Skip to content

Epic: Plugin extensibility phase 2 roadmap after governed MVP #1102

@tamirdresher

Description

@tamirdresher

Recommendation

PR #1092 is the safe governed MVP and should merge as-is. It delivers declarative plugin manifests, provider contracts, lifecycle commands, state/audit persistence, and allowlisted Graphify artifact generation without opening arbitrary execution.

This epic tracks the next extensibility wave: distribution, more governed built-in providers, and a separately reviewed trusted executable provider runtime.

Phase plan

  1. Marketplace distribution — install/search/update declarative plugins from remote sources while preserving the no-execution boundary.
  2. Governed provider expansion — add more built-in approved providers such as MemPalace and Index Server using deterministic artifact generation only.
  3. Trusted executable provider RFC/runtime — design and implement explicit trust tiers, permission grants, sandboxing, approval gates, provenance, and audit before any plugin-supplied execution is allowed.

Non-goals for #1092

  • No arbitrary plugin-supplied code execution.
  • No shell/package-manager execution.
  • No live MCP startup.
  • No network calls from plugin content.
  • No dynamic provider assemblies.

Definition of done

Metadata

Metadata

Assignees

No one assigned

    Labels

    priority:p2Next sprintsquadSquad triage inbox — Lead will assign to a memberstatus:backlogBacklog itemtype:featureNew capability

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions