GitHub Copilot plugins
Plugins are preview functionality in VS Code and can bundle executable hooks
or MCP servers. Inspect the installed version and active plugin schema first.
Package only components that genuinely share installation,
versioning, trust, and lifecycle.
Workflow
- Define the bundle's user job, component graph, portability target, license,
publisher, update path, executable behavior, and uninstall contract.
- Prefer Agent Plugins 1.0 for portable skills and MCP servers: root
plugin.json, skills/, and mcp.json.
- Use a host-specific Copilot/Claude compatibility format only when agents,
hooks, or slash commands are required and document the lost portability.
- Validate every embedded skill, MCP server, hook, agent, command, reference,
root token, version, and license independently before packaging.
- Keep writable state under the format's data location; never write into the
installed package or embed credentials.
- Inspect the full package before separately authorized local installation.
Test enable, disable, update, and uninstall without assuming trust persists.
Rules
- Do not create a plugin merely to distribute one skill; a skill repository is simpler.
- Agent Plugins 1.0 portable components are skills and MCP servers. Treat
agents, hooks, and slash commands as client-specific unless the active spec says otherwise.
- Plugin MCP servers can be trusted as part of installation; make that expansion visible.
- Never claim Microsoft/GitHub endorsement or copy vendor documentation/examples.
- Pin versions and retain third-party notices for any bundled material.
Read plugin contracts, use bundle patterns, and apply verification.
Completion
The manifest and every component validate; portability claims match the chosen
format; executable trust and licenses are visible; no secrets/private authoring
material are bundled; and an approved VS Code smoke proves install, discovery,
disable, update behavior, and clean uninstall.
1---2name: github-copilot-plugins3description: Use for designing, creating, reviewing, or packaging GitHub Copilot and Agent Plugins for Visual Studio Code, including plugin.json, portable skills, MCP components, client-specific agents, commands, and hooks. Do not use for a single standalone skill, ordinary VS Code extensions, or installing an unreviewed plugin.4---56# GitHub Copilot plugins78Plugins are preview functionality in VS Code and can bundle executable hooks9or MCP servers. Inspect the installed version and active plugin schema first.10Package only components that genuinely share installation,11versioning, trust, and lifecycle.1213## Workflow14151. Define the bundle's user job, component graph, portability target, license,16 publisher, update path, executable behavior, and uninstall contract.172. Prefer Agent Plugins 1.0 for portable skills and MCP servers: root18 `plugin.json`, `skills/`, and `mcp.json`.193. Use a host-specific Copilot/Claude compatibility format only when agents,20 hooks, or slash commands are required and document the lost portability.214. Validate every embedded skill, MCP server, hook, agent, command, reference,22 root token, version, and license independently before packaging.235. Keep writable state under the format's data location; never write into the24 installed package or embed credentials.256. Inspect the full package before separately authorized local installation.26 Test enable, disable, update, and uninstall without assuming trust persists.2728## Rules2930- Do not create a plugin merely to distribute one skill; a skill repository is simpler.31- Agent Plugins 1.0 portable components are skills and MCP servers. Treat32 agents, hooks, and slash commands as client-specific unless the active spec says otherwise.33- Plugin MCP servers can be trusted as part of installation; make that expansion visible.34- Never claim Microsoft/GitHub endorsement or copy vendor documentation/examples.35- Pin versions and retain third-party notices for any bundled material.3637Read [plugin contracts](references/artifact-contracts.md), use [bundle patterns](references/patterns.md), and apply [verification](references/verification.md).3839## Completion4041The manifest and every component validate; portability claims match the chosen42format; executable trust and licenses are visible; no secrets/private authoring43material are bundled; and an approved VS Code smoke proves install, discovery,44disable, update behavior, and clean uninstall.