VibeX

Plugin

A VibeX plugin package is installed, enabled, updated, and uninstalled under one identity. One package may contribute UI, agent, Host, and runtime at once. Install treats it as a product package. UI, Agent, and Host contributions may share the package.

Lifecycle

Discover or import yields a source package. That is not yet execution rights. Install accepts an exact version/digest as the Host’s immutable install. Sources are marketplace snapshot, GitHub snapshot, local archive, or linked development. A Git #tag / #commit, a marketplace install, or a GitHub Release digest pins a snapshot; an unpinned repository is unlocked. New installs start disabled. Enable is the durable intent to publish contributions. After enable, the Host produces an activation generation: an atomic snapshot of package, grants, Runtime locks, and ready contributions. A candidate generation is invisible until fully validated. A failed update keeps the previous complete generation. When the origin lock is valid and a newer tag or semver appears remotely, Installed shows Update available. The Host watches a linked development directory and republishes a candidate generation when the digest changes.

Agent-side contributions (Skill, managed MCP, Hook) enter conversations created or rebound after enable. UI and Provider contributions appear on enable and vanish on disable. Conversations that already exist keep the tool list from creation.

Turning enable off withdraws UI and Provider entries immediately. New Agent-side turns stop using the package’s contributions. History in the event log stays. An installed package can be uninstalled: membership, agent bindings, and Skill projections go away. Conversation, artifact, and automation history remain. Config stays by default; delete plugin data also drops the Host-managed snapshot, and unreferenced Runtimes are reclaimed. A linked development directory stays on disk.

Trust

Enabling a VibeX plugin package allows it to run workers and UI with the same local rights as the Host. Separate processes exist for lifecycle, hot reload, and crash isolation. Package layout, content index, and validation are in the developer docs.

Agent-native plugins (Codex / Claude Code package formats) are held by that agent’s storage and trust. VibeX may project a read-only view and forward install/enable when the adapter is reliable. Native trust and VibeX enablement are separate authorities.

How-to: Install and enable a Plugin.

Control plane

The plugin control plane is the sole fact source for install, grant, start/stop, update, diagnostics, rollback, and uninstall. It can also read projections of agent-native plugins. Additions and deletions in native directories still follow that agent. External disable or a broken link must be shown as-is.

Identity

Plugin identity is stable Publisher plus Plugin ID. Display name, folder name, and similar contents leave identity unchanged. Packages with the same ID and different publishers keep separate grants and data. A linked development plugin keeps following a user-chosen directory. After the source changes, contributions, grants, and identity must be revalidated. The development directory stays on disk.

Official plugins and third-party plugins use the same public SDK and contribution points. A plugin targets Host contribution points; reuse another plugin by copying its source and packaging it under a new identity.

Contribution attach

Plugin contributions attach by type to different places in the product. Usability is judged per contribution. A Skill inside the package is one contribution among others. Each contribution has its own identity, type, compatibility conditions, and readiness.

Contribution Attach point When it applies
Skill / MCP / Hook Agent conversation; visible to that agent after Agent binding New or rebound conversation
Command / toolbar / status / slash / timeline card / settings section Matching Host chrome slot On enable
Top-level tab / workspace panel / kanban view / settings page Central bar, Dockview, Kanban container, settings sidebar On enable
File opener / preview / editable file tab Workspace files and artifacts On enable
Provider import / remote provisioner Model Provider import menu; provision of a saved Host On enable
Workflow Orchestration; publish path matches the source file in the repo Available after enable
Host Worker Host background; clients observe a projection With the activation generation
Runtime Exact CLI / Binary / sidecar version, resolved and locked by the Host Ready after a passing probe

Binding and readiness

Enable allows those contributions to be published. Missing runtime, missing binding, or an agent that rejects the contribution leaves it unready. All-agents binding intent projects compatible contributions onto current and future enabled agents that support the capability. Exclusions are stored separately.

A Skill projection is a controlled read-only entry written to the agent-native Skill location. A user Skill of the same name stays. A Plugin Command and an agent-native command may share a display name and remain distinct by source identity.

Several plugins may occupy the same slot. The Host aggregates what can be aggregated (status items, side-by-side panels). When a single selection is required (default opener, same-pattern priority), the user chooses. Replacement is “disable A, enable B”.

A remote workstation changes state on the Host. Companion and chat-channel plugin management lives in Settings → Plugins on the Host or a workstation desktop.

Rendering tracks

The Host chooses a rendering track by interaction density: descriptors (status items, commands, light blocks) are drawn by Host components; structure surfaces (tab, panel, kanban view, settings page) default to Module Federation; document-style UI and artifact.editor use an iframe App surface.

Runtime lock

A Runtime requirement is an author declaration. The install lock records the exact version the Host resolved, integrity, and probe evidence. A successful declaration and a spawned process still require a passing probe before ready. A Host-owned Runtime enters reclamation only after references drop to zero.

Official product plugins

Official product plugins live in the marketplace official category. Install them from the marketplace tab or CLI. They start disabled and can be uninstalled. The Host family still ships official MCP binaries. Bytes on disk are not an installed plugin. After the runtime is on disk, enable still has to be turned on. Agent-side tools enter later new or rebound conversations. UI and Provider contributions appear on enable. The switch lives on the plugin itself. Official packages use the same public SDK as third-party packages.

Plugin Effect after enable
Session Enhance Questions, live feedback, session lookup, and session control
Multi-agent & as a delegation mention; depth and child defaults apply to delegated children
Workflow Creator Source edit, validate, debug, and publish
VibeX Office Skills, workflows, and read-only preview for DOCX / XLSX / PPTX
Plugin Development Author Skill and references; install from the official category when you need that product
Remote SSH Install and start a remote Host over SSH, save it, and open a new window attached to it

Official reference plugins demonstrate public contribution points on the same install path:

Plugin Contributions shown
Host chrome sample app.command / app.toolbar / app.status / app.composer.slash / app.timeline.card / app.settings.section
Structure-surface sample app.tab / app.panel / app.kanban.view / app.composer.action / app.settings.page
Environment-variable provider import provider.model.importSource

Delivery

Official MCP ships with the Host family. After the plugin is enabled, the Host injects the matching MCP into later new or rebound agent sessions and trims tools/list per session. Conversations already open keep the tool list from creation.

The four Session Enhance tools can be turned off individually in plugin config. Multi-agent enablement is delegation enablement. Workflow Creator depends on the running Host loopback gateway. Office preview uses the Host-locked officecli Runtime. Native Workflow Studio does not depend on the Workflow Creator plugin. Uninstalling Remote SSH keeps saved Hosts by default.

Config writes each package’s config.json and applies to later new sessions, new previews, or the next connect.

Relation to Settings

Session tools and the delegation master switch live on those plugins’ Config tabs. Office preview idle timeout, Workflow Creator’s default completion policy, and Remote SSH host fields also live in each package config. Install from Settings → Plugins → Marketplace.