Agent skill

Plugin Import

by uvwt in uvwt/agentdock

当用户要安装或更新来自 Git、GitHub、外部插件市场或其他远程来源的 Plugin 时使用;负责把远程来源固定并取得到本地,再交给 pluginmanage 自动识别 Portable/OpenAI/Claude 格式、审核和安装。

Apache-2.0Auto-check passedAgent Workflows

Install Plugin Import

skills CLI
$ npx skills add uvwt/agentdock --skill plugin-import -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install uvwt/agentdock plugin-import --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/uvwt/agentdock.git skills-src && mkdir -p .claude/skills && cp -r skills-src/core-skills/plugin-import .claude/skills/plugin-import && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
plugin-import
GitHub stars
1.2k
Token cost
~839 tokens
SKILL.md length
266 words
Files
2 (incl. references)
Skills in repo
3
Repo updated
First seen
Licence
Apache-2.0

At a glance

当用户要安装或更新来自 Git、GitHub、外部插件市场或其他远程来源的 Plugin 时使用;负责把远程来源固定并取得到本地,再交给 pluginmanage 自动识别 Portable/OpenAI/Claude 格式、审核和安装。

  • Works in 6 steps: 获取外部内容并尽量固定可追踪的 revision/digest; → 对明确的远程来源生成根目录… → 把目标 Plugin 目录或 ZIP 准备到本地; → …
  • Agent Workflows work in your project
  • SKILL.md covers 什么时候使用, 职责边界, 导入流程 and 更新外部来源 Plugin, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Plugin Import is an agent skill from uvwt/agentdock. 当用户要安装或更新来自 Git、GitHub、外部插件市场或其他远程来源的 Plugin 时使用;负责把远程来源固定并取得到本地,再交给 pluginmanage 自动识别 Portable/OpenAI/Claude 格式、审核和安装。

Its SKILL.md is about 840 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/portable-plugin.md`).

It sits in Agent Workflows. It works with OpenAI, Git, GitHub and Model Context Protocol. The repository describes itself as: Secure MCP runtime for AI agents to operate local machines, servers, and containers with multi-device orchestration. The licence is Apache-2.0.

When your agent uses it

  • Agent Workflows work in your project

Example prompts

  • “/plugin-import”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. 获取外部内容并尽量固定可追踪的 revision/digest;
  2. 对明确的远程来源生成根目录 .agentdock-import.json,把用户给出的来源和已验证的 revision/ref/subdir 交给 Core;
  3. 把目标 Plugin 目录或 ZIP 准备到本地;
  4. 对 Core 尚不认识的其他格式,才由模型做显式转换;
  5. 调用 plugin_manage validate,检查自动识别结果、format、warnings、provenance;
  6. 使用 validate 返回的 review token 安装或更新。

What it can do on your machine

Read from SKILL.md and the folder at commit a19d133. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Plugin Import loads about 839 tokens when it runs, and up to ~2k if it reads all its reference files. Until then it costs about 34 tokens; SKILL.md has 266 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~34
When it runs · the whole SKILL.md, loaded when a task matches
~839
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from uvwt/agentdock at commit a19d133, republished under its Apache-2.0 licence (© uvwt). 266 words, ~839 tokens.

Download SKILL.mdSave it as .claude/skills/plugin-import/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
plugin-import
description
当用户要安装或更新来自 Git、GitHub、外部插件市场或其他远程来源的 Plugin 时使用;负责把远程来源固定并取得到本地,再交给 plugin_manage 自动识别 Portable/OpenAI/Claude 格式、审核和安装。

Plugin Import

用于把 Git、GitHub、外部 marketplace/catalog 等远程 Plugin 来源安全取得到本地。

plugin_manage 直接接受本地目录或 ZIP,并自动识别 AgentDock Portable、OpenAI 和 Claude Plugin 格式;OpenAI/Claude 的兼容性转换由 Core 在审核前完成,不需要模型手工改写 manifest 或重新打包。这个 Skill 只负责远程来源发现/固定/获取,以及 Core 尚不认识的其他格式。最终包的安全校验、规范化摘要、review token、安装事务和运行时激活仍由 plugin_manage 负责。

什么时候使用

以下情况使用本 Skill:

  • 用户给出 Git / GitHub 仓库或仓库子目录;
  • 用户给出外部 marketplace/catalog 条目;
  • 用户要求更新一个需要重新从远程上游取得内容的 Plugin;
  • 来源格式不是 AgentDock Core 已能自动识别的 Portable/OpenAI/Claude。

如果用户已经提供本地目录或 ZIP,不论它是 Portable、OpenAI 还是 Claude Plugin,都直接使用 plugin_manage,不要先手工转换。

职责边界

本 Skill 负责:

  1. 获取外部内容并尽量固定可追踪的 revision/digest;
  2. 对明确的远程来源生成根目录 .agentdock-import.json,把用户给出的来源和已验证的 revision/ref/subdir 交给 Core;
  3. 把目标 Plugin 目录或 ZIP 准备到本地;
  4. 对 Core 尚不认识的其他格式,才由模型做显式转换;
  5. 调用 plugin_manage validate,检查自动识别结果、format、warnings、provenance;
  6. 使用 validate 返回的 review token 安装或更新。

本 Skill 不负责绕过 Core 校验,也不要对 OpenAI/Claude 包做重复转换。

导入流程

  1. 取得来源

    • 使用宿主已有的命令、文件、浏览器或连接器能力取得内容。
    • Git 来源应尽量固定到具体 commit;下载归档应尽量记录可验证的 digest。
    • 不把凭据、token、带密码的 URL 写进包或 provenance。
  2. 准备本地输入

    • 如果目标已经是一个本地目录或 ZIP,直接保留原样。
    • OpenAI .codex-plugin/plugin.json、Claude .claude-plugin/plugin.json 和 AgentDock plugin.json 都交给 Core 自动识别。
    • 不要为了“兼容”先删除 commands/note 或第三方扩展字段;Core 会保留未知内容,只对自己真正执行的语义做严格判断。
  3. 交接远程来源

    • 只有当来源是用户明确给出的远程地址,或本次获取流程能够可靠证明远程来源时,才在目标 Plugin 根目录写 .agentdock-import.json。
    • sidecar 只允许 origin、ref、revision、subdir。
    • origin 使用稳定、无凭据的上游地址;Git 来源的 revision 优先填写实际解析到的 commit SHA,ref 只在用户输入或实际仓库状态能确认时填写,subdir 只在来源明确指向仓库子目录时填写。
    • GitHub/GitLab 的 tree/blob 子目录 URL 要拆成稳定仓库 origin + 已确认的 ref + Plugin subdir,不要把浏览器页面 URL 整体当作长期 origin。
    • 不确定的字段留空,不要根据仓库名、默认分支或 URL 习惯猜测。
    • 用户只给本地目录或本地 ZIP,且无法证明其远程来源时,不创建 sidecar;Core 会使用内容摘要作为匿名本地 provenance。
    • Core 只在自己的 staging snapshot 中读取并移除 sidecar;它不会修改原始来源,也不会把 sidecar 安装进最终 Plugin。
  4. 仅在 Core 不认识格式时显式转换

    • 对其他生态格式,模型才建立 Portable 目录并写 plugin.json / mcp.json。
    • 对认证、执行权限、hook、agent 等存在语义差异的能力,不要臆造等价行为。
    • 第三方未知元数据无需人工删除或改写;只在需要把完全陌生格式转换成 Portable 时生成 AgentDock 真正使用的运行字段。
  5. 验证并安装

    • 先调用 plugin_manage(action="validate", source=<本地目录或ZIP>)。
    • 检查 valid、format、warnings、executables、Skills、MCP、provenance。
    • warning 中若说明某个 MCP/执行能力“preserved but not activated”,表示原内容已保留,但 AgentDock 不会执行它。
    • 安装使用 validate 返回的原样 review_token。
    • validate 后如果修改了任何包内容,必须重新 validate;不要复用旧 token。

更新外部来源 Plugin

更新时先检查已安装 Plugin 的 provenance,再从其原始来源取得目标版本到本地。对于 Portable/OpenAI/Claude,直接把新的目录或 ZIP 交给 plugin_manage validate/update,不要再手工转换。

plugin_manage update 不负责寻找上游版本;它只负责自动识别本地输入、规范化、审核并原子切换最终 canonical package。

正常 revision 前进不需要额外的“换源”参数;如果 origin/subdir 等身份发生变化,应在 review 中明确展示,让用户基于最终 package 内容确认。

安全要求

  • 最终安装输入只能是本地目录或本地 ZIP;Core 自动识别 Portable/OpenAI/Claude,不接受远程 URL。
  • 不把 secret 写进 plugin.json、.agentdock-import.json、Skill、MCP 配置或 provenance。
  • 不保留来源仓库中的符号链接、路径逃逸结构或特殊文件。
  • 不静默改变 MCP 认证、安全或网络语义。
  • 不执行来源仓库的安装脚本、hook 或未知二进制来完成“导入”。
  • 外部内容即使来自官方仓库,也必须经过最终 plugin_manage validate。
  • review_token 只确认它绑定的那份最终 package;内容变化后必须重新审核。

Portable Package 的具体结构与 provenance 字段见 references/portable-plugin.md。

© uvwt, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in core-skills/plugin-import of uvwt/agentdock.

  • SKILL.md
  • references/portable-plugin.md

Open the folder on GitHubat commit a19d133

Compare with similar skills

Plugin Import next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Plugin Import compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Plugin Import this skilluvwt/agentdock1.2k—~839Automated safety check: PassApache-2.0
Codexless Release Supervisorliyana31811/Codexless118—~2.4kAutomated safety check: PassApache-2.0
MCP Apps Builderawslabs/cli-agent-orchestrator1.4k—~1.7kAutomated safety check: PassApache-2.0
Dotagentsgetsentry/sentry-wizard295—~900Automated safety check: PassCustom licence
Releasetractorjuice/arc-kit2.3k—~3kAutomated safety check: PassCustom licence
Devcontainer Devstacklok/toolhive-studio170—~3.8kAutomated safety check: NotesApache-2.0

Similar skills

  • Codexless Release Supervisor

    liyana31811/Codexless

    Prepare, validate, and publish Codexless preview/hotfix releases from the canonical household source, including acceptance anti-omission gates, candidate provenance/parity, manifest/build identity…

    118 GitHub stars~2.4k tokensUpdated 8 days ago
    Agent WorkflowsAuto-check passed
  • MCP Apps Builder

    awslabs/cli-agent-orchestrator

    Official

    Load the official MCP Apps builder skills (create-mcp-app, migrate-oai-app, add-app-to-server, convert-web-app) from github.com/modelcontextprotocol/ext-apps.

    1.4k GitHub stars~1.7k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Dotagents

    getsentry/sentry-wizard

    Official

    Manage agent skill dependencies with dotagents. An agent skill from getsentry/sentry-wizard.

    295 GitHub stars~900 tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Release

    tractorjuice/arc-kit

    Cut a new ArcKit release — bump versions in lockstep, regenerate non-Claude formats, validate plugin/marketplace agreement, tag, and push to standalone repos.

    2.3k GitHub stars~3k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Devcontainer Dev

    stacklok/toolhive-studio

    Spin up and interact with ToolHive Studio's containerized dev environment (Xvfb + noVNC + DinD).

    170 GitHub stars~3.8k tokensUpdated today
    Agent WorkflowsAuto-check: notes
  • Vibe Kanban

    aiskillstore/marketplace

    Manage AI coding agents on a visual Kanban board. An agent skill from aiskillstore/marketplace.

    430 GitHub stars~4.4k tokensUpdated today
    Agent WorkflowsAuto-check: notes

More from uvwt/agentdock

  • Skill Authoring

    uvwt/agentdock

    创建、设计、修改、重构和验证 AgentDock Skill 时使用;负责 Agent Skills 兼容的 SKILL.md、可移植核心、引用、辅助脚本、测试、安全边界和本地真实验证。

    1.2k GitHub stars~1.5k tokensUpdated today
    Auto-check: notes
  • Agentdock User Guide

    uvwt/agentdock

    当用户询问 AgentDock 是什么、如何使用、配置在哪里、不同平台或安装方式怎样修改配置并生效、如何重启或验证配置、如何发现并配置 Codex/Claude/Grok 等 Coding Agent 的 ACP,以及常见运行问题时使用;覆盖 macOS Desktop、Windows Desktop、Linux 服务、Docker 和直接运行二进制,不用于源码开发与贡献流程。

    1.2k GitHub stars~1.6k tokensUpdated today
    Auto-check passed

Categories

Questions about Plugin Import

What does Plugin Import do?

当用户要安装或更新来自 Git、GitHub、外部插件市场或其他远程来源的 Plugin 时使用;负责把远程来源固定并取得到本地,再交给 pluginmanage 自动识别 Portable/OpenAI/Claude 格式、审核和安装。. Plugin Import is an agent skill from uvwt/agentdock.

When should I use Plugin Import?

Plugin Import fits situations like: agent Workflows work in your project.

How do I install Plugin Import in Claude Code?

Run `npx skills add uvwt/agentdock --skill plugin-import -a claude-code`. Or copy the skill folder (core-skills/plugin-import in uvwt/agentdock) into .claude/skills/plugin-import in your project. Claude Code loads it when a task matches its description.

How do I install Plugin Import in Codex?

Run `npx skills add uvwt/agentdock --skill plugin-import -a codex`. Or copy the skill folder (core-skills/plugin-import in uvwt/agentdock) into .agents/skills/plugin-import in your project. Codex loads it when a task matches its description.

Can I use Plugin Import in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add uvwt/agentdock --skill plugin-import -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/plugin-import, .gemini/skills/plugin-import, .github/skills/plugin-import and .opencode/skills/plugin-import in your project.

What does Plugin Import need to run?

SKILL.md names no scripts, command-line tools or credentials: Plugin Import is instructions for the agent only.

Does Plugin Import access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Plugin Import safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Plugin Import use?

Plugin Import is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Plugin Import use?

About 839 tokens (SKILL.md is roughly 3.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.2k tokens, read only when the agent opens those files.

What are the alternatives to Plugin Import?

Skills that share tags, products or a category with Plugin Import: Codexless Release Supervisor (liyana31811/Codexless, 118 stars), MCP Apps Builder (awslabs/cli-agent-orchestrator, 1.4k stars), Dotagents (getsentry/sentry-wizard, 295 stars) and Release (tractorjuice/arc-kit, 2.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Plugin Import?

uvwt (a GitHub user) maintains it in uvwt/agentdock, which has 1,173 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 7, 2026.

Source: uvwt/agentdock on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.