Agent skill

Plugin Development

by matrixorigin in matrixorigin/memoria

Create, test, sign, and publish Memoria governance plugins. An agent skill from matrixorigin/memoria.

Apache-2.0Auto-check passedBackend & APIs

Install Plugin Development

skills CLI
$ npx skills add matrixorigin/memoria --skill plugin-development -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install matrixorigin/memoria plugin-development --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/matrixorigin/memoria.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/plugin-development .claude/skills/plugin-development && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
plugin-development
GitHub stars
607
Token cost
~1k tokens
SKILL.md length
184 words
Files
1
Skills in repo
9
Repo updated
First seen
Licence
Apache-2.0

At a glance

Create, test, sign, and publish Memoria governance plugins. An agent skill from matrixorigin/memoria.

  • Works in 4 steps: Local dev (no signature, no DB) → Contract testing → Sign and publish → …
  • Managing plugins
  • SKILL.md covers Quick Start, manifest.json, policy.rhai and Runtime Types, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Plugin Development is an agent skill from matrixorigin/memoria. Create, test, sign, and publish Memoria governance plugins. Covers Rhai and gRPC runtimes, manifest format, lifecycle. Use when developing or managing plugins.

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Hooks and plugins and gRPC and Protobuf. It works with gRPC. The repository describes itself as: Secure memory management for AI Agents • Ensures data integrity • Reduces hallucinations • Maintains consistent long-term context. The licence is Apache-2.0.

When your agent uses it

  • Managing plugins
  • Tasks that involve Hooks and plugins
  • Tasks that involve gRPC and Protobuf

Example prompts

  • “/plugin-development”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Local dev (no signature, no DB)
  2. Contract testing
  3. Sign and publish
  4. Production

What it can do on your machine

Read from SKILL.md and the folder at commit 81c5cc6. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash, json and rhai).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Plugin Development loads about 1k tokens when it runs. Until then it costs about 45 tokens; SKILL.md has 184 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~45
When it runs · the whole SKILL.md, loaded when a task matches
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from matrixorigin/memoria at commit 81c5cc6, republished under its Apache-2.0 licence (© matrixorigin). 184 words, ~1,043 tokens.

Download SKILL.mdSave it as .claude/skills/plugin-development/SKILL.md (or your agent's skills folder).
name
plugin-development
description
Create, test, sign, and publish Memoria governance plugins. Covers Rhai and gRPC runtimes, manifest format, lifecycle. Use when developing or managing plugins.

Quick Start

bash
memoria plugin init --dir ./my-plugin --name my-governance \
  --capabilities governance.plan,governance.execute

Creates:

my-plugin/
├── manifest.json    # Plugin metadata, permissions, limits
└── policy.rhai      # Governance logic (Rhai script)

manifest.json

json
{
  "name": "memoria-my-governance",
  "version": "0.1.0",
  "api_version": "v1",
  "runtime": "rhai",
  "entry": { "rhai": { "script": "policy.rhai", "entrypoint": "memoria_plugin" } },
  "capabilities": ["governance.plan", "governance.execute"],
  "compatibility": { "memoria": ">=0.1.0" },
  "permissions": { "network": false, "filesystem": false, "env": [] },
  "limits": { "timeout_ms": 500, "max_memory_mb": 32, "max_output_bytes": 8192 },
  "integrity": { "sha256": "", "signature": "", "signer": "" },
  "metadata": { "display_name": "My Governance Plugin" }
}

Key fields:

  • runtime: rhai (sandboxed) or grpc (remote service)
  • capabilities: must include governance.plan and/or governance.execute
  • integrity: auto-filled by memoria plugin publish

policy.rhai

rhai
fn memoria_plugin(ctx) {
    if ctx["phase"] == "plan" {
        let review = decision("my-plugin:check", "Description", 0.8);
        review["evidence"] = [evidence("source", "What was found")];
        return #{
            requires_approval: false,
            actions: [review],
            estimated_impact: #{ "my.metric": 1.0 }
        };
    }
    if ctx["phase"] == "execute" {
        return #{ warnings: [], metrics: #{ "my.metric": 1.0 } };
    }
    return #{};
}

Built-in helpers: decision(id, reason, confidence), evidence(source, description)

Runtime Types

RuntimeSandboxingUse Case
rhaiIn-process, memory/time limitedSimple rules, no external deps
grpcOut-of-process, network callComplex logic, external services

Development Workflow

1. Local dev (no signature, no DB)
bash
MEMORIA_GOVERNANCE_ENABLED=true \
MEMORIA_GOVERNANCE_PLUGIN_DIR=./my-plugin \
memoria serve
2. Contract testing

See memoria-service/tests/plugin_contract.rs — uses GovernancePluginContractHarness.

3. Sign and publish
bash
memoria plugin dev-keygen --dir ./my-plugin
memoria plugin signer-add --signer my-team --public-key <base64-ed25519>
memoria plugin publish --package-dir ./my-plugin
memoria plugin review --key governance:my-governance:v1 --version 0.1.0 --status active
memoria plugin activate --domain governance --binding default \
  --plugin-key governance:my-governance:v1 --version 0.1.0
4. Production
bash
MEMORIA_GOVERNANCE_ENABLED=true
MEMORIA_GOVERNANCE_PLUGIN_BINDING=default
MEMORIA_GOVERNANCE_PLUGIN_SUBJECT=system

Lifecycle

scaffold → local dev → sign → publish → review → activate → scheduler loads

CLI Reference

CommandDescription
memoria plugin init --dir <d> --name <n>Scaffold
memoria plugin dev-keygen --dir <d>Generate ed25519 keypair
memoria plugin publish --package-dir <d>Sign and publish
memoria plugin listList published
memoria plugin review --key <k> --version <v> --status <s>Review
memoria plugin activate --domain <d> --binding <b> --plugin-key <k> --version <v>Activate
memoria plugin rulesList binding rules
memoria plugin score --key <k> --version <v>Compatibility score
memoria plugin matrixCompatibility matrix
memoria plugin eventsAudit events

Code Reference

FilePurpose
plugin/manifest.rsPluginManifest, PluginPackage, signing
plugin/repository.rsPublish, review, score, binding CRUD
plugin/rhai_runtime.rsRhaiGovernanceStrategy
plugin/grpc_runtime.rsGrpcGovernanceStrategy
plugin/governance_hook.rsContract testing harness
plugin/templates/Rhai template

© matrixorigin, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/plugin-development of matrixorigin/memoria.

Open the folder on GitHubat commit 81c5cc6

Compare with similar skills

Plugin Development next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Plugin Development compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Plugin Development this skillmatrixorigin/memoria607—~1kAutomated safety check: PassApache-2.0
Use Yaakmountain-loop/yaak19k—~1.9kAutomated safety check: PassMIT
Golang Proantoniopaya22/go-rest-template1723 repos~1.2kAutomated safety check: PassMIT
Debug Grpc ConnectionGetBindu/Bindu10k—~1.2kAutomated safety check: PassCustom licence
Aspnet Corefanslead/ReverseProxy.Store1632 repos~1.4kAutomated safety check: PassApache-2.0
Regenerate Grpc StubsGetBindu/Bindu10k—~810Automated safety check: PassCustom licence

Similar skills

  • Use Yaak

    mountain-loop/yaak

    A skill your agent uses when the user mentions Yaak, a Yaak workspace, or the yaak command, or asks to call, hit, or smoke test HTTP/REST endpoints, save or organize API requests for reuse or manual…

    19k GitHub stars~1.9k tokensUpdated today
    Backend & APIsAuto-check passed
  • Golang Pro

    antoniopaya22/go-rest-template

    Implements concurrent Go patterns using goroutines and channels, designs and builds microservices with gRPC or REST, optimizes Go application performance with pprof, and enforces idiomatic Go with…

    172 GitHub starsUsed in 3 repos~1.2k tokens
    Backend & APIsAuto-check passed
  • Debug Grpc Connection

    GetBindu/Bindu

    Diagnose gRPC connection issues between the Bindu core and a language SDK.

    10k GitHub stars~1.2k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Aspnet Core

    fanslead/ReverseProxy.Store

    Build, review, refactor, or architect ASP.NET Core web applications using current official guidance for .NET web development.

    163 GitHub starsUsed in 2 repos~1.4k tokens
    Backend & APIsAuto-check passed
  • Regenerate Grpc Stubs

    GetBindu/Bindu

    Regenerate Python + TypeScript gRPC stubs after editing proto files.

    10k GitHub stars~810 tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Spider King

    aoyunyang/spider-king-skill

    Pure-web protocol reverse skill: turn hostile browser clients into browser-free Python collectors.

    507 GitHub stars~7.3k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed

More from matrixorigin/memoria

All 9 skills in this repo
  • Thememoria

    matrixorigin/memoria

    Use Memoria as OpenClaw's durable memory slot. An agent skill from matrixorigin/memoria.

    607 GitHub stars~728 tokensUpdated today
    Auto-check passed
  • API Reference

    matrixorigin/memoria

    Memoria REST API endpoints, request/response formats, auth, rate limits.

    607 GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Architecture

    matrixorigin/memoria

    Memoria codebase structure, workspace layout, key traits, database tables, config patterns, and testing conventions.

    607 GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Deployment

    matrixorigin/memoria

    Deploy Memoria with Docker Compose or Kubernetes. An agent skill from matrixorigin/memoria.

    607 GitHub stars~1.6k tokensUpdated today
    Auto-check: notes
  • Local Embedding

    matrixorigin/memoria

    Run embedding on-device with ONNX Runtime. An agent skill from matrixorigin/memoria.

    607 GitHub stars~444 tokensUpdated today
    Auto-check: notes
  • Release

    matrixorigin/memoria

    Cut a Memoria release. An agent skill from matrixorigin/memoria.

    607 GitHub stars~494 tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Plugin Development

What does Plugin Development do?

Create, test, sign, and publish Memoria governance plugins. An agent skill from matrixorigin/memoria. Plugin Development is an agent skill from matrixorigin/memoria. Create, test, sign, and publish Memoria governance plugins.

When should I use Plugin Development?

Plugin Development fits situations like: managing plugins; tasks that involve Hooks and plugins; tasks that involve gRPC and Protobuf.

How do I install Plugin Development in Claude Code?

Run `npx skills add matrixorigin/memoria --skill plugin-development -a claude-code`. Or copy the skill folder (skills/plugin-development in matrixorigin/memoria) into .claude/skills/plugin-development in your project. Claude Code loads it when a task matches its description.

How do I install Plugin Development in Codex?

Run `npx skills add matrixorigin/memoria --skill plugin-development -a codex`. Or copy the skill folder (skills/plugin-development in matrixorigin/memoria) into .agents/skills/plugin-development in your project. Codex loads it when a task matches its description.

Can I use Plugin Development in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add matrixorigin/memoria --skill plugin-development -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/plugin-development, .gemini/skills/plugin-development, .github/skills/plugin-development and .opencode/skills/plugin-development in your project.

What does Plugin Development need to run?

SKILL.md names no scripts, command-line tools or credentials: Plugin Development is instructions for the agent only.

Does Plugin Development access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Plugin Development safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Plugin Development use?

Plugin Development is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Plugin Development use?

About 1k tokens (SKILL.md is roughly 4.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Plugin Development?

Skills that share tags, products or a category with Plugin Development: Use Yaak (mountain-loop/yaak, 19k stars), Golang Pro (antoniopaya22/go-rest-template, 172 stars), Debug Grpc Connection (GetBindu/Bindu, 10k stars) and Aspnet Core (fanslead/ReverseProxy.Store, 163 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Plugin Development?

matrixorigin (a GitHub organization) maintains it in matrixorigin/memoria, which has 607 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 7, 2026.

Source: matrixorigin/memoria on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.