Semogram Docs
PluginsCustom creation

Secrets and skills

Bundle operational guidance or implement scoped credential resolution.

Skills add instructions to a plugin. Secret providers resolve credentials for supported execution paths. They have different runtime requirements and can coexist with other capabilities in one package.

Bundle a skill

Place each skill at skills/<skill-key>/SKILL.md and reference that path from a skill capability’s resourcePath. Include YAML frontmatter with a non-empty description.

A complete minimal skill package has two files:

craven.plugin.yaml
apiVersion: 1
kind: plugin
name: orders-review
packageName: orders-review
version: 1.0.0
displayName: Orders review
description: Guidance for reviewing order evidence
author:
  name: Operations team
capabilities:
  - kind: skill
    key: orders-review
    displayName: Orders review
    description: Review delivery changes against source evidence
    resourcePath: skills/orders-review/SKILL.md
skills/orders-review/SKILL.md
---
name: Orders review
description: Review delivery changes using accessible order and receipt evidence
---

Ask which project and time window to inspect.
Read accessible orders and receipts and compare their delivery dates.
Show the records supporting each discrepancy.
If evidence is missing, report the gap rather than inventing a date.
Review any proposed changes with the user before executing them.

A skill-only package can consist of the manifest and instruction file. If it also contains runtime code, include the runtime package and declarations described in Package format.

Implement a secret provider

Define a secret_provider capability, protected installation settings and a secret_resolution contract. Implement the runtime secret-provider declaration with create(config) returning the provider interface.

Scope the names and locations it may resolve. Report a missing or disallowed secret as an error. Do not fall back to arbitrary host environment values or log resolved credentials. See Environment Variables for the internal provider’s behavior.

Verify

For skills, verify frontmatter, referenced resource paths and that the installed instructions match the reviewed version. Skills supply guidance; they do not grant access to records or execute connector code themselves.

For secret providers, test allowed, missing and forbidden references. Then test the intended connector operation without displaying the secret. Validate the deployed resolver path; package tests alone do not prove the provider is registered in the hosted runtime.

FAQ

Does a skill need a runtime entrypoint?

A resource-based skill is loaded from its instruction file. Runtime entrypoints are required for executable capabilities according to their declared interfaces.

Can I use another plugin manifest format?

The custom authoring flow requires the canonical craven.plugin.yaml format. It rejects .claude-plugin/plugin.json and a root manifest.json.