Skip to content
This repository was archived by the owner on Sep 7, 2026. It is now read-only.
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 7 additions & 5 deletions .github/PULL_REQUEST_TEMPLATE.md
Original file line number Diff line number Diff line change
@@ -1,20 +1,22 @@
## What changes

<!-- Describe the plugin or registry/tooling change. -->
<!-- Name the Plugin or repository tooling change. -->

## User value

<!-- What can a MiniMax Code user do after this change? Include an example prompt. -->

## Plugin submission checklist

- [ ] Source is public, open-source licensed, and pinned to a full commit SHA.
- [ ] Declared Skills and MCP servers match the pinned source.
- [ ] Plugin lives at `plugins/<github-owner>/<plugin-name>`.
- [ ] `plugin.json` name matches the Plugin directory.
- [ ] `README.md` includes a real example prompt and expected result.
- [ ] `LICENSE` and `plugin.json` declare an open-source license.
- [ ] Required executables, accounts, paid services, and supported platforms are disclosed.
- [ ] Network destinations and data handled by the plugin are disclosed.
- [ ] No credentials, private endpoints, installers, or native binaries are included.
- [ ] No credentials, private endpoints, hidden telemetry, installers, symlinks, or native binaries are included.
- [ ] Every scaffold `TODO` has been replaced.
- [ ] `npm run check` passes.
- [ ] `npm run verify -- registry/<plugin>.json` passes for a registry change.

## Evidence

Expand Down
31 changes: 0 additions & 31 deletions .github/workflows/verify-submissions.yml

This file was deleted.

86 changes: 43 additions & 43 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
@@ -1,66 +1,66 @@
# Contributing

Thank you for helping the MCode plugin ecosystem grow. Contributions may improve the registry
tooling and documentation or submit a plugin that you maintain in another public repository.
One folder is one Plugin. One pull request is one contribution.

## Submit a plugin
## 1. Create your Plugin

Your plugin must:

- be hosted in a public GitHub repository;
- include a recognized open-source license;
- pin a full 40-character Git commit SHA in the registry entry;
- use the MCode-compatible Agent Plugins surface documented in
[`docs/plugin-compatibility.md`](docs/plugin-compatibility.md);
- contain no embedded credentials, private endpoints, telemetry without disclosure, installers, or
native binaries;
- document required executables, accounts, paid services, network access, and operating-system
limits; and
- expose at least one Skill or MCP server that a reviewer can understand and exercise.

Generate the first draft instead of writing catalog metadata by hand:
Fork this repository, install dependencies, and run:

```bash
npm install
npm run add -- https://github.com/<owner>/<repository> --path <plugin-subdirectory>
npm run create -- <github-owner>/<plugin-name>
```

Then edit the generated entry, run:
The command creates `plugins/<github-owner>/<plugin-name>` with a portable `plugin.json`, README,
Apache-2.0 license, and starter Skill.

## 2. Make it real

Replace every scaffold `TODO`. Your Plugin must:

- expose at least one Skill or MCP server;
- use the supported package shape in [`docs/plugin-compatibility.md`](docs/plugin-compatibility.md);
- include `README.md`, `LICENSE`, and a matching open-source license in `plugin.json`;
- explain the user problem, an example prompt, and the expected result;
- disclose required executables, accounts, paid services, platforms, network destinations, and data;
- contain no credentials, private endpoints, hidden telemetry, installers, native binaries, or symlinks.

Keep source and docs inside your Plugin directory. Do not edit another contributor's Plugin in the
same pull request.

## 3. Check it

```bash
npm run check
npm run verify -- registry/<plugin-name>.json
```

and open a pull request. Include the user problem, an example prompt, expected result, dependencies,
network destinations, data handled by the plugin, and test evidence. One pull request should add or
update one plugin unless the entries are inseparable.
The validator checks the hosted directory, Manifest, Skills, MCP transports, required docs,
placeholders, and path safety. CI runs the same command.

## Registry review
## 4. Open the pull request

Reviewers verify the pinned source rather than a mutable branch. Automated checks cover package
shape and declared capabilities. Human review covers usefulness, clear ownership, dependency and
data-flow disclosure, obvious credential or supply-chain risks, and whether the example can be
reproduced.
Include:

Acceptance means “listed as community software.” It is not an audit or product endorsement. A
plugin can be removed or marked unavailable if its pinned source disappears, changes ownership
without explanation, becomes malicious, or is no longer maintained.
- the problem your Plugin solves;
- a copyable example prompt;
- the expected result;
- dependencies and supported platforms;
- network and data behavior;
- automated and manual test evidence.

## Update a plugin
Review covers usefulness, reproducibility, clear ownership, data flow, dependency risk, and obvious
supply-chain issues. Acceptance means “available as community software”; it is not a MiniMax
endorsement or a complete security audit.

Open a pull request that changes the pinned commit and any metadata affected by that release. Include
a short changelog and rerun both local and remote verification. Never replace source at an existing
tag to bypass registry review.
## Update or remove a Plugin

## Improve this repository
The owner directory identifies the maintainer. Submit changes under the same path and explain user
impact. A Plugin may be quarantined or removed if it becomes malicious, abandoned, misleading, or
unsafe.

For validator, schema, example, documentation, or workflow changes:
## Improve the platform

1. Open an issue for contract-breaking changes.
2. Keep the change focused and add or update automated tests.
3. Run `npm run check`.
4. Explain user impact and migration requirements in the pull request.
Validator, documentation, example, and workflow changes are welcome. Open an issue before a
contract-breaking change, add focused tests, and describe migration impact.

Contributions to this repository are licensed under Apache-2.0. External plugin repositories retain
their own licenses.
Repository contributions are licensed under Apache-2.0. Each hosted Plugin carries its own license.
11 changes: 6 additions & 5 deletions GOVERNANCE.md
Original file line number Diff line number Diff line change
@@ -1,14 +1,14 @@
# Governance

MCode Plugins is maintained in the open. The initial maintainers are responsible for registry
policy, compatibility contracts, releases of the validation toolkit, and time-sensitive security
actions. Plugin authors retain responsibility for their own repositories and users.
MiniMax Code Plugins is maintained in the open. Maintainers own contribution policy, compatibility
contracts, validation tooling, review queues, and time-sensitive security actions. Plugin authors
own the code and user support under their `plugins/<owner>/` path.

## Decision principles

1. Match documented MiniMax Code runtime behavior before expanding the catalog format.
2. Prefer portable Agent Plugins and Agent Skills contracts over host-specific invention.
3. Keep submissions reproducible by pinning immutable source.
3. Keep the contribution path to one hosted folder and one pull request.
4. Make dependencies, data access, network access, and maintenance ownership visible.
5. Use evidence from real users and contributors; plugin count and stars are not success metrics.

Expand All @@ -17,4 +17,5 @@ migration note. Security removals and obvious malicious submissions may be handl
documented after users are protected.

The project may introduce additional reviewer and maintainer roles as contribution volume grows.
No contributor gains authority over external plugin code merely because it is listed here.
No contributor gains authority over another owner's Plugin because their own contribution is hosted
here.
157 changes: 89 additions & 68 deletions README.md
Original file line number Diff line number Diff line change
@@ -1,102 +1,123 @@
# MCode Plugins
<p align="center">
<img src="assets/hero.svg" alt="MiniMax Code Plugins — one folder, one pull request, a new agent superpower" width="100%" />
</p>

<p align="center">
<a href="README.zh-CN.md">简体中文</a> ·
<a href="CONTRIBUTING.md">Contribute</a> ·
<a href="docs/plugin-compatibility.md">Plugin contract</a> ·
<a href="SECURITY.md">Security</a>
</p>

<p align="center">
<a href="https://github.com/hetaoBackend/MiniMax-Code-Plugins/actions/workflows/ci.yml"><img src="https://img.shields.io/github/actions/workflow/status/hetaoBackend/MiniMax-Code-Plugins/ci.yml?branch=main&amp;style=flat-square&amp;label=build" alt="Build status" /></a>
<img src="https://img.shields.io/badge/Agent_Plugins-1.0-8b5cf6?style=flat-square" alt="Agent Plugins 1.0" />
<img src="https://img.shields.io/github/license/hetaoBackend/MiniMax-Code-Plugins?style=flat-square&amp;color=22c55e" alt="Apache-2.0 license" />
<img src="https://img.shields.io/badge/PRs-welcome-ec4899?style=flat-square" alt="Pull requests welcome" />
</p>

## One folder is the release

MiniMax Code Plugins is the community home for Agent Plugins that run in MiniMax Code. Put a
portable Plugin under `plugins/<github-owner>/<plugin-name>`, open a pull request, and let CI check
the package users will actually install.

[简体中文](README.zh-CN.md)
```text
fork → create → build → check → pull request → discover
```

MCode Plugins is the community registry and contribution toolkit for plugins that run in MiniMax
Code. Plugin authors keep their source and release history in their own GitHub repositories. This
repository provides a searchable catalog, a pinned and reviewable submission format, offline
validation, compatibility guidance, and a shared contribution process.
No second repository. No catalog JSON. No commit pin to copy. Your Plugin source, docs, review, and
history live together.

> Status: community preview. A catalog entry means the package passed automated compatibility
> checks at the pinned commit. It is not an endorsement, security audit, or guarantee by MiniMax.
## Ship your first Plugin

## Why this repository exists
```bash
git clone https://github.com/<you>/MiniMax-Code-Plugins.git
cd MiniMax-Code-Plugins
npm install
npm run create -- <you>/my-first-plugin
```

A useful plugin ecosystem needs more than a list of links. It needs a complete path from creation to
real use:
The scaffold gives you a Skill-first Plugin:

```text
create -> validate -> submit -> review -> discover -> install -> feedback -> maintain
plugins/<you>/my-first-plugin/
├── plugin.json
├── README.md
├── LICENSE
└── skills/
└── my-first-plugin/
└── SKILL.md
```

MCode Plugins keeps that path open and auditable:
Replace every `TODO`, then run:

- Authors own their plugin repository, issues, license, and release cadence.
- Catalog entries pin a full commit SHA, so review and installation refer to immutable source.
- CI validates the exact MCode-compatible surface instead of inferring support from a README.
- Capability and security metadata make dependencies and network access visible before install.
- Users report problems to the plugin author; registry policy issues stay in this repository.
```bash
npm run check
```

## Supported plugin surface
If it passes, open one pull request for that Plugin. Start with
[`CONTRIBUTING.md`](CONTRIBUTING.md) when you want the full review checklist.

The first public contract intentionally stays small:
## What can a Plugin add?

- `plugin.json` using [Agent Plugins 1.0](https://agent-plugins.org/schemas/1.0.0/plugin.schema.json)
- zero or more Agent Skills at `skills/<skill-name>/SKILL.md`
- an optional `mcp.json` with `stdio`, `streamable-http`, or `sse` servers
### Skills

MiniMax Code does not currently promise Plugin Hooks, custom Agents, Commands, LSP servers, Apps,
generic OAuth configuration, or arbitrary `extensions`. A cross-client plugin may contain those
components, but its catalog entry must describe only the capabilities that MCode can load. See
[Plugin compatibility](docs/plugin-compatibility.md).
Package reusable instructions, workflows, and domain knowledge. Skills are the fastest path from a
good prompt pattern to a capability anyone can install.

## Create a plugin
### MCP servers

Start from the Skill-only [`examples/hello-mcode`](examples/hello-mcode) or the dependency-free
stdio [`examples/hello-mcode-mcp`](examples/hello-mcode-mcp):
Connect MiniMax Code to local tools or remote services with `stdio`, `streamable-http`, or `sse`.
Dependencies, accounts, network destinations, and data handling must be visible before install.

### Both

Use a Skill to teach the workflow and MCP to provide the tools. The portable package stays small:

```text
my-plugin/
plugin-root/
├── plugin.json
├── mcp.json # optional
└── skills/
└── my-skill/
└── SKILL.md
└── skills/ # optional
```

Keep the plugin in its own public GitHub repository. Then fork this registry and generate a pinned
entry:
This repository is for **Agent capabilities**. TUI Extensions are a separate system and are not
loaded from this package format.

```bash
npm install
npm run add -- https://github.com/you/my-plugin --path optional/subdirectory
npm run check
npm run verify -- registry/my-plugin.json
```
## The gate is simple

The generator resolves the repository's current default-branch commit, reads the package, and writes
a draft registry entry. Review the generated categories and security metadata before opening a pull
request.
A contribution must:

## Submit an existing plugin
- live at `plugins/<github-owner>/<plugin-name>`;
- include `plugin.json`, `README.md`, and `LICENSE`;
- expose at least one valid Skill or MCP server;
- document a copyable example, requirements, network access, and data use;
- contain no secrets, private endpoints, hidden telemetry, native binaries, or symlinks;
- pass `npm run check` and human review.

1. Make the plugin source public and add a recognized open-source license.
2. Ensure the root (or declared subdirectory) contains a valid `plugin.json`.
3. Generate a registry entry pinned to a 40-character Git commit SHA.
4. Run `npm run check` and `npm run verify -- registry/<plugin>.json`.
5. Open a pull request using the checklist in [CONTRIBUTING.md](CONTRIBUTING.md).
Passing review means the Plugin is available as community software. It is not a MiniMax endorsement
or a complete security audit. Read the source and requested capabilities before installing.

Review focuses on reproducibility, MCode compatibility, transparent dependencies, least privilege,
and a runnable example. It does not transfer maintenance ownership to the registry maintainers.
## Explore the project

## Trust model
- [`plugins/`](plugins/) — community Plugin source
- [`examples/hello-mcode`](examples/hello-mcode/) — smallest Skill Plugin
- [`examples/hello-mcode-mcp`](examples/hello-mcode-mcp/) — dependency-free stdio MCP
- [`docs/plugin-compatibility.md`](docs/plugin-compatibility.md) — exact supported contract
- [`docs/security-model.md`](docs/security-model.md) — validation and trust model
- [`docs/architecture.md`](docs/architecture.md) — hosted contribution architecture
- [`GOVERNANCE.md`](GOVERNANCE.md) — decisions and maintainer responsibilities

Catalog packages are community code. Read the plugin source and requested capabilities before use.
Never put credentials directly in `plugin.json`, `mcp.json`, a Skill, or a registry entry. A plugin
may invoke local executables or remote services; those dependencies remain the plugin author's
responsibility. See [Security](SECURITY.md) and the [security model](docs/security-model.md).
## Community preview

## Project layout
The contract is intentionally narrow while MiniMax Code's public Plugin surface stabilizes. Hooks,
custom Agents, Commands, LSP, Apps, generic OAuth, and TUI Extensions are not advertised as current
Agent Plugin capabilities.

```text
registry/ pinned plugin catalog entries
schemas/ machine-readable registry entry contract
scripts/ dependency-free validation and submission tools
examples/ known-good plugin packages
docs/ compatibility, architecture, governance, and security notes
```
Bring one useful capability. Make the example undeniable. Ship it in one pull request.

## License

Registry code and documentation are licensed under Apache-2.0. Every external plugin keeps its own
license; inclusion in the catalog does not relicense it.
Repository tooling and documentation use Apache-2.0. Every hosted Plugin includes and declares its
own open-source license.
Loading