All skills
deepseek-ai avatar

/cordis-plugin-development

@1f84756
by DeepSeekdeepseek-ai/deepseek-harness241k stars
28,946

Use when designing, reviewing, adding, enabling, disabling, installing, configuring, or debugging a plugin, bundle, feature, page, panel, tool, or MCP connection in the current Harness profile, including a shipped plugin that is disabled by default, and for any visual object, decoration, or widget request that names no other destination, which means an installed UI plugin rendered in the Harness Web UI.

Use this Skill: https://skilld.dev/gh/deepseek-ai/deepseek-harness/cordis-plugin-development

This session only. Nothing lands on disk.

referencesuser-actions.md

≈344 tokens on demand. Your agent reads this file only when SKILL.md points to it.

User actions and agent tools

Expose the plugin UI's operations on application data and configuration to the agent. Pure view interactions, such as switching tabs or expanding details, do not need tools. Confirm the Host entry points and tools you use with cordis_inspect_query before relying on them.

One operation, two callers

  1. Implement the operation once as a Host service method. It returns the result or an explicit status, and a failure carries its reason.
  2. The UI action calls it through a Client-callable Host entry point found with inspection, such as a session command that ctx.remote.commands.execute() runs, and shows the returned failure.
  3. Expose the operation through an agent tool with matching parameters and meaning. Related operations may share a tool with an action parameter. The tool calls the same method and returns its result as the tool result.

An action that grants or confirms authority, such as approving a tool call, answering a question the agent asked, or loosening a policy, stays user-only. Do not maintain separate operation logic in the UI and tool paths.

Verification

For operations available to both callers, perform the operation through the tool alone and compare its state changes, return values, and failures with the UI action. For user-only actions, verify that the agent cannot execute or authorize them.

Source: SKILL.md on GitHub

1 warning3d3 checks · Risk MEDIUM
  • Gen Agent Trust Hub3d

    This skill provides a framework for the agent to develop and execute dynamic JavaScript plugins. It enables host-level access including shell commands (bash), process management (subprocess), and networking. While the framework includes safety constraints and manual approval steps, it creates a powerful environment for runtime code generation and execution.

  • Socket3d

    No alerts

  • Snyk3d

    Risk: LOW · No issues

Signed by skilld at 1f84756. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 4 days ago

README badge

README badge for deepseek-ai/deepseek-harness/cordis-plugin-development