Agent skill

Plugin Runtime Debug

by oh-my-dsh in oh-my-dsh/dsh-plugin-upgrade-skill

A skill your agent uses when an installed DSH Web plugin misbehaves only at runtime in the browser — paste/attachment/composer features that work once then fail, chips or panels showing stale…

MITAuto-check passed

Install Plugin Runtime Debug

skills CLI
$ npx skills add oh-my-dsh/dsh-plugin-upgrade-skill --skill plugin-runtime-debug -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install oh-my-dsh/dsh-plugin-upgrade-skill plugin-runtime-debug --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/oh-my-dsh/dsh-plugin-upgrade-skill.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/plugin-runtime-debug .claude/skills/plugin-runtime-debug && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
plugin-runtime-debug
GitHub stars
248
Token cost
~3.1k tokens
SKILL.md length
1,741 words
Files
3 (incl. references)
Skills in repo
3
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when an installed DSH Web plugin misbehaves only at runtime in the browser — paste/attachment/composer features that work once then fail, chips or panels showing stale…

  • Works in 4 steps: Which text does an offset count into?… → What does one "unit" weigh in each… → When the verb declines, who notices? A… → …
  • An installed DSH Web plugin misbehaves only at runtime in the browser — paste/attachment/composer features that work once then fail
  • SKILL.md covers The standing rule: read the…, Symptom families and where… and Workflow
  • Calls node and pnpm

What it does

Plugin Runtime Debug is an agent skill from oh-my-dsh/dsh-plugin-upgrade-skill. Use when an installed DSH Web plugin misbehaves only at runtime in the browser — paste/attachment/composer features that work once then fail, chips or panels showing stale placeholder state, update chips claiming the wrong version, a surface working in one browser engine but not another — and the fix must be diagnosed against the exact host API semantics rather than guessed from names. Also use when reviewing a plugin's calls into input-machine or facade verbs (insert, consume, remove, subscribe) before a release.

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `README.md` and `references/browser-forensics.md`).

The repository describes itself as: 帮助插件自动随着dsh版本升级的skill. The licence is MIT.

When your agent uses it

  • An installed DSH Web plugin misbehaves only at runtime in the browser — paste/attachment/composer features that work once then fail
  • Panels showing stale placeholder state
  • Update chips claiming the wrong version
  • Reviewing a plugins calls into input-machine

Example prompts

  • “/plugin-runtime-debug”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Which text does an offset count into? When a verb takes a span or an
  2. What does one "unit" weigh in each representation? If the document
  3. When the verb declines, who notices? A boolean-returning verb that
  4. Which engine evaluates this line? Web-platform behavior that tests

What it can do on your machine

Read from SKILL.md and the folder at commit ef07576. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • node
    • pnpm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Plugin Runtime Debug loads about 3.1k tokens when it runs, and up to ~5.3k if it reads all its reference files. Until then it costs about 135 tokens; SKILL.md has 1,741 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~135
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from oh-my-dsh/dsh-plugin-upgrade-skill at commit ef07576, republished under its MIT licence (© oh-my-dsh). 1,741 words, ~3,089 tokens.

Download SKILL.mdSave it as .claude/skills/plugin-runtime-debug/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
plugin-runtime-debug
description
Use when an installed DSH Web plugin misbehaves only at runtime in the browser — paste/attachment/composer features that work once then fail, chips or panels showing stale placeholder state, update chips claiming the wrong version, a surface working in one browser engine but not another — and the fix must be diagnosed against the exact host API semantics rather than guessed from names. Also use when reviewing a plugin's calls into input-machine or facade verbs (insert, consume, remove, subscribe) before a release.

Debug DSH Web Plugin Runtime Behavior

External Web plugins call host client APIs whose contracts live in the DSH source tree, not in the plugin's own types. When behavior diverges from intent at runtime, the failure is almost always a misread contract — and the diagnosis must come from the host source, never from the API's name.

The standing rule: read the verb's contract in the host source first

Before changing any call into a host API, open the implementing package in the DSH source checkout (~/.dsh/source/current, or the vendored copy) and read the actual method — its doc comment, its guards, and the types it compares against. Repeat for every value the plugin passes. Four questions cover most incidents:

  1. Which text does an offset count into? When a verb takes a span or an offset, find out what string those numbers index. Published snapshot fields and internal editor projections are not always the same string; a plugin that feeds one representation's offsets into a verb whose guard compares against another representation fails silently — the call returns false or no-ops, nothing throws.
  2. What does one "unit" weigh in each representation? If the document contains opaque inline units (chips, tokens, attachments), check whether a unit occupies the same width in the published field as in the projection the verb guards. When widths differ, offsets are only correct while no unit exists — verify what the first call succeeding and every later call failing tells you.
  3. When the verb declines, who notices? A boolean-returning verb that fails silently turns into a downstream state bug: the caller deletes its own bookkeeping anyway, and the UI renders a "missing/unavailable" placeholder next to an object that never went away. Audit every call site for the "fire, ignore the result, clean up state anyway" shape.
  4. Which engine evaluates this line? Web-platform behavior that tests run under Node never exercise can differ in the user's browser, because older engines predate the current standard. The known family: URL parsing of non-special schemes — the WHATWG URL Standard requires new URL('dsh-resource://file/…').hostname to be "file", which Node and current Chromium return, but Chromium before its standards-compliant non-special URL parsing change returned "", so an older Chromium-based Edge build returns "", silently. Record the exact browser version when you see this. Any host or plugin code that routes by URL.hostname/.pathname on a custom scheme works in every Node-based test and fails only in affected real browsers. Before trusting a URL property on a custom scheme, assert it in the actual browser engine (see references/browser-forensics.md), or parse the string by hand.

Symptom families and where they point

  • First interaction works, every subsequent one errors — state written by the earlier call changed the mapping between what the plugin computes and what the verb expects. Compare the two representations before and after one insertion; derive the correction from the unit widths in the host source, then apply the same derivation at every call site that passes offsets, not just the crashing one.

  • A removal button leaves the row behind with a placeholder label — the removal verb declined (see question 3) while bookkeeping was already dropped. Confirm with the verb's return value, and only retire the bookkeeping after the removal actually applied.

  • Derived UI shows stale or phantom entries — find the authoritative source of the fact and derive the view from it. A plugin-side cache with a subscription that retires entries on any transient snapshot (an empty moment during reconcile/remount) will drop live entries; prefer reading the live published state at decision time and treat the cache as an accelerator only.

  • Update/version chips report a wrong "latest" — remote tag and raw-file endpoints are CDN-cached and lag minutes behind a real push. Never present a fetched remote value as ground truth when it can be older than the running build; decide "current vs update" against the running version and display the newer of the two.

  • A built-in surface shows its generic "service unavailable" fallback in the user's browser while registration, composition, and module activation all verify clean — stop auditing registration and start auditing what the failing code reads from its platform. Real case (0.1.6-alpha.2, 2026-09): the right-sidebar document preview showed 「文件资源服务不可用。」 for every file; the file resource provider WAS registered, __DSH_BOOT__ was complete, and zero activation failures existed — the provider router had asked new URL(address) .hostname for the protocol of a dsh-resource:// address and gotten "" on the user's Edge, so lookup always missed and no request was ever sent. The placeholder copy names the feature, not the failure layer; only instrumenting the router produced the decisive line (parsedHost=""). When a fallback string is all the user can report, reproduce with instrumented bundles in a driven browser (see references/browser-forensics.md) before concluding anything about registration state — an earlier misdiagnosis of this exact incident blamed "provider silently unregistered".

  • A whole slot's UI silently vanishes after a release — a throwing expression inside a slot component (classically a dangling identifier: another component's state variable referenced out of scope) is caught by the framework's slot-level error boundary, which unmounts the entire entry; the error is console-only, so users just report "the chips/panel are gone". Two latency mechanisms hide it from the author: an || short-circuit keeps the expression unevaluated until the left operand is false, and components that early-return on the empty state never evaluate it until real data renders. Do not blame the newest diff by default — bisect by rollback or a minimal render mount with data present, check whether the throwing line shipped earlier, and fix by removing the reference (scope any such state locally). Cheap hardening for slot components: defensive reads (x?.items ?? []) and optional-chained DOM access (target.closest?.()) — inside an error boundary any throw costs the whole slot.

  • Repo edits never reach the GUI / EBUSY under the profile's node_modules — first determine the install mode: Get-Item <profile>/node_modules/<pkg> | Select LinkType, Target (or the link:<path> marker in cordis.patch.yml). A Junction/link install means the repo working tree IS the installed copy — no copy step exists or is needed, and Copy-Item into node_modules is a no-op at best. The EBUSY holder is the running dsh host process (closing the browser does not release it), and the browser can still serve a cached client bundle after the host restarts. Activation for a link-installed lib-only plugin: fully stop the host, restart dsh web, hard-refresh, then verify the loaded version marker. Never rename-aside files under an unresolved path: through a junction "two" directories are one, and the rename moves the only copy. A source-launched host (pnpm dsh web in the harness checkout) adds two constraints: the client bundle combo is assembled once at boot (no HMR rebuilds it — every plugin edit needs a full host restart), and on Windows the listener port stays bound by the dying tree unless you stop the whole process tree (taskkill /PID <pid> /T /F), or the next boot dies on EADDRINUSE.

  • One plugin with raw ESM in its client bundle takes every plugin down, and the error names an innocent entry — the host concatenates all client bundles into one classic <script> combo; a single top-level import anywhere makes the whole multi-megabyte combo fail to compile, zero plugins register, and the browser surfaces failed to import loader entry <first-entry> — the first awaited entry (often dsh-typert-registry, itself perfectly fine), not the culprit. Do not chase the named entry: bisect the profile's insert rows (or point the suspect bundle through node --check) until the combo loads again. The client half is not a bare ESM module — it must register through window.__ModuleLoader__.load({ id, factory }), pull react inside the factory via require("react"), and export inject/apply.

  • Phantom pixels at the right edges of a terminal sprite (outline, Z symbols, hearts), and ghost pixels surviving frame switches — two half-block ANSI rendering defects, both invisible in the frame data: (a) a half-filled cell (upper-half block with only one half colored) sets the foreground but leaves the SGR background from the PREVIOUS cell set — SGR persists across cells, so the stale background paints a phantom pixel into the empty half; reset it explicitly (ESC[49m on every half-filled cell). (b) rows trimmed at their trailing transparent cells let a NARROWER frame leave the previous frame's pixels to the right of the trim — paint every row across the full sprite width (transparent cells as plain spaces) and close with an erase-to-EOL (ESC[K). And pin the frame data itself: hand-ported sprite frames drift from the source art a few cells at a time (a regression over an excerpt misses it) — digest every frame against the source and assert the digests.

  • A head/UI process hangs for minutes (or until the CI timeout) after its work is done — a rescheduling timer chain (an animation planner that re-arms setTimeout forever while mounted) keeps the event loop alive on hosts that mount the component without ever unmounting it (probe and test hosts; a GitHub job defaults to a 6h timeout). The interactive TUI stays alive on its TTY/stdin handles regardless — so unref the chain (timer.unref()): the probes drain and exit, real sessions lose nothing. Suspect this whenever enabling a feature flips previously-finishing jobs into timeouts.

Show full SKILL.md (237 more words)Show less

Workflow

  1. Reproduce once and capture the exact user-visible strings (toast text, chip labels, console output) — they are the contract of the bug report.
  2. Map each string to the code path that emitted it; identify the host verb at the boundary.
  3. Open the host source for that verb; answer the four standing questions.
  4. State the mismatch precisely (which representation, which guard, which call sites) before writing any fix; if you cannot state it, you have not read enough source.
  5. When the mismatch is not visible in any console output — generic fallback copy, silent no-op, or a divergence only the user's browser shows — reproduce it in a driven browser with temporarily instrumented bundles (backup, patch with one decisive log line, verify, revert), following references/browser-forensics.md. A user-pasted DevTools screenshot is evidence of the symptom, never of the cause.
  6. Fix every call site that passes representation-dependent values, not only the reported symptom; the same mismatch usually breaks two features through two different verbs.
  7. Prove the fix with the interaction sequence that failed: repeat the action twice in a row and assert both attempts behave identically, and assert the removal path clears every view of the object.
  8. For lib-only plugin bundles (no build step): keep hand-inlined version constants in sync with package.json, syntax-check the bundle (node --check), and verify in the browser after a hard refresh — the served artifact is the file you edited.

© oh-my-dsh, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in skills/plugin-runtime-debug of oh-my-dsh/dsh-plugin-upgrade-skill.

  • SKILL.md
  • README.md
  • references/browser-forensics.md

Open the folder on GitHubat commit ef07576

Compare with similar skills

Plugin Runtime Debug next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Plugin Runtime Debug compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Plugin Runtime Debug this skilloh-my-dsh/dsh-plugin-upgrade-skill248—~3.1kAutomated safety check: PassMIT
Debugasgeirtj/system_prompts_leaks69k—~439Automated safety check: PassCC0-1.0
Openclaw Debuggingopenclaw/openclaw392k—~1.9kAutomated safety check: PassMIT
Debugging Executionsn8n-io/n8n207k—~2.6kAutomated safety check: PassCustom licence
Debugging Toolkitsickn33/agentic-awesome-skills47k1 repos~344Automated safety check: PassMIT
Runtime Debugvercel/next.js143k1 repos~618Automated safety check: PassMIT

Similar skills

  • Debug

    asgeirtj/system_prompts_leaks

    Enable debug logging for this session and help diagnose issues

    69k GitHub stars~439 tokensUpdated today
    Auto-check passed
  • Openclaw Debugging

    openclaw/openclaw

    Debug OpenClaw model, provider, tool-surface, code-mode, streaming, and live/Crabbox behavior by choosing the right logs, probes, and proof path before changing code, including fetching stored…

    392k GitHub stars~1.9k tokensUpdated today
    DevelopmentAuto-check passed
  • Official

    Debug failed or wrong-output workflow executions using executions tools.

    207k GitHub stars~2.6k tokensUpdated today
    DevelopmentAuto-check passed
  • Debugging Toolkit

    sickn33/agentic-awesome-skills

    A skill your agent uses when working with debugging toolkit smart debug (Alias for debugging-toolkit-smart-debug)

    47k GitHub starsUsed in 1 repo~344 tokens
    DevelopmentAuto-check passed
  • Runtime Debug

    vercel/next.js

    Official

    Debug and verification workflow for runtime-bundle and module-resolution regressions.

    143k GitHub starsUsed in 1 repo~618 tokens
    DevelopmentAuto-check passed
  • Hypothesis-Driven Debugging

    code-yeongyu/oh-my-openagent

    Runs a hypothesis-driven debugging loop for crashes, hangs and silent failures in any language, grounding every claim in runtime evidence and locking the fix with a test.

    70k GitHub stars~3.2k tokensUpdated today
    DevelopmentAuto-check passed

More from oh-my-dsh/dsh-plugin-upgrade-skill

  • Plugin Fleet Sweep

    oh-my-dsh/dsh-plugin-upgrade-skill

    A skill your agent uses when the DSH host itself has been upgraded (or is about to be) and the whole installed fleet of Web/client plugins must be checked against the new host - one or more surfaces…

    248 GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Generic Migration

    oh-my-dsh/dsh-plugin-upgrade-skill

    Framework-agnostic methodology for migrating a plugin, extension, or integration across a breaking upstream release — inventory coupling points, classify changes, stage the migration, and verify in…

    248 GitHub stars~1.3k tokensUpdated 2 days ago
    Auto-check passed

Questions about Plugin Runtime Debug

What does Plugin Runtime Debug do?

A skill your agent uses when an installed DSH Web plugin misbehaves only at runtime in the browser — paste/attachment/composer features that work once then fail, chips or panels showing stale…. Plugin Runtime Debug is an agent skill from oh-my-dsh/dsh-plugin-upgrade-skill. Use when an installed DSH Web plugin misbehaves only at runtime in the browser — paste/attachment/composer features that work once then fail, chips or panels showing stale placeholder state, update chips claiming the wrong version, a surface working in one browser engine but not another — and the fix must be diagnosed against the exact host API semantics rather than guessed from names.

When should I use Plugin Runtime Debug?

Plugin Runtime Debug fits situations like: an installed DSH Web plugin misbehaves only at runtime in the browser — paste/attachment/composer features that work once then fail; panels showing stale placeholder state; update chips claiming the wrong version; reviewing a plugins calls into input-machine.

How do I install Plugin Runtime Debug in Claude Code?

Run `npx skills add oh-my-dsh/dsh-plugin-upgrade-skill --skill plugin-runtime-debug -a claude-code`. Or copy the skill folder (skills/plugin-runtime-debug in oh-my-dsh/dsh-plugin-upgrade-skill) into .claude/skills/plugin-runtime-debug in your project. Claude Code loads it when a task matches its description.

How do I install Plugin Runtime Debug in Codex?

Run `npx skills add oh-my-dsh/dsh-plugin-upgrade-skill --skill plugin-runtime-debug -a codex`. Or copy the skill folder (skills/plugin-runtime-debug in oh-my-dsh/dsh-plugin-upgrade-skill) into .agents/skills/plugin-runtime-debug in your project. Codex loads it when a task matches its description.

Can I use Plugin Runtime Debug in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add oh-my-dsh/dsh-plugin-upgrade-skill --skill plugin-runtime-debug -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/plugin-runtime-debug, .gemini/skills/plugin-runtime-debug, .github/skills/plugin-runtime-debug and .opencode/skills/plugin-runtime-debug in your project.

What does Plugin Runtime Debug need to run?

Going by SKILL.md and its folder, Plugin Runtime Debug needs the command-line tools its instructions call (node and pnpm).

Does Plugin Runtime Debug access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Plugin Runtime Debug safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Plugin Runtime Debug use?

Plugin Runtime Debug is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Plugin Runtime Debug use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.2k tokens, read only when the agent opens those files.

What are the alternatives to Plugin Runtime Debug?

Skills that share tags, products or a category with Plugin Runtime Debug: Debug (asgeirtj/system_prompts_leaks, 69k stars), Openclaw Debugging (openclaw/openclaw, 392k stars), Debugging Executions (n8n-io/n8n, 207k stars) and Debugging Toolkit (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Plugin Runtime Debug?

oh-my-dsh (a GitHub organization) maintains it in oh-my-dsh/dsh-plugin-upgrade-skill, which has 248 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 5, 2026.

Source: oh-my-dsh/dsh-plugin-upgrade-skill on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.