Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/pr-pm/prpm/creating-zed-extensionsnpx skills add pr-pm/prpm --skill creating-zed-extensionsgit clone --depth 1 https://github.com/pr-pm/prpmWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/pr-pm/prpm/creating-zed-extensions)<a href="https://agentmods.dev/skills/pr-pm/prpm/creating-zed-extensions"><img src="https://agentmods.dev/badge/skills/pr-pm/prpm/creating-zed-extensions.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00052 | $0.02813 |
| Opus 5 | $0.00026 | $0.01406 |
| Sonnet 5 | $0.00010 | $0.00563 |
| Haiku 4.5 | $0.00005 | $0.00281 |
Grade C, and why
creating-zed-extensions scanned grade C with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Downloads and executes remote codehighSupply chain
curl | sh runs whatever the server returns today, which is not necessarily what it returned when this was reviewed.
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
let output = Command::new("curl") How it starts
The opening of the file, as written. The whole thing — 457 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Creating Zed Extensions
Overview
Zed extensions are Rust programs compiled to WebAssembly that can provide slash commands, language support, themes, grammars, and MCP servers. Extensions implement the zed::Extension trait and are distributed via Zed's extension registry.
When to Use
Create a Zed extension when:
- Adding custom slash commands to the Assistant (
/deploy,/analyze,/fetch-docs) - Providing language support (syntax highlighting, LSP, formatting)
- Creating custom color themes
- Integrating external tools via slash commands
- Providing MCP server integrations
Don't create for:
- Simple rules or instructions (use
.rulesfiles) - One-time scripts (use terminal)
- Project-specific configuration (use
.zed/settings.json)
Quick Reference
Extension Structure
my-extension/
├── Cargo.toml # Rust manifest
├── extension.toml # Extension metadata
└── src/
└── lib.rs # Extension implementation
Minimal Slash Command Extension
# extension.toml
id = "my-commands"
name = "My Commands"
version = "0.1.0"
authors = ["Your Name"]
repository = "https://github.com/username/my-commands"
license = "MIT"
[slash_commands.echo]
description = "echoes the provided input"
requires_argument = true
[slash_commands.greet]
description = "greets the user"
requires_argument = false
// src/lib.rs
use zed_extension_api::{self as zed, Result, SlashCommand, SlashCommandOutput};
struct MyExtension;
impl zed::Extension for MyExtension {
fn run_slash_command(
&self,
command: SlashCommand,
args: Vec<String>,
_worktree: Option<&zed::Worktree>,
) -> Result<SlashCommandOutput> {
match command.name.as_str() {
"echo" => {
if args.is_empty() {
return Err("echo requires an argument".to_string());
}
Ok(SlashCommandOutput {
text: args.join(" "),
sections: vec![],
})
}
"greet" => {
Ok(SlashCommandOutput {
text: "Hello! How can I help you today?".to_string(),
sections: vec![],
})
}
_ => Err(format!("Unknown command: {}", command.name)),
}
}
}
zed::register_extension!(MyExtension);
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 457 lines · 52 tokens per session scan C 6dcdb30ba517
creating-zed-extensions is a skill published in the GitHub repository pr-pm/prpm (120 stars, last pushed 2mo ago), licensed MIT. It adds 52 tokens to every session and 2,813 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it C with 2 findings (downloads and executes remote code, makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
dependency-analysis
This rule automatically analyzes dependencies before they're installed to provide insights about maintenance frequency, security vulnerabilities, and popularity in the developer ecosystem.
biome
Biome JavaScript/TypeScript linter and formatter.
laravel
Laravel PHP framework best practices.
nextjs-react19
Next.js with React 19 App Router patterns.
android-new-project
Workflow for turning a fresh copy of this Android template into a new app — renaming the package/namespace/applicationId, branding (icons, splash, palette, fonts), Firebase setup, signing config, stripping unused sample screens, and verifying the foundation. Use when the user says they are starting a new app…
template-helpers
Catalog of the reusable building blocks shipped with this Android template — BaseActivity/BaseFragment, the helpers/ extension files (navigation, lifecycle, toast, snackbar, dialogs, images, permissions, theme, locale, settings intents, date, delay), common/ (Firebase, network, observers), and…