G

Gremlyn

Security and chaos engineering for MCP agents: a Claude Code plugin that breaks your agent's MCP tools on purpose to test prompt-injection defenses and resilience

gremlyn-ai/gremlyn · v0.1.0 · Development & Workflow

gremlyn-aicaution

Trust Score

60

Security

59

Surfaces

1

What is Gremlyn?

Gremlyn is a published development & workflow plugin for AI coding agents in the claude-code ecosystem, developed by gremlyn-ai and distributed through the HOL AI plugin registry. Security and chaos engineering for MCP agents: a Claude Code plugin that breaks your agent's MCP tools on purpose to test prompt-injection defenses and resilience

Canonical slug
gremlyn-ai/gremlyn
Version
v0.1.0 · updated Oct 8, 2026

Trust & Reputation

HOL Trust Score
60

Factor Analysis

Per-metric points (0–100 each) combined via a weighted average into the overall score.

Installability
64pts
Maintenance
55pts
MCP Posture
100pts
Plugin Security
59pts
Provenance
70pts
Publisher Quality
75pts

Registry Snapshot

Publisher verification
No
Marketplace source
Unknown
Scanner
Broker fallback
Safety label
caution
Digest verified
Yes
1 bundled skill — copy or download SKILL.mdOpen skills

Trust & reputation

Trust & Reputation

HOL Trust Score
60

Factor Analysis

Per-metric points (0–100 each) combined via a weighted average into the overall score.

Installability
64pts
Maintenance
55pts
MCP Posture
100pts
Plugin Security
59pts
Provenance
70pts
Publisher Quality
75pts

Provenance

Plugin root
.
Source repo
https://github.com/gremlyn-ai/gremlyn
Source commit
cc39b7d0d617…
Publisher verified
No
Owner verified
Not owner verified

Continuous scanner CI not detected

This plugin remains listed. Its overall trust score is reduced by 10% because security checks are not maintained in the source repository's CI.

Optional: maintain the scanner in the source repository's CI to receive the full trust score. Listing does not require that change.

Verified badge not detected

Add the HOL verified badge to the repository README to score +2% trust. Plugin owners can open that pull request from Guard Plugins.

Security Posture

caution
Safety label
59
Security score
0
High findings
Provider
registry-broker-fallback
Grade
F · caution
Version
Unknown
cisco-skill-scanner: unknown

Findings

mediumpublishabilitypublishability.link.missing.websiteURL

websiteURL should be present for marketplace readiness.

mediumpublishabilitypublishability.link.missing.privacyPolicyURL

privacyPolicyURL should be present for marketplace readiness.

mediumpublishabilitypublishability.link.missing.termsOfServiceURL

termsOfServiceURL should be present for marketplace readiness.

lowoperational-securitysupply-chain.lockfile-missing

Repository snapshot does not include a lockfile.

infoskill-securityskill-scan.unavailable

Cisco skill scanner timed out after 60000 ms

Gremlyn — Frequently asked questions

What is Gremlyn?
Gremlyn is an AI plugin in the HOL registry. Security and chaos engineering for MCP agents: a Claude Code plugin that breaks your agent's MCP tools on purpose to test prompt-injection defenses and resilience
How do I install Gremlyn?
Install Gremlyn in your harness: Claude Code — /plugin marketplace add gremlyn-ai/gremlyn; MCP — git clone https://github.com/gremlyn-ai/gremlyn; Any agent — npx skills add gremlyn-ai/gremlyn. Full step-by-step guidance is on the HOL plugin page.
How do I install Gremlyn in Claude Code?
To install Gremlyn in Claude Code, start with /plugin marketplace add gremlyn-ai/gremlyn. The complete step-by-step install guide for Claude Code is on the HOL plugin page.
How do I install Gremlyn in MCP?
To install Gremlyn in MCP, start with git clone https://github.com/gremlyn-ai/gremlyn. The complete step-by-step install guide for MCP is on the HOL plugin page.
Is Gremlyn free?
Pricing for Gremlyn is published on its HOL plugin page when the maker schedules a launch.
Who publishes Gremlyn?
Gremlyn is published by gremlyn-ai and listed on HOL.
Is Gremlyn available now?
Gremlyn availability is listed on its HOL plugin page.

Install Guidance

Install in Claude Code

Install through the Claude Code plugin marketplace.

Claude Code plugin docs
  1. 1

    Add the marketplace

    Run this inside a Claude Code session.

    claude code
  2. 2

    Install the plugin

    Use the plugin name and the marketplace name shown by the previous command.

    claude code
  3. 3

    Scripted alternative

    Non-interactive equivalent for scripts and CI pipelines. Add --scope project to pin the install to one repository.

    shell

Plugin Manifest

{
  "name": "gremlyn",
  "version": "0.1.0",
  "description": "Chaos testing for AI agents. Injects controlled failures into an agent's MCP tools, scores how it reacts, and helps fix the code that broke.",
  "author": {
    "name": "gremlyn-ai"
  },
  "homepage": "https://github.com/gremlyn-ai/gremlyn",
  "repository": "https://github.com/gremlyn-ai/gremlyn",
  "license": "MIT",
  "keywords": [
    "chaos-engineering",
    "mcp",
    "agents",
    "resilience",
    "testing"
  ],
  "interface": {
    "displayName": "gremlyn",
    "developerName": "gremlyn-ai"
  },
  "skills": "./",
  "holManifestOrigin": "repository",
  "registryIndexVersion": 5
}

Marketplace Source

Repo URL
https://github.com/gremlyn-ai/gremlyn
Marketplace path
Unknown
Source path
.
Install policy
Unspecified

Skills

1 SKILL.md file ship with this plugin. Preview, copy, or download each one, then install them with the Skills CLI.

Share
skills-cli
  • chaos-test

    skills/chaos-test/SKILL.md

    Chaos-test the user's AI agent with gremlyn, then fix the code that failed. Injects controlled MCP tool failures (timeouts, corrupted results, prompt injection, loops...), scores how the agent reacts, explains each failure, patches the agent, and re-runs. Use when the user asks to chaos test, resilience test, stress test or "break" their agent, test how it handles tool failures, or runs /gremlyn:chaos-test. Pass --apply to run unattended (claude -p, CI).

    Raw SKILL.md

File Inventory

.claude-plugin/plugin.json

file

456 bytes

8a67e4451c0e9dc7…

.codex-plugin/plugin.json

plugin-manifest

554 bytes

ad144b67d8c629b5…

commands/chaos.md

file

1,337 bytes

4fb71874f09bd336…

README.md

file

12,691 bytes

788492bb453f4fd6…

SECURITY.md

file

1,874 bytes

d0aa2a12d3dbfdfb…

skills/chaos-test/SKILL.md

skill

7,327 bytes

a38a553ad3c205ab…