Scrape
- Daily. GitHub code search for mod fingerprints, plus repo topics.
- Verified. Every repo tree walked; only a
hooks.jsonwithmodulescounts. - Nothing re-hosted. Installs point at the author's repo.
- Skipped. Forks under five stars.
Preview
- Sandboxed. The mod runs in a fresh JS realm with a fake mods API.
- One scripted turn. Reads, an edit, a TODO, a failing test, a risky
rm -rf, acat .env. - Then it draws. Every render site is asked; the trees are drawn like the terminal.
- Shape, not behaviour. Canned git, files and model answers. Facts come from
claude plugin validate.
Trust
- Your permissions. A mod can read files, run processes, hit the network, approve tool calls.
- Not vetted. Read the source (every page has it).
- Check it.
claude plugin validateon a clone lists every call it makes.
Get listed
- Push a public repo with a mod. The next scrape finds it.
- Missing? Open an issue on ryx2/slopshopper.
- Better listing:
plugin.jsonwith name, description, author, license, homepage.
Run it
git clone https://github.com/ryx2/slopshopper
cd slopshopper && bun install
bun run scrape && bun run previews
bun run build && bun run devMarketplace
- 4,902 mods, one file:
https://www.slopshopper.com/community/marketplace.json - Names are the mod's own; the author's login is appended on a clash.
