Agent Skills › Hmbown/Codewhale › plugin-creator

plugin-creator

GitHub

用于快速生成 Codewhale 本地插件包骨架,包含版本化清单、命名空间技能及信任审查流程。指导用户创建 plugin.toml,配置技能、命令、代理等组件,并执行验证与信任激活步骤,确保插件安全合规地集成到系统中。

crates/tui/assets/skills/plugin-creator/SKILL.md Hmbown/Codewhale

Trigger Scenarios

需要创建新的 Codewhale 插件包 初始化插件目录结构和配置文件 设置插件的信任审查和启用流程

Install

npx skills add Hmbown/Codewhale --skill plugin-creator -g -y
More Options

Non-standard path

npx skills add https://github.com/Hmbown/Codewhale/tree/main/crates/tui/assets/skills/plugin-creator -g -y

Use without installing

npx skills use Hmbown/Codewhale@plugin-creator

指定 Agent (Claude Code)

npx skills add Hmbown/Codewhale --skill plugin-creator -a claude-code -g -y

安装 repo 全部 skill

npx skills add Hmbown/Codewhale --all -g -y

预览 repo 内 skill

npx skills add Hmbown/Codewhale --list

SKILL.md

Frontmatter
{
    "name": "plugin-creator",
    "description": "Scaffold a local Codewhale plugin bundle with a versioned manifest, namespaced Skills, and an explicit trust review."
}

Plugin Creator

Use this skill when a user wants a local Codewhale plugin bundle. Trusted and enabled bundles may add declarative Skills, commands, agents, hooks, and MCP servers (stdio and remote) through the existing engines. LSP, native extensions, filesystem roots, and lifecycle mutation are inventory-only.

Workflow

  1. Pick a Codewhale-owned location:
    • User bundle: ~/.codewhale/plugins/<plugin-name>/
    • Workspace bundle: <workspace>/.codewhale/plugins/<plugin-name>/
  2. Normalize the bundle name to lowercase hyphen-case.
  3. Create plugin.toml:
schema_version = 1

[plugin]
name = "my-plugin"
version = "0.1.0"
description = "What this bundle provides"

[skills]
path = "skills"
  1. Put each Skill under skills/<skill-name>/SKILL.md. Codewhale exposes it as my-plugin:<skill-name>, never as an unqualified command.
  2. Add [mcp_servers.<name>] only when the bundle needs an existing MCP engine. Keep stdio commands and paths inside the bundle. Map local environment values only as exact ${SOURCE_ENV} references. For remote MCP, use HTTPS (or loopback HTTP), forbid URL user information/query/fragment, use only environment-backed headers or bearer tokens, and declare the exact normalized endpoint host set in [capabilities].network_hosts. Never place credentials in the manifest.
  3. Commands (commands/*.md), agents (agents/*.toml), and hooks (hooks/*.toml) activate under the current policy — workspace bundles win same-name collisions over user and built-in bundles. LSP, native extensions, filesystem roots, and lifecycle mutation are inventory-only: declare them only when inventorying future work. A bundle that declares only unsupported surfaces cannot be enabled.
  4. Validate and review without executing bundle content:
    • /plugin validate <plugin-name>
    • /plugin show <plugin-name>
    • /plugin enable <plugin-name> to open the content/capability review
    • run the exact /plugin trust ... confirmation shown, then enable again
  5. Verify /skills inspect reports plugin provenance and /plugin list reports the expected trust and activation state. Trust stages the reviewed content but does not activate it. After enablement, follow the host's reload notice: use /reload or a new session to apply changes to a live session's pinned skills and tools.

Every user and workspace bundle starts untrusted and disabled. Reuse the existing /plugin marketplace, install, update, review and reload surfaces; do not add a parallel installer, registry or automatic trust flow. Catalog membership alone never installs, trusts or enables a plugin.

Version History

  • 6e005de Current 2026-09-22 10:00

    新增对 agents、hooks 和 LSP 等组件的声明支持;明确 workspace bundle 优先级;细化 MCP 安全规范。

  • 0fe366b 2026-08-16 09:03

    从整体捆绑门控改为按组件兼容性激活,支持混合插件中 Skill 和 MCP 的独立启用,引入 v2 能力哈希以绑定激活策略。

  • b0e4926 2026-07-24 17:42

Same Skill Collection

crates/tui/assets/skills/batch/SKILL.md
crates/tui/assets/skills/best-of-n/SKILL.md
crates/tui/assets/skills/contributor-onboarding/SKILL.md
crates/tui/assets/skills/dataviz/SKILL.md
crates/tui/assets/skills/debug/SKILL.md
crates/tui/assets/skills/delegate/SKILL.md
crates/tui/assets/skills/dependency-update/SKILL.md
crates/tui/assets/skills/docx/SKILL.md
crates/tui/assets/skills/feishu/SKILL.md
crates/tui/assets/skills/fleet-manager/SKILL.md
crates/tui/assets/skills/forget/SKILL.md
crates/tui/assets/skills/frontend-design/SKILL.md
crates/tui/assets/skills/gmail/SKILL.md
crates/tui/assets/skills/google-calendar/SKILL.md
crates/tui/assets/skills/handoff/SKILL.md
crates/tui/assets/skills/help/SKILL.md
crates/tui/assets/skills/implement/SKILL.md
crates/tui/assets/skills/interview/SKILL.md
crates/tui/assets/skills/mcp-builder/SKILL.md
crates/tui/assets/skills/mcp-discovery/SKILL.md
crates/tui/assets/skills/pdf/SKILL.md
crates/tui/assets/skills/photos/SKILL.md
crates/tui/assets/skills/plan/SKILL.md
crates/tui/assets/skills/pptx/SKILL.md
crates/tui/assets/skills/research/SKILL.md
crates/tui/assets/skills/review/SKILL.md
crates/tui/assets/skills/security-review/SKILL.md
crates/tui/assets/skills/simplify/SKILL.md
crates/tui/assets/skills/skill-creator/SKILL.md
crates/tui/assets/skills/skill-installer/SKILL.md
crates/tui/assets/skills/test/SKILL.md
crates/tui/assets/skills/v4-best-practices/SKILL.md
crates/tui/assets/skills/verify/SKILL.md
crates/tui/assets/skills/webapp-testing/SKILL.md
crates/tui/assets/skills/xlsx/SKILL.md
docs/skills/codew-release-qa-sweep/SKILL.md
docs/skills/contributor-onboarding/SKILL.md
docs/skills/cw-dogfood/SKILL.md
docs/skills/cw-gates/SKILL.md
docs/skills/cw-handoff/SKILL.md
docs/skills/cw-land/SKILL.md
docs/skills/cw-orient/SKILL.md
docs/skills/cw-slice/SKILL.md
docs/skills/gh-assign-issues/SKILL.md
docs/skills/gh-close-issues/SKILL.md
docs/skills/gh-compile-issues/SKILL.md
docs/skills/gh-credit-harvest/SKILL.md
docs/skills/gh-file-issue/SKILL.md
docs/skills/gh-find-prs/SKILL.md

Metadata

Files
0
Version
94130d9
Hash
32139a0b
Indexed
2026-07-24 17:42

ホーム - Wiki
Copyright © 2011-2026 iteam. Current version is 2.155.2. UTC+08:00, 2026-09-28 13:40
浙ICP备14020137号-1