CR

creating-plugins

Build and scaffold custom plugins for the EmDash CMS environment.

Install

mkdir -p .claude/skills/creating-plugins && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/10979" && unzip -o skill.zip -d .claude/skills/creating-plugins && rm skill.zip

Installs to .claude/skills/creating-plugins

Activation

This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.

Create EmDash CMS plugins with hooks, storage, settings, admin UI, API routes, and Portable Text block types. Use this skill when asked to build, scaffold, or implement an EmDash plugin, or when creating plugin features like custom block types, admin pages, or content hooks.
275 chars✓ has a “when” triggerlonger than Claude Code's old 250-char listing cap (fine on current versions)
Advanced

Key capabilities

  • →Scaffolds EmDash CMS plugins
  • →Implements hooks and routes
  • →Manages admin UI and block types
  • →Supports standard and native plugin formats

How it works

It provides a standardized structure and tools for creating TypeScript-based plugins for EmDash CMS.

Inputs & outputs

You give it
Plugin requirements
You get back
Plugin scaffold and code

When to use creating-plugins

  • →Scaffolding a new plugin
  • →Implementing custom content hooks
  • →Adding admin pages to CMS

About this skill

Creating EmDash plugins

Build against the API that reaches the intended execution mode. Source types and production-boundary tests take precedence over examples in this skill when they disagree.

Choose a format

FormatRuntime sourceAdmin UIDistribution
Sandboxedsrc/plugin.ts default-exports a SandboxedPluginBlock Kit pages, widgets, saved-entry panels, and actionsPlugin CLI and registry
NativedefinePlugin() / createPlugin()React, Block Kit, and Astro componentsTrusted site dependency only

Use a sandboxed plugin unless the feature needs host-process access, React admin code, Astro rendering components, raw page fragments, or custom Portable Text block definitions. Native plugins run with the site's authority and cannot be installed from the registry.

Scaffold a sandboxed plugin

pnpm dlx @emdash-cms/plugin-cli init my-plugin
cd my-plugin
pnpm install
pnpm run test

The manifest is the identity and trust contract. Runtime hooks and routes live in src/plugin.ts; the CLI generates descriptors, manifests, and bundles. Do not create a separate descriptor factory or sandbox-entry.ts.

import type { SandboxedPlugin } from "emdash/plugin";

const plugin: SandboxedPlugin = {
	hooks: {
		"content:afterSave": async (event, ctx) => {
			ctx.log.info("Content saved", { id: event.content.id });
		},
	},
};

export default plugin;

Import authoring types from emdash/plugin with import type. Value imports are limited to lightweight helpers such as pluginRoute() and pluginResponse(), which the CLI bundles. Sandboxed runtime code can use Web APIs but not Node.js built-ins.

Declare access

Declare every host API in emdash-plugin.jsonc. Adding authority, exposing a route publicly, or adding MCP tools requires renewed administrator approval.

CapabilityGrants
schema:readPublic collection and field definitions
admin.editor-draft:readSelected unsaved field values after an explicit editor interaction
admin.editor-draft:patchHost-validated unsaved field changes proposed for editor review
content:readContent identity, translations, and published public URLs
content:revisions:readRetained revision data; implies content read
content:writeCreate, update, delete, and translation creation; implies read
content:publishRevision-fenced publish, unpublish, schedule, and unschedule; implies read
content:restoreRevision-fenced reads and restoration of trashed content
hooks.content-policy:registerPre-publish, pre-schedule, and pre-unpublish policy hooks
taxonomies:readTaxonomy definitions, terms, and entry assignments
taxonomies:writeTerm creation and assignment deltas; implies read
bylines:readPublic byline profiles and single or batched entry credits
redirects:readVersioned redirect inspection
redirects:writeVersioned redirect creation, update, and deletion; implies read
comments:readStored non-trashed comments and their personal data
comments:moderateExpected-status moderation; implies read
media:readReady-media metadata and authenticated asset URLs
media:bytes:readBounded media bytes and content hashes
media:metadata:writeAlt text, caption, and focal-point updates
media:writeUpload and delete; implies media read
network:requestctx.http.fetch() restricted to allowedHosts
network:request:unrestrictedctx.http.fetch() without a host list
users:readUser directory lookup; also required by comment hooks
email:sendEmail delivery when a transport is configured
hooks.email-transport:registerExclusive email:deliver hook
hooks.email-events:registerEmail before/after hooks
hooks.page-fragments:registerTrusted-only page fragments; excluded from sandbox registration

Settings, KV, declared storage, logging, and cron scheduling are plugin-scoped and need no capability. Use ctx.settings for user configuration, ctx.kv for internal key-value state, and declared ctx.storage.<collection> for queryable records.

Read the focused reference for the API being used:

Routes, HTTP, and MCP

Routes are private by default and require authentication, their declared RBAC permission, token scope or CSRF as appropriate. Public routes are internet-facing and require explicit install consent.

Undeclared routes keep the legacy JSON/query envelope. Declare methods and body modes for host-enforced parsing. Use pluginResponse() only on a route that declares a raw response. Outbound ctx.http.fetch() responses and declared route bodies are buffered and bounded.

MCP tools reference private JSON routes with explicit permissions and Zod input schemas. Mark difficult-to-reverse operations destructive: true. Read API routes and MCP tools.

Hooks

Sandboxed hooks enter the same priority, dependency, timeout, error-policy, enablement, exclusive-provider, and capability pipeline as trusted hooks. Publication policy hooks identify action origin and actor without granting publication authority. Comment moderation invoked through ctx.comments reports plugin origin and runs the normal after-hook once. Read Hooks.

Declarative admin UI

Sandboxed pages and widgets return validated Block Kit. Structured links use host-resolved targets; routeCtx.ui carries host-attested locale, direction, and surface. External images require matching network authority.

Saved-entry panels and actions point to private routes. Ordinary panel load receives only host-reloaded saved identity and version. Add admin.editor-draft:read or admin.editor-draft:patch plus extension-level collection and field selectors when an explicit interaction must receive selected unsaved fields or propose an atomic whole-field patch. Patch does not imply read. The host previews accepted patches, marks the form dirty, and never saves them automatically. Read saved content through capability-gated ctx.content.

Declarative field widgets currently compose supported Block Kit elements into a JSON value. Custom Portable Text blocks and Astro render components remain native-only. Read Admin UI, Block Kit, and Portable Text blocks.

Runner parity

Cloudflare Worker Loader and Node/workerd execute the same bundle behind a plugin-scoped bridge. Both return buffered WHATWG responses from ctx.http.fetch() with binary bytes preserved and decoded request/response bodies limited to 8 MiB. Write against exported types, not extra methods found in one wrapper.

Read Sandbox boundaries before designing around an API not listed here.

Test the production boundary

Use createPluginTestHost() for fast hook, route, manifest, capability, KV, settings, and storage transport tests. Use createPluginRuntimeTestHost() when the test must exercise real content actions, plugin activation, media, comments, redirects, scheduling, restart, authorization, CSRF, caching, Block Kit validation, or saved-entry extensions.

Runtime fixtures establish state without firing hooks. Runtime actions call production boundaries; inspectors read observable state. Queue outbound HTTP responses with host.http.respond() and inspect requests with host.http.requests(). Dispose every host after use. Add Node/workerd parity only for runner-sensitive behavior.

References


Content truncated.

When not to use it

  • →When the project is not an EmDash CMS plugin
  • →When the user wants a non-TypeScript plugin

Limitations

  • →Specific to EmDash CMS
  • →Requires TypeScript knowledge

How it compares

It offers a dedicated, standardized framework for EmDash CMS plugin development.

Compared to similar skills

creating-plugins side by side with the closest alternatives in the catalog.

SkillInstallsUpdatedSafetyDifficulty
creating-plugins (this skill)03moReviewAdvanced
scaffold-feature05moReviewIntermediate
supabase-developer959moReviewIntermediate
payload734moReviewIntermediate

Try saying

Example prompts that trigger this skill in your AI assistant.

You might also like

scaffold-feature

niklasbrandt

Scaffold a complete full-stack feature: FastAPI endpoint, dashboard Web Component, i18n keys, test stubs, and documentation checks.

00

supabase-developer

daffy0208

Build full-stack applications with Supabase (PostgreSQL, Auth, Storage, Real-time, Edge Functions). Use when implementing authentication, database design with RLS, file storage, real-time features, or serverless functions.

95185

payload

payloadcms

Use when working with Payload CMS projects (payload.config.ts, collections, fields, hooks, access control, Payload API). Use when debugging validation errors, security issues, relationship queries, transactions, or hook behavior.

73206

telegram-mini-app

davila7

Expert in building Telegram Mini Apps (TWA) - web apps that run inside Telegram with native-like experience. Covers the TON ecosystem, Telegram Web App API, payments, user authentication, and building viral mini apps that monetize. Use when: telegram mini app, TWA, telegram web app, TON app, mini app.

62163

stripe-integration

wshobson

Implement Stripe payment processing for robust, PCI-compliant payment flows including checkout, subscriptions, and webhooks. Use when integrating Stripe payments, building subscription systems, or implementing secure checkout flows.

48165

deepwiki-rs

sopaco

AI-powered Rust documentation generation engine for comprehensive codebase analysis, C4 architecture diagrams, and automated technical documentation. Use when Claude needs to analyze source code, understand software architecture, generate technical specs, or create professional documentation from any programming language.

25170

Search skills

Search the agent skills registry