publish-copy

An internal command that copies approved plugin files from a toolkit repository to a separate publishing repository. It reads inclusion and exclusion rules and determines the destination from configuration or the environment.

In plain words
What is it for?
Use it to prepare marketplace-ready plugin artifacts for publication, including plugin folders, MCP configuration, and skills.
Why use it?
It keeps internal tooling out of the published package and makes the copy scope and destination explicit.

Command

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/wake-engineering/ai-plugin/publish-copy
Clone the repo
git clone --depth 1 https://github.com/wake-engineering/ai-plugin
Per session 69 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,205 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00069 $0.01205
Opus 5 $0.00034 $0.00602
Sonnet 5 $0.00014 $0.00241
Haiku 4.5 $0.00007 $0.00120

Measured 2d ago against content hash f6ca86162b25, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

publish-copy scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

tooling/commands/publish-copy.md · 95 lines

How it starts

The opening of the file, as written. The whole thing — 95 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Publish-Copy Command (internal)

Internal tooling. This command lives under tooling/ and is excluded from the marketplace payload. End users never see it.

Canonical Wake API docs: https://wakecommerce.readme.io/docs/schema (for any Wake API references in copied content).

Copy marketplace-ready plugin artifacts from the toolkit repo to the publish repository. Only spec-derived paths are copied; internal tooling (including this command) is excluded.

Prerequisites

  1. Read the rule: Load tooling/rules/publish-copy.mdc for inclusion and exclusion paths.

  2. Resolve destination:

    • If .publish-config.json exists and has destination: use it
    • Else if PUBLISH_REPO_PATH env is set (in shell or read from .env.local via the safe parser below): use it
    • Else: prompt user for destination path

    Config overrides env if both are set.

Workflow

  1. Read tooling/rules/publish-copy.mdc — get inclusion and exclusion lists.
  2. Resolve destination per Prerequisites above.
  3. Create destination if it does not exist (mkdir -p).
  4. Copy each inclusion path from repo root to destination:
    • .cursor-plugin/
    • .claude-plugin/
    • .mcp.json
    • skills/
    • agents/
    • commands/
    • README-publish.md (copied as README.md — marketplace version without toolkit-only Publish-Copy section)
    • assets/
    • scripts/
  5. Never copy tooling/ or rules/ (the publish-copy command and rule must not ship).
  6. Overwrite existing files at destination.
  7. Report:
    • If nothing to copy (no inclusion paths exist): report and exit
    • Otherwise: list copied paths and confirm completion

Execution

Read PUBLISH_REPO_PATH from .env.local with an explicit KEY=VALUE parser. Do NOT source the file — sourcing executes arbitrary shell from a config file and is unsafe.

PowerShell (default on Windows):

if (Test-Path .env.local) {
  $line = Select-String -Path .env.local -Pattern '^PUBLISH_REPO_PATH=' | Select-Object -Last 1
  if ($line) { $env:PUBLISH_REPO_PATH = ($line.Line -replace '^PUBLISH_REPO_PATH=','').Trim('"',"'") }
}
$dest = $env:PUBLISH_REPO_PATH
if (-not $dest -and (Test-Path .publish-config.json)) {
  $dest = (Get-Content .publish-config.json -Raw | ConvertFrom-Json).destination
}
if (-not $dest) { Write-Error "Set PUBLISH_REPO_PATH in .env.local, or create .publish-config.json with destination"; exit 1 }
New-Item -ItemType Directory -Force -Path $dest | Out-Null
foreach ($d in '.cursor-plugin','.claude-plugin','skills','agents','commands','assets','scripts') {
  if (Test-Path $d) { Copy-Item -Recurse -Force $d $dest }
}
if (Test-Path .mcp.json)         { Copy-Item -Force .mcp.json "$dest\.mcp.json" }
if (Test-Path README-publish.md) { Copy-Item -Force README-publish.md "$dest\README.md" }
Write-Host "Publish-copy complete. Destination: $dest"

Read the full file on GitHub · 95 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 95 lines · 69 tokens per session scan A f6ca86162b25

Subscribe to this mod's changes

publish-copy is a command published in the GitHub repository wake-engineering/ai-plugin (2 stars, last pushed 3mo ago), licensed MIT. It adds 69 tokens to every session and 1,205 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.