All skills
deepseek-ai avatar

/cordis-plugin-development

@1f84756
by DeepSeekdeepseek-ai/deepseek-harness241k stars
28,946

Use when designing, reviewing, adding, enabling, disabling, installing, configuring, or debugging a plugin, bundle, feature, page, panel, tool, or MCP connection in the current Harness profile, including a shipped plugin that is disabled by default, and for any visual object, decoration, or widget request that names no other destination, which means an installed UI plugin rendered in the Harness Web UI.

Use this Skill: https://skilld.dev/gh/deepseek-ai/deepseek-harness/cordis-plugin-development

This session only. Nothing lands on disk.

referencesui-plugin.md

≈498 tokens on demand. Your agent reads this file only when SKILL.md points to it.

UI plugins in the Web page

Read templates/decoration/ with the file-read tool and write its files into your bundle directory: its package.json adds a dsh.client section (platform, immediately, inject) and a ./client export beside the bundle patch.

index.js exports export function apply() {}; the patch inserts one row named after the package. For a simple drawing, prefer a slot with allocated space, such as conversation.composer.dock when available. Keep the first version within that slot's flow; do not plan a motion path around host controls. Use shell.overlay only when the request needs an overlay and its placement is known.

Client module

The browser artifact registers a lazy factory whose id equals the package name. React comes from the browser module table; no duplicate React installation, CDN script, or UMD search is needed. For compiled sources, use the deployment's Client build tooling to emit this format; declare non-baseline runtime imports in dsh.client.external.

templates/decoration/client.js registers a lazy factory into conversation.composer.dock through ctx.slots.inject and ctx.slots.register; follow the selected slot's props and options from Slots.listSubTree when you change the slot.

Keep factories free of side effects. Register styles, timers, listeners and other resources inside apply with ctx.effect/ctx.on and return their cleanup functions. Component-local styles can render as React elements so unmounting removes them. Verify disposal for resources you add. Inherit the host theme for containers and controls; artwork may use its own colors. A page or panel beyond a decoration follows the UI rules in references/practices.md. Route visible UI text through the Client locale service. Do not replace the app root or append a second application to document.body. Do not read another plugin's DOM, stylesheet, or component source to estimate placement; choose a slot that already allocates space.

Source: SKILL.md on GitHub

1 warning3d3 checks · Risk MEDIUM
  • Gen Agent Trust Hub3d

    This skill provides a framework for the agent to develop and execute dynamic JavaScript plugins. It enables host-level access including shell commands (bash), process management (subprocess), and networking. While the framework includes safety constraints and manual approval steps, it creates a powerful environment for runtime code generation and execution.

  • Socket3d

    No alerts

  • Snyk3d

    Risk: LOW · No issues

Signed by skilld at 1f84756. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 4 days ago

README badge

README badge for deepseek-ai/deepseek-harness/cordis-plugin-development