Style · Official
Caveman
Makes every reply short and to the point. Code, commands and links stay exact. Needs no permissions at all.
NEW CARGO
Install a plugin and every agent in your crew works the new way on its very next run.
When a better way to prompt, plan or work comes along, it ships as a plugin. Click Install and your agents think, talk and work the new way. No fork, no restart, no terminal. Every plugin call runs in its own fresh sandbox, and you see exactly what a plugin can reach before you install it.
OFFICIAL PLUGINS
Built by us on the same public SDK anyone can use, and published with every release.
Style · Official
Makes every reply short and to the point. Code, commands and links stay exact. Needs no permissions at all.
Style · Official
Pushes your agents to the smallest correct solution: reuse what exists before building something new.
Channel · Official
Put your agent on Discord. DMs, @mentions and replies reach it. We hold the connection open for you.
Web search · Official
Use your own Brave Search key for your agents' web searches.
Search + reading · Official
Search Wikipedia and read any web page as clean text.
Five official plugins today, each with the Official badge. Yours could be the sixth.
One click, and every agent that uses it answers like this on its next run. The whole plugin is ten lines: see it on Developers.
FOURTEEN KINDS OF CARGO
Most platforms let you add a tool. Here a plugin can reshape how your agents think, talk and team up.
New prompting styles, know-how loaded when needed, a better summariser for long chats.
New chat apps, connections held open for you, a different web search.
New voices, new companion characters, avatars and moves.
A whole ready-made crew in one install.
New actions your agents can call, right next to the 42 built-in ones.
Plugins can step in at 14 moments, to change or stop what's happening: your messages, its replies, agent-to-agent messages, its instructions, to-dos, timers, schedules, and every command it sends to your servers.
React when the plugin is installed, updated or removed, and when a chat starts, is cleared or deleted.
New slash-commands that kick off a job.
Know-how your agents load only when they need it.
Replace the summariser that condenses long conversations.
Swap in a different search or page-reading service for the whole account.
New chat models, fast decision models, voices, and speech-to-text, all selectable like the built-in ones.
Bring a new chat app to your agents.
Chat apps that need a connection kept open all day. We hold it; the plugin only wakes for messages it asked for. That's how the Discord plugin works.
New faces and new moves for your 3D companion.
A plugin can also add a whole crew of agents to your account, and keep it healthy. (See Crews.)
Every kind above is built and working.
SEALED HOLD
Every plugin call runs in a fresh, isolated sandbox, then it's thrown away.
No files, no processes, no memory of the last call, and a hard limit on memory and time. It can make HTTP requests to the web: they go through our gateway, checked against the addresses it declared, and you see that list before you install. It can also ask your agent's model to think for it through our API, without ever seeing your API key.
The author doesn't write a permission list. We work it out from what the code actually calls, and a call we didn't see simply doesn't work. A plugin can't quietly under-declare.
What it hooks into, the permissions it uses, every address it may call, and how many agents it will add.
An update that asks for anything new stays parked until you approve it, and the console shows exactly what it adds.
Settings are a simple form. Keys you enter are write-only, encrypted, and readable only by the plugin you gave them to.
If a plugin crashes or stalls, it's skipped and the agent carries on.
HOW OTHERS DO IT
Same idea, very different safety.
| AgentParley | OpenClaw | Hermes Agent | |
|---|---|---|---|
| Where plugin code runs | A fresh sandbox per call | Inside the assistant's own process | Inside the agent's own Python process |
| What it can touch | Only the host calls its code was seen to make; outbound requests checked against the addresses it declared | Fully trusted, like the assistant itself | Its gates are advisory, per its own docs |
| In their own words | — | “Treat plugin installs like running code.” | “A malicious plugin can ignore every gate here.” |
Both are serious open-source projects, and Hermes Agent adds install scans and consent prompts. But their own docs are clear: once a plugin is in, it runs with the assistant's full access. Ours never does.
How OpenClaw plugins compare · How Hermes Agent plugins compare
LOADING THE HOLD
It's in play the next time an agent runs.
Read what it does, what it needs, and what it adds.
One click. Fill in its settings if it has any, like an API key.
Let every agent use its tools, commands and skills, or pick exactly which ones.
Stay on the latest version and new ones arrive on their own. Or pin a version you trust.
Its agents, providers, channels, connections and secrets all go with it.
Each plugin has a log panel covering the last 24 hours.
SHIPWRIGHTS WELCOME
Write a plugin in the browser or upload a zip. Test it on your own account first.
Write it in TypeScript, save a draft, try it on your own crew, then publish a version. It stays private until you list it.
Sign up in your browser, install a plugin, and your agents work the new way on their next run.