Agent skill

Codewhale Plugin Bundle Scaffolder

by codewhale-hq in codewhale-hq/Codewhale

Scaffolds a local Codewhale plugin bundle with a versioned manifest, namespaced skills under it, and an explicit trust review before anything in the bundle is enabled.

MITAuto-check passedAgent Workflows

Install Codewhale Plugin Bundle Scaffolder

skills CLI
$ npx skills add codewhale-hq/Codewhale --skill plugin-creator -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install codewhale-hq/Codewhale plugin-creator --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/codewhale-hq/Codewhale.git skills-src && mkdir -p .claude/skills && cp -r skills-src/crates/tui/assets/skills/plugin-creator .claude/skills/plugin-creator && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
plugin-creator
GitHub stars
41k
Token cost
~1.2k tokens
SKILL.md length
570 words
Files
4
Skills in repo
63
Repo updated
First seen
Licence
MIT

At a glance

Scaffolds a local Codewhale plugin bundle with a versioned manifest, namespaced skills under it, and an explicit trust review before anything in the bundle is enabled.

  • Works in 8 steps: Pick a Codewhale-owned location → Normalize the bundle name to lowercase… → Create plugin.json (Agent Plugins… → …
  • Creating a new local Codewhale plugin bundle for a user or a workspace
  • SKILL.md covers Workflow and Experimental host code
  • Reaches agent-plugins.org

What it does

This skill sets up a plugin bundle, whether at a user-level or a workspace-level location Codewhale owns, normalizing the bundle name to lowercase hyphen-case and creating a plugin.json manifest following the Agent Plugins v1.0.0 schema; a legacy plugin.toml still works but new bundles use the JSON form. Each skill goes under a skills/<skill-name>/SKILL.md path, which Codewhale finds automatically and exposes as a namespaced my-plugin:<skill-name> command rather than an unqualified one, avoiding collisions with other bundles.

MCP servers are added only when the bundle genuinely needs an existing MCP engine, kept in a sibling mcp.json with stdio commands and paths inside the bundle and environment values mapped only as exact references; remote MCP servers must use HTTPS or loopback HTTP, forbid user information, query strings or fragments in the URL, use only environment-backed headers or bearer tokens, and declare their exact host set under the bundle's network capabilities, with credentials never placed directly in the manifest.

Commands, agents and hooks activate under the current policy, with workspace bundles winning same-name collisions over user and built-in ones, while LSP, filesystem roots and lifecycle mutation stay inventory-only unless explicitly declared for future work. A native host-code entry only runs under an experimental extension-host flag, must be a single ES module file, and always requires explicit approval rather than a plugin's read-only hint. The bundle is validated and reviewed before anything in it executes.

When your agent uses it

  • Creating a new local Codewhale plugin bundle for a user or a workspace
  • Adding a declarative skill, command, agent or hook to a plugin bundle
  • Wiring an MCP server into a plugin bundle safely
  • Reviewing a plugin bundle's trust surface before enabling it

Example prompts

  • “Scaffold a new workspace plugin bundle called release-helper with one skill in it.”
  • “Add a remote MCP server to my plugin bundle using an environment-backed bearer token.”
  • “Review this plugin bundle's manifest for anything that needs explicit trust approval.”
  • “Set up a namespaced skill under my-plugin so it doesn't collide with the built-in commands.”

Requirements

  • A Codewhale installation with plugin support enabled

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Pick a Codewhale-owned location
  2. Normalize the bundle name to lowercase hyphen-case.
  3. Create plugin.json (Agent Plugins v1.0.0; a legacy plugin.toml stays
  4. Put each Skill under skills//SKILL.md; Codewhale finds
  5. Add MCP servers in a sibling mcp.json only when the bundle needs an
  6. Commands (commands/*.md), agents (agents/*.toml), and hooks
  7. Validate and review without executing bundle content
  8. Verify /skills inspect reports plugin provenance and /plugin list

What it can do on your machine

Read from SKILL.md and the folder at commit ad333fd. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are json).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • agent-plugins.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Codewhale Plugin Bundle Scaffolder loads about 1.2k tokens when it runs. Until then it costs about 33 tokens; SKILL.md has 570 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~33
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from codewhale-hq/Codewhale at commit ad333fd, republished under its MIT licence (© codewhale-hq). 570 words, ~1,159 tokens.

Download SKILL.mdSave it as .claude/skills/plugin-creator/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
plugin-creator
description
Scaffold a local Codewhale plugin bundle with a versioned manifest, namespaced Skills, and an explicit trust review.

Plugin Creator

Use this skill when a user wants a local Codewhale plugin bundle. Trusted and enabled bundles may add declarative Skills, commands, agents, hooks, and MCP servers (stdio and remote) through the existing engines. LSP, filesystem roots, and lifecycle mutation are inventory-only. Native extensions (host code) are inventory-only unless the user has turned on the experimental [features] extension_host flag.

Workflow

  1. Pick a Codewhale-owned location:
    • User bundle: ~/.codewhale/plugins/<plugin-name>/
    • Workspace bundle: <workspace>/.codewhale/plugins/<plugin-name>/
  2. Normalize the bundle name to lowercase hyphen-case.
  3. Create plugin.json (Agent Plugins v1.0.0; a legacy plugin.toml stays readable, but new bundles use plugin.json):
json
{
  "$schema": "https://agent-plugins.org/schemas/plugin.json",
  "name": "my-plugin",
  "version": "0.1.0",
  "description": "What this bundle provides"
}
  1. Put each Skill under skills/<skill-name>/SKILL.md; Codewhale finds skills/ automatically and exposes each as my-plugin:<skill-name>, never as an unqualified command.
  2. Add MCP servers in a sibling mcp.json only when the bundle needs an existing MCP engine. Keep stdio commands and paths inside the bundle. Map local environment values only as exact ${SOURCE_ENV} references. For remote MCP, use HTTPS (or loopback HTTP), forbid URL user information/query/fragment, use only environment-backed headers or bearer tokens, and declare the exact normalized endpoint host set in capabilities.network_hosts under extensions["net.codewhale"]. Never place credentials in the manifest.
  3. Commands (commands/*.md), agents (agents/*.toml), and hooks (hooks/*.toml), declared under extensions["net.codewhale"], activate under the current policy — workspace bundles win same-name collisions over user and built-in bundles. LSP, filesystem roots, and lifecycle mutation are inventory-only: declare them only when inventorying future work. A native entry runs only under the experimental extension host; there it must be one .mjs, .js or .mts ES module file, /plugin validate rejects anything else, and its tools always use Required approval, never a plugin's read-only hint. Full Access, Bypass, or an exact session grant for the reviewed build can satisfy that gate without a prompt. A bundle that declares only unsupported surfaces cannot be enabled.
  4. Validate and review without executing bundle content:
    • /plugin validate <plugin-name>
    • /plugin show <plugin-name>
    • stop and present these results; the person runs /plugin enable <plugin-name> to open the content/capability review, reviews it, runs the exact /plugin trust ... confirmation shown, then enables the bundle
  5. Verify /skills inspect reports plugin provenance and /plugin list reports the expected trust and activation state. Trust stages the reviewed content but does not activate it. After enablement, follow the host's reload notice: use /reload or a new session to apply changes to a live session's pinned skills and tools.
Show full SKILL.md (180 more words)Show less

Every user and workspace bundle starts untrusted and disabled. Reuse the existing /plugin marketplace, install, update, review and reload surfaces; do not add a parallel installer, registry or automatic trust flow. Catalog membership alone never installs, trusts or enables a plugin.

Experimental host code

Only scaffold host code when the person explicitly uses the experimental extension-host feature. Start from the tested hello-extension example and docs/EXTENSIONS.md in the Codewhale repository. A typed .mts entry may use Node's erasable TypeScript syntax; bundle dependencies locally. Register tools with a plugin-specific prefix and an object input schema, propagate exec.signal, and use ctx.effect for bounded asynchronous cleanup. The current execution context exposes signal, callId and args; it does not expose the calling workspace path. Do not change the shared process cwd.

Stop after install, validate and show; never automate the trust token. A person reviews, trusts and enables the bundle. /plugin show <name> reports owner state, live tools and recent attributed diagnostics. Recovery may create fresh registrations, but never replays an interrupted tool call. Explain the shared-process and current platform sandbox limits without claiming isolation.

© codewhale-hq, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files in crates/tui/assets/skills/plugin-creator of codewhale-hq/Codewhale.

  • SKILL.md
  • SKILL.generation-13.md
  • SKILL.generation-15.md
  • SKILL.generation-16.md

Open the folder on GitHubat commit ad333fd

Compare with similar skills

Codewhale Plugin Bundle Scaffolder next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Codewhale Plugin Bundle Scaffolder compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Codewhale Plugin Bundle Scaffolder this skillcodewhale-hq/Codewhale41k—~1.2kAutomated safety check: PassMIT
Mistral Vibe Plugin Creatormistralai/mistral-vibe5.1k—~3.1kAutomated safety check: PassApache-2.0
Skill Creatorstacklok/toolhive-studio170—~677Automated safety check: PassApache-2.0
Claude Code Skill Developer Guidediet103/claude-code-infrastructure-showcase10k10 repos~3.5kAutomated safety check: PassMIT
MCP Integration for Pluginsanthropics/claude-plugins-official37k11 repos~3.1kAutomated safety check: PassApache-2.0
Claude Code Command Developmentanthropics/claude-plugins-official37k10 repos~4.8kAutomated safety check: PassApache-2.0

Similar skills

  • Mistral Vibe Plugin Creator

    mistralai/mistral-vibe

    Official

    Shows how to build a Vibe plugin package in the Agent Plugins 1.0 format, with a plugin.json manifest and optional skills, MCP servers, hooks and other components.

    5.1k GitHub stars~3.1k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Skill Creator

    stacklok/toolhive-studio

    Create new AI agent skills for Claude Code, Codex, and Cursor.

    170 GitHub stars~677 tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Claude Code Skill Developer Guide

    diet103/claude-code-infrastructure-showcase

    A guide to creating and managing Claude Code skills with auto-activation: skill-rules.json triggers, hooks, enforcement levels, YAML frontmatter and progressive disclosure.

    10k GitHub starsUsed in 10 repos~3.5k tokens
    Agent WorkflowsAuto-check passed
  • MCP Integration for Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to bundle Model Context Protocol servers in a Claude Code plugin, covering config files, stdio, SSE, HTTP and WebSocket server types, and authentication.

    37k GitHub starsUsed in 11 repos~3.1k tokens
    Agent WorkflowsAuto-check passed
  • Claude Code Command Development

    anthropics/claude-plugins-official

    Official

    Explains how to write Claude Code slash commands: Markdown files with YAML frontmatter, arguments, file references, bash context and interactive prompts.

    37k GitHub starsUsed in 10 repos~4.8k tokens
    Agent WorkflowsAuto-check passed
  • Claude Code Plugin Structure

    anthropics/claude-plugins-official

    Official

    Explains the directory layout, plugin.json manifest and component organization of a Claude Code plugin, including auto-discovery and portable paths.

    37k GitHub starsUsed in 10 repos~3.4k tokens
    Agent WorkflowsAuto-check passed

More from codewhale-hq/Codewhale

All 63 skills in this repo
  • Codewhale Dogfood Install

    codewhale-hq/Codewhale

    Proves a Codewhale change in the real product: a stamped release build, an atomic local install, fresh-shell verification and manual QA that automated gates cannot cover.

    41k GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Codewhale Session Handoff

    codewhale-hq/Codewhale

    Writes a paste-ready handoff for the next agent session, opening with a state-check command block and separating done, suspected and blocked work.

    41k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Codewhale Landing Workflow

    codewhale-hq/Codewhale

    Decides how verified work should reach main, directly, in a worktree or on an integration branch, while keeping contributor credit and respecting merge gates.

    41k GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Sub-Agent Delegation

    codewhale-hq/Codewhale

    Guides when and how to split multi-step coding, research or verification work into focused sub-agent runs while the parent keeps integration and final checks.

    41k GitHub stars~790 tokensUpdated today
    Auto-check passed
  • Codewhale Fleet Manager

    codewhale-hq/Codewhale

    Triages and manages Codewhale fleet runs and workers with typed commands, classifying failures and choosing a safe restart, resume or escalation.

    41k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • GitHub Issue Bulk Assigner

    codewhale-hq/Codewhale

    Moves a list of GitHub issues into a milestone or assigns them to owners with the gh CLI, checking each one before and after the change.

    41k GitHub stars~953 tokensUpdated today
    Auto-check passed

Categories

Questions about Codewhale Plugin Bundle Scaffolder

What does Codewhale Plugin Bundle Scaffolder do?

Scaffolds a local Codewhale plugin bundle with a versioned manifest, namespaced skills under it, and an explicit trust review before anything in the bundle is enabled. toml still works but new bundles use the JSON form.md path, which Codewhale finds automatically and exposes as a namespaced my-plugin:<skill-name> command rather than an unqualified one, avoiding collisions with other bundles.

When should I use Codewhale Plugin Bundle Scaffolder?

Codewhale Plugin Bundle Scaffolder fits situations like: creating a new local Codewhale plugin bundle for a user or a workspace; adding a declarative skill, command, agent or hook to a plugin bundle; wiring an MCP server into a plugin bundle safely; reviewing a plugin bundle's trust surface before enabling it.

How do I install Codewhale Plugin Bundle Scaffolder in Claude Code?

Run `npx skills add codewhale-hq/Codewhale --skill plugin-creator -a claude-code`. Or copy the skill folder (crates/tui/assets/skills/plugin-creator in codewhale-hq/Codewhale) into .claude/skills/plugin-creator in your project. Claude Code loads it when a task matches its description.

How do I install Codewhale Plugin Bundle Scaffolder in Codex?

Run `npx skills add codewhale-hq/Codewhale --skill plugin-creator -a codex`. Or copy the skill folder (crates/tui/assets/skills/plugin-creator in codewhale-hq/Codewhale) into .agents/skills/plugin-creator in your project. Codex loads it when a task matches its description.

Can I use Codewhale Plugin Bundle Scaffolder in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add codewhale-hq/Codewhale --skill plugin-creator -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/plugin-creator, .gemini/skills/plugin-creator, .github/skills/plugin-creator and .opencode/skills/plugin-creator in your project.

What does Codewhale Plugin Bundle Scaffolder need to run?

SKILL.md names no scripts, command-line tools or credentials: Codewhale Plugin Bundle Scaffolder is instructions for the agent only. Our summary lists: A Codewhale installation with plugin support enabled.

Does Codewhale Plugin Bundle Scaffolder access the network?

SKILL.md names 1 domain. In commands or code: agent-plugins.org; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Codewhale Plugin Bundle Scaffolder safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Codewhale Plugin Bundle Scaffolder use?

Codewhale Plugin Bundle Scaffolder is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Codewhale Plugin Bundle Scaffolder use?

About 1.2k tokens (SKILL.md is roughly 4.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Codewhale Plugin Bundle Scaffolder?

Skills that share tags, products or a category with Codewhale Plugin Bundle Scaffolder: Mistral Vibe Plugin Creator (mistralai/mistral-vibe, 5.1k stars), Skill Creator (stacklok/toolhive-studio, 170 stars), Claude Code Skill Developer Guide (diet103/claude-code-infrastructure-showcase, 10k stars) and MCP Integration for Plugins (anthropics/claude-plugins-official, 37k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Codewhale Plugin Bundle Scaffolder?

codewhale-hq (a GitHub organization) maintains it in codewhale-hq/Codewhale, which has 41,067 GitHub stars. The repository holds 63 skills in this directory. The repository was last updated on October 7, 2026.

Source: codewhale-hq/Codewhale on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.