Hook Development for Claude Code Plugins
anthropics/claude-plugins-official
Explains how to write Claude Code plugin hooks, both prompt-based checks and bash commands, for events such as PreToolUse, Stop and SessionStart.
How to design plugins: architecture, artifact choice, manifests, marketplaces.
$ npx skills add xiaolai/nlpm --skill writing-plugins -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install xiaolai/nlpm writing-plugins --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/xiaolai/nlpm.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/nlpm/writing-plugins .claude/skills/writing-plugins && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "writing-plugins" agent skill from https://github.com/xiaolai/nlpm/tree/main/skills/nlpm/writing-plugins into .claude/skills/writing-plugins/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "writing-plugins", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/xiaolai/nlpm/tree/main/skills/nlpm/writing-pluginsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add xiaolai/nlpm --skill writing-plugins -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install xiaolai/nlpm writing-plugins --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/xiaolai/nlpm.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/nlpm/writing-plugins .agents/skills/writing-plugins && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "writing-plugins" agent skill from https://github.com/xiaolai/nlpm/tree/main/skills/nlpm/writing-plugins into .agents/skills/writing-plugins/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "writing-plugins", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add xiaolai/nlpm --skill writing-plugins -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install xiaolai/nlpm writing-plugins --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/xiaolai/nlpm.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/nlpm/writing-plugins .cursor/skills/writing-plugins && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "writing-plugins" agent skill from https://github.com/xiaolai/nlpm/tree/main/skills/nlpm/writing-plugins into .cursor/skills/writing-plugins/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "writing-plugins", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/xiaolai/nlpm.git --path skills/nlpm/writing-plugins--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add xiaolai/nlpm --skill writing-plugins -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install xiaolai/nlpm writing-plugins --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/xiaolai/nlpm.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/nlpm/writing-plugins .gemini/skills/writing-plugins && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "writing-plugins" agent skill from https://github.com/xiaolai/nlpm/tree/main/skills/nlpm/writing-plugins into .gemini/skills/writing-plugins/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "writing-plugins", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install xiaolai/nlpm writing-pluginsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add xiaolai/nlpm --skill writing-plugins -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/xiaolai/nlpm.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/nlpm/writing-plugins .github/skills/writing-plugins && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "writing-plugins" agent skill from https://github.com/xiaolai/nlpm/tree/main/skills/nlpm/writing-plugins into .github/skills/writing-plugins/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "writing-plugins", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add xiaolai/nlpm --skill writing-plugins -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install xiaolai/nlpm writing-plugins --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/xiaolai/nlpm.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/nlpm/writing-plugins .opencode/skills/writing-plugins && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "writing-plugins" agent skill from https://github.com/xiaolai/nlpm/tree/main/skills/nlpm/writing-plugins into .opencode/skills/writing-plugins/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "writing-plugins", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
writing-pluginsHow to design plugins: architecture, artifact choice, manifests, marketplaces.
Writing Plugins is an agent skill from xiaolai/nlpm. How to design plugins: architecture, artifact choice, manifests, marketplaces.
Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Agent Workflows, covering Hooks and plugins. The repository describes itself as: Natural-Language Programming Manager — scan, lint, and score NL artifacts with Claude-native quality scoring. The licence is ISC.
10 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 6fdbd05. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
claudenpxFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Writing Plugins loads about 3.5k tokens when it runs. Until then it costs about 24 tokens; SKILL.md has 1,264 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from xiaolai/nlpm at commit 6fdbd05, republished under its ISC licence (© xiaolai). 1,264 words, ~3,531 tokens.
.claude/skills/writing-plugins/SKILL.md (or your agent's skills folder).Scope: covers plugin design and architecture. The examples use the Claude Code layout (
.claude-plugin/plugin.json+ auto-discoveredcommands/,agents/,skills/,hooks/). The same artifact-selection and architecture reasoning maps to the other tools — only the manifest path and packaging differ:
- Codex CLI:
.codex-plugin/plugin.jsonmanifest +.agents/plugins/marketplace.json; skills live at.agents/skills/. See [[nlpm:conventions-codex]].- Antigravity:
gemini-extension.json(becoming "Antigravity plugins"); skills at.agent/skills/. See [[nlpm:conventions-antigravity]].- Cross-tool skills: a
SKILL.mdcollection with no plugin wrapper installs into any tool vianpx skills add. See [[writing-skills]].For individual artifact authoring, see [[writing-skills]], [[writing-agents]], [[writing-hooks]], [[writing-rules]].
A plugin is a collection of NL artifacts that work together. Before writing anything, decide which artifacts you need.
| User need | Artifact | Example |
|---|---|---|
| User runs a slash command | Command | /nlpm:score path/to/file.md |
| AI works autonomously on a task | Agent | Security scanner dispatched by a command |
| Domain knowledge for agents/Claude | Skill | SKILL.md with patterns and decision tables |
| Something must happen automatically on events | Hook | Lint-on-save, block force push |
| External service integration | MCP server (.mcp.json) | GitHub API, Slack notifications |
The smallest useful plugin has one artifact:
my-plugin/
.claude-plugin/
plugin.json
commands/
do-thing.mdDon't add agents, skills, or hooks until you need them. Each artifact adds maintenance burden.
Command does everything itself. No agents, no orchestration.
Command receives input --> processes --> outputs resultUse when: task is simple, deterministic, single-step.
Example: loc-guardian /scan -- counts lines, checks limits, reports.
File structure:
my-plugin/
.claude-plugin/plugin.json
commands/do-thing.mdCommand parses input and dispatches one agent for heavy work.
Command parses input --> dispatches agent --> formats outputUse when: task requires AI judgment but has a clear entry point.
Example: /nlpm:score dispatches a scorer agent.
File structure:
my-plugin/
.claude-plugin/plugin.json
commands/analyze.md
agents/analyzer.mdCommand dispatches 2–6 agents in parallel, synthesizes results.
Command --> agent-1 (security)
--> agent-2 (performance) --> synthesize --> output
--> agent-3 (architecture)Use when: multiple independent analyses of the same input. Example: grill dispatches 6 review agents in parallel.
File structure:
my-plugin/
.claude-plugin/plugin.json
commands/review.md
agents/
security-agent.md
performance-agent.md
architecture-agent.mdEach agent feeds into the next. Stages have different model requirements.
Command --> parse (haiku) --> analyze (sonnet) --> QC (sonnet) --> outputUse when: multi-phase processing where each phase depends on the previous. Example: reading-assistant's 4-phase pipeline.
File structure:
my-plugin/
.claude-plugin/plugin.json
commands/process.md
agents/
parser.md # haiku
analyzer.md # sonnet
qc-agent.md # sonnetPlugin enforces policy silently via hooks. No user-facing commands.
Event fires --> hook checks --> allow/deny/adviseUse when: enforcement should be automatic, not user-initiated. Example: tdd-guardian's pre-commit quality gate.
File structure:
my-plugin/
.claude-plugin/plugin.json
hooks/hooks.json
scripts/check.sh| Question | Yes --> | No --> |
|---|---|---|
| Does the user explicitly trigger it? | Needs a command | Hooks only |
| Does it require AI judgment? | Needs agents | Command-only or hooks |
| Are there independent sub-analyses? | Parallel agents | Sequential or single agent |
| Does each step depend on the previous? | Sequential pipeline | Parallel or single |
| Should it run automatically on events? | Add hooks | Commands only |
| Does Claude need domain knowledge? | Add skills | No skills needed |
Only name is strictly required:
{
"name": "my-plugin"
}Ship with these for discoverability and marketplace listing:
{
"name": "my-plugin",
"version": "0.1.0",
"description": "What this plugin does in one sentence",
"author": { "name": "your-name" },
"license": "MIT",
"keywords": ["relevant", "search", "terms"]
}category is not a manifest field: it belongs to the plugin's entry in a marketplace.json (see §9 and nlpm:conventions-claude §1). Claude Code ignores it in plugin.json.
| Field | Purpose | Example |
|---|---|---|
name | Unique identifier, used in slash commands | "nlpm" |
version | Semver, used by marketplace and update checks | "0.1.0" |
description | One-line summary for marketplace listing | "NL programming quality tools" |
author.name | Creator attribution | "xiaolai" |
license | Open source license | "MIT" |
keywords | Search terms for marketplace discovery | ["linter", "quality"] |
my-plugin/
.claude-plugin/
plugin.json # manifest (required)
marketplace.json # for marketplace publishing
commands/ # auto-discovered by Claude Code
do-thing.md # user-invocable: /plugin:do-thing
advanced-thing.md
shared/ # non-invocable partials
common-logic.md # user-invocable: false
format-output.md
agents/ # auto-discovered
worker.md
reviewer.md
skills/ # auto-discovered
my-plugin/
domain-knowledge/
SKILL.md
advanced-topic/
SKILL.md
references/
deep-dive.md
hooks/
hooks.json # hook definitions
scripts/ # hook scripts, utilities
check.sh
validate.sh
AGENTS.md # developer notes and architecture (for the model); no root CLAUDE.md
README.md # user documentation (for humans)
LICENSE| Directory | Auto-discovered? | What goes here |
|---|---|---|
.claude-plugin/ | Yes (manifest) | Plugin metadata |
commands/ | Yes | Slash command definitions |
commands/shared/ | Yes (but not invocable) | Shared command logic |
agents/ | Yes | Agent definitions |
skills/ | Yes | Domain knowledge |
hooks/ | Yes (hooks.json) | Event hooks |
scripts/ | No | Shell scripts, utilities |
| Artifact | File naming | Example |
|---|---|---|
| Commands | kebab-case, descriptive verb | scan-files.md, generate-report.md |
| Agents | kebab-case, role-noun | security-reviewer.md, parser.md |
| Skills | kebab-case directory, always SKILL.md | skills/my-plugin/react-patterns/SKILL.md |
| Hook scripts | kebab-case, descriptive | check-loc.sh, validate-config.sh |
| Change type | Bump | Example |
|---|---|---|
| Bug fixes, typo corrections, penalty adjustments | Patch: 0.1.0 -> 0.1.1 | Fix scoring formula |
| New commands, new agents, new features | Minor: 0.1.0 -> 0.2.0 | Add /plugin:export command |
| Breaking changes (renamed commands, removed features) | Major: 0.1.0 -> 1.0.0 | Rename /scan to /analyze |
When bumping version, update in four places:
| Location | File | Field |
|---|---|---|
| 1. Plugin manifest | .claude-plugin/plugin.json | version |
| 2. Plugin marketplace | .claude-plugin/marketplace.json | version in the plugin's entry |
| 3. Central marketplace manifest | ~/.claude/plugins/marketplaces/xiaolai/.claude-plugin/marketplace.json | version |
| 4. Central marketplace README | ~/.claude/plugins/marketplaces/xiaolai/README.md | Version in the table |
Order: push plugin repo first, then update central marketplace. The marketplace points to the repo -- if the repo isn't updated yet, users pull stale code.
Your plugin's AGENTS.md is for the model (Claude, Codex), not the user. It tells the model how the plugin's artifacts relate to each other. Claude Code 2.1.277+ reads AGENTS.md natively. Do not put a CLAUDE.md at the plugin root: it is not loaded as plugin context, claude plugin validate warns about it, and while it exists Claude Code skips AGENTS.md in that directory (see nlpm:conventions-claude §10).
# my-plugin
## Architecture
Brief description of what the plugin does and how artifacts interact.
## Artifacts
### Commands
| Command | Purpose |
|---------|---------|
| /plugin:scan | Discovers and inventories files |
| /plugin:fix | Auto-fixes issues found by scan |
### Agents
| Agent | Model | Role |
|-------|-------|------|
| scanner | haiku | Mechanical file discovery |
| fixer | sonnet | AI-powered fix generation |
### Conventions
- All agents output findings in severity-tagged format
- Scanner runs before fixer (sequential dependency)
- Hook scripts use fail-open patternExtract repeated logic into commands/shared/*.md with user-invocable: false.
---
user-invocable: false
description: "Shared config loading logic"
---| Partial | Content | When to extract |
|---|---|---|
shared/load-config.md | Read and validate config file | 3+ commands need config |
shared/discover-files.md | Find target files by pattern | 3+ commands scan files |
shared/validate-prereqs.md | Check tool availability | 2+ commands need same tools |
shared/format-report.md | Report header, footer, severity format | 3+ commands output reports |
| Check | How | Pass criteria |
|---|---|---|
| Structure validation | claude plugin validate /path/to/plugin | No errors |
| Command: no args | Run each command with no arguments | Helpful error or usage message |
| Command: normal args | Run each command with typical input | Correct output |
| Command: edge cases | Empty files, huge files, missing files | Graceful error handling |
| Agent triggering | Try queries that should and shouldn't trigger | Correct dispatch decisions |
| Hook scripts | chmod +x check, run with test JSON | Valid JSON output |
| Hook fail-open | Kill script mid-execution | Action is allowed |
For each agent, test with 3 types of queries:
| Query type | Expected | Example |
|---|---|---|
| Direct match | Agent triggers | "Scan this code for security issues" |
| Adjacent topic | Agent may or may not trigger | "Is this code okay?" |
| Unrelated | Agent does NOT trigger | "What's the weather?" |
marketplace.json (name, source, description, version, author, license, keywords, category)README.md version tableclaude plugin install my-plugin@xiaolai --scope projectPre-publish checks: claude plugin validate ., verify no hardcoded paths (grep -r '/Users/' commands/ agents/ hooks/), verify all scripts executable, verify version matches in all 4 locations.
| Mistake | Impact | Fix |
|---|---|---|
| Commands that do too much | Hard to maintain, unreliable | Split into focused commands |
| Agents without examples | 40% trigger accuracy | Add 1 specific scenario example in the description + a "Not for" sentence |
| Skills over 500 lines | Context bloat, slow loading | Extract to references/ subdirectory |
| Hooks that block without explanation | Frustrating UX | Always include permissionDecisionReason |
| No AGENTS.md | Claude doesn't understand plugin architecture | Add architecture overview to AGENTS.md (no root CLAUDE.md) |
| README documents internals | Users confused by implementation details | README = user guide, AGENTS.md = internals |
| Hardcoded paths | Breaks on other machines | Use the plugin-root variable $+{CLAUDE_PLUGIN_ROOT} everywhere (split by a + so Claude Code does not replace it when it loads this skill; the real token has no +) |
| No error handling in commands | Silent failures | Add explicit error cases |
| Version not updated in all 4 places | Marketplace shows wrong version | Use the four-place update checklist |
| Premature extraction into shared/ | Over-abstracted, harder to understand | Extract only when 3+ consumers exist |
© xiaolai, ISC. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/nlpm/writing-plugins of xiaolai/nlpm.
Open the folder on GitHubat commit 6fdbd05
Writing Plugins next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Writing Plugins this skillxiaolai/nlpm | 146 | — | ~3.5k | Automated safety check: Pass | ISC | |
| Hook Development for Claude Code Pluginsanthropics/claude-plugins-official | 38k | 11 repos | ~4.1k | Automated safety check: Notes | Apache-2.0 | |
| Claude Code Agent Developmentanthropics/claude-plugins-official | 38k | 8 repos | ~2.8k | Automated safety check: Pass | Apache-2.0 | |
| Claude Code Skill Developer Guidediet103/claude-code-infrastructure-showcase | 10k | 11 repos | ~3.5k | Automated safety check: Pass | MIT | |
| Plugin Settings Patternanthropics/claude-plugins-official | 38k | 7 repos | ~3k | Automated safety check: Pass | Apache-2.0 | |
| MCP Integration for Pluginsanthropics/claude-plugins-official | 38k | 11 repos | ~3.1k | Automated safety check: Pass | Apache-2.0 |
anthropics/claude-plugins-official
Explains how to write Claude Code plugin hooks, both prompt-based checks and bash commands, for events such as PreToolUse, Stop and SessionStart.
anthropics/claude-plugins-official
Explains how to write agents for Claude Code plugins: the markdown file with YAML frontmatter, trigger descriptions, model and color settings, and system prompt design.
diet103/claude-code-infrastructure-showcase
A guide to creating and managing Claude Code skills with auto-activation: skill-rules.json triggers, hooks, enforcement levels, YAML frontmatter and progressive disclosure.
anthropics/claude-plugins-official
Shows how Claude Code plugins keep per-project settings and state in .claude/plugin-name.local.md files with YAML frontmatter and a markdown body.
anthropics/claude-plugins-official
Explains how to bundle Model Context Protocol servers in a Claude Code plugin, covering config files, stdio, SSE, HTTP and WebSocket server types, and authentication.
anthropics/claude-plugins-official
Explains how to write Claude Code slash commands: Markdown files with YAML frontmatter, arguments, file references, bash context and interactive prompts.
xiaolai/nlpm
Universal NL conventions: SKILL.md open spec, AGENTS.md, vague quantifiers, naming.
xiaolai/nlpm
Antigravity and Gemini CLI artifact schemas: .gemini/ paths, extensions, hooks.
xiaolai/nlpm
Codex CLI artifact schemas: config.toml, .codex-plugin, skills, hooks, AGENTS.md.
xiaolai/nlpm
Multi-agent workflow patterns: parallel dispatch, pipelines, QC gates, retries.
xiaolai/nlpm
NL artifact anti-patterns: vague quantifiers, bare prohibitions, oversized skills.
xiaolai/nlpm
100-point NL artifact rubric: penalty tables per artifact type, calibration cases.
Categories
How to design plugins: architecture, artifact choice, manifests, marketplaces. Writing Plugins is an agent skill from xiaolai/nlpm. How to design plugins: architecture, artifact choice, manifests, marketplaces.
Writing Plugins fits situations like: tasks that involve Hooks and plugins.
Run `npx skills add xiaolai/nlpm --skill writing-plugins -a claude-code`. Or copy the skill folder (skills/nlpm/writing-plugins in xiaolai/nlpm) into .claude/skills/writing-plugins in your project. Claude Code loads it when a task matches its description.
Run `npx skills add xiaolai/nlpm --skill writing-plugins -a codex`. Or copy the skill folder (skills/nlpm/writing-plugins in xiaolai/nlpm) into .agents/skills/writing-plugins in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add xiaolai/nlpm --skill writing-plugins -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/writing-plugins, .gemini/skills/writing-plugins, .github/skills/writing-plugins and .opencode/skills/writing-plugins in your project.
Going by SKILL.md and its folder, Writing Plugins needs the command-line tools its instructions call (claude and npx). Our summary lists: Node.js.
SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Writing Plugins is published under the ISC licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Writing Plugins: Hook Development for Claude Code Plugins (anthropics/claude-plugins-official, 38k stars), Claude Code Agent Development (anthropics/claude-plugins-official, 38k stars), Claude Code Skill Developer Guide (diet103/claude-code-infrastructure-showcase, 10k stars) and Plugin Settings Pattern (anthropics/claude-plugins-official, 38k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
xiaolai (a GitHub user) maintains it in xiaolai/nlpm, which has 146 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 8, 2026.
Source: xiaolai/nlpm on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.