Migrate Internal Package into Ghost
TryGhost/Ghost
Moves a package from another TryGhost repository into Ghost as an internal workspace package while keeping its Git history, with checkpoints for the steps that need an administrator.
A skill your agent uses when creating, reviewing, or refactoring a WrongStack plugin in packages/plugins/.
$ npx skills add WrongStack/WrongStack --skill plugin-author -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install WrongStack/WrongStack plugin-author --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .claude/skills && cp -r skills-src/packages/core/skills/plugin-author .claude/skills/plugin-author && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "plugin-author" agent skill from https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/plugin-author into .claude/skills/plugin-author/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "plugin-author", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/plugin-authorType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add WrongStack/WrongStack --skill plugin-author -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install WrongStack/WrongStack plugin-author --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .agents/skills && cp -r skills-src/packages/core/skills/plugin-author .agents/skills/plugin-author && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "plugin-author" agent skill from https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/plugin-author into .agents/skills/plugin-author/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "plugin-author", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add WrongStack/WrongStack --skill plugin-author -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install WrongStack/WrongStack plugin-author --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/packages/core/skills/plugin-author .cursor/skills/plugin-author && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "plugin-author" agent skill from https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/plugin-author into .cursor/skills/plugin-author/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "plugin-author", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/WrongStack/WrongStack.git --path packages/core/skills/plugin-author--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add WrongStack/WrongStack --skill plugin-author -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install WrongStack/WrongStack plugin-author --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/packages/core/skills/plugin-author .gemini/skills/plugin-author && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "plugin-author" agent skill from https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/plugin-author into .gemini/skills/plugin-author/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "plugin-author", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install WrongStack/WrongStack plugin-authorInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add WrongStack/WrongStack --skill plugin-author -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .github/skills && cp -r skills-src/packages/core/skills/plugin-author .github/skills/plugin-author && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "plugin-author" agent skill from https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/plugin-author into .github/skills/plugin-author/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "plugin-author", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add WrongStack/WrongStack --skill plugin-author -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install WrongStack/WrongStack plugin-author --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/packages/core/skills/plugin-author .opencode/skills/plugin-author && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "plugin-author" agent skill from https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/plugin-author into .opencode/skills/plugin-author/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "plugin-author", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
plugin-authorA skill your agent uses when creating, reviewing, or refactoring a WrongStack plugin in packages/plugins/.
Plugin Author is an agent skill from WrongStack/WrongStack. Use this skill when creating, reviewing, or refactoring a WrongStack plugin in packages/plugins/. Covers the Plugin interface, tool registration, config schema, the H1 audit pattern (teardown + health), PluginAPI extension for host data, and the entry-point registration steps (package.json and index.ts). Triggers: user says "new plugin", "add a plugin", "plugin teardown", "plugin health", "register a tool", "PluginAPI extension".
Its SKILL.md is about 4.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Refactoring. It works with npm and Git. The repository describes itself as: An AI coding agent that reads your code, edits files, runs commands, and reasons through bugs — across a terminal REPL, a full-screen TUI, and a browser UI, while you keep your… The licence is MIT.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 57f6018. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pnpmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use pnpm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Plugin Author loads about 4.1k tokens when it runs. Until then it costs about 112 tokens; SKILL.md has 1,305 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from WrongStack/WrongStack at commit 57f6018, republished under its MIT licence (© WrongStack). 1,305 words, ~4,146 tokens.
.claude/skills/plugin-author/SKILL.md (or your agent's skills folder).Guides the creation and maintenance of first-party plugins in
packages/plugins/. A plugin is a TypeScript module that implements
the Plugin interface from @wrongstack/core, registering tools,
hooks, slash commands, or pipelines into the agent's runtime.
There are currently 21 official plugins in the suite:
| Plugin | Tools | Hooks | Stateful |
|---|---|---|---|
auto-doc | auto_doc | — | ✅ teardown+health |
git-autocommit | git_autocommit | — | ✅ teardown+health |
shell-check | shellcheck | — | ✅ teardown+health |
cost-tracker | cost_summary, cost_reset, cost_export | — | ✅ teardown+health |
file-watcher | watch_start, watch_stop, watch_list | — | ✅ teardown+health |
cron | cron_schedule, cron_list, cron_cancel | — | ✅ teardown+health |
template-engine | template_expand, template_render, template_create, template_list | — | ✅ teardown+health |
semver-bump | semver_bump, semver_current, semver_changelog | — | ✅ teardown+health |
secret-scanner | secret_scanner_status, secret_scanner_test | PreToolUse + PostToolUse | ✅ teardown+health |
todo-tracker | todo_tracker_list/add/complete/drop/remove/pull/status | — | ✅ teardown+health |
token-budget | token_budget_status | Stop + PostToolUse | ✅ teardown+health |
lint-gate | lint_gate_status | PreToolUse (write|edit) | ✅ teardown+health |
branch-guard | branch_guard_status | PreToolUse (bash|git_autocommit) | ✅ teardown+health |
diff-summary | diff_summary_status | PostToolUse (write|edit) | ✅ teardown+health |
commit-validator | commit_validator_status | PreToolUse (bash|git_autocommit) | ✅ teardown+health |
format-on-save | format_on_save_status | PostToolUse (write|edit) | ✅ teardown+health |
test-runner-gate | test_gate_status | PostToolUse (write|edit) | ✅ teardown+health |
import-organizer | import_organizer_status | PostToolUse (write|edit) | ✅ teardown+health |
todo-listener | todo_listener_status | PostToolUse (todo) | ✅ teardown+health |
session-recap | session_recap_status | Stop | ✅ teardown+health |
spec-linker | spec_linker_status | PostToolUse (write|edit) | ✅ teardown+health |
teardown() and health(). Even
stateless plugins (shell-check, semver-bump) add both — the teardown
logs a completion line with per-session counters, and health()
reports ok: true + counters for /diag plugins. This is the H1
audit pattern (see below).setup() → teardown(). If
teardown needs to clean up a resource (timer, watcher, counter),
the reference must live at module scope. State in the setup
closure is unreachable from teardown and leaks on reload.setup() is idempotent. It must zero/clear state before
re-initializing. Calling setup() twice (e.g. across a hot-reload)
leaves a clean slate, not accumulated state.teardown() never deletes on-disk state. File-based plugins
(todo-tracker) leave the file in place — the user may return. Only
in-memory counters and resource handles (timers, watchers) are
cleaned up.snake_case. Plugin-level tools registered via
api.tools.register() must be unique across the suite. The built-in
tools (bash, write, read, edit, fetch, search, json,
todo, git, etc.) are always present; don't collide.apiVersion must satisfy ^0.1 (current kernel API = 0.1.10).
Bump only when the PluginAPI surface breaks. Additive changes (new
optional fields on PluginAPI) do NOT require a bump.config.extensions['<plugin-name>'], not
config.plugins. The loader's buildPluginOptions merges both
surfaces; plugins read from api.config.extensions.import type { Plugin } from '@wrongstack/core';
const plugin: Plugin = {
name: 'my-plugin',
version: '0.1.0',
description: 'One-line summary for wstack plugins list',
apiVersion: '^0.1.10',
capabilities: { tools: true }, // hints for /diag
// Optional: JSON Schema for config validation
defaultConfig: { enabled: true },
configSchema: {
type: 'object',
properties: {
enabled: { type: 'boolean', default: true },
},
},
// Called by the host to activate the plugin.
setup(api) { /* register tools, hooks, events */ },
// Called by the host during unload. Same api instance as setup.
teardown(api) { /* clear state, release resources, log */ },
// Called by /diag plugins. Return ok + message + counters.
async health() {
return { ok: true, message: 'healthy', invocationCount: 0 };
},
};
export default plugin;After the 2026-06-03 audit found that several plugins leaked resources on reload (timers, chokidar watchers, in-memory caches unreachable from teardown), the following lifecycle pattern was formalized. Every plugin in the suite follows it.
// ✅ Module scope — teardown can reach this
const state = {
invocationCount: 0,
timers: new Map<string, NodeJS.Timeout>(),
lastRun: null as null | { when: string; result: string },
};
// ❌ NEVER — setup closure, unreachable from teardown
setup(api) {
const timers = new Map(); // LEAKS on reload
}setup(api) {
// Clear everything first, then re-init from config.
state.invocationCount = 0;
for (const t of state.timers.values()) clearTimeout(t);
state.timers.clear();
state.lastRun = null;
// Now register tools, apply config, subscribe to events.
api.tools.register({ /* ... */ });
}teardown(api) {
const count = state.invocationCount;
state.invocationCount = 0;
state.lastRun = null;
// Release every resource that was acquired in setup().
for (const t of state.timers.values()) clearTimeout(t);
state.timers.clear();
api.log.info('my-plugin: teardown complete', { invocations: count });
}async health() {
return {
ok: true,
message: state.lastRun === null
? 'my-plugin: no calls yet'
: `my-plugin: last call at ${state.lastRun.when}`,
invocationCount: state.invocationCount,
lastRun: state.lastRun,
};
}api.tools.register({
name: 'my_tool',
description: 'What this tool does. Include when to use and what it returns.',
inputSchema: {
type: 'object',
properties: {
path: { type: 'string', description: 'File path' },
},
required: ['path'],
},
permission: 'auto', // 'auto' | 'confirm'
mutating: false, // does it change external state?
category: 'Project',
async execute(input: Record<string, unknown>) {
const path = input['path'] as string;
// ... do the work ...
return { path, result: '...' };
},
});Signal failure by throwing. The executor marks a call failed only when
execute() throws (throw a ToolValidationError for bad input). A returned
{ ok: false }, { status: 'error' }, or "Error: ..." string is recorded
and shown as a SUCCESS. Return normally only for real data outcomes (zero
results, a check that computed "no").
| Permission | When |
|---|---|
auto | Safe operations (read, list, query). No user confirmation. |
confirm | Destructive or side-effecting operations (write, commit, delete). User must approve. |
Two surfaces exist. The loader merges them:
config.plugins — loading control: [{ name: 'my-plugin', enabled: false }]config.extensions['my-plugin'] — options: { option1: value1 }Plugins read from api.config.extensions:
setup(api) {
const ext = api.config.extensions?.['my-plugin'] as Record<string, unknown> | undefined;
const myOption = (ext?.['myOption'] as string) ?? 'default';
}If the plugin declares configSchema, the loader validates the
options section before calling setup and rejects the plugin with a
clear error on failure.
// secret-scanner pattern: block tools whose args contain secrets
api.registerHook('PreToolUse', 'bash|write|edit', (input) => {
const text = JSON.stringify(input.toolInput ?? {});
if (detectSecret(text)) {
return {
decision: 'block',
reason: 'Plaintext credential detected in tool arguments',
};
}
// Omitted decision = allow (no-op)
});Available events: PreToolUse, PostToolUse, UserPromptSubmit,
SessionStart, Stop, plus the observational Notification,
SubagentStart, SubagentStop, PreCompact, PostCompact and SessionEnd
(their outcome is ignored — they cannot block or add context).
HookOutcome fields:
decision: 'block' | 'allow' — block stops the actionreason: string — surfaced to the model when blockingmodifiedInput: Record<string, unknown> — PreToolUse replacement argsadditionalContext: string — extra context folded back to the modelWhen a plugin needs host data not yet on PluginAPI (e.g.
modelsRegistry, projectDir), extend the surface in three steps:
packages/core/src/types/plugin.ts — add the optional field to PluginAPIpackages/core/src/plugin/api.ts — add to PluginAPIInit + DefaultPluginAPIpackages/cli/src/wiring/plugins.ts — destructure + forward in setupPluginsPrecedent: commit 9bed619f added modelsRegistry?: ModelsRegistry for
cost-tracker's pricing hydration.
After writing src/<name>/index.ts, wire it into two package files. The
central scripts/build-package.mjs driver discovers plugin entry points from
the exports map automatically.
src/index.ts — named re-exportexport { default as myPluginPlugin } from './my-plugin/index.js';package.json — subpath export"./my-plugin": {
"types": "./dist/my-plugin.d.ts",
"import": "./dist/my-plugin.js"
}packages/cli/src/wiring/plugins.ts — built-in factoryasync () => (await import('@wrongstack/plugins/my-plugin')).default,Every plugin gets two test files:
tests/<name>.test.ts — unit tests (mock API, tool registration,
config validation, teardown log line, health() shape)tests/<name>-exec.test.ts — integration tests (real filesystem,
real CLI tools if applicable)For the H1 pattern, extend tests/plugin-teardown.test.ts with a
describe('<name>') block covering:
teardown logs a completion line and does not throwhealth() reports ok + non-empty messageteardown zeros counters/diag plugins shows a gap; reload leaks.read, write, bash, etc. are built-in.void (async () => { ... })()
for fire-and-forget; let the first call fall through to fallback if
the async hasn't completed yet.model.toLowerCase() everywhere.src/<name>/index.tssetup()index.ts and package.jsonBUILTIN_PLUGIN_FACTORIES in CLI wiring<name>.test.ts (unit) + extend plugin-teardown.test.tspnpm --filter @wrongstack/plugins test + pnpm --filter @wrongstack/plugins typecheck + pnpm --filter @wrongstack/plugins buildsrc/index.ts doc comment — bump the plugin countsetup() closure. State must live at module scope; the Plugin interface does not thread state from setup() to teardown(). Closure state leaks on reload.teardown() and health(). Even stateless plugins add both. The H1 audit pattern is the floor; /diag plugins exposes the gap.setup() non-idempotent. Calling setup() twice must leave a clean slate. Hot-reload must not accumulate state.teardown(). File-based plugins leave the file in place. Only in-memory counters and resource handles (timers, watchers) are cleaned.read, write, bash, edit, fetch, search, json, todo, git are reserved. Pick unique names; api.tools.register() enforces uniqueness.apiVersion for additive changes. New optional fields on PluginAPI don't break the contract. Bump only when the surface breaks.config.plugins. Config options go under config.extensions['<plugin-name>']. The loader's buildPluginOptions merges both, but the convention is extensions.setup() with async hydration. Use void (async () => { ... })() for fire-and-forget. The first call should fall through to fallback if the async hasn't completed.tests/<name>.test.ts (unit) and tests/<name>-exec.test.ts (integration) are required. Plugins without tests rot fast.model.toLowerCase() everywhere.name, version, apiVersion: '^0.1.x' (current), description, capabilities setsetup() closuresetup() idempotent: clears state before re-initializingteardown() releases every resource acquired in setup(), never deletes on-disk statehealth() returns { ok, message, invocationCount, lastRun? }snake_case; no collision with built-insapi.config.extensions['<plugin-name>'], validated by configSchemaapi.registerHook(...) with the correct event/matcher; HookOutcome shape honoredsrc/index.ts re-exports the plugin; package.json adds the subpath exportpackages/cli/src/wiring/plugins.ts adds the built-in factory<name>.test.ts + <name>-exec.test.ts + plugin-teardown.test.ts blockpnpm --filter @wrongstack/plugins test && typecheck && build all passsrc/index.ts doc comment updated with the new plugin count<nextsteps> lists each open follow-up (config, hooks, tests, build)skill-creator — for the SKILL.md format and frontmatter rulesprompt-engineering — for crafting tool descriptions and usageHinttypescript-strict — for strict TypeScript patterns in plugin codenode-modern — for ESM imports, AbortSignal, and async patternstesting — for vitest patterns and mock API constructionoutput-standards — for standardized <nextsteps> formatting© WrongStack, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in packages/core/skills/plugin-author of WrongStack/WrongStack.
Open the folder on GitHubat commit 57f6018
Plugin Author next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Plugin Author this skillWrongStack/WrongStack | 370 | — | ~4.1k | Automated safety check: Pass | MIT | |
| Migrate Internal Package into GhostTryGhost/Ghost | 55k | — | ~3.8k | Automated safety check: Pass | MIT | |
| Open Code Review CLIalibaba/open-code-review | 44k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | |
| Codexskills-directory/skill-codex | 1.5k | 3 repos | ~1.8k | Automated safety check: Pass | MIT | |
| Open Code Review Delegatealibaba/open-code-review | 44k | — | ~2k | Automated safety check: Pass | Apache-2.0 | |
| Verdaccio Pull Request Workflowverdaccio/verdaccio | 18k | — | ~1.9k | Automated safety check: Pass | MIT |
TryGhost/Ghost
Moves a package from another TryGhost repository into Ghost as an internal workspace package while keeping its Git history, with checkpoints for the steps that need an administrator.
alibaba/open-code-review
Runs the ocr command-line tool to review Git changes, a commit or a branch comparison with an AI model, returning line-level comments and optionally applying fixes.
skills-directory/skill-codex
A skill your agent uses when the user asks to run Codex CLI (codex exec, codex resume) or references OpenAI Codex for code analysis, refactoring, or automated editing
alibaba/open-code-review
Has the host agent do the code review itself while the ocr CLI handles file selection and rule lookup, covering workspace changes, branch ranges or single commits.
verdaccio/verdaccio
Takes a change through a verdaccio pull request: branch, local checks, changeset, title and body, labels, CI and review rounds, and ports to other release lines.
yaklang/yakit
对 Yakit 仓库的代码改动做规范化 code review:按代码逻辑、TS 定义、UI 引用与 Props、CSS 样式、依赖版本、配置项六个维度审查,检查测试用例缺失,强制执行 tsc 类型检查与 vitest 测试验证,输出「结果汇总 / 明细解释 / 合并结论」三块报告,经用户确认后写入文件。当用户要求 review、审查、评审代码改动,或在提交、合并、提 PR…
WrongStack/WrongStack
Design or substantially improve user-facing interfaces with a product-specific visual direction, content hierarchy, and rendered critique.
WrongStack/WrongStack
A skill your agent uses to audit an interface that already exists and say precisely why it looks generated, templated, or unfinished — a scored rubric across composition, typography, color, states…
WrongStack/WrongStack
A skill your agent uses when external coding agents (Claude Code, Aider, custom scripts) need to participate in the project's shared WrongStack mailbox, or when a user asks to "expose the mailbox"…
WrongStack/WrongStack
A skill your agent uses whenever work can be split across multiple AI agents running in parallel, or when orchestrating leader/worker patterns in WrongStack.
WrongStack/WrongStack
Use this skill before asserting that a CSS, HTML or accessibility capability is available, unavailable, or the right tool — it carries dated, refreshable platform facts and refuses to let stale…
WrongStack/WrongStack
A skill your agent uses when the user wants to communicate with WrongStack's shared project mailbox from outside WrongStack — read messages sent by WrongStack agents, send replies, broadcast to all…
Categories
A skill your agent uses when creating, reviewing, or refactoring a WrongStack plugin in packages/plugins/. Plugin Author is an agent skill from WrongStack/WrongStack. Use this skill when creating, reviewing, or refactoring a WrongStack plugin in packages/plugins/.
Plugin Author fits situations like: refactoring a WrongStack plugin in packages/plugins/; tasks that involve Refactoring.
Run `npx skills add WrongStack/WrongStack --skill plugin-author -a claude-code`. Or copy the skill folder (packages/core/skills/plugin-author in WrongStack/WrongStack) into .claude/skills/plugin-author in your project. Claude Code loads it when a task matches its description.
Run `npx skills add WrongStack/WrongStack --skill plugin-author -a codex`. Or copy the skill folder (packages/core/skills/plugin-author in WrongStack/WrongStack) into .agents/skills/plugin-author in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add WrongStack/WrongStack --skill plugin-author -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/plugin-author, .gemini/skills/plugin-author, .github/skills/plugin-author and .opencode/skills/plugin-author in your project.
Going by SKILL.md and its folder, Plugin Author needs the command-line tools its instructions call (pnpm). Our summary lists: Node.js.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Plugin Author is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.1k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Plugin Author: Migrate Internal Package into Ghost (TryGhost/Ghost, 55k stars), Open Code Review CLI (alibaba/open-code-review, 44k stars), Codex (skills-directory/skill-codex, 1.5k stars) and Open Code Review Delegate (alibaba/open-code-review, 44k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
WrongStack (a GitHub organization) maintains it in WrongStack/WrongStack, which has 370 GitHub stars. The repository holds 38 skills in this directory. The repository was last updated on October 7, 2026.
Source: WrongStack/WrongStack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.