All skills
michtio avatar

/craft-plugins

@44a2800

Index and router for plugin-specific Craft CMS 5 guidance — configuration, Twig API, PHP API, migrations, deployment, and pitfalls for the plugins this pack documents. Triggers whenever a task names one of these plugins in ANY context (build, configure, style, render, query, import, migrate, deploy, cache, debug): Formie (forms, submissions, File Upload, form in a migration, notifications, translations), SEOmatic (meta, sitemaps, JSON-LD, SEO field), Blitz (static/page caching, purge), Feed Me (XML/JSON/CSV import), Imager-X (transforms, srcset, quick syntax, named transforms, Power Pack, pppicture, ppimg), ImageOptimize (OptimizedImages), CKEditor (rich text, nested entries), Sprig (reactive, htmx), Element API (JSON endpoints), Retour (redirects, 404s), Navigation (nav menus), Hyper (link field), Colour Swatches, Password Policy (HIBP), Typogrify, Cache Igniter, Knock Knock (staging password), Elements Panel (N+1 debug), Sherlock (security scan), Amazon SES (SES/SNS bounce), Embedded Assets (oEmbed), Timeloop (recurring dates), Vite (craft.vite.*, asset bundling), Warp (passwordless login, magic link, one-time code/OTP, passkeys, WebAuthn, craft.warp, member sessions). Also load for passwordless or magic-link auth with NO plugin named. Always load when a task names one of these plugins — read references/<plugin>.md first. Do NOT trigger for Craft core with no plugin named (craftcms), template architecture (craft-site), or content modeling (craft-content-modeling).

Use this Skill: https://skilld.dev/gh/michtio/craftcms-claude-skills/craft-plugins

This session only. Nothing lands on disk.

referencessherlock.md

≈808 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Sherlock

Security scanner and monitor by PutYourLightsOn. Scans for vulnerabilities — file permissions, HTTP headers, CMS configuration, encrypted connections, critical updates, Content Security Policy. Supports scheduled scans, IP-based CP/front-end access restriction, monitoring with email alerts, and integrations with Bugsnag/Rollbar/Sentry. Used in 6/6 projects.

putyourlightson/craft-sherlock — Lite (free) / Plus ($199) / Pro ($299)

Documentation

When unsure about a feature, WebFetch the docs page.

Editions

Feature Lite Plus Pro
Security scans ✅ ✅ ✅
Encrypted connections ✅ ✅ ✅
Critical updates ✅ ✅ ✅
CMS configuration ✅ ✅ ✅
Header protection — ✅ ✅
Content Security Policy — ✅ ✅
Scheduled scans — ✅ ✅
Monitoring (email alerts) — — ✅
CP access restriction — — ✅
Front-end access restriction — — ✅
Basic auth — — ✅
API — — ✅
Integrations — — ✅

Setup

  1. Install via Plugin Store or Composer
  2. CP → Sherlock → run first security scan
  3. Review results and fix flagged issues

Scheduled Scans

Set up a cron job for automatic scanning:

# Daily scan at 3 AM
0 3 * * * cd /path/to/project && ddev craft sherlock/scans/run

Config File

// config/sherlock.php
return [
    '*' => [
        // 'standard' or 'high' security level
        'highSecurityLevel' => false,

        // Maximum number of scan records to keep
        'maxScans' => 50,
    ],
    'production' => [
        'highSecurityLevel' => true,
    ],
];

Copy the config template from the plugin's config.php for all available settings.

What It Scans

  • File permissions — writable directories, exposed config files
  • HTTP headers — X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy
  • CORS — cross-origin resource sharing configuration
  • CSRF — cross-site request forgery protection
  • Encrypted connections — HTTPS enforcement on front-end and CP
  • CMS config — devMode, allowAdminChanges, enableCsrfProtection, etc.
  • Critical updates — CMS version, plugin versions, PHP version
  • Plugin vulnerabilities — checks against PutYourLightsOn's vulnerability feed

Common Pitfalls

  • Running in high security level on development — some checks only make sense in production. Use environment-based config.
  • Ignoring header warnings — HTTP security headers are low-effort, high-impact fixes. Don't dismiss them.
  • Not scheduling scans — running manually is better than nothing, but automated daily/weekly scans catch regressions.
  • Using Plus when Pro is needed — if you need IP restriction or monitoring, you need Pro edition.

Pair With

  • Knock Knock — Sherlock secures the production site, Knock Knock password-protects staging
  • Password Policy — Sherlock checks CMS config, Password Policy enforces strong user passwords

Source: SKILL.md on GitHub

No alerts16d3 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The 'craft-plugins' skill is a technical reference and router for Craft CMS 5 plugins. It provides guidance on configuration, Twig and PHP APIs, and best practices for popular extensions in the Craft ecosystem. The skill consists of documentation files that describe legitimate plugin behaviors and does not contain any malicious code, obfuscation, or security vulnerabilities.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

Signed by skilld at 44a2800. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 weeks ago.

Activeupdated last month

README badge

README badge for michtio/craftcms-claude-skills/craft-plugins