Mistral Vibe Plugin Creator
mistralai/mistral-vibe
Shows how to build a Vibe plugin package in the Agent Plugins 1.0 format, with a plugin.json manifest and optional skills, MCP servers, hooks and other components.
Scaffolds a local Codewhale plugin bundle with a versioned manifest, namespaced skills under it, and an explicit trust review before anything in the bundle is enabled.
$ npx skills add codewhale-hq/Codewhale --skill plugin-creator -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install codewhale-hq/Codewhale plugin-creator --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/codewhale-hq/Codewhale.git skills-src && mkdir -p .claude/skills && cp -r skills-src/crates/tui/assets/skills/plugin-creator .claude/skills/plugin-creator && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "plugin-creator" agent skill from https://github.com/codewhale-hq/Codewhale/tree/main/crates/tui/assets/skills/plugin-creator into .claude/skills/plugin-creator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "plugin-creator", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/codewhale-hq/Codewhale/tree/main/crates/tui/assets/skills/plugin-creatorType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add codewhale-hq/Codewhale --skill plugin-creator -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install codewhale-hq/Codewhale plugin-creator --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/codewhale-hq/Codewhale.git skills-src && mkdir -p .agents/skills && cp -r skills-src/crates/tui/assets/skills/plugin-creator .agents/skills/plugin-creator && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "plugin-creator" agent skill from https://github.com/codewhale-hq/Codewhale/tree/main/crates/tui/assets/skills/plugin-creator into .agents/skills/plugin-creator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "plugin-creator", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add codewhale-hq/Codewhale --skill plugin-creator -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install codewhale-hq/Codewhale plugin-creator --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/codewhale-hq/Codewhale.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/crates/tui/assets/skills/plugin-creator .cursor/skills/plugin-creator && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "plugin-creator" agent skill from https://github.com/codewhale-hq/Codewhale/tree/main/crates/tui/assets/skills/plugin-creator into .cursor/skills/plugin-creator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "plugin-creator", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/codewhale-hq/Codewhale.git --path crates/tui/assets/skills/plugin-creator--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add codewhale-hq/Codewhale --skill plugin-creator -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install codewhale-hq/Codewhale plugin-creator --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/codewhale-hq/Codewhale.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/crates/tui/assets/skills/plugin-creator .gemini/skills/plugin-creator && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "plugin-creator" agent skill from https://github.com/codewhale-hq/Codewhale/tree/main/crates/tui/assets/skills/plugin-creator into .gemini/skills/plugin-creator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "plugin-creator", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install codewhale-hq/Codewhale plugin-creatorInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add codewhale-hq/Codewhale --skill plugin-creator -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/codewhale-hq/Codewhale.git skills-src && mkdir -p .github/skills && cp -r skills-src/crates/tui/assets/skills/plugin-creator .github/skills/plugin-creator && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "plugin-creator" agent skill from https://github.com/codewhale-hq/Codewhale/tree/main/crates/tui/assets/skills/plugin-creator into .github/skills/plugin-creator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "plugin-creator", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add codewhale-hq/Codewhale --skill plugin-creator -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install codewhale-hq/Codewhale plugin-creator --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/codewhale-hq/Codewhale.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/crates/tui/assets/skills/plugin-creator .opencode/skills/plugin-creator && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "plugin-creator" agent skill from https://github.com/codewhale-hq/Codewhale/tree/main/crates/tui/assets/skills/plugin-creator into .opencode/skills/plugin-creator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "plugin-creator", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
plugin-creatorScaffolds a local Codewhale plugin bundle with a versioned manifest, namespaced skills under it, and an explicit trust review before anything in the bundle is enabled.
This skill sets up a plugin bundle, whether at a user-level or a workspace-level location Codewhale owns, normalizing the bundle name to lowercase hyphen-case and creating a plugin.json manifest following the Agent Plugins v1.0.0 schema; a legacy plugin.toml still works but new bundles use the JSON form. Each skill goes under a skills/<skill-name>/SKILL.md path, which Codewhale finds automatically and exposes as a namespaced my-plugin:<skill-name> command rather than an unqualified one, avoiding collisions with other bundles.
MCP servers are added only when the bundle genuinely needs an existing MCP engine, kept in a sibling mcp.json with stdio commands and paths inside the bundle and environment values mapped only as exact references; remote MCP servers must use HTTPS or loopback HTTP, forbid user information, query strings or fragments in the URL, use only environment-backed headers or bearer tokens, and declare their exact host set under the bundle's network capabilities, with credentials never placed directly in the manifest.
Commands, agents and hooks activate under the current policy, with workspace bundles winning same-name collisions over user and built-in ones, while LSP, filesystem roots and lifecycle mutation stay inventory-only unless explicitly declared for future work. A native host-code entry only runs under an experimental extension-host flag, must be a single ES module file, and always requires explicit approval rather than a plugin's read-only hint. The bundle is validated and reviewed before anything in it executes.
8 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit ad333fd. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are json).
From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
agent-plugins.orgFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Codewhale Plugin Bundle Scaffolder loads about 1.2k tokens when it runs. Until then it costs about 33 tokens; SKILL.md has 570 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from codewhale-hq/Codewhale at commit ad333fd, republished under its MIT licence (© codewhale-hq). 570 words, ~1,159 tokens.
.claude/skills/plugin-creator/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Use this skill when a user wants a local Codewhale plugin bundle. Trusted and
enabled bundles may add declarative Skills, commands, agents, hooks, and MCP
servers (stdio and remote) through the existing engines. LSP, filesystem
roots, and lifecycle mutation are inventory-only. Native extensions (host
code) are inventory-only unless the user has turned on the experimental
[features] extension_host flag.
~/.codewhale/plugins/<plugin-name>/<workspace>/.codewhale/plugins/<plugin-name>/plugin.json (Agent Plugins v1.0.0; a legacy plugin.toml stays
readable, but new bundles use plugin.json):{
"$schema": "https://agent-plugins.org/schemas/plugin.json",
"name": "my-plugin",
"version": "0.1.0",
"description": "What this bundle provides"
}skills/<skill-name>/SKILL.md; Codewhale finds
skills/ automatically and exposes each as my-plugin:<skill-name>,
never as an unqualified command.mcp.json only when the bundle needs an
existing MCP engine. Keep stdio commands and paths inside the bundle. Map local
environment values only as exact ${SOURCE_ENV} references. For remote MCP,
use HTTPS (or loopback HTTP), forbid URL user information/query/fragment,
use only environment-backed headers or bearer tokens, and declare the exact
normalized endpoint host set in capabilities.network_hosts under
extensions["net.codewhale"]. Never place credentials in the manifest.commands/*.md), agents (agents/*.toml), and hooks
(hooks/*.toml), declared under extensions["net.codewhale"], activate
under the current policy — workspace bundles win same-name collisions over
user and built-in bundles. LSP, filesystem roots, and lifecycle mutation
are inventory-only: declare them only when inventorying future work. A
native entry runs only under the experimental extension host; there it
must be one .mjs, .js or .mts ES module file, /plugin validate rejects
anything else, and its tools always use Required approval, never a
plugin's read-only hint. Full Access, Bypass, or an exact session grant
for the reviewed build can satisfy that gate without a prompt. A bundle
that declares only unsupported surfaces cannot be enabled./plugin validate <plugin-name>/plugin show <plugin-name>/plugin enable <plugin-name>
to open the content/capability review, reviews it, runs the exact
/plugin trust ... confirmation shown, then enables the bundle/skills inspect reports plugin provenance and /plugin list
reports the expected trust and activation state. Trust stages the reviewed
content but does not activate it. After enablement, follow the host's
reload notice: use /reload or a new session to apply changes to a live
session's pinned skills and tools.Every user and workspace bundle starts untrusted and disabled. Reuse the
existing /plugin marketplace, install, update, review and reload surfaces;
do not add a parallel installer, registry or automatic trust flow. Catalog
membership alone never installs, trusts or enables a plugin.
Only scaffold host code when the person explicitly uses the experimental
extension-host feature. Start from the tested hello-extension example and
docs/EXTENSIONS.md in the Codewhale repository. A typed .mts entry may use
Node's erasable TypeScript syntax; bundle dependencies locally. Register tools
with a plugin-specific prefix and an object input schema, propagate
exec.signal, and use ctx.effect for bounded asynchronous cleanup. The
current execution context exposes signal, callId and args; it does not
expose the calling workspace path. Do not change the shared process cwd.
Stop after install, validate and show; never automate the trust token. A
person reviews, trusts and enables the bundle. /plugin show <name> reports
owner state, live tools and recent attributed diagnostics. Recovery may create
fresh registrations, but never replays an interrupted tool call. Explain the
shared-process and current platform sandbox limits without claiming isolation.
© codewhale-hq, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files in crates/tui/assets/skills/plugin-creator of codewhale-hq/Codewhale.
Open the folder on GitHubat commit ad333fd
Codewhale Plugin Bundle Scaffolder next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Codewhale Plugin Bundle Scaffolder this skillcodewhale-hq/Codewhale | 41k | — | ~1.2k | Automated safety check: Pass | MIT | |
| Mistral Vibe Plugin Creatormistralai/mistral-vibe | 5.1k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | |
| Skill Creatorstacklok/toolhive-studio | 170 | — | ~677 | Automated safety check: Pass | Apache-2.0 | |
| Claude Code Skill Developer Guidediet103/claude-code-infrastructure-showcase | 10k | 10 repos | ~3.5k | Automated safety check: Pass | MIT | |
| MCP Integration for Pluginsanthropics/claude-plugins-official | 37k | 11 repos | ~3.1k | Automated safety check: Pass | Apache-2.0 | |
| Claude Code Command Developmentanthropics/claude-plugins-official | 37k | 10 repos | ~4.8k | Automated safety check: Pass | Apache-2.0 |
mistralai/mistral-vibe
Shows how to build a Vibe plugin package in the Agent Plugins 1.0 format, with a plugin.json manifest and optional skills, MCP servers, hooks and other components.
stacklok/toolhive-studio
Create new AI agent skills for Claude Code, Codex, and Cursor.
diet103/claude-code-infrastructure-showcase
A guide to creating and managing Claude Code skills with auto-activation: skill-rules.json triggers, hooks, enforcement levels, YAML frontmatter and progressive disclosure.
anthropics/claude-plugins-official
Explains how to bundle Model Context Protocol servers in a Claude Code plugin, covering config files, stdio, SSE, HTTP and WebSocket server types, and authentication.
anthropics/claude-plugins-official
Explains how to write Claude Code slash commands: Markdown files with YAML frontmatter, arguments, file references, bash context and interactive prompts.
anthropics/claude-plugins-official
Explains the directory layout, plugin.json manifest and component organization of a Claude Code plugin, including auto-discovery and portable paths.
codewhale-hq/Codewhale
Proves a Codewhale change in the real product: a stamped release build, an atomic local install, fresh-shell verification and manual QA that automated gates cannot cover.
codewhale-hq/Codewhale
Writes a paste-ready handoff for the next agent session, opening with a state-check command block and separating done, suspected and blocked work.
codewhale-hq/Codewhale
Decides how verified work should reach main, directly, in a worktree or on an integration branch, while keeping contributor credit and respecting merge gates.
codewhale-hq/Codewhale
Guides when and how to split multi-step coding, research or verification work into focused sub-agent runs while the parent keeps integration and final checks.
codewhale-hq/Codewhale
Triages and manages Codewhale fleet runs and workers with typed commands, classifying failures and choosing a safe restart, resume or escalation.
codewhale-hq/Codewhale
Moves a list of GitHub issues into a milestone or assigns them to owners with the gh CLI, checking each one before and after the change.
Works with
Categories
Scaffolds a local Codewhale plugin bundle with a versioned manifest, namespaced skills under it, and an explicit trust review before anything in the bundle is enabled. toml still works but new bundles use the JSON form.md path, which Codewhale finds automatically and exposes as a namespaced my-plugin:<skill-name> command rather than an unqualified one, avoiding collisions with other bundles.
Codewhale Plugin Bundle Scaffolder fits situations like: creating a new local Codewhale plugin bundle for a user or a workspace; adding a declarative skill, command, agent or hook to a plugin bundle; wiring an MCP server into a plugin bundle safely; reviewing a plugin bundle's trust surface before enabling it.
Run `npx skills add codewhale-hq/Codewhale --skill plugin-creator -a claude-code`. Or copy the skill folder (crates/tui/assets/skills/plugin-creator in codewhale-hq/Codewhale) into .claude/skills/plugin-creator in your project. Claude Code loads it when a task matches its description.
Run `npx skills add codewhale-hq/Codewhale --skill plugin-creator -a codex`. Or copy the skill folder (crates/tui/assets/skills/plugin-creator in codewhale-hq/Codewhale) into .agents/skills/plugin-creator in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add codewhale-hq/Codewhale --skill plugin-creator -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/plugin-creator, .gemini/skills/plugin-creator, .github/skills/plugin-creator and .opencode/skills/plugin-creator in your project.
SKILL.md names no scripts, command-line tools or credentials: Codewhale Plugin Bundle Scaffolder is instructions for the agent only. Our summary lists: A Codewhale installation with plugin support enabled.
SKILL.md names 1 domain. In commands or code: agent-plugins.org; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Codewhale Plugin Bundle Scaffolder is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.2k tokens (SKILL.md is roughly 4.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Codewhale Plugin Bundle Scaffolder: Mistral Vibe Plugin Creator (mistralai/mistral-vibe, 5.1k stars), Skill Creator (stacklok/toolhive-studio, 170 stars), Claude Code Skill Developer Guide (diet103/claude-code-infrastructure-showcase, 10k stars) and MCP Integration for Plugins (anthropics/claude-plugins-official, 37k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
codewhale-hq (a GitHub organization) maintains it in codewhale-hq/Codewhale, which has 41,067 GitHub stars. The repository holds 63 skills in this directory. The repository was last updated on October 7, 2026.
Source: codewhale-hq/Codewhale on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.