Atlas / Skills / ruvnet / Create Plugin

Create PluginCAUTION

skills/ruvnet/create-plugin

๐ŸŒŠ The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated

Verdict
CAUTION
Grade
B
Trust score
89 /100
Version
โ€”
Hosts
1 documented
License
MIT
Stars
73,227
01

Overview

๐ŸŒŠ The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated

Read from source at commit ef7d4f0535e5OBSERVED ยท 2026-09-25
02

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
03

What it tells the agent

The instruction file, verbatim from the audited commit โ€” this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: create-plugin
description: Scaffold a new Claude Code plugin with proper directory structure, plugin.json, skills, commands, and agents
argument-hint: "<plugin-name>"
allowed-tools: mcp__plugin_ruflo-core_ruflo__transfer_plugin-info mcp__plugin_ruflo-core_ruflo__transfer_plugin-search mcp__plugin_ruflo-core_ruflo__transfer_store-search Bash Read Write Edit
---

# Create Plugin

Scaffold a new Claude Code plugin from scratch.

## When to use

When you want to create a new plugin that extends Claude Code with skills, commands, and agents. This generates the correct directory structure and wires up MCP tools.

## Steps

1. **Get plugin name and description** from the user
2. **Check for conflicts** โ€” call `mcp__plugin_ruflo-core_ruflo__transfer_plugin-search` to ensure the name isn't taken
3. **Create directory structure** (follows the canonical plugin contract from sibling plugins' ADR-0001s):
   ```
   plugins/<name>/
   โ”œโ”€โ”€ .claude-plugin/
   โ”‚   โ””โ”€โ”€ plugin.json
   โ”œโ”€โ”€ skills/
   โ”‚   โ””โ”€โ”€ <skill-name>/
   โ”‚       โ””โ”€โ”€ SKILL.md
   โ”œโ”€โ”€ commands/
   โ”‚   โ””โ”€โ”€ <command-name>.md
   โ”œโ”€โ”€ agents/
   โ”‚   โ””โ”€โ”€ <agent-name>.md
   โ”œโ”€โ”€ docs/
   โ”‚   โ””โ”€โ”€ adrs/
   โ”‚       โ””โ”€โ”€ 0001-<name>-contract.md     # Plugin-level ADR (Proposed)
   โ”œโ”€โ”€ scripts/
   โ”‚   โ””โ”€โ”€ smoke.sh                         # Structural contract (โ‰ฅ8 checks)
   โ””โ”€โ”€ README.md                            # Compatibility + Namespace coordination + Verification + ADR sections
   ```
4. **Generate plugin.json** with name, description, version, author (do NOT include `skills`, `commands`, or `agents` arrays โ€” Claude Code auto-discovers these from directory structure)
5. **Generate SKILL.md files** with proper frontmatter:
   ```yaml
   ---
   name: skill-name
   description: What this skill does
   allowed-tools: mcp__plugin_ruflo-core_ruflo__tool1 mcp__plugin_ruflo-core_ruflo__tool2 Bash
   ---
   ```
6. **Generate command files** with name and description frontmatter
7. **Generate agent files** with name, description, and `model: sonnet`
8. **Generate README.md** with install instructions, features, commands, skills, AND the canonical plugin-contract sections:
   - **Compatibility** โ€” pin to `@claude-flow/cli` v3.6 major+minor
   - **Namespace coordination** โ€” claim a kebab-case `<plugin-stem>-<intent>` namespace; defer to ruflo-agentdb ADR-0001 ยง"Namespace convention"
   - **Verification** โ€” `bash plugins/<name>/scripts/smoke.sh`
   - **Architecture Decisions** โ€” link to ADR-0001
9. **Generate ADR-0001 (Proposed)** at `docs/adrs/0001-<name>-contract.md` documenting: pinning, namespace coordination, MCP-tool surface count if applicable, smoke contract scope. Status: `Proposed`.
10. **Generate scripts/smoke.sh** โ€” at minimum 8 structural checks: version + keywords; skills/agents/commands present with valid frontmatter; v3.6 pin in README; namespace coordination block in README; ADR exists with status `Proposed`; no wildcard tools in skills.
11. **Update marketplace.json** if adding to the ruflo marketplace.

## MCP-tool drift to avoid (per sibling-ADR lessons learned)

Several plugins shipped with subtle MCP bugs the loop has been finding. Don't replicate them:

- **`embeddings_embed` does not exist.** Real tool is `embeddings_generate`. Don't reference `embeddings_embed` in any `allowed-tools` line.
- **`agentdb_hierarchical-*` does NOT route by namespace.** It routes by tier (`working|episodic|semantic`). Pass `tier`, not `namespace`. For namespaced reads/writes, use `memory_*` instead.
- **`agentdb_pattern-*` does NOT route by namespace.** It routes through ReasoningBank. Don't pass a `namespace` arg โ€” fallback writes to the reserved `pattern` namespace via `memory-store-fallback`.
- **`pattern` (singular) and `patterns` (plural) are different namespaces.** ReasoningBank fallback writes to `pattern`; `hooks_pretrain` writes to `patterns`. Don't conflate them.

## Plugin.json schema

Required fields:
- `name` โ€” plugin identifier (kebab-case)
- `description` โ€” what the plugin does
- `version` โ€” semver

Recommended fields:
- `author` โ€” `{ "name": "...", "url": "..." }`
- `homepage`, `license`, `keywords`

Optional fields:
- `graph_adapter` โ€” ADR-130 graph intelligence contract (commented out by default in generated output):
  ```json
  // "graph_adapter": {
  //   "edgeRelations": ["my-relation-type"],
  //   "nodeTypes": ["entity"],
  //   "autoRegister": true
  // }
  ```
  When `autoRegister: true`, the plugin's edges are automatically included in `graph_edges` writes
  by the core graph layer. Declare `edgeRelations` โ€” the relation types this plugin produces.

**Do NOT include** `skills`, `commands`, or `agents` arrays in plugin.json โ€” these are auto-discovered from the directory structure by Claude Code and will cause validation errors if present.

## Available MCP tools to wire

Browse available tools: `mcp__plugin_ruflo-core_ruflo__transfer_plugin-info`

Common tool categories:
- `memory_*` โ€” storage, search, retrieval
- `agentdb_*` โ€” 15 controller-bridge tools (do NOT pass `namespace` arg โ€” they route by tier or ReasoningBank); call `agentdb_controllers` at runtime for the canonical list
- `neural_*` โ€” neural training and prediction
- `hooks_*` โ€” lifecycle hooks and intelligence
- `browser_*` โ€” browser automation
- `workflow_*` โ€” workflow management
- `aidefence_*` โ€” safety scanning
- `embeddings_*` โ€” 10 vector-embedding tools (use `embeddings_generate`, NOT `embeddings_embed` which does not exist)
04

Trust audit

CAUTIONgrade B ยท trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeNA
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (4)

MEDIUMInventory / provenance ยท inv.symlink ยท CWE-1104
crates
crates
Why it matters. link not followed
MEDIUMInventory / provenance ยท inv.symlink ยท CWE-1104
plugin/agents
plugin/agents
Why it matters. link not followed
MEDIUMInventory / provenance ยท inv.symlink ยท CWE-1104
plugin/commands
plugin/commands
Why it matters. link not followed
MEDIUMInventory / provenance ยท inv.symlink ยท CWE-1104
plugin/skills
plugin/skills
Why it matters. link not followed

Gates applied: no_behavioural_pass.

Audited 2026-09-25 ยท audit v0.4.1 ยท source sha ef7d4f0535e5full audit observations/trust-audit/skill/ruvnet__create-plugin.json ยท Report an issue / request a re-scan
05

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-09-25ef7d4f0535e5CAUTIONB89first audit
06

Questions

What does the Create Plugin skill do?

๐ŸŒŠ The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated

Is Create Plugin safe to install?

With care. The audit graded it B (89/100) and found 4 things worth knowing before you trust this skill, listed below with the exact line each was found on.

What can Create Plugin access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

Which assistants does Create Plugin work with?

Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (ef7d4f0535e5), read on 2026-09-25. The repository is watched, and a new audit runs when it changes โ€” this is the first audit.

Advertisement