cordis-plugin-development

A skill for creating and maintaining dynamic Cordis plugins, which are extensions that add host services, interface elements, events, tools, or client-to-host calls.

In plain words
What is it for?
It helps inspect registered interfaces, define and run plugin code, handle approvals and loading errors, update plugins, and stop or remove them.
Why use it?
It checks the platform's currently available interfaces before writing code, reducing failures caused by assumed or outdated APIs.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/whitelonng/dshcode/cordis-plugin-development
Any agent
npx skills add whitelonng/dshcode --skill cordis-plugin-development
Clone the repo
git clone --depth 1 https://github.com/whitelonng/dshcode

Made for: Claude Code, Codex.

Per session 80 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 4,618 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin 100% copy Near-identical to another mod in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00080 $0.04618
Opus 5 $0.00040 $0.02309
Sonnet 5 $0.00016 $0.00924
Haiku 4.5 $0.00008 $0.00462

Measured yesterday against content hash 01811d3ee9c0, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

cordis-plugin-development scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

This is a copy

100% identical to cordis-plugin-development — 0 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.

apps/cli/config/agent-presets/cordis/skills/cordis-plugin-development/SKILL.md · 421 lines

How it starts

The opening of the file, as written. The whole thing — 421 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Develop Dynamic Cordis Plugins

First determine whether a capability belongs on Host or Client, then query the real interface before writing code. Never infer a complete API from a Service name, Event payload, Slot props, theme token, or example.

Standard workflow

  1. Call cordis_inspect_list to obtain the Providers, methods, and schemas currently registered on Host and Client.
  2. Select the smallest set of cordis_inspect_query calls needed to read the exact Services, Events, Builtins, Slots, Theme tokens, or Tools that the implementation will use.
  3. For a new Plugin, design its first Package. To modify an existing Plugin, first use cordis_inspect_self(pluginId, packageId) to read the base source and diagnostics.
  4. Write plain JavaScript in code.host, code.client, or both, then call cordis_define.
  5. Call cordis_run with the final pluginId and packageId returned by define.
  6. Handle approval, waiting, Client loading, and render failures from the Run card, steering messages, or cordis_inspect_self.
  7. Use cordis_stop to disable the Plugin temporarily. Use cordis_undefine only when it is no longer needed.

Do not wait in the same turn for user approval or asynchronous browser results. After cordis_run returns awaiting-approval or starting, end the current Tool flow and wait for the system to report the final outcome through state updates and steering.

Tool usage guidance

Tool Use it when Do not
cordis_inspect_list Discover current Host/Client Providers and method schemas in one call; refresh after the runtime capability directory changes Hard-code Provider names and skip list; treat a manifest as business data
cordis_inspect_query Confirm exact Service methods, Event modes, Builtins, Slots, tokens, or Tool schemas before writing code Use it instead of calling a real Service from the Plugin; assume a Client query will finish without a responding page
cordis_inspect_self List current Plugins, inspect version pointers, or read exact Package source and runtime diagnostics Fetch all source just to build a list; use it to modify or start a Plugin
cordis_define Create a Plugin's first version or append an immutable Package to an existing Plugin; let the user preview the code first Expect define to execute apply, request approval, or update current
cordis_run Activate an exact Package; use run for first activation, restart, or rollback, and update to switch versions Use run to switch versions implicitly; treat pending or starting as success
cordis_stop Pause current effects while preserving Packages, grants, and version pointers for later use Use stop to mean permanent deletion
cordis_undefine Permanently remove a Plugin and all of its Packages and clear historical business views Call it while rollback, inspection, or restart is still needed

Read the full file on GitHub · 421 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 421 lines · 80 tokens per session scan A 01811d3ee9c0

Subscribe to this mod's changes

cordis-plugin-development is a skill published in the GitHub repository whitelonng/dshcode (553 stars, last pushed 2d ago), licensed MIT. It adds 80 tokens to every session and 4,618 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. It is 100% identical to cordis-plugin-development, differing in 0 lines, and is treated as a copy.

Related

Other skills, from other repositories

visionary-cli

Analyze images with DeepSeek's vision model via the visionary-server CLI. Use this whenever the user provides an image, photo, screenshot, or document with images - run vision to look at it rather than guessing.

xlight/deepseek-visionary · 46 tokens

deepseek-harness

Use when building AI agent applications with a plugin-based architecture — Web UI, CLI, Python SDK, Cordis plugin system, multi-model orchestration. DeepSeek Harness (dsh): open-source agent harness by DeepSeek AI where everything is a plugin, powered by Cordis for spatiotemporal composability.

znlgis/opengis-skills · 68 tokens

deepseek-harness

Use this skill whenever the user wants to call DeepSeek V4-Pro / V4-Flash (or its legacy aliases deepseek-chat / deepseek-reasoner), or you see code that imports from openai import OpenAI with baseurl="https://api.deepseek.com". This skill teaches you the 10 protocol contract rules required to avoid the 16 documented…

HenryZ838978/deepseek-harness · 144 tokens

web-ui-motion

Build polished front-end UI together with a signature motion effect in a single self-contained HTML file, combining SVG.js / SVG filters and the Canvas 2D API. Use when the user asks to build a web page, landing page, dashboard, or component that has a special visual effect, animation, particle system, fluid/water…

creativedswork/dscode · 152 tokens

openspec-propose

Create a complete OpenSpec proposal with design, specs, prototype, and tasks. Use when the user wants a change ready for implementation.

creativedswork/dscode · 32 tokens

prototype-workflow

Generate and lifecycle-manage HTML prototypes for UI exploration and OpenSpec changes. Use when creating, validating, completing, or archiving a UI prototype.

creativedswork/dscode · 34 tokens