Skip to content

docs: describe the plugin contract as the loader enforces it - #4

Merged
praxagent merged 1 commit into
mainfrom
docs/refresh-2026-09
Sep 7, 2026
Merged

praxagent merged 1 commit into
mainfrom
docs/refresh-2026-09

Conversation

@praxagent

Copy link
Copy Markdown
Owner

README's permissions section now centres on permissions.md ## secrets (the loader ignores PLUGIN_PERMISSIONS for IMPORTED plugins); "the enforced ceiling" is qualified (self-declared, no operator approval step); "plugins never touch API keys" is qualified (imagegen requests OPENAI_KEY); imagegen added to the table with a new README; radio's expose_ngrok documented as not working with its shipped allowlist. Docs only; 124 tests green.

- README: the "Plugin permissions (recommended)" section now centres on
  permissions.md `## secrets` — the loader ignores PLUGIN_PERMISSIONS for
  IMPORTED plugins (prax loader.py reads permissions.md) — and keeps
  PLUGIN_PERMISSIONS only as a BUILTIN/WORKSPACE note. "permissions.md is
  the enforced ceiling" is qualified: the command allowlist and secrets
  list are enforced, but the file is authored by the plugin and there is no
  operator approval step. "Plugins never touch API keys" is qualified
  (imagegen requests OPENAI_KEY). The "no raw socket usage" row states what
  the scanner actually flags. imagegen added to the plugin table.
- radio/README.md + Skills.md: the expose_ngrok feature shells out to sh and
  pkill, which radio's permissions.md does not allow, so it does not work
  with the shipped allowlist — documented rather than silently broken.
- elevenmusic/README.md: secrets wording matches the loader.
- imagegen/README.md: new, written from imagegen/plugin.py.

Docs only; permissions.md files (enforced configuration) are untouched.
@praxagent
praxagent merged commit fd9fbbd into main Sep 7, 2026
1 check passed
@github-actions github-actions Bot mentioned this pull request Sep 7, 2026
@praxagent
praxagent deleted the docs/refresh-2026-09 branch September 7, 2026 22:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant