Skip to content

Commit e94d6c5

Browse files
fix(portable): declare install roles, per-surface shadowing, and planned paths
1 parent 24e3451 commit e94d6c5

10 files changed

Lines changed: 465 additions & 140 deletions

File tree

‎.changeset/portable-client-records.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,4 +2,4 @@
22
"agent-bundle": patch
33
---
44

5-
Record third-party clients of the emitted Agent Plugins artifact in the pinned portable capability table (`clients`), with the paths each client reads, the manifests that shadow them, its verbatim install commands, and a dated row per surface it does and does not load. `INSTALL.md` names, per client, only the discovery paths the built bundle actually carries, and the generated host reference renders the same records through the same validator instead of an unsourced list of native clients. A record fails the build when it claims a tier its own rows and paths do not support, marks a surface degraded or supported without dated evidence, names an artifact path with no evidence that it is read, or declares an install block with no command. (#721)
5+
Record third-party clients of the emitted Agent Plugins artifact in the pinned portable capability table (`clients`), with the paths each client reads, per-file precedence naming the surfaces each shadow takes, install commands carrying the role its own documentation gives them, and a dated row per surface it does and does not load. `INSTALL.md` names, per client, only the discovery paths the build actually planned, prints the action declared `install` rather than whichever command is listed first, marks a client whose documentation shows no local-directory form as marketplace-only, and prints the reason behind every narrowed surface. The generated host reference renders the same records through the same validator instead of an unsourced list of native clients. A record fails the build when it claims a tier its own rows and paths do not support, marks a surface degraded or supported without dated evidence, names an artifact path with no evidence that it is read, shadows a path without naming the surfaces it takes, or declares an install block without a source and exactly one install action. (#721)

‎packages/agent-bundle/src/adapters/capabilities/portable-1.0.0.json‎

Lines changed: 132 additions & 25 deletions
Original file line numberDiff line numberDiff line change
@@ -333,10 +333,20 @@
333333
"observed": "Agent Plugins 1.0.0; docs retrieved 2026-09-06, plugins documented as closed beta",
334334
"tier": "agent-plugins",
335335
"install": {
336-
"commands": [
337-
"devin plugins install <plugin directory>",
338-
"devin plugins info <name>",
339-
"devin plugins remove <name>"
336+
"source": "local-directory",
337+
"actions": [
338+
{
339+
"role": "install",
340+
"command": "devin plugins install <plugin directory>"
341+
},
342+
{
343+
"role": "inspect",
344+
"command": "devin plugins info <name>"
345+
},
346+
{
347+
"role": "remove",
348+
"command": "devin plugins remove <name>"
349+
}
340350
],
341351
"location": "Devin's own plugin store; the CLI manages the copy"
342352
},
@@ -347,8 +357,30 @@
347357
"mcp.json"
348358
],
349359
"shadowedBy": [
350-
".devin-plugin/plugin.json",
351-
".claude-plugin/plugin.json"
360+
{
361+
"path": ".devin-plugin/plugin.json",
362+
"surfaces": [
363+
"manifest",
364+
"skills",
365+
"mcp",
366+
"placeholders"
367+
]
368+
},
369+
{
370+
"path": ".claude-plugin/plugin.json",
371+
"surfaces": [
372+
"manifest",
373+
"skills",
374+
"mcp",
375+
"placeholders"
376+
]
377+
},
378+
{
379+
"path": ".mcp.json",
380+
"surfaces": [
381+
"mcp"
382+
]
383+
}
352384
],
353385
"evidence": [
354386
"2026-09-06: https://docs.devin.ai/cli/extensibility/plugins/overview states \"Devin also loads plugins packaged in two other layouts, with manifest precedence .devin-plugin/plugin.json > .claude-plugin/plugin.json > root plugin.json\", so a composite root that also carries a Devin or Claude manifest is read as that plugin instead.",
@@ -393,10 +425,24 @@
393425
"observed": "xai-org/grok-build main 72a61251fcffb464bcc687aeb5a998e5a98ec0c9, docs retrieved 2026-09-06",
394426
"tier": "skills",
395427
"install": {
396-
"commands": [
397-
"grok plugin install ./<plugin directory> --trust",
398-
"grok plugin validate <plugin directory>",
399-
"grok plugin enable <name>"
428+
"source": "marketplace",
429+
"actions": [
430+
{
431+
"role": "install",
432+
"command": "grok plugin install <marketplace plugin name>"
433+
},
434+
{
435+
"role": "trust",
436+
"command": "grok plugin install <marketplace plugin name> --trust"
437+
},
438+
{
439+
"role": "enable",
440+
"command": "grok plugin enable <name>"
441+
},
442+
{
443+
"role": "verify",
444+
"command": "grok plugin validate <plugin directory>"
445+
}
400446
],
401447
"location": "~/.grok/plugins/<name> is trusted automatically; .grok/plugins/<name> requires /hooks-trust or --trust"
402448
},
@@ -407,7 +453,8 @@
407453
"shadowedBy": [],
408454
"evidence": [
409455
"2026-09-06: https://raw.githubusercontent.com/xai-org/grok-build/main/crates/codegen/xai-grok-pager/docs/user-guide/09-plugins.md states \"An optional plugin.json manifest can override paths or add metadata; without one, Grok discovers components from these standard directories\", and lists skills/ among them.",
410-
"2026-09-06: the same pinned file lists the accepted install sources including \"a local path (`./local-dir` or `/absolute/path`)\", and states \"Grok trusts plugins in `~/.grok/plugins/` automatically; project plugins in `.grok/plugins/` require trust\", so the emitted directory installs in place with `--trust`.",
456+
"2026-09-06: the documented install spec is a marketplace plugin name (`grok plugin install deploy-tools --trust`). The same pinned file lists \"a local path (`./local-dir` or `/absolute/path`)\" among the accepted source forms, but no page shows that form accepting a directory that is not a Grok plugin or marketplace layout, so no local-directory recipe for this artifact is recorded here.",
457+
"2026-09-06: trust is a separate step from installation — \"Enabling a plugin loads its skills, commands, and agents. Trust is separate and controls whether a plugin's code runs\", and \"Grok trusts plugins in `~/.grok/plugins/` automatically; project plugins in `.grok/plugins/` require trust\".",
411458
"2026-09-06: no upstream page publishes the manifest's required fields or a precedence order among plugin.json, .grok-plugin/plugin.json, and .claude-plugin/plugin.json."
412459
]
413460
},
@@ -445,10 +492,20 @@
445492
"observed": "Agent Plugins 1.0.0; docs retrieved 2026-09-06",
446493
"tier": "agent-plugins",
447494
"install": {
448-
"commands": [
449-
"openclaw plugins install <plugin directory>",
450-
"openclaw plugins inspect <id>",
451-
"openclaw plugins uninstall <id>"
495+
"source": "local-directory",
496+
"actions": [
497+
{
498+
"role": "install",
499+
"command": "openclaw plugins install <plugin directory>"
500+
},
501+
{
502+
"role": "inspect",
503+
"command": "openclaw plugins inspect <id>"
504+
},
505+
{
506+
"role": "remove",
507+
"command": "openclaw plugins uninstall <id>"
508+
}
452509
],
453510
"location": "OpenClaw's own plugin store; `openclaw plugins inspect` reports `Bundle format: agent (Agent Plugins)`"
454511
},
@@ -459,10 +516,42 @@
459516
"mcp.json"
460517
],
461518
"shadowedBy": [
462-
"openclaw.plugin.json",
463-
".claude-plugin/plugin.json",
464-
".codex-plugin/plugin.json",
465-
".cursor-plugin/plugin.json"
519+
{
520+
"path": "openclaw.plugin.json",
521+
"surfaces": [
522+
"manifest",
523+
"skills",
524+
"mcp",
525+
"placeholders"
526+
]
527+
},
528+
{
529+
"path": ".claude-plugin/plugin.json",
530+
"surfaces": [
531+
"manifest",
532+
"skills",
533+
"mcp",
534+
"placeholders"
535+
]
536+
},
537+
{
538+
"path": ".codex-plugin/plugin.json",
539+
"surfaces": [
540+
"manifest",
541+
"skills",
542+
"mcp",
543+
"placeholders"
544+
]
545+
},
546+
{
547+
"path": ".cursor-plugin/plugin.json",
548+
"surfaces": [
549+
"manifest",
550+
"skills",
551+
"mcp",
552+
"placeholders"
553+
]
554+
}
466555
],
467556
"evidence": [
468557
"2026-09-06: https://docs.openclaw.ai/plugins/bundles publishes the detection order — a native manifest or a package.json with openclaw.extensions, then client-specific bundle markers (.codex-plugin/, .cursor-plugin/, .claude-plugin/), then \"A root plugin.json -> Agent Plugins bundle\" — and states \"If a package carries both a client-specific marker and a root plugin.json, the client-specific format wins\", so a composite root is read as the client-specific bundle instead.",
@@ -507,10 +596,20 @@
507596
"observed": "docs retrieved 2026-09-06; no CLI version is published on any page",
508597
"tier": "skills",
509598
"install": {
510-
"commands": [
511-
"qoder plugins install <plugin directory> --scope user",
512-
"qoder plugins validate <plugin directory>",
513-
"qoder plugins list --json"
599+
"source": "local-directory",
600+
"actions": [
601+
{
602+
"role": "install",
603+
"command": "qoder plugins install <plugin directory> --scope user"
604+
},
605+
{
606+
"role": "verify",
607+
"command": "qoder plugins validate <plugin directory>"
608+
},
609+
{
610+
"role": "inspect",
611+
"command": "qoder plugins list --json"
612+
}
514613
],
515614
"location": "the --scope target (user, project, or local); enablement is recorded in settings.json as enabledPlugins"
516615
},
@@ -519,11 +618,19 @@
519618
"skills",
520619
"mcp.json"
521620
],
522-
"shadowedBy": [],
621+
"shadowedBy": [
622+
{
623+
"path": ".mcp.json",
624+
"surfaces": [
625+
"mcp"
626+
]
627+
}
628+
],
523629
"evidence": [
524630
"2026-09-06: https://docs.qoder.com/cli/plugins-reference states the manifest \"is located at .qoder-plugin/plugin.json and must not be placed in the plugin root directory\", and that without a manifest \"the CLI loads components from conventional directories and uses the plugin directory name as the plugin name\".",
525631
"2026-09-06: https://docs.qoder.com/cli/plugins states \"plugins install for a local plugin requires at least one recognizable component or resource\", which the emitted skills/ tree and mcp.json satisfy.",
526-
"2026-09-06: no manifest-precedence order is published, so the behavior of a composite root carrying both .qoder-plugin/plugin.json and plugin.json is unproven."
632+
"2026-09-06: no manifest-precedence order is published, so the behavior of a composite root carrying both .qoder-plugin/plugin.json and plugin.json is unproven.",
633+
"2026-09-06: precedence that is published is per file, not per root: https://docs.qoder.com/cli/mcp-reference states \"If both exist, .mcp.json takes precedence, and they are not merged\", which withholds the emitted mcp.json alone and leaves the shared skills/ tree discovered."
527634
]
528635
},
529636
"surfaces": {

0 commit comments

Comments
 (0)