Skip to content
Back to skills

Decisions

ASecurity

**Date:** 2026-03-10 **Status:** accepted **Branch:** feat/marketplace-publish

  • 3 stars
  • 0 votes
  • 0 copies
  • 3 views
  • Added May 28, 2026
developmentgitapi

Works with

  • claude code
  • api

Security analysis

A100/100

Pro scans all 21 files and shows the line behind each finding

Scanned May 28, 2026

npx -y skills add martineserios/thebrana --skill decisions --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Decisions?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Decisions
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/martineserios-decisions/badge)](https://www.skillsdirectory.com/skills/martineserios-decisions)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
depends_on:
  - docs/architecture/decisions/ADR-012-acquire-skills.md
informs:
  - docs/architecture/decisions/ADR-015-state-consolidation-plugin-first.md
status: accepted
---

# ADR-014: Plugin Management Skill

**Date:** 2026-03-10
**Status:** accepted
**Branch:** feat/marketplace-publish

## Context

Brana v0.7.0 introduced the plugin architecture (t-232) and `/brana:acquire-skills` for individual skill discovery (t-206). Two gaps remain:

1. **No plugin-level management.** Users can discover individual skills but can't install, update, or remove entire plugins (bundles of skills + agents + hooks). Claude Code's native `/plugin` commands don't exist yet.
2. **No auto-registration.** After cloning thebrana, users must pass `--plugin-dir ./system` every time. Bootstrap should register the plugin so CC auto-loads it.
3. **Marketplace readiness.** When CC ships native marketplace support, brana should be discoverable and installable with zero changes.

## Decision

### 1. `/brana:plugin` skill

Build a unified plugin management skill with subcommands:

| Subcommand | Action |
|------------|--------|
| `add <owner/repo>` | Register a GitHub marketplace in `known_marketplaces.json` |
| `install <name>` | Clone marketplace repo, snapshot plugin source to `~/.claude/plugins/cache/`, register in `installed_plugins.json` |
| `list` | Show installed plugins + available from known marketplaces |
| `remove <name>` | Delete cache + deregister from `installed_plugins.json` |
| `update [name]` | Re-clone and re-snapshot (all or specific plugin) |
| `sync` | Shortcut for `bootstrap.sh --sync-plugin` (dev mode cache sync) |

Key design choices:
- **Mirrors CC's planned API.** When `/plugin` ships natively, `/brana:plugin` becomes a thin wrapper or is retired gracefully.
- **Uses CC's existing file format.** Writes to `installed_plugins.json` (version 2) and `known_marketplaces.json` — same format CC already reads.
- **GitHub-first.** Marketplace source is a GitHub repo with `.claude-plugin/marketplace.json` at root. No npm, no registry server.
- **User confirms everything.** No auto-install, no auto-update without approval.

### 2. Auto-registration in bootstrap.sh

Add Step 7 to bootstrap.sh: register the local `system/` as the brana plugin in CC's config files.

- Write `known_marketplaces.json` entry for `martineserios/thebrana`
- Snapshot `system/` to `~/.claude/plugins/cache/brana/brana/{version}/`
- Register in `installed_plugins.json`
- Idempotent — safe to re-run

### 3. Marketplace metadata

Already in place (`.claude-plugin/marketplace.json` + `system/.claude-plugin/plugin.json`). Version synced to 1.0.0. No changes needed beyond ensuring the schema stays compatible.

## Consequences

- **Easier:** installing brana on a new machine — `./bootstrap.sh` handles everything
- **Easier:** discovering and installing other CC plugins from GitHub
- **Risk:** CC may ship `/plugin` with a different format than what we implement. Mitigated by using CC's existing file formats and keeping the skill thin enough to adapt.
- **Risk:** `installed_plugins.json` overwrite on CC reload. Mitigated by writing the canonical format CC expects. If CC still overwrites, the plugin cache + marketplace registration provide the fallback path.

Files in this skill

  • ADR-001-reconcile-command-for-spec-implementation-drift.md5.7 KB
  • ADR-002-scheduler-thin-layer-over-systemd.md6.6 KB
  • ADR-002-tasks-as-data-layer.md3.3 KB
  • ADR-003-agent-driven-task-execution.md6.1 KB
  • ADR-004-session-handoff-self-learning-loop.md3.5 KB
  • ADR-005-agentdb-v3-unified-knowledge-backend.md10.2 KB
  • ADR-006-merge-enter-into-thebrana.md8.9 KB
  • ADR-007-verify-counts-deploy-hook.md1.2 KB
  • ADR-008-smart-tasks-add-suggest-only.md2 KB
  • ADR-009-test-lint-feedback-hook.md4.6 KB
  • ADR-010-pr-review-agent.md3.1 KB
  • ADR-011-skills-bundling.md3.1 KB
  • ADR-012-acquire-skills.md2.3 KB
  • ADR-013-event-log.md2.8 KB
  • ADR-014-plugin-management-skill.md3.2 KB
  • ADR-015-state-consolidation-plugin-first.md26.7 KB
  • ADR-016-spec-dependency-graph.md3.4 KB
  • ADR-017-decision-log.md3.1 KB
  • ADR-018-dynamic-model-routing.md2.9 KB
  • ADR-019-brana-chat-sessions.md15.7 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…