Skip to content
Back to skills

Plugin Authoring

ASecurity

Create or change Cloudroom plugins and Plugin SDK extensions, including CLI commands, agent tools, providers, and UI surfaces.

  • 11 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 5, 2026
ai-agentstypescriptrusttestinggitapifrontendbackend

Works with

  • cli
  • api

Security analysis

A100/100

Pro scans all 20 files and shows the line behind each finding

Scanned October 5, 2026

npx -y skills add davidondrej/cloudroom-gui --skill plugin-authoring --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Plugin Authoring?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Plugin Authoring
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/davidondrej-plugin-authoring/badge)](https://www.skillsdirectory.com/skills/davidondrej-plugin-authoring)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: plugin-authoring
description: "Create or change Cloudroom plugins and Plugin SDK extensions, including CLI commands, agent tools, providers, and UI surfaces."
---

# Author Cloudroom plugins

A Cloudroom plugin is a TypeScript package that can add server behavior, agent
capabilities, host-rendered UI, or a frontend bundle.

Use the current SDK types and repository source as the contract. This skill
routes to detailed references, but the installed Cloudroom version decides the exact
API.

## Implement and verify

Inspect the affected package and current SDK declarations to select backend,
frontend, or both. Build the plugin and verify the affected contracts and user
workflow. Install or reload when a live check is needed for the requested work.

Use room-cli plugin new <name> for a new plugin. The scaffold includes frontend files.
Remove `bb.app` and those files when the plugin is headless.

Every new public Plugin SDK surface starts with an experimental\_ prefix and an
entry in docs/api_to_audit.md. Add its Plugin Guide card and API inventory in
the same change.

## Read only the relevant reference

### Start, package, and release

- Read references/quickstart.md for package structure, manifest fields,
  scaffold output, build, install, and the first plugin.
- Read references/distribution.md for exact API lookup, Git or npm release,
  multi-plugin repositories, and custom marketplaces.

### Backend

- Read references/backend-foundation.md for the factory, logging, settings,
  storage, server information, and host access.
- Read references/backend-sdk.md for projects, environments, threads,
  interactions, provider models, browser sessions, and event history.
- Read references/backend-api-index.md to check every public backend, host,
  AI-service, and test export.
- Read references/backend-events.md for lifecycle events, environment providers,
  HTTP, RPC, realtime, background services, and schedules.
- Read references/backend-machines.md for machine providers, core project source
  setup, enrollment/bootstrap helpers, and server access.
- Read references/backend-cli-agents.md for CLI commands, input forms, agent
  tools, agent configuration, and helper AI services.
- Read references/providers.md only when the plugin registers an agent provider.
- Read references/provider-bridge-api-index.md to check every public provider
  bridge, bridge-test, and ACP export.
- Read references/backend-ui-lifecycle.md for host-rendered UI, status, cleanup,
  and reload behavior.

### Frontend

- Read references/frontend-registration.md for definePluginApp, thread header,
  sidebar replacement, providers, and top-level registration.
- Read references/frontend-api-index.md to check every public frontend
  runtime value and type export.
- Read references/frontend-core-slots.md for trusted content scripts, homepage,
  settings, navigation, thread panels, interactions, sidebar actions, and file
  openers.
- Read references/frontend-renderer-slots.md for source, diff, message,
  timeline, palette, and provider-icon renderers or actions.
- Read references/frontend-components.md for ThreadChat, provider controls,
  source and diff viewers, links, panels, and the new-thread composer.
- Read references/frontend-hooks-and-ui.md for hooks, composer customization,
  vendored components, runtime shims, styling, and crash isolation.

### Testing

- Read references/frontend-testing-api-index.md to check every frontend test
  runtime value and type export.
- Read references/testing.md before you add tests or run a live plugin loop.

## Contract rules

- Parse freeform input at the boundary and pass typed values internally.
- Declare only manifest fields and settings that the plugin implements.
- Keep secret settings on the server.
- Treat frontend parameters and persisted values as untrusted input.
- Return bounded CLI and agent-tool output.
- Document plugin commands, settings, and operating constraints in the plugin's
  own `skills/` directory. The core CLI skill owns generic plugin management,
  not individual plugin behavior.
- Dispose every service, schedule, listener, content script, and resource.
- Use SDK host components and navigation for host-owned behavior.
- Use vendored UI source for plugin-owned controls.
- Keep experimental names until the public API audit stabilizes them.
- Use current names. Compatibility aliases can warn and can expire after one
  release. Removed APIs can throw.
- Run room-cli plugin types when SDK declaration versions can drift.
- Run room-cli plugin build before install, release, or marketplace submission.

## Verification

Confirm the backend contract, frontend contract, manifest, generated bundle,
and live behavior that the change affects. Use focused tests for failure-prone
policy and lifecycle behavior.

Files in this skill

  • SKILL.md4.7 KB
  • references/backend-api-index.md13.8 KB
  • references/backend-cli-agents.md11.9 KB
  • references/backend-events.md22.5 KB
  • references/backend-foundation.md14.4 KB
  • references/backend-machines.md12.4 KB
  • references/backend-sdk.md23.8 KB
  • references/backend-ui-lifecycle.md2.4 KB
  • references/distribution.md9.9 KB
  • references/frontend-api-index.md6.7 KB
  • references/frontend-components.md19.4 KB
  • references/frontend-core-slots.md16.9 KB
  • references/frontend-hooks-and-ui.md11.4 KB
  • references/frontend-registration.md12.1 KB
  • references/frontend-renderer-slots.md9.2 KB
  • references/frontend-testing-api-index.md910 B
  • references/provider-bridge-api-index.md12.5 KB
  • references/providers.md17.8 KB
  • references/quickstart.md11.4 KB
  • references/testing.md15.1 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…