Objective
After PLC7 is complete and its three-view review findings are fixed, freeze and publish the minimum public Plugin author SDK and converge native/package managed Skill actions over the single Resource Catalog.
Hard prerequisite
Ordered scope
- Freeze declaration IR and engine-feature negotiation against synthetic, LSP, Base, and Arch evidence.
- Publish the minimum documented author surface under
loushang.plugin without owner authority objects.
- Add inert package validation and a separate explicitly approved execution-conformance command.
- Preserve each
SKILL.md as a resource_item; converge list/enable/load/refresh through one Catalog.
- Add strict native/package managed Skill-action declarations with exact digest, runtime, argv/cwd/env/effects/containment and Approval evidence.
- Add compatibility fixtures for two IR/engine versions, author documentation, and a non-example conformance package.
Exit gate
- no public Graph, registry, scope, approval store, mutable Plugin context, or owner authority leaks;
- validation never imports or executes Plugin code;
- Skill content is revision/digest reconstructible;
- native and packaged actions prove containment, Approval use, and revision pinning;
- three independent review views pass and every blocking finding is fixed/re-reviewed before PLC9 starts.
Canonical plan: docs/internals/architecture/harness/plugin/plugin-lifecycle-coding-pluginization-plan.md.
This issue is Product/Harness work only. It does not authorize MCP expansion, marketplace work, remote-service shortcuts, or a second Plugin/Graph/Resource authority.
Objective
After PLC7 is complete and its three-view review findings are fixed, freeze and publish the minimum public Plugin author SDK and converge native/package managed Skill actions over the single Resource Catalog.
Hard prerequisite
Ordered scope
loushang.pluginwithout owner authority objects.SKILL.mdas aresource_item; converge list/enable/load/refresh through one Catalog.Exit gate
Canonical plan:
docs/internals/architecture/harness/plugin/plugin-lifecycle-coding-pluginization-plan.md.This issue is Product/Harness work only. It does not authorize MCP expansion, marketplace work, remote-service shortcuts, or a second Plugin/Graph/Resource authority.