentation for response shapes and examples, or consume the OpenAPI schema.

Run locally

Requirements: Node.js 20.9+ and npm. The synchronization workflow currently runs on Node.js 24.

git clone https://github.com/IchenDEV/agent-plugin-mkt.git
cd agent-plugin-mkt
npm ci
cp .env.example .env
npx prisma db push
npm run db:seed
npm run dev

Open http://localhost:3000.

The default development database is SQLite at prisma/dev.db. Fonts are self-hosted through @fontsource, so the application does not fetch web fonts at build or runtime.

Index public GitHub repositories

Authenticate with GitHub, then run the indexer:

GITHUB_TOKEN="$(gh auth token)" npm run index:github -- --max 40

Useful options:

OptionPurpose
--repository-max <n>Limit repository candidates
--skip-code-searchUse repository discovery and Git-tree validation only
--allow-partialKeep completed transactions if an API quota is exhausted

The indexer only talks to api.github.com, caps fetched file sizes, respects rate limits, and is idempotent.

To clear the local database before loading fixtures, run npm run db:seed -- --reset.

Development commands

CommandPurpose
npm run devStart the Next.js development server
npm run buildCreate a production build
npm testRun protocol and validation tests
npm run lintRun ESLint
npm run db:pushApply the Prisma schema
npm run db:seedLoad fixture plugins
npm run db:validateCheck SQLite integrity and report totals
npm run index:githubDiscover and refresh public plugins
npm run marketplace:generateRegenerate Codex and Claude Code install catalogs
npm run marketplace:checkVerify generated install catalogs match the snapshot
npm run test:mcpRun the MCP protocol suite against a running server

For MCP end-to-end tests:

npm run dev
BASE_URL=http://localhost:3000 npm run test:mcp

Validation and trust model

Everything fetched from a plugin repository is treated as untrusted data.

  • Manifests are parsed and validated according to their plugin format's rules.
  • Invalid individual skills or MCP servers are isolated where the protocol permits it.
  • Indexed descriptions and metadata are rendered as plain text.
  • Only http: and https: URLs are linkified.
  • Clipboard text is stripped of control characters.
  • The directory links back to the source repository so users can inspect code and licensing before installation.

An index entry is evidence that a repository published a structurally valid manifest; it is not a security audit or endorsement of that plugin.

Repository layout

app/ Next.js pages, REST routes, MCP, and text feeds
components/ Shared server and client UI components
lib/ Queries, validation, GitHub discovery, and MCP logic
prisma/ Schema and deployable directory snapshot
scripts/ Indexing, seeding, validation, and MCP test tools
tests/ Protocol validation tests
fixtures/ Fictional local development plugins
.github/workflows/ Twice-daily synchronization

The visual language and component rules live in DESIGN.md.

Contributing

Bug reports, discovery gaps, protocol compatibility fixes, and focused pull requests are welcome. Before opening a change:

npm ci
npm test
npm run lint
npm run build

If a public plugin is missing, first confirm that its repository contains a canonical manifest listed under Plugin format compatibility. Include the repository URL and manifest path in the issue so the discovery gap can be reproduced.

License

Released under the MIT License. Indexed plugins retain their own licenses and remain the responsibility of their respective authors.

About

Open-source marketplace for discovering Codex, Claude Code, and Agent Plugins—with web, REST API, MCP, and agent-readable catalogs.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

Agent Plugins Marketplace

Find open-source plugins for Codex, Claude Code, and Agent Plugins.

Search public plugins, compare their supported formats, skills, and MCP servers, and review the source before installing.

Browse the directory · API & MCP docs · OpenAPI 3.1 · Full agent-readable catalog

Sync GitHub pluginsLiveLicense: MIT

Agent Plugins Marketplace preview

What is this?

Agent Plugins Marketplace is a community index of open-source packages that follow one or more canonical plugin formats. It discovers repositories on GitHub, validates their manifests, merges cross-format variants into one entry, and exposes the result through a website, REST API, MCP server, and LLM-friendly text feeds.

It is an index, not a package host. Plugin code stays in its source repository, and the directory does not execute third-party plugins during indexing.

One index, five surfaces

SurfaceBest forURL
Web appBrowse, search, filter, and inspect pluginspluginsmp.com
REST APIApplications, scripts, and integrations/api/v1/*
MCPNative search from an agent sessionPOST /api/mcp
llms.txtA concise guide for agents/llms.txt
llms-full.txtRetrieval over the complete catalog/llms-full.txt

All five surfaces read from the same validated snapshot.

Try it

Search from a browser:

https://pluginsmp.com/plugins?q=github

Open any compatible listing and copy its Codex or Claude Code install command block. It adds and refreshes this repository as the agent-plugin-marketplace catalog, then installs the selected source plugin for the current user. The generated catalogs are refreshed alongside the SQLite snapshot.

Search from code:

curl "https://pluginsmp.com/api/v1/plugins?q=github&protocol=codex&protocol=claude-code&sort=stars&per_page=10"

Connect an MCP client:

{
"mcpServers": {
"agent-plugin-marketplace": {
"type": "streamable-http",
"url": "https://pluginsmp.com/api/mcp"
}
}
}

The MCP server is stateless and exposes three tools:

  • search_plugins — search and filter the index
  • get_plugin — retrieve a plugin, its manifests, skills, and MCP servers
  • get_stats — retrieve current directory totals

Plugin format compatibility

ClientPlugin manifestCatalog file
Codex.codex-plugin/plugin.json.agents/plugins/marketplace.json
Claude Code.claude-plugin/plugin.json.claude-plugin/marketplace.json
Agent Plugins v1plugin.json

A repository may support one plugin format or several. When Codex and Claude Code manifests describe the same plugin root, the index stores one logical plugin with multiple protocols instead of duplicate listings.

Shared components are discovered from skills/<name>/SKILL.md. MCP configuration is read from canonical or manifest-referenced configuration files and normalized to stdio, streamable-http, or sse for filtering.

How automatic discovery works

The index is refreshed by GitHub Actions every day at 00:17 and 12:17 UTC. It can also be started manually.

flowchart LR
A["GitHub repository search"] --> B["Inspect candidate Git trees"]
B --> C["Load canonical manifests"]
C --> D["Validate skills and MCP config"]
D --> E["Merge runtimes and upsert plugins"]
E --> F["Validate SQLite snapshot"]
F --> G["Commit snapshot to main"]
G --> H["Vercel production deploy"]
H --> I["Web · REST · MCP · llms.txt"]
Loading

Discovery combines repository metadata, topics, README signals, Git-tree inspection, and — when a dedicated token is configured — GitHub's legacy Code Search. It searches for all three supported manifest families instead of relying on a hand-maintained allowlist, so first-party and community repositories follow the same path.

Each sync:

  1. Discovers candidate repositories across the supported protocols.
  2. Inspects their trees for canonical manifests, including monorepos with multiple plugin roots.
  3. Validates manifest fields, skills, and MCP server declarations.
  4. Merges sibling runtime manifests and updates repository metadata and star counts.
  5. Runs database integrity checks, protocol tests, and linting.
  6. Commits a changed snapshot to main; Vercel deploys that snapshot automatically.

Unchanged repositories reuse their indexed components based on GitHub's pushed_at value. Sync is deliberately upsert-only: a plugin is not deleted merely because a bounded search fails to return it on a later run.

Coverage boundaries

GitHub search is broad but not mathematically exhaustive. Individual search queries are capped at 1,000 results, API quotas apply, repositories can be private or temporarily unavailable, and some projects do not publish a canonical manifest. The workflow uses multiple protocol-specific windows and safely commits completed transactions when a run becomes quota-limited, but it does not claim to enumerate every repository on GitHub.

REST API

The API is read-only, requires no authentication, and allows cross-origin requests.

EndpointDescription
GET /api/v1/pluginsSearch and paginate plugins
GET /api/v1/plugins/:slugRetrieve one plugin with manifests and components
GET /api/v1/statsRetrieve live directory totals
GET /api/v1/categoriesList manifest-keyword tags with counts

Useful list parameters include q, category, type, transport, sort, page, and per_page. Repeat protocol to match any selected plugin format:

/api/v1/plugins?protocol=codex&protocol=claude-code&type=mcp&sort=stars

See the interactive documentation for response shapes and examples, or consume the OpenAPI schema.

Run locally

Requirements: Node.js 20.9+ and npm. The synchronization workflow currently runs on Node.js 24.

git clone https://github.com/IchenDEV/agent-plugin-mkt.git
cd agent-plugin-mkt
npm ci
cp .env.example .env
npx prisma db push
npm run db:seed
npm run dev

Open http://localhost:3000.

The default development database is SQLite at prisma/dev.db. Fonts are self-hosted through @fontsource, so the application does not fetch web fonts at build or runtime.

Index public GitHub repositories

Authenticate with GitHub, then run the indexer:

GITHUB_TOKEN="$(gh auth token)" npm run index:github -- --max 40

Useful options:

OptionPurpose
--repository-max <n>Limit repository candidates
--skip-code-searchUse repository discovery and Git-tree validation only
--allow-partialKeep completed transactions if an API quota is exhausted

The indexer only talks to api.github.com, caps fetched file sizes, respects rate limits, and is idempotent.

To clear the local database before loading fixtures, run npm run db:seed -- --reset.

Development commands

CommandPurpose
npm run devStart the Next.js development server
npm run buildCreate a production build
npm testRun protocol and validation tests
npm run lintRun ESLint
npm run db:pushApply the Prisma schema
npm run db:seedLoad fixture plugins
npm run db:validateCheck SQLite integrity and report totals
npm run index:githubDiscover and refresh public plugins
npm run marketplace:generateRegenerate Codex and Claude Code install catalogs
npm run marketplace:checkVerify generated install catalogs match the snapshot
npm run test:mcpRun the MCP protocol suite against a running server

For MCP end-to-end tests:

npm run dev
BASE_URL=http://localhost:3000 npm run test:mcp

Validation and trust model

Everything fetched from a plugin repository is treated as untrusted data.

  • Manifests are parsed and validated according to their plugin format's rules.
  • Invalid individual skills or MCP servers are isolated where the protocol permits it.
  • Indexed descriptions and metadata are rendered as plain text.
  • Only http: and https: URLs are linkified.
  • Clipboard text is stripped of control characters.
  • The directory links back to the source repository so users can inspect code and licensing before installation.

An index entry is evidence that a repository published a structurally valid manifest; it is not a security audit or endorsement of that plugin.

Repository layout

app/ Next.js pages, REST routes, MCP, and text feeds
components/ Shared server and client UI components
lib/ Queries, validation, GitHub discovery, and MCP logic
prisma/ Schema and deployable directory snapshot
scripts/ Indexing, seeding, validation, and MCP test tools
tests/ Protocol validation tests
fixtures/ Fictional local development plugins
.github/workflows/ Twice-daily synchronization

The visual language and component rules live in DESIGN.md.

Contributing

Bug reports, discovery gaps, protocol compatibility fixes, and focused pull requests are welcome. Before opening a change:

npm ci
npm test
npm run lint
npm run build

If a public plugin is missing, first confirm that its repository contains a canonical manifest listed under Plugin format compatibility. Include the repository URL and manifest path in the issue so the discovery gap can be reproduced.

License

Released under the MIT License. Indexed plugins retain their own licenses and remain the responsibility of their respective authors.

About

Open-source marketplace for discovering Codex, Claude Code, and Agent Plugins—with web, REST API, MCP, and agent-readable catalogs.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Agent Plugins Marketplace

Find open-source plugins for Codex, Claude Code, and Agent Plugins.

Search public plugins, compare their supported formats, skills, and MCP servers, and review the source before installing.

Browse the directory · API & MCP docs · OpenAPI 3.1 · Full agent-readable catalog

Sync GitHub pluginsLiveLicense: MIT

Agent Plugins Marketplace preview

What is this?

Agent Plugins Marketplace is a community index of open-source packages that follow one or more canonical plugin formats. It discovers repositories on GitHub, validates their manifests, merges cross-format variants into one entry, and exposes the result through a website, REST API, MCP server, and LLM-friendly text feeds.

It is an index, not a package host. Plugin code stays in its source repository, and the directory does not execute third-party plugins during indexing.

One index, five surfaces

SurfaceBest forURL
Web appBrowse, search, filter, and inspect pluginspluginsmp.com
REST APIApplications, scripts, and integrations/api/v1/*
MCPNative search from an agent sessionPOST /api/mcp
llms.txtA concise guide for agents/llms.txt
llms-full.txtRetrieval over the complete catalog/llms-full.txt

All five surfaces read from the same validated snapshot.

Try it

Search from a browser:

https://pluginsmp.com/plugins?q=github

Open any compatible listing and copy its Codex or Claude Code install command block. It adds and refreshes this repository as the agent-plugin-marketplace catalog, then installs the selected source plugin for the current user. The generated catalogs are refreshed alongside the SQLite snapshot.

Search from code:

curl "https://pluginsmp.com/api/v1/plugins?q=github&protocol=codex&protocol=claude-code&sort=stars&per_page=10"

Connect an MCP client:

{
"mcpServers": {
"agent-plugin-marketplace": {
"type": "streamable-http",
"url": "https://pluginsmp.com/api/mcp"
}
}
}

The MCP server is stateless and exposes three tools:

  • search_plugins — search and filter the index
  • get_plugin — retrieve a plugin, its manifests, skills, and MCP servers
  • get_stats — retrieve current directory totals

Plugin format compatibility

ClientPlugin manifestCatalog file
Codex.codex-plugin/plugin.json.agents/plugins/marketplace.json
Claude Code.claude-plugin/plugin.json.claude-plugin/marketplace.json
Agent Plugins v1plugin.json

A repository may support one plugin format or several. When Codex and Claude Code manifests describe the same plugin root, the index stores one logical plugin with multiple protocols instead of duplicate listings.

Shared components are discovered from skills/<name>/SKILL.md. MCP configuration is read from canonical or manifest-referenced configuration files and normalized to stdio, streamable-http, or sse for filtering.

How automatic discovery works

The index is refreshed by GitHub Actions every day at 00:17 and 12:17 UTC. It can also be started manually.

flowchart LR
A["GitHub repository search"] --> B["Inspect candidate Git trees"]
B --> C["Load canonical manifests"]
C --> D["Validate skills and MCP config"]
D --> E["Merge runtimes and upsert plugins"]
E --> F["Validate SQLite snapshot"]
F --> G["Commit snapshot to main"]
G --> H["Vercel production deploy"]
H --> I["Web · REST · MCP · llms.txt"]
Loading

Discovery combines repository metadata, topics, README signals, Git-tree inspection, and — when a dedicated token is configured — GitHub's legacy Code Search. It searches for all three supported manifest families instead of relying on a hand-maintained allowlist, so first-party and community repositories follow the same path.

Each sync:

  1. Discovers candidate repositories across the supported protocols.
  2. Inspects their trees for canonical manifests, including monorepos with multiple plugin roots.
  3. Validates manifest fields, skills, and MCP server declarations.
  4. Merges sibling runtime manifests and updates repository metadata and star counts.
  5. Runs database integrity checks, protocol tests, and linting.
  6. Commits a changed snapshot to main; Vercel deploys that snapshot automatically.

Unchanged repositories reuse their indexed components based on GitHub's pushed_at value. Sync is deliberately upsert-only: a plugin is not deleted merely because a bounded search fails to return it on a later run.

Coverage boundaries

GitHub search is broad but not mathematically exhaustive. Individual search queries are capped at 1,000 results, API quotas apply, repositories can be private or temporarily unavailable, and some projects do not publish a canonical manifest. The workflow uses multiple protocol-specific windows and safely commits completed transactions when a run becomes quota-limited, but it does not claim to enumerate every repository on GitHub.

REST API

The API is read-only, requires no authentication, and allows cross-origin requests.

EndpointDescription
GET /api/v1/pluginsSearch and paginate plugins
GET /api/v1/plugins/:slugRetrieve one plugin with manifests and components
GET /api/v1/statsRetrieve live directory totals
GET /api/v1/categoriesList manifest-keyword tags with counts

Useful list parameters include q, category, type, transport, sort, page, and per_page. Repeat protocol to match any selected plugin format:

/api/v1/plugins?protocol=codex&protocol=claude-code&type=mcp&sort=stars

See the interactive documentation for response shapes and examples, or consume the OpenAPI schema.

Run locally

Requirements: Node.js 20.9+ and npm. The synchronization workflow currently runs on Node.js 24.

git clone https://github.com/IchenDEV/agent-plugin-mkt.git
cd agent-plugin-mkt
npm ci
cp .env.example .env
npx prisma db push
npm run db:seed
npm run dev

Open http://localhost:3000.

The default development database is SQLite at prisma/dev.db. Fonts are self-hosted through @fontsource, so the application does not fetch web fonts at build or runtime.

Index public GitHub repositories

Authenticate with GitHub, then run the indexer:

GITHUB_TOKEN="$(gh auth token)" npm run index:github -- --max 40

Useful options:

OptionPurpose
--repository-max <n>Limit repository candidates
--skip-code-searchUse repository discovery and Git-tree validation only
--allow-partialKeep completed transactions if an API quota is exhausted

The indexer only talks to api.github.com, caps fetched file sizes, respects rate limits, and is idempotent.

To clear the local database before loading fixtures, run npm run db:seed -- --reset.

Development commands

CommandPurpose
npm run devStart the Next.js development server
npm run buildCreate a production build
npm testRun protocol and validation tests
npm run lintRun ESLint
npm run db:pushApply the Prisma schema
npm run db:seedLoad fixture plugins
npm run db:validateCheck SQLite integrity and report totals
npm run index:githubDiscover and refresh public plugins
npm run marketplace:generateRegenerate Codex and Claude Code install catalogs
npm run marketplace:checkVerify generated install catalogs match the snapshot
npm run test:mcpRun the MCP protocol suite against a running server

For MCP end-to-end tests:

npm run dev
BASE_URL=http://localhost:3000 npm run test:mcp

Validation and trust model

Everything fetched from a plugin repository is treated as untrusted data.

  • Manifests are parsed and validated according to their plugin format's rules.
  • Invalid individual skills or MCP servers are isolated where the protocol permits it.
  • Indexed descriptions and metadata are rendered as plain text.
  • Only http: and https: URLs are linkified.
  • Clipboard text is stripped of control characters.
  • The directory links back to the source repository so users can inspect code and licensing before installation.

An index entry is evidence that a repository published a structurally valid manifest; it is not a security audit or endorsement of that plugin.

Repository layout

app/ Next.js pages, REST routes, MCP, and text feeds
components/ Shared server and client UI components
lib/ Queries, validation, GitHub discovery, and MCP logic
prisma/ Schema and deployable directory snapshot
scripts/ Indexing, seeding, validation, and MCP test tools
tests/ Protocol validation tests
fixtures/ Fictional local development plugins
.github/workflows/ Twice-daily synchronization

The visual language and component rules live in DESIGN.md.

Contributing

Bug reports, discovery gaps, protocol compatibility fixes, and focused pull requests are welcome. Before opening a change:

npm ci
npm test
npm run lint
npm run build

If a public plugin is missing, first confirm that its repository contains a canonical manifest listed under Plugin format compatibility. Include the repository URL and manifest path in the issue so the discovery gap can be reproduced.

License

Released under the MIT License. Indexed plugins retain their own licenses and remain the responsibility of their respective authors.

About

Open-source marketplace for discovering Codex, Claude Code, and Agent Plugins—with web, REST API, MCP, and agent-readable catalogs.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Agent Plugins Marketplace

Find open-source plugins for Codex, Claude Code, and Agent Plugins.

Search public plugins, compare their supported formats, skills, and MCP servers, and review the source before installing.

Browse the directory · API & MCP docs · OpenAPI 3.1 · Full agent-readable catalog

Sync GitHub pluginsLiveLicense: MIT

Agent Plugins Marketplace preview

What is this?

Agent Plugins Marketplace is a community index of open-source packages that follow one or more canonical plugin formats. It discovers repositories on GitHub, validates their manifests, merges cross-format variants into one entry, and exposes the result through a website, REST API, MCP server, and LLM-friendly text feeds.

It is an index, not a package host. Plugin code stays in its source repository, and the directory does not execute third-party plugins during indexing.

One index, five surfaces

SurfaceBest forURL
Web appBrowse, search, filter, and inspect pluginspluginsmp.com
REST APIApplications, scripts, and integrations/api/v1/*
MCPNative search from an agent sessionPOST /api/mcp
llms.txtA concise guide for agents/llms.txt
llms-full.txtRetrieval over the complete catalog/llms-full.txt

All five surfaces read from the same validated snapshot.

Try it

Search from a browser:

https://pluginsmp.com/plugins?q=github

Open any compatible listing and copy its Codex or Claude Code install command block. It adds and refreshes this repository as the agent-plugin-marketplace catalog, then installs the selected source plugin for the current user. The generated catalogs are refreshed alongside the SQLite snapshot.

Search from code:

curl "https://pluginsmp.com/api/v1/plugins?q=github&protocol=codex&protocol=claude-code&sort=stars&per_page=10"

Connect an MCP client:

{
"mcpServers": {
"agent-plugin-marketplace": {
"type": "streamable-http",
"url": "https://pluginsmp.com/api/mcp"
}
}
}

The MCP server is stateless and exposes three tools:

  • search_plugins — search and filter the index
  • get_plugin — retrieve a plugin, its manifests, skills, and MCP servers
  • get_stats — retrieve current directory totals

Plugin format compatibility

ClientPlugin manifestCatalog file
Codex.codex-plugin/plugin.json.agents/plugins/marketplace.json
Claude Code.claude-plugin/plugin.json.claude-plugin/marketplace.json
Agent Plugins v1plugin.json

A repository may support one plugin format or several. When Codex and Claude Code manifests describe the same plugin root, the index stores one logical plugin with multiple protocols instead of duplicate listings.

Shared components are discovered from skills/<name>/SKILL.md. MCP configuration is read from canonical or manifest-referenced configuration files and normalized to stdio, streamable-http, or sse for filtering.

How automatic discovery works

The index is refreshed by GitHub Actions every day at 00:17 and 12:17 UTC. It can also be started manually.

flowchart LR
A["GitHub repository search"] --> B["Inspect candidate Git trees"]
B --> C["Load canonical manifests"]
C --> D["Validate skills and MCP config"]
D --> E["Merge runtimes and upsert plugins"]
E --> F["Validate SQLite snapshot"]
F --> G["Commit snapshot to main"]
G --> H["Vercel production deploy"]
H --> I["Web · REST · MCP · llms.txt"]
Loading

Discovery combines repository metadata, topics, README signals, Git-tree inspection, and — when a dedicated token is configured — GitHub's legacy Code Search. It searches for all three supported manifest families instead of relying on a hand-maintained allowlist, so first-party and community repositories follow the same path.

Each sync:

  1. Discovers candidate repositories across the supported protocols.
  2. Inspects their trees for canonical manifests, including monorepos with multiple plugin roots.
  3. Validates manifest fields, skills, and MCP server declarations.
  4. Merges sibling runtime manifests and updates repository metadata and star counts.
  5. Runs database integrity checks, protocol tests, and linting.
  6. Commits a changed snapshot to main; Vercel deploys that snapshot automatically.

Unchanged repositories reuse their indexed components based on GitHub's pushed_at value. Sync is deliberately upsert-only: a plugin is not deleted merely because a bounded search fails to return it on a later run.

Coverage boundaries

GitHub search is broad but not mathematically exhaustive. Individual search queries are capped at 1,000 results, API quotas apply, repositories can be private or temporarily unavailable, and some projects do not publish a canonical manifest. The workflow uses multiple protocol-specific windows and safely commits completed transactions when a run becomes quota-limited, but it does not claim to enumerate every repository on GitHub.

REST API

The API is read-only, requires no authentication, and allows cross-origin requests.

EndpointDescription
GET /api/v1/pluginsSearch and paginate plugins
GET /api/v1/plugins/:slugRetrieve one plugin with manifests and components
GET /api/v1/statsRetrieve live directory totals
GET /api/v1/categoriesList manifest-keyword tags with counts

Useful list parameters include q, category, type, transport, sort, page, and per_page. Repeat protocol to match any selected plugin format:

/api/v1/plugins?protocol=codex&protocol=claude-code&type=mcp&sort=stars

See the interactive documentation for response shapes and examples, or consume the OpenAPI schema.

Run locally

Requirements: Node.js 20.9+ and npm. The synchronization workflow currently runs on Node.js 24.

git clone https://github.com/IchenDEV/agent-plugin-mkt.git
cd agent-plugin-mkt
npm ci
cp .env.example .env
npx prisma db push
npm run db:seed
npm run dev

Open http://localhost:3000.

The default development database is SQLite at prisma/dev.db. Fonts are self-hosted through @fontsource, so the application does not fetch web fonts at build or runtime.

Index public GitHub repositories

Authenticate with GitHub, then run the indexer:

GITHUB_TOKEN="$(gh auth token)" npm run index:github -- --max 40

Useful options:

OptionPurpose
--repository-max <n>Limit repository candidates
--skip-code-searchUse repository discovery and Git-tree validation only
--allow-partialKeep completed transactions if an API quota is exhausted

The indexer only talks to api.github.com, caps fetched file sizes, respects rate limits, and is idempotent.

To clear the local database before loading fixtures, run npm run db:seed -- --reset.

Development commands

CommandPurpose
npm run devStart the Next.js development server
npm run buildCreate a production build
npm testRun protocol and validation tests
npm run lintRun ESLint
npm run db:pushApply the Prisma schema
npm run db:seedLoad fixture plugins
npm run db:validateCheck SQLite integrity and report totals
npm run index:githubDiscover and refresh public plugins
npm run marketplace:generateRegenerate Codex and Claude Code install catalogs
npm run marketplace:checkVerify generated install catalogs match the snapshot
npm run test:mcpRun the MCP protocol suite against a running server

For MCP end-to-end tests:

npm run dev
BASE_URL=http://localhost:3000 npm run test:mcp

Validation and trust model

Everything fetched from a plugin repository is treated as untrusted data.

  • Manifests are parsed and validated according to their plugin format's rules.
  • Invalid individual skills or MCP servers are isolated where the protocol permits it.
  • Indexed descriptions and metadata are rendered as plain text.
  • Only http: and https: URLs are linkified.
  • Clipboard text is stripped of control characters.
  • The directory links back to the source repository so users can inspect code and licensing before installation.

An index entry is evidence that a repository published a structurally valid manifest; it is not a security audit or endorsement of that plugin.

Repository layout

app/ Next.js pages, REST routes, MCP, and text feeds
components/ Shared server and client UI components
lib/ Queries, validation, GitHub discovery, and MCP logic
prisma/ Schema and deployable directory snapshot
scripts/ Indexing, seeding, validation, and MCP test tools
tests/ Protocol validation tests
fixtures/ Fictional local development plugins
.github/workflows/ Twice-daily synchronization

The visual language and component rules live in DESIGN.md.

Contributing

Bug reports, discovery gaps, protocol compatibility fixes, and focused pull requests are welcome. Before opening a change:

npm ci
npm test
npm run lint
npm run build

If a public plugin is missing, first confirm that its repository contains a canonical manifest listed under Plugin format compatibility. Include the repository URL and manifest path in the issue so the discovery gap can be reproduced.

License

Released under the MIT License. Indexed plugins retain their own licenses and remain the responsibility of their respective authors.

About

Open-source marketplace for discovering Codex, Claude Code, and Agent Plugins—with web, REST API, MCP, and agent-readable catalogs.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

Agent Plugins Marketplace

Find open-source plugins for Codex, Claude Code, and Agent Plugins.

Search public plugins, compare their supported formats, skills, and MCP servers, and review the source before installing.

Browse the directory · API & MCP docs · OpenAPI 3.1 · Full agent-readable catalog

Sync GitHub pluginsLiveLicense: MIT

Agent Plugins Marketplace preview

What is this?

Agent Plugins Marketplace is a community index of open-source packages that follow one or more canonical plugin formats. It discovers repositories on GitHub, validates their manifests, merges cross-format variants into one entry, and exposes the result through a website, REST API, MCP server, and LLM-friendly text feeds.

It is an index, not a package host. Plugin code stays in its source repository, and the directory does not execute third-party plugins during indexing.

One index, five surfaces

SurfaceBest forURL
Web appBrowse, search, filter, and inspect pluginspluginsmp.com
REST APIApplications, scripts, and integrations/api/v1/*
MCPNative search from an agent sessionPOST /api/mcp
llms.txtA concise guide for agents/llms.txt
llms-full.txtRetrieval over the complete catalog/llms-full.txt

All five surfaces read from the same validated snapshot.

Try it

Search from a browser:

https://pluginsmp.com/plugins?q=github

Open any compatible listing and copy its Codex or Claude Code install command block. It adds and refreshes this repository as the agent-plugin-marketplace catalog, then installs the selected source plugin for the current user. The generated catalogs are refreshed alongside the SQLite snapshot.

Search from code:

curl "https://pluginsmp.com/api/v1/plugins?q=github&protocol=codex&protocol=claude-code&sort=stars&per_page=10"

Connect an MCP client:

{
"mcpServers": {
"agent-plugin-marketplace": {
"type": "streamable-http",
"url": "https://pluginsmp.com/api/mcp"
}
}
}

The MCP server is stateless and exposes three tools:

  • search_plugins — search and filter the index
  • get_plugin — retrieve a plugin, its manifests, skills, and MCP servers
  • get_stats — retrieve current directory totals

Plugin format compatibility

ClientPlugin manifestCatalog file
Codex.codex-plugin/plugin.json.agents/plugins/marketplace.json
Claude Code.claude-plugin/plugin.json.claude-plugin/marketplace.json
Agent Plugins v1plugin.json

A repository may support one plugin format or several. When Codex and Claude Code manifests describe the same plugin root, the index stores one logical plugin with multiple protocols instead of duplicate listings.

Shared components are discovered from skills/<name>/SKILL.md. MCP configuration is read from canonical or manifest-referenced configuration files and normalized to stdio, streamable-http, or sse for filtering.

How automatic discovery works

The index is refreshed by GitHub Actions every day at 00:17 and 12:17 UTC. It can also be started manually.

flowchart LR
A["GitHub repository search"] --> B["Inspect candidate Git trees"]
B --> C["Load canonical manifests"]
C --> D["Validate skills and MCP config"]
D --> E["Merge runtimes and upsert plugins"]
E --> F["Validate SQLite snapshot"]
F --> G["Commit snapshot to main"]
G --> H["Vercel production deploy"]
H --> I["Web · REST · MCP · llms.txt"]
Loading

Discovery combines repository metadata, topics, README signals, Git-tree inspection, and — when a dedicated token is configured — GitHub's legacy Code Search. It searches for all three supported manifest families instead of relying on a hand-maintained allowlist, so first-party and community repositories follow the same path.

Each sync:

  1. Discovers candidate repositories across the supported protocols.
  2. Inspects their trees for canonical manifests, including monorepos with multiple plugin roots.
  3. Validates manifest fields, skills, and MCP server declarations.
  4. Merges sibling runtime manifests and updates repository metadata and star counts.
  5. Runs database integrity checks, protocol tests, and linting.
  6. Commits a changed snapshot to main; Vercel deploys that snapshot automatically.

Unchanged repositories reuse their indexed components based on GitHub's pushed_at value. Sync is deliberately upsert-only: a plugin is not deleted merely because a bounded search fails to return it on a later run.

Coverage boundaries

GitHub search is broad but not mathematically exhaustive. Individual search queries are capped at 1,000 results, API quotas apply, repositories can be private or temporarily unavailable, and some projects do not publish a canonical manifest. The workflow uses multiple protocol-specific windows and safely commits completed transactions when a run becomes quota-limited, but it does not claim to enumerate every repository on GitHub.

REST API

The API is read-only, requires no authentication, and allows cross-origin requests.

EndpointDescription
GET /api/v1/pluginsSearch and paginate plugins
GET /api/v1/plugins/:slugRetrieve one plugin with manifests and components
GET /api/v1/statsRetrieve live directory totals
GET /api/v1/categoriesList manifest-keyword tags with counts

Useful list parameters include q, category, type, transport, sort, page, and per_page. Repeat protocol to match any selected plugin format:

/api/v1/plugins?protocol=codex&protocol=claude-code&type=mcp&sort=stars

See the interactive documentation for response shapes and examples, or consume the OpenAPI schema.

Run locally

Requirements: Node.js 20.9+ and npm. The synchronization workflow currently runs on Node.js 24.

git clone https://github.com/IchenDEV/agent-plugin-mkt.git
cd agent-plugin-mkt
npm ci
cp .env.example .env
npx prisma db push
npm run db:seed
npm run dev

Open http://localhost:3000.

The default development database is SQLite at prisma/dev.db. Fonts are self-hosted through @fontsource, so the application does not fetch web fonts at build or runtime.

Index public GitHub repositories

Authenticate with GitHub, then run the indexer:

GITHUB_TOKEN="$(gh auth token)" npm run index:github -- --max 40

Useful options:

OptionPurpose
--repository-max <n>Limit repository candidates
--skip-code-searchUse repository discovery and Git-tree validation only
--allow-partialKeep completed transactions if an API quota is exhausted

The indexer only talks to api.github.com, caps fetched file sizes, respects rate limits, and is idempotent.

To clear the local database before loading fixtures, run npm run db:seed -- --reset.

Development commands

CommandPurpose
npm run devStart the Next.js development server
npm run buildCreate a production build
npm testRun protocol and validation tests
npm run lintRun ESLint
npm run db:pushApply the Prisma schema
npm run db:seedLoad fixture plugins
npm run db:validateCheck SQLite integrity and report totals
npm run index:githubDiscover and refresh public plugins
npm run marketplace:generateRegenerate Codex and Claude Code install catalogs
npm run marketplace:checkVerify generated install catalogs match the snapshot
npm run test:mcpRun the MCP protocol suite against a running server

For MCP end-to-end tests:

npm run dev
BASE_URL=http://localhost:3000 npm run test:mcp

Validation and trust model

Everything fetched from a plugin repository is treated as untrusted data.

  • Manifests are parsed and validated according to their plugin format's rules.
  • Invalid individual skills or MCP servers are isolated where the protocol permits it.
  • Indexed descriptions and metadata are rendered as plain text.
  • Only http: and https: URLs are linkified.
  • Clipboard text is stripped of control characters.
  • The directory links back to the source repository so users can inspect code and licensing before installation.

An index entry is evidence that a repository published a structurally valid manifest; it is not a security audit or endorsement of that plugin.

Repository layout

app/ Next.js pages, REST routes, MCP, and text feeds
components/ Shared server and client UI components
lib/ Queries, validation, GitHub discovery, and MCP logic
prisma/ Schema and deployable directory snapshot
scripts/ Indexing, seeding, validation, and MCP test tools
tests/ Protocol validation tests
fixtures/ Fictional local development plugins
.github/workflows/ Twice-daily synchronization

The visual language and component rules live in DESIGN.md.

Contributing

Bug reports, discovery gaps, protocol compatibility fixes, and focused pull requests are welcome. Before opening a change:

npm ci
npm test
npm run lint
npm run build

If a public plugin is missing, first confirm that its repository contains a canonical manifest listed under Plugin format compatibility. Include the repository URL and manifest path in the issue so the discovery gap can be reproduced.

License

Released under the MIT License. Indexed plugins retain their own licenses and remain the responsibility of their respective authors.

About

Open-source marketplace for discovering Codex, Claude Code, and Agent Plugins—with web, REST API, MCP, and agent-readable catalogs.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Agent Plugins Marketplace

Find open-source plugins for Codex, Claude Code, and Agent Plugins.

Search public plugins, compare their supported formats, skills, and MCP servers, and review the source before installing.

Browse the directory · API & MCP docs · OpenAPI 3.1 · Full agent-readable catalog

Sync GitHub pluginsLiveLicense: MIT

Agent Plugins Marketplace preview

What is this?

Agent Plugins Marketplace is a community index of open-source packages that follow one or more canonical plugin formats. It discovers repositories on GitHub, validates their manifests, merges cross-format variants into one entry, and exposes the result through a website, REST API, MCP server, and LLM-friendly text feeds.

It is an index, not a package host. Plugin code stays in its source repository, and the directory does not execute third-party plugins during indexing.

One index, five surfaces

SurfaceBest forURL
Web appBrowse, search, filter, and inspect pluginspluginsmp.com
REST APIApplications, scripts, and integrations/api/v1/*
MCPNative search from an agent sessionPOST /api/mcp
llms.txtA concise guide for agents/llms.txt
llms-full.txtRetrieval over the complete catalog/llms-full.txt

All five surfaces read from the same validated snapshot.

Try it

Search from a browser:

https://pluginsmp.com/plugins?q=github

Open any compatible listing and copy its Codex or Claude Code install command block. It adds and refreshes this repository as the agent-plugin-marketplace catalog, then installs the selected source plugin for the current user. The generated catalogs are refreshed alongside the SQLite snapshot.

Search from code:

curl "https://pluginsmp.com/api/v1/plugins?q=github&protocol=codex&protocol=claude-code&sort=stars&per_page=10"

Connect an MCP client:

{
"mcpServers": {
"agent-plugin-marketplace": {
"type": "streamable-http",
"url": "https://pluginsmp.com/api/mcp"
}
}
}

The MCP server is stateless and exposes three tools:

  • search_plugins — search and filter the index
  • get_plugin — retrieve a plugin, its manifests, skills, and MCP servers
  • get_stats — retrieve current directory totals

Plugin format compatibility

ClientPlugin manifestCatalog file
Codex.codex-plugin/plugin.json.agents/plugins/marketplace.json
Claude Code.claude-plugin/plugin.json.claude-plugin/marketplace.json
Agent Plugins v1plugin.json

A repository may support one plugin format or several. When Codex and Claude Code manifests describe the same plugin root, the index stores one logical plugin with multiple protocols instead of duplicate listings.

Shared components are discovered from skills/<name>/SKILL.md. MCP configuration is read from canonical or manifest-referenced configuration files and normalized to stdio, streamable-http, or sse for filtering.

How automatic discovery works

The index is refreshed by GitHub Actions every day at 00:17 and 12:17 UTC. It can also be started manually.

flowchart LR
A["GitHub repository search"] --> B["Inspect candidate Git trees"]
B --> C["Load canonical manifests"]
C --> D["Validate skills and MCP config"]
D --> E["Merge runtimes and upsert plugins"]
E --> F["Validate SQLite snapshot"]
F --> G["Commit snapshot to main"]
G --> H["Vercel production deploy"]
H --> I["Web · REST · MCP · llms.txt"]
Loading

Discovery combines repository metadata, topics, README signals, Git-tree inspection, and — when a dedicated token is configured — GitHub's legacy Code Search. It searches for all three supported manifest families instead of relying on a hand-maintained allowlist, so first-party and community repositories follow the same path.

Each sync:

  1. Discovers candidate repositories across the supported protocols.
  2. Inspects their trees for canonical manifests, including monorepos with multiple plugin roots.
  3. Validates manifest fields, skills, and MCP server declarations.
  4. Merges sibling runtime manifests and updates repository metadata and star counts.
  5. Runs database integrity checks, protocol tests, and linting.
  6. Commits a changed snapshot to main; Vercel deploys that snapshot automatically.

Unchanged repositories reuse their indexed components based on GitHub's pushed_at value. Sync is deliberately upsert-only: a plugin is not deleted merely because a bounded search fails to return it on a later run.

Coverage boundaries

GitHub search is broad but not mathematically exhaustive. Individual search queries are capped at 1,000 results, API quotas apply, repositories can be private or temporarily unavailable, and some projects do not publish a canonical manifest. The workflow uses multiple protocol-specific windows and safely commits completed transactions when a run becomes quota-limited, but it does not claim to enumerate every repository on GitHub.

REST API

The API is read-only, requires no authentication, and allows cross-origin requests.

EndpointDescription
GET /api/v1/pluginsSearch and paginate plugins
GET /api/v1/plugins/:slugRetrieve one plugin with manifests and components
GET /api/v1/statsRetrieve live directory totals
GET /api/v1/categoriesList manifest-keyword tags with counts

Useful list parameters include q, category, type, transport, sort, page, and per_page. Repeat protocol to match any selected plugin format:

/api/v1/plugins?protocol=codex&protocol=claude-code&type=mcp&sort=stars

See the interactive documentation for response shapes and examples, or consume the OpenAPI schema.

Run locally

Requirements: Node.js 20.9+ and npm. The synchronization workflow currently runs on Node.js 24.

git clone https://github.com/IchenDEV/agent-plugin-mkt.git
cd agent-plugin-mkt
npm ci
cp .env.example .env
npx prisma db push
npm run db:seed
npm run dev

Open http://localhost:3000.

The default development database is SQLite at prisma/dev.db. Fonts are self-hosted through @fontsource, so the application does not fetch web fonts at build or runtime.

Index public GitHub repositories

Authenticate with GitHub, then run the indexer:

GITHUB_TOKEN="$(gh auth token)" npm run index:github -- --max 40

Useful options:

OptionPurpose
--repository-max <n>Limit repository candidates
--skip-code-searchUse repository discovery and Git-tree validation only
--allow-partialKeep completed transactions if an API quota is exhausted

The indexer only talks to api.github.com, caps fetched file sizes, respects rate limits, and is idempotent.

To clear the local database before loading fixtures, run npm run db:seed -- --reset.

Development commands

CommandPurpose
npm run devStart the Next.js development server
npm run buildCreate a production build
npm testRun protocol and validation tests
npm run lintRun ESLint
npm run db:pushApply the Prisma schema
npm run db:seedLoad fixture plugins
npm run db:validateCheck SQLite integrity and report totals
npm run index:githubDiscover and refresh public plugins
npm run marketplace:generateRegenerate Codex and Claude Code install catalogs
npm run marketplace:checkVerify generated install catalogs match the snapshot
npm run test:mcpRun the MCP protocol suite against a running server

For MCP end-to-end tests:

npm run dev
BASE_URL=http://localhost:3000 npm run test:mcp

Validation and trust model

Everything fetched from a plugin repository is treated as untrusted data.

  • Manifests are parsed and validated according to their plugin format's rules.
  • Invalid individual skills or MCP servers are isolated where the protocol permits it.
  • Indexed descriptions and metadata are rendered as plain text.
  • Only http: and https: URLs are linkified.
  • Clipboard text is stripped of control characters.
  • The directory links back to the source repository so users can inspect code and licensing before installation.

An index entry is evidence that a repository published a structurally valid manifest; it is not a security audit or endorsement of that plugin.

Repository layout

app/ Next.js pages, REST routes, MCP, and text feeds
components/ Shared server and client UI components
lib/ Queries, validation, GitHub discovery, and MCP logic
prisma/ Schema and deployable directory snapshot
scripts/ Indexing, seeding, validation, and MCP test tools
tests/ Protocol validation tests
fixtures/ Fictional local development plugins
.github/workflows/ Twice-daily synchronization

The visual language and component rules live in DESIGN.md.

Contributing

Bug reports, discovery gaps, protocol compatibility fixes, and focused pull requests are welcome. Before opening a change:

npm ci
npm test
npm run lint
npm run build

If a public plugin is missing, first confirm that its repository contains a canonical manifest listed under Plugin format compatibility. Include the repository URL and manifest path in the issue so the discovery gap can be reproduced.

License

Released under the MIT License. Indexed plugins retain their own licenses and remain the responsibility of their respective authors.

About

Open-source marketplace for discovering Codex, Claude Code, and Agent Plugins—with web, REST API, MCP, and agent-readable catalogs.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Agent Plugins Marketplace

Find open-source plugins for Codex, Claude Code, and Agent Plugins.

Search public plugins, compare their supported formats, skills, and MCP servers, and review the source before installing.

Browse the directory · API & MCP docs · OpenAPI 3.1 · Full agent-readable catalog

Sync GitHub pluginsLiveLicense: MIT

Agent Plugins Marketplace preview

What is this?

Agent Plugins Marketplace is a community index of open-source packages that follow one or more canonical plugin formats. It discovers repositories on GitHub, validates their manifests, merges cross-format variants into one entry, and exposes the result through a website, REST API, MCP server, and LLM-friendly text feeds.

It is an index, not a package host. Plugin code stays in its source repository, and the directory does not execute third-party plugins during indexing.

One index, five surfaces

SurfaceBest forURL
Web appBrowse, search, filter, and inspect pluginspluginsmp.com
REST APIApplications, scripts, and integrations/api/v1/*
MCPNative search from an agent sessionPOST /api/mcp
llms.txtA concise guide for agents/llms.txt
llms-full.txtRetrieval over the complete catalog/llms-full.txt

All five surfaces read from the same validated snapshot.

Try it

Search from a browser:

https://pluginsmp.com/plugins?q=github

Open any compatible listing and copy its Codex or Claude Code install command block. It adds and refreshes this repository as the agent-plugin-marketplace catalog, then installs the selected source plugin for the current user. The generated catalogs are refreshed alongside the SQLite snapshot.

Search from code:

curl "https://pluginsmp.com/api/v1/plugins?q=github&protocol=codex&protocol=claude-code&sort=stars&per_page=10"

Connect an MCP client:

{
"mcpServers": {
"agent-plugin-marketplace": {
"type": "streamable-http",
"url": "https://pluginsmp.com/api/mcp"
}
}
}

The MCP server is stateless and exposes three tools:

  • search_plugins — search and filter the index
  • get_plugin — retrieve a plugin, its manifests, skills, and MCP servers
  • get_stats — retrieve current directory totals

Plugin format compatibility

ClientPlugin manifestCatalog file
Codex.codex-plugin/plugin.json.agents/plugins/marketplace.json
Claude Code.claude-plugin/plugin.json.claude-plugin/marketplace.json
Agent Plugins v1plugin.json

A repository may support one plugin format or several. When Codex and Claude Code manifests describe the same plugin root, the index stores one logical plugin with multiple protocols instead of duplicate listings.

Shared components are discovered from skills/<name>/SKILL.md. MCP configuration is read from canonical or manifest-referenced configuration files and normalized to stdio, streamable-http, or sse for filtering.

How automatic discovery works

The index is refreshed by GitHub Actions every day at 00:17 and 12:17 UTC. It can also be started manually.

flowchart LR
A["GitHub repository search"] --> B["Inspect candidate Git trees"]
B --> C["Load canonical manifests"]
C --> D["Validate skills and MCP config"]
D --> E["Merge runtimes and upsert plugins"]
E --> F["Validate SQLite snapshot"]
F --> G["Commit snapshot to main"]
G --> H["Vercel production deploy"]
H --> I["Web · REST · MCP · llms.txt"]
Loading

Discovery combines repository metadata, topics, README signals, Git-tree inspection, and — when a dedicated token is configured — GitHub's legacy Code Search. It searches for all three supported manifest families instead of relying on a hand-maintained allowlist, so first-party and community repositories follow the same path.

Each sync:

  1. Discovers candidate repositories across the supported protocols.
  2. Inspects their trees for canonical manifests, including monorepos with multiple plugin roots.
  3. Validates manifest fields, skills, and MCP server declarations.
  4. Merges sibling runtime manifests and updates repository metadata and star counts.
  5. Runs database integrity checks, protocol tests, and linting.
  6. Commits a changed snapshot to main; Vercel deploys that snapshot automatically.

Unchanged repositories reuse their indexed components based on GitHub's pushed_at value. Sync is deliberately upsert-only: a plugin is not deleted merely because a bounded search fails to return it on a later run.

Coverage boundaries

GitHub search is broad but not mathematically exhaustive. Individual search queries are capped at 1,000 results, API quotas apply, repositories can be private or temporarily unavailable, and some projects do not publish a canonical manifest. The workflow uses multiple protocol-specific windows and safely commits completed transactions when a run becomes quota-limited, but it does not claim to enumerate every repository on GitHub.

REST API

The API is read-only, requires no authentication, and allows cross-origin requests.

EndpointDescription
GET /api/v1/pluginsSearch and paginate plugins
GET /api/v1/plugins/:slugRetrieve one plugin with manifests and components
GET /api/v1/statsRetrieve live directory totals
GET /api/v1/categoriesList manifest-keyword tags with counts

Useful list parameters include q, category, type, transport, sort, page, and per_page. Repeat protocol to match any selected plugin format:

/api/v1/plugins?protocol=codex&protocol=claude-code&type=mcp&sort=stars

See the interactive documentation for response shapes and examples, or consume the OpenAPI schema.

Run locally

Requirements: Node.js 20.9+ and npm. The synchronization workflow currently runs on Node.js 24.

git clone https://github.com/IchenDEV/agent-plugin-mkt.git
cd agent-plugin-mkt
npm ci
cp .env.example .env
npx prisma db push
npm run db:seed
npm run dev

Open http://localhost:3000.

The default development database is SQLite at prisma/dev.db. Fonts are self-hosted through @fontsource, so the application does not fetch web fonts at build or runtime.

Index public GitHub repositories

Authenticate with GitHub, then run the indexer:

GITHUB_TOKEN="$(gh auth token)" npm run index:github -- --max 40

Useful options:

OptionPurpose
--repository-max <n>Limit repository candidates
--skip-code-searchUse repository discovery and Git-tree validation only
--allow-partialKeep completed transactions if an API quota is exhausted

The indexer only talks to api.github.com, caps fetched file sizes, respects rate limits, and is idempotent.

To clear the local database before loading fixtures, run npm run db:seed -- --reset.

Development commands

CommandPurpose
npm run devStart the Next.js development server
npm run buildCreate a production build
npm testRun protocol and validation tests
npm run lintRun ESLint
npm run db:pushApply the Prisma schema
npm run db:seedLoad fixture plugins
npm run db:validateCheck SQLite integrity and report totals
npm run index:githubDiscover and refresh public plugins
npm run marketplace:generateRegenerate Codex and Claude Code install catalogs
npm run marketplace:checkVerify generated install catalogs match the snapshot
npm run test:mcpRun the MCP protocol suite against a running server

For MCP end-to-end tests:

npm run dev
BASE_URL=http://localhost:3000 npm run test:mcp

Validation and trust model

Everything fetched from a plugin repository is treated as untrusted data.

  • Manifests are parsed and validated according to their plugin format's rules.
  • Invalid individual skills or MCP servers are isolated where the protocol permits it.
  • Indexed descriptions and metadata are rendered as plain text.
  • Only http: and https: URLs are linkified.
  • Clipboard text is stripped of control characters.
  • The directory links back to the source repository so users can inspect code and licensing before installation.

An index entry is evidence that a repository published a structurally valid manifest; it is not a security audit or endorsement of that plugin.

Repository layout

app/ Next.js pages, REST routes, MCP, and text feeds
components/ Shared server and client UI components
lib/ Queries, validation, GitHub discovery, and MCP logic
prisma/ Schema and deployable directory snapshot
scripts/ Indexing, seeding, validation, and MCP test tools
tests/ Protocol validation tests
fixtures/ Fictional local development plugins
.github/workflows/ Twice-daily synchronization

The visual language and component rules live in DESIGN.md.

Contributing

Bug reports, discovery gaps, protocol compatibility fixes, and focused pull requests are welcome. Before opening a change:

npm ci
npm test
npm run lint
npm run build

If a public plugin is missing, first confirm that its repository contains a canonical manifest listed under Plugin format compatibility. Include the repository URL and manifest path in the issue so the discovery gap can be reproduced.

License

Released under the MIT License. Indexed plugins retain their own licenses and remain the responsibility of their respective authors.

About

Open-source marketplace for discovering Codex, Claude Code, and Agent Plugins—with web, REST API, MCP, and agent-readable catalogs.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

Agent Plugins Marketplace

Find open-source plugins for Codex, Claude Code, and Agent Plugins.

Search public plugins, compare their supported formats, skills, and MCP servers, and review the source before installing.

Browse the directory · API & MCP docs · OpenAPI 3.1 · Full agent-readable catalog

Sync GitHub pluginsLiveLicense: MIT

Agent Plugins Marketplace preview

What is this?

Agent Plugins Marketplace is a community index of open-source packages that follow one or more canonical plugin formats. It discovers repositories on GitHub, validates their manifests, merges cross-format variants into one entry, and exposes the result through a website, REST API, MCP server, and LLM-friendly text feeds.

It is an index, not a package host. Plugin code stays in its source repository, and the directory does not execute third-party plugins during indexing.

One index, five surfaces

SurfaceBest forURL
Web appBrowse, search, filter, and inspect pluginspluginsmp.com
REST APIApplications, scripts, and integrations/api/v1/*
MCPNative search from an agent sessionPOST /api/mcp
llms.txtA concise guide for agents/llms.txt
llms-full.txtRetrieval over the complete catalog/llms-full.txt

All five surfaces read from the same validated snapshot.

Try it

Search from a browser:

https://pluginsmp.com/plugins?q=github

Open any compatible listing and copy its Codex or Claude Code install command block. It adds and refreshes this repository as the agent-plugin-marketplace catalog, then installs the selected source plugin for the current user. The generated catalogs are refreshed alongside the SQLite snapshot.

Search from code:

curl "https://pluginsmp.com/api/v1/plugins?q=github&protocol=codex&protocol=claude-code&sort=stars&per_page=10"

Connect an MCP client:

{
"mcpServers": {
"agent-plugin-marketplace": {
"type": "streamable-http",
"url": "https://pluginsmp.com/api/mcp"
}
}
}

The MCP server is stateless and exposes three tools:

  • search_plugins — search and filter the index
  • get_plugin — retrieve a plugin, its manifests, skills, and MCP servers
  • get_stats — retrieve current directory totals

Plugin format compatibility

ClientPlugin manifestCatalog file
Codex.codex-plugin/plugin.json.agents/plugins/marketplace.json
Claude Code.claude-plugin/plugin.json.claude-plugin/marketplace.json
Agent Plugins v1plugin.json

A repository may support one plugin format or several. When Codex and Claude Code manifests describe the same plugin root, the index stores one logical plugin with multiple protocols instead of duplicate listings.

Shared components are discovered from skills/<name>/SKILL.md. MCP configuration is read from canonical or manifest-referenced configuration files and normalized to stdio, streamable-http, or sse for filtering.

How automatic discovery works

The index is refreshed by GitHub Actions every day at 00:17 and 12:17 UTC. It can also be started manually.

flowchart LR
A["GitHub repository search"] --> B["Inspect candidate Git trees"]
B --> C["Load canonical manifests"]
C --> D["Validate skills and MCP config"]
D --> E["Merge runtimes and upsert plugins"]
E --> F["Validate SQLite snapshot"]
F --> G["Commit snapshot to main"]
G --> H["Vercel production deploy"]
H --> I["Web · REST · MCP · llms.txt"]
Loading

Discovery combines repository metadata, topics, README signals, Git-tree inspection, and — when a dedicated token is configured — GitHub's legacy Code Search. It searches for all three supported manifest families instead of relying on a hand-maintained allowlist, so first-party and community repositories follow the same path.

Each sync:

  1. Discovers candidate repositories across the supported protocols.
  2. Inspects their trees for canonical manifests, including monorepos with multiple plugin roots.
  3. Validates manifest fields, skills, and MCP server declarations.
  4. Merges sibling runtime manifests and updates repository metadata and star counts.
  5. Runs database integrity checks, protocol tests, and linting.
  6. Commits a changed snapshot to main; Vercel deploys that snapshot automatically.

Unchanged repositories reuse their indexed components based on GitHub's pushed_at value. Sync is deliberately upsert-only: a plugin is not deleted merely because a bounded search fails to return it on a later run.

Coverage boundaries

GitHub search is broad but not mathematically exhaustive. Individual search queries are capped at 1,000 results, API quotas apply, repositories can be private or temporarily unavailable, and some projects do not publish a canonical manifest. The workflow uses multiple protocol-specific windows and safely commits completed transactions when a run becomes quota-limited, but it does not claim to enumerate every repository on GitHub.

REST API

The API is read-only, requires no authentication, and allows cross-origin requests.

EndpointDescription
GET /api/v1/pluginsSearch and paginate plugins
GET /api/v1/plugins/:slugRetrieve one plugin with manifests and components
GET /api/v1/statsRetrieve live directory totals
GET /api/v1/categoriesList manifest-keyword tags with counts

Useful list parameters include q, category, type, transport, sort, page, and per_page. Repeat protocol to match any selected plugin format:

/api/v1/plugins?protocol=codex&protocol=claude-code&type=mcp&sort=stars

See the interactive documentation for response shapes and examples, or consume the OpenAPI schema.

Run locally

Requirements: Node.js 20.9+ and npm. The synchronization workflow currently runs on Node.js 24.

git clone https://github.com/IchenDEV/agent-plugin-mkt.git
cd agent-plugin-mkt
npm ci
cp .env.example .env
npx prisma db push
npm run db:seed
npm run dev

Open http://localhost:3000.

The default development database is SQLite at prisma/dev.db. Fonts are self-hosted through @fontsource, so the application does not fetch web fonts at build or runtime.

Index public GitHub repositories

Authenticate with GitHub, then run the indexer:

GITHUB_TOKEN="$(gh auth token)" npm run index:github -- --max 40

Useful options:

OptionPurpose
--repository-max <n>Limit repository candidates
--skip-code-searchUse repository discovery and Git-tree validation only
--allow-partialKeep completed transactions if an API quota is exhausted

The indexer only talks to api.github.com, caps fetched file sizes, respects rate limits, and is idempotent.

To clear the local database before loading fixtures, run npm run db:seed -- --reset.

Development commands

CommandPurpose
npm run devStart the Next.js development server
npm run buildCreate a production build
npm testRun protocol and validation tests
npm run lintRun ESLint
npm run db:pushApply the Prisma schema
npm run db:seedLoad fixture plugins
npm run db:validateCheck SQLite integrity and report totals
npm run index:githubDiscover and refresh public plugins
npm run marketplace:generateRegenerate Codex and Claude Code install catalogs
npm run marketplace:checkVerify generated install catalogs match the snapshot
npm run test:mcpRun the MCP protocol suite against a running server

For MCP end-to-end tests:

npm run dev
BASE_URL=http://localhost:3000 npm run test:mcp

Validation and trust model

Everything fetched from a plugin repository is treated as untrusted data.

  • Manifests are parsed and validated according to their plugin format's rules.
  • Invalid individual skills or MCP servers are isolated where the protocol permits it.
  • Indexed descriptions and metadata are rendered as plain text.
  • Only http: and https: URLs are linkified.
  • Clipboard text is stripped of control characters.
  • The directory links back to the source repository so users can inspect code and licensing before installation.

An index entry is evidence that a repository published a structurally valid manifest; it is not a security audit or endorsement of that plugin.

Repository layout

app/ Next.js pages, REST routes, MCP, and text feeds
components/ Shared server and client UI components
lib/ Queries, validation, GitHub discovery, and MCP logic
prisma/ Schema and deployable directory snapshot
scripts/ Indexing, seeding, validation, and MCP test tools
tests/ Protocol validation tests
fixtures/ Fictional local development plugins
.github/workflows/ Twice-daily synchronization

The visual language and component rules live in DESIGN.md.

Contributing

Bug reports, discovery gaps, protocol compatibility fixes, and focused pull requests are welcome. Before opening a change:

npm ci
npm test
npm run lint
npm run build

If a public plugin is missing, first confirm that its repository contains a canonical manifest listed under Plugin format compatibility. Include the repository URL and manifest path in the issue so the discovery gap can be reproduced.

License

Released under the MIT License. Indexed plugins retain their own licenses and remain the responsibility of their respective authors.

About

Open-source marketplace for discovering Codex, Claude Code, and Agent Plugins—with web, REST API, MCP, and agent-readable catalogs.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages