fix: scope plugin source to ./skills so installs ship 50 KB, not 230 MB - #795
Open
rymalia wants to merge 1 commit into
Open
fix: scope plugin source to ./skills so installs ship 50 KB, not 230 MB#795rymalia wants to merge 1 commit into
rymalia wants to merge 1 commit into
Conversation
|
Dear tobi/qmd,
We would like to acknowledge that we have received your request and a ticket has been created.
A support representative will be reviewing your request and will send you a personal response.(usually within 24-48 hours).
Thank you for your patience.
…On Sun, Jul 26 2026, at 07:25 PM, tobi/qmd ***@***.***> wrote:
Fixes #790. Related: (#790) #789 / PR (#789) #794 (same manifest, different lines — the two changes are merge-independent; a three-way merge test of both diffs combines cleanly). (#794)
Problem
The plugin entry in .claude-plugin/marketplace.json declares "source": "./" — the repository root. Two consequences: Every install copies the entire repository into ~/.claude/plugins/cache/, when the plugin machinery only reads the skill files and the manifest metadata (~50 KB total). Because the copied plugin root contains a inside the cache. On a canonical install ( package.json, claude plugin install also runs a full npm dependency install claude plugin marketplace add tobi/qmd + claude plugin install ***@***.***) the resulting ~/.claude/plugins/cache/qmd/qmd/0.1.0/ folder is 230 MB with 9,000+ items, including node_modules with native builds — per machine, for a few KB of skills.
Fix
Scope the plugin source to the skills directory — nothing is added or removed, both skills ( qmd and release) ship exactly as before: Note: #790 led with the narrower (#790) "source": "./skills/qmd" as its verified fix, which would also stop shipping the release skill. This PR deliberately implements the issue's other offered scoping which does not alter which skills are included so there is no disruption to either skill functionalities. - "source": "./", ... + "source": "./skills", - "skills": ["./skills/"], + "skills": ["./qmd", "./release"],
The payload drops 230 MB → ~50 KB, and no dependency install runs (there is no package.json anywhere under skills/).
The mcpServers declaration is untouched and unaffected: "command": "qmd" resolves via PATH, not relative to the plugin root.
Verified locally with the equivalent scoping ( "source": "./skills/qmd"): the install snapshot shrinks as described, the skill arrives byte-identical (md5-checked), no dependency install runs, and claude plugin details parses the component inventory cleanly.
Notes Optional further trim: if you decide the release skill is maintainer-only and shouldn't ship to plugin users, "source": "./skills/qmd" with "skills": ["./"] narrows the payload to just the qmd skill (~24 KB) — that's the variant verified byte-for-byte in #790. Happy to amend this PR or follow up either way. (#790) Delivery: fresh installs benefit immediately. Already-installed plugins only pick up manifest changes after a version bump — that's #789 / PR (#789) #794. (#794) Changelog: this and #794 both add an entry under (#794) [Unreleased], so whichever merges second will need a trivial changelog rebase — happy to handle that on my side. You can view, comment on, or merge this pull request online at: #795 (#795) Commit Summary 12cc093 fix: scope plugin source to ./skills so installs ship 50 KB, not 230 MB (12cc093) File Changes
( 2 files) (https://github.com/tobi/qmd/pull/795/files) M .claude-plugin/marketplace.json
(4) (https://github.com/tobi/qmd/pull/795/files#diff-5352ee4067f17e7948e1425843f0a454e045bc8edf338f0bcf75c6804ddabd9a) M CHANGELOG.md
(9) (https://github.com/tobi/qmd/pull/795/files#diff-06572a96a58dc510037d5efa622f9bec8519bc1beab13c9f251e97e657a9d4ed) Patch Links: https://github.com/tobi/qmd/pull/795.patch (https://github.com/tobi/qmd/pull/795.patch) https://github.com/tobi/qmd/pull/795.diff (https://github.com/tobi/qmd/pull/795.diff)
—
Reply to this email directly, view it on GitHub, or (#795?email_source=notifications&email_token=BRF3HG55DSYWN7ODCKO32CD5GZLLZA5CNFSNUABEM5UWIORPF5TWS5BNNB2WEL2QOVWGYUTFOF2WK43UF42DCMZXGUYDEOJYGSTHEZLBONXW5KTTOVRHGY3SNFRGKZFFMV3GK3TUVRTG633UMVZF6Y3MNFRWW) unsubscribe. (https://github.com/notifications/unsubscribe-auth/BRF3HG2IBCGKSUVC47BXXZT5GZLLZAVCNFSNUABGKJSXA33TNF2G64TZHMYTCMJSGM3DKMZQGE5US43TOVSTWNBZHAZDCNRRG42DDILWAI)
Triage notifications, keep track of coding agent tasks and review pull requests on the go with GitHub Mobile for iOS and (https://github.com/notifications/mobile/ios/BRF3HG5JOD7M623XTZP534D5GZLLZA5CNFSNUABEM5UWIORPF5TWS5BNNB2WEL2QOVWGYUTFOF2WK43UF42DCMZXGUYDEOJYGSTHEZLBONXW5KTTOVRHGY3SNFRGKZFFMV3GK3TUVJTG633UMVZF62LPOM) Android. Download it today! (https://github.com/notifications/mobile/android/BRF3HG34X3HHI2WEKUB7GYT5GZLLZA5CNFSNUABEM5UWIORPF5TWS5BNNB2WEL2QOVWGYUTFOF2WK43UF42DCMZXGUYDEOJYGSTHEZLBONXW5KTTOVRHGY3SNFRGKZFFMV3GK3TUVZTG633UMVZF6YLOMRZG62LE)
You are receiving this because you are subscribed to this thread. Message ID: <tobi/qmd/pull/795 @ github . com> [
{
***@***.***": "http://schema.org",
***@***.***": "EmailMessage",
"potentialAction": {
***@***.***": "ViewAction",
"target": "#795?email_source=notifications\u0026email_token=BRF3HG52V3IX5BTGXMLOYVD5GZLLZA5CNFSNUABEM5UWIORPF5TWS5BNNB2WEL2QOVWGYUTFOF2WK43UF42DCMZXGUYDEOJYGSTHEZLBONXW5KTTOVRHGY3SNFRGKZFFMV3GK3TUVNTW2YLJNRPWG3DJMNVQ",
"url": "#795?email_source=notifications\u0026email_token=BRF3HG52V3IX5BTGXMLOYVD5GZLLZA5CNFSNUABEM5UWIORPF5TWS5BNNB2WEL2QOVWGYUTFOF2WK43UF42DCMZXGUYDEOJYGSTHEZLBONXW5KTTOVRHGY3SNFRGKZFFMV3GK3TUVNTW2YLJNRPWG3DJMNVQ",
"name": "View Pull Request"
},
"description": "View this Pull Request on GitHub",
"publisher": {
***@***.***": "Organization",
"name": "GitHub",
"url": "https://github.com"
}
}
]
|
The plugin's source was the repo root, so every install copied the entire repository into ~/.claude/plugins/cache/ — and because that copy includes package.json, 'claude plugin install' also ran a full npm dependency install: 230 MB / 9,000+ items for a few KB of skills. Scoping source to the skills directory eliminates both. No feature change: both skills (qmd, release) still ship, and the PATH-resolved mcpServers entry is unaffected. Fixes tobi#790
rymalia
force-pushed
the
fix/plugin-payload-scope
branch
from
July 26, 2026 19:34
12cc093 to
d79ffb6
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #790. Related: #789 / PR #794 (same manifest, different lines — the two changes are merge-independent; a three-way merge test of both diffs combines cleanly).
Problem
The plugin entry in
.claude-plugin/marketplace.jsondeclares"source": "./"— the repository root. Two consequences:~/.claude/plugins/cache/, when the plugin machinery only reads the skill files and the manifest metadata (~50 KB total).package.json,claude plugin installalso runs a full npm dependency install inside the cache. On a canonical install (claude plugin marketplace add tobi/qmd+claude plugin install qmd@qmd) the resulting~/.claude/plugins/cache/qmd/qmd/0.1.0/folder is 230 MB with 9,000+ items, includingnode_moduleswith native builds — per machine, for a few KB of skills.Fix
Scope the plugin source to the skills directory — nothing is added or removed, both skills (
qmdandrelease) ship exactly as before:The payload drops 230 MB → ~50 KB, and no dependency install runs (there is no
package.jsonanywhere underskills/).The
mcpServersdeclaration is untouched and unaffected:"command": "qmd"resolves viaPATH, not relative to the plugin root.Verified locally with the equivalent scoping (
"source": "./skills/qmd"): the install snapshot shrinks as described, the skill arrives byte-identical (md5-checked), no dependency install runs, andclaude plugin detailsparses the component inventory cleanly.Notes
releaseskill is maintainer-only and shouldn't ship to plugin users,"source": "./skills/qmd"with"skills": ["./"]narrows the payload to just the qmd skill (~24 KB) — that's the variant verified byte-for-byte in Claude Code plugin: ships the whole repo for a 24 KB skill #790. Happy to amend this PR or follow up either way.[Unreleased], so whichever merges second will need a trivial changelog rebase — happy to handle that on my side.