Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add Kihara777/NixKits --skill cordis-plugin-developmentgit clone --depth 1 https://github.com/Kihara777/NixKitsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/kihara777/nixkits/cordis-plugin-development)<a href="https://agentmods.dev/skills/kihara777/nixkits/cordis-plugin-development"><img src="https://agentmods.dev/badge/skills/kihara777/nixkits/cordis-plugin-development/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/kihara777/nixkits/cordis-plugin-development"><img src="https://agentmods.dev/badge/skills/kihara777/nixkits/cordis-plugin-development.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00080 | $0.04618 |
| Opus 5 | $0.00040 | $0.02309 |
| Sonnet 5 | $0.00016 | $0.00924 |
| Haiku 4.5 | $0.00008 | $0.00462 |
Grade A, and why
cordis-plugin-development scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
100% identical to cordis-plugin-development — 0 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 421 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Develop Dynamic Cordis Plugins
First determine whether a capability belongs on Host or Client, then query the real interface before writing code. Never infer a complete API from a Service name, Event payload, Slot props, theme token, or example.
Standard workflow
- Call
cordis_inspect_listto obtain the Providers, methods, and schemas currently registered on Host and Client. - Select the smallest set of
cordis_inspect_querycalls needed to read the exact Services, Events, Builtins, Slots, Theme tokens, or Tools that the implementation will use. - For a new Plugin, design its first Package. To modify an existing Plugin, first use
cordis_inspect_self(pluginId, packageId)to read the base source and diagnostics. - Write plain JavaScript in
code.host,code.client, or both, then callcordis_define. - Call
cordis_runwith the finalpluginIdandpackageIdreturned by define. - Handle approval, waiting, Client loading, and render failures from the Run card, steering messages, or
cordis_inspect_self. - Use
cordis_stopto disable the Plugin temporarily. Usecordis_undefineonly when it is no longer needed.
Do not wait in the same turn for user approval or asynchronous browser results. After cordis_run returns awaiting-approval or starting, end the current Tool flow and wait for the system to report the final outcome through state updates and steering.
Tool usage guidance
| Tool | Use it when | Do not |
|---|---|---|
cordis_inspect_list |
Discover current Host/Client Providers and method schemas in one call; refresh after the runtime capability directory changes | Hard-code Provider names and skip list; treat a manifest as business data |
cordis_inspect_query |
Confirm exact Service methods, Event modes, Builtins, Slots, tokens, or Tool schemas before writing code | Use it instead of calling a real Service from the Plugin; assume a Client query will finish without a responding page |
cordis_inspect_self |
List current Plugins, inspect version pointers, or read exact Package source and runtime diagnostics | Fetch all source just to build a list; use it to modify or start a Plugin |
cordis_define |
Create a Plugin's first version or append an immutable Package to an existing Plugin; let the user preview the code first | Expect define to execute apply, request approval, or update current |
cordis_run |
Activate an exact Package; use run for first activation, restart, or rollback, and update to switch versions |
Use run to switch versions implicitly; treat pending or starting as success |
cordis_stop |
Pause current effects while preserving Packages, grants, and version pointers for later use | Use stop to mean permanent deletion |
cordis_undefine |
Permanently remove a Plugin and all of its Packages and clear historical business views | Call it while rollback, inspection, or restart is still needed |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 421 lines · 80 tokens per session scan A 01811d3ee9c0
cordis-plugin-development is a skill published in the GitHub repository Kihara777/NixKits (25 stars, last pushed 6d ago), licensed MIT. It adds 80 tokens to every session and 4,618 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. It is 100% identical to cordis-plugin-development, differing in 0 lines, and is treated as a copy.
Other skills, from other repositories
why
Use for 'why does X work this way', 'why we picked Y', design rationale, regressions, postmortems, or data-backed thresholds. Discovers available MCPs and queries each evidence category (source control, issue tracker, long-form docs, real-time chat, infrastructure observability, error tracking, product analytics…
technical-writing
Layered technical-writing standard: Diátaxis structure, Google developer style sentences, STE instruction rules, Global English syntax. Use for /technical-writing or when writing or reviewing docs, RFCs, readmes, PR descriptions, or commit messages.
unslop
Cut AI tells from any writing. Must always apply.
how
Use for "how does X work", code walkthroughs before changing something, and placement / ownership / layering questions ("where should this live", "which package owns this", "is this the right layer"). Explains subsystem architecture, runtime flow, onboarding mental models. Can critique architecture. Use why for…
quality-code
Standards for writing or modifying handwritten source code. Use when implementing code changes or reviewing handwritten code. Do not use for browsing, explanation, diagnosis without implementation, generated code, or vendored code.
teach
Explain a body of work plainly so a person actually understands it. Runs the how and why skills and weaves what they find into one clear explanation. Use for 'teach me this', 'help me really understand X', 'explain this change or subsystem to me'.