Skip to main content
A plugin is a package of agent parts that you install from GitHub or from a connected device. A skill is a folder of instructions that an agent can load during a run. Skills arrive inside plugins, or on their own through pinework skill add and pinework skill create. You manage both on the Customize page, under Plugins and Skills.

A plugin brings skills, MCP servers and commands

Pinework reads plugin manifests written for Claude Code, Codex, Cursor or the open agent-plugins format. A manifest can declare many kinds of parts. Pinework installs three of them:
  • Skills, which agents load into a run.
  • MCP servers, which give agents new tools.
  • Commands, which you can turn on or off.
Pinework records the other declared kinds, such as hooks, subagents and rules, without installing them. A plugin MCP server cannot carry a raw credential. Its settings must point to a secret or a connection. Pinework refuses the install otherwise.

A marketplace is a list of plugins

A marketplace is a GitHub repo that publishes an index of plugins. Two are built in: “Anthropic official plugins” and “Cursor official plugins”. You can add your own:
The marketplace name comes from its index, not from the repo name. Removing a marketplace leaves its installed plugins in place. Before it installs anything, Pinework fetches the plugin and checks the archive. It refuses symlinks, hard links, paths that escape the plugin folder, and archives over 10,000 entries or 256 MiB. If the check finds no parts, nothing is installed.

Plugin parts are read-only because the plugin owns them

An installed plugin stays tied to its source. Once a day, Pinework checks the branch a plugin follows for a new commit. When the commit changed, it scans the plugin again and replaces its parts in place. You can also run pinework plugin refresh on one plugin. A local edit would not survive that replacement. So Pinework blocks edits to parts a plugin owns. An edit attempt fails with this message: “This resource is owned by a plugin and is read-only.” You can still change a few settings on plugin parts:
  • Turn the whole plugin on or off for the workspace.
  • Turn a plugin skill on or off by default.
  • Turn a plugin MCP server on or off, and pick the credential it uses.
To delete a plugin skill, uninstall its plugin. The skill page shows which plugin a skill came from and offers no editor.

To change a plugin skill, make your own copy

Pinework has no fork button. To change what a plugin skill says, read its files, then create a standalone skill with your version. Then turn the plugin’s skill off, so agents do not load both.
Your copy belongs to the workspace, not to the plugin. The daily check never touches it. It also never receives the plugin author’s later fixes. Two kinds of plugins never update on their own. A plugin pinned to a commit stays on that commit. A plugin installed from a device stays as it was installed.

A skill reaches a run when it is on for the agent

Plugins and their skills apply to the whole workspace. Each agent can override one skill:
An override cannot turn on a skill whose plugin is off. Turn the plugin on first. When a run starts, Pinework collects the skills that are on for that agent. A skill is on when its plugin is on and ready. It must also be on by default, or turned on for this agent. Pinework then writes each skill into the run’s files in the layout its harness reads. Claude Code, Codex, Cursor and OpenCode each get their native layout. The harness decides when to read a skill’s full text. Pinework also adds its own skill for working in Pinework. A skill that cannot be placed is dropped from that run. A name that collides with another skill is one cause. The run continues without it.

Install a plugin

Add a plugin from a marketplace.

Add an MCP server

Give agents a tool outside any plugin.