v0.1.0
Pi Plugins v0.1.0
Initial public release of @nklisch/pi-plugins.
Features
- Install and manage compatible Claude Code and Codex marketplaces without either foreign host, with read-only adoption of foreign marketplace declarations.
- Activate Agent Skills, command hooks, and MCP servers as one revision-bound plugin across install, enable, disable, update, and uninstall.
- Manage plugins through the Pi-native interface or deterministic
plugin-control/v1commands, including inspection, diagnosis, update policy, notices, and operation control. - Ship receipt-qualified maintained MCP and subagent integrations with plugin-scoped lifecycle and faithful subagent hook interception.
Reliability and security
- Transactional lifecycle mutations across processes with exact conflict handling, crash recovery, rollback, offline restart, and persistent-data retention choices.
- Origin-authorized, DNS-pinned marketplace egress; credentialed MCP transport requires HTTPS; hardened YAML parsing.
- Exact package SRI, installed-tree, manifest, API, license, and runtime-range verification before maintained adapter code executes.
- Callback-scoped MCP launch values and no sensitive plaintext in durable state, projections, diagnostics, logs, or control output.
Verification
- 333 unit/integration files, 1,651 tests.
- 17 E2E files, 57 tests using real Pi 0.80.8 RPC, JSON, PTY, Git, SQLite, MCP, subagent, recovery, and multiprocess paths.
- From-empty offline npm lock/SRI replay passed.
npm audit: zero vulnerabilities.- All five release gates completed: security, tests, cruft, documentation, and patterns.
Provenance
- Git commit:
8db10578ce6d2d283b23d1270f7ccaddc2c81173 - Annotated tag object:
17760f8453b31ff94b467046a1c0df00bfce106b - Candidate npm SHA-1:
0b9ef185f34ab19b1d052c0a5d743044656a1f89 - Candidate npm integrity:
sha512-dbnL6bP0Vsy6TYoIqF96YVFTPBOHsnszUoOgdt0IkN1KjOwrUE9OLqi6yxlLH9cgZe02Ff9me/As6IHsr7Es4Q==