4 min read

wshobson/agents: Plugins and Subagents for Every Coding Agent (GitHub, Scanned)

One catalogue of plugins, subagents, skills and commands for Claude Code, Codex, Cursor and more.

wshobson/agents logo
✅
Scan: safe. Nothing malicious. Two optional plugins add hooks that run a third-party npm package on every tool call, so install those only if you want that policy layer. Scanned Oct 8, 2026; the full report is below.

Seth Hobson's agents repository is a plugin marketplace for AI coding tools. It groups 202 specialist subagents, 184 skills and 105 commands into 92 local plugins (plus 2 external entries), each aimed at one kind of work: Python or JavaScript development, code review, testing, infrastructure, security scanning, and many narrower domains. You install only the plugins you need, so a Python project does not load the Kubernetes agents.

What sets it apart is that one Markdown source serves several harnesses. Claude Code and Codex install it as a native plugin marketplace, Cursor reads a committed registry, and make targets generate the formats OpenCode, Antigravity CLI, GitHub Copilot and Pi expect. Individual skills can also be pulled on their own with gh skill or npx skills, without the agents, commands or hooks.

It has about 40,000 stars, 88 contributors and an MIT licence. The repository also carries plugin-eval, a scoring tool for skills; the README is candid that its LLM judge layers are experimental and do not prove a skill works in your project.

  • Repository: github.com/wshobson/agents
  • Licence: MIT (MIT License)
  • Language: Python. Stars: 40.3K. Forks: 4,290. Last push: Oct 5, 2026.
  • Scan: safe, Oct 8, 2026, commit 46891e7

Who it is for

Developers who use Claude Code, Codex, Cursor or another coding agent and want ready-made specialist subagents and workflows, and teams who switch between agents and want one shared set of instructions.

Getting started

1. In Claude Code, add the repository as a plugin marketplace

/plugin marketplace add wshobson/agents

2. Install a plugin, for example Python development

/plugin install python-development@claude-code-workflows

3. Or, in Codex CLI, add the marketplace and the same plugin

codex plugin marketplace add wshobson/agents && codex plugin add python-development@claude-code-workflows

4. Or install a single skill into any supported agent

npx skills add wshobson/agents --skill python-testing-patterns

The /plugin commands are typed inside Claude Code, not a shell. For OpenCode, Antigravity CLI, GitHub Copilot and Pi, clone the repository and run the matching make install target (for example make install-opencode); that needs uv and Python 3.12 or later.

Safety scan

We cloned wshobson/agents at commit 46891e7 on Oct 8, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.

  • No secrets, no suspicious code patterns and no committed binaries across 1,149 files and about 238,000 lines, most of it Markdown. A second, skill-specific pass (invisible Unicode, prompt-injection phrases, exfiltration hosts, credential paths, pipe-to-shell, long base64 and plugin hooks) found nothing malicious.
  • Two optional plugins, protect-mcp and review-agent-governance, install PreToolUse and PostToolUse hooks that run npx protect-mcp@0.7.4, a third-party npm package, before and after every tool call. The version is pinned and the hooks fail closed, which is the intended design of a policy layer; install them only if you want it and trust that package. No other plugin in the catalogue ships hooks.
  • The superself plugin documents installing a third-party CLI globally with npm install -g superself@0.6.1 and tells the agent to ask before running it. Nothing installs it automatically.
  • One known advisory, rated high: fsspec 2026.4.0 in tools/yt-design-extractor/uv.lock, a side tool for extracting design notes from YouTube videos rather than a plugin. The plugin-eval lockfile has none.
  • Six workflows, none using pull_request_target, and all 14 third-party actions are pinned to commits. Dependabot is on; licence, contributing guide and code of conduct present; no security policy.

What the scanner counted

CheckResult
SecretsNone found.
Suspicious codeNone found.
Install-time codeNone: nothing runs at install beyond the package manager itself.
Committed binariesNone.
CI workflows6 workflows. None use pull_request_target. 0 of 14 third-party actions pinned to a tag rather than a commit.
Network hosts5 distinct hosts referenced from source; most often youtu.be, github.com, opencode.ai, antigravity.google. No URLs to bare IP addresses.
Known vulnerabilities1 advisory across 111 pinned packages: 0 critical, 1 high, 0 moderate, 0 low. plugins/plugin-eval/uv.lock: 51 packages, 0 advisories; tools/yt-design-extractor/uv.lock: 62 packages, 1 advisories.
Project hygieneHas automated dependency updates, licence file, contributing guide. Missing security policy, CodeQL.
OpenSSF ScorecardNot scored: the project is not in Scorecard's weekly index.

The raw findings

Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.

Worst known vulnerabilities (1 of 1)
AdvisorySeverityPackageSummary
GHSA-27vj-qcqg-25rchighfsspec@2026.4.0fsspec: Server-Side Template Injection in ReferenceFileSystem leads to Remote Code Execution

By the numbers

Stars40.3K
Forks4,290
Contributors88
Commits604
Open issues2
Open pull requests4
Releases0
Latest releasenone tagged
LicenceMIT
Main languagePython
Project age1 year
Last pushOct 5, 2026
Tracked files1,149
Lines of code238.1K
Checkout size8 MB

Lines by language: Markdown 204.6K, Python 19.7K, JSON 9,510, YAML 2,524, Shell 904, C# 861.

Questions

Is wshobson/agents free?

Yes. The repository is MIT-licensed and free to install. The two external plugin entries carry their own licences. You still need a coding agent to run the plugins, such as Claude Code or Codex, under that product's own pricing.

Which coding agents does it work with?

Claude Code and Codex CLI install it as a native plugin marketplace and Cursor through its plugin registry. OpenCode, Antigravity CLI, GitHub Copilot and Pi get generated versions through make targets in a local clone. What you get varies by harness: Pi, for example, needs a subagent extension to run the agents.

Should I install every plugin?

No. Each plugin adds agents, skills and commands to your setup, so pick the few that match your work. The plugin catalogue in docs/plugins.md lists all 94 entries by task.


This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.