Create Plugin

A guided workflow for creating Copilot CLI plugins, from defining the idea through building, checking, and testing the result.

In plain words
What is it for?
Use it to gather requirements, plan plugin components, create the needed files, and validate and test a new plugin.
Why use it?
It helps turn an unclear plugin idea into a planned project and reduces mistakes caused by missing requirements or structure.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/poorgramer-zack/copilot-cli-things/create-plugin
Any agent
npx skills add Poorgramer-Zack/copilot-cli-things --skill create-plugin
Clone the repo
git clone --depth 1 https://github.com/Poorgramer-Zack/copilot-cli-things

Made for: Claude Code, Codex.

Per session 40 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 3,200 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00040 $0.03200
Opus 5 $0.00020 $0.01600
Sonnet 5 $0.00008 $0.00640
Haiku 4.5 $0.00004 $0.00320

Measured 2d ago against content hash b47d9269b8e3, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

Create Plugin scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

plugins/plugin-dev/skills/create-plugin/SKILL.md · 399 lines

How it starts

The opening of the file, as written. The whole thing — 399 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Plugin Creation Workflow

Create a complete, high-quality Copilot CLI plugin from initial concept to tested implementation. Follow a systematic approach: understand requirements, design components, clarify details, implement following best practices, validate, and test.

Core Principles

  • Ask clarifying questions: Identify all ambiguities about plugin purpose, triggering, scope, and components. Ask specific, concrete questions rather than making assumptions. Wait for user answers before proceeding with implementation.
  • Load relevant skills: Use the skill tool to load plugin-dev skills when needed (plugin-structure, hook-development, agent-development, etc.)
  • Use specialized agents: Leverage agent-creator, plugin-validator, and skill-reviewer agents for AI-assisted development
  • Follow best practices: Apply patterns from plugin-dev's own implementation
  • Progressive disclosure: Create lean skills with references/examples
  • Use sql: Track all progress throughout all phases

Phase 1: Discovery

Goal: Understand what plugin needs to be built and what problem it solves

Actions:

  1. Create todo list with all 7 phases
  2. If plugin purpose is clear from context:
    • Summarize understanding
    • Identify plugin type (integration, workflow, analysis, toolkit, etc.)
  3. If plugin purpose is unclear, ask user:
    • What problem does this plugin solve?
    • Who will use it and when?
    • What should it do?
    • Any similar plugins to reference?
  4. Summarize understanding and confirm with user before proceeding

Output: Clear statement of plugin purpose and target users


Phase 2: Component Planning

Goal: Determine what plugin components are needed

MUST load plugin-structure skill using skill tool before this phase.

Actions:

  1. Load plugin-structure skill to understand component types
  2. Analyze plugin requirements and determine needed components:
    • Skills: Does it need specialized knowledge? (hooks API, MCP patterns, etc.)
    • Skills: User-initiated actions? (deploy, configure, analyze)
    • Agents: Autonomous tasks? (validation, generation, analysis)
    • Hooks: Event-driven automation? (validation, notifications)
    • MCP: External service integration? (databases, APIs)
    • Settings: User configuration? (.local.md files)
  3. For each component type needed, identify:
    • How many of each type
    • What each one does
    • Rough triggering/usage patterns
  4. Present component plan to user as table:
    | Component Type | Count | Purpose |
    |----------------|-------|---------|
    | Skills         | 2     | Hook patterns, MCP usage |
    | Skills         | 3     | Deploy, configure, validate |
    | Agents         | 1     | Autonomous validation |
    | Hooks          | 0     | Not needed |
    | MCP            | 1     | Database integration |
    
  5. Get user confirmation or adjustments

Read the full file on GitHub · 399 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 399 lines · 40 tokens per session scan A b47d9269b8e3

Subscribe to this mod's changes

Create Plugin is a skill published in the GitHub repository Poorgramer-Zack/copilot-cli-things (2 stars, last pushed 5mo ago), licensed MIT. It adds 40 tokens to every session and 3,200 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

speckit-init

Scaffold a Spec Kit (spec-driven development) project for GitHub Copilot by running specify init --integration copilot --integration-options="--skills". USE FOR: starting a new spec-kit project, bootstrapping spec-driven development in an existing repo, installing spec-kit templates/scripts/commands for Copilot. DO…

github/spec-kit-copilot · 113 tokens

speckit-bundle

Discover, install, and author Spec Kit bundles via specify bundle. USE FOR: searching/showing/listing bundles, installing/updating/removing a bundle (a curated set of extensions/presets/integrations/workflows), validating a bundle manifest, building a distributable bundle artifact, initializing a project and…

github/spec-kit-copilot · 99 tokens

speckit-extension

Manage Spec Kit extensions via specify extension. USE FOR: installing/removing/updating spec-kit extensions, searching the extension catalog, showing extension info, enabling/disabling extensions, setting extension resolution priority, managing extension catalogs. DO NOT USE FOR: presets (use speckit-preset), bundles…

github/spec-kit-copilot · 83 tokens

speckit-preset

Manage Spec Kit presets via specify preset. USE FOR: installing/removing presets, searching the preset catalog, showing preset info, resolving which template a preset name maps to, enabling/disabling presets, setting preset resolution priority, managing preset catalogs. DO NOT USE FOR: extensions (use…

github/spec-kit-copilot · 88 tokens

speckit-workflow

Manage and run Spec Kit automation workflows via specify workflow. USE FOR: running a workflow by ID or local YAML, resuming a paused/failed run, checking run status, listing/installing/removing workflows, searching the workflow catalog, showing a workflow step graph. DO NOT USE FOR: extensions (use…

github/spec-kit-copilot · 93 tokens

speckit-check

Check the local environment for Spec Kit by running specify check (and specify version). USE FOR: verifying required tools are installed, diagnosing a broken spec-kit setup, reporting CLI version/feature capabilities. DO NOT USE FOR: installing or upgrading the CLI itself (use the speckit-self skill).

github/spec-kit-copilot · 69 tokens