Use plugins

What a plugin is

Everything specific to your company ships as a plugin, a Git repository with one manifest.

A plugin is a Git repository with an oz0-plugin.yaml at its root. It is how anything specific gets into Orchestrator Zero: your tools, your agents, your skills. The core stays the same, and the building blocks official plugins use are the same ones you get.

The building blocks

BlockWhat you writeStatus
ToolsAn MCP server: your own code, an existing PyPI or npm package, or a remote serverWorks today
AgentsA YAML file: instructions, model, tools, contracts, limits, delegationWorks today (Pydantic AI)
SkillsFolders with a SKILL.md in the Agent Skills formatWorks today
HarnessesA command that runs one session of an agent harness, such as the Claude Agent SDK, per jobWorks today
HooksFunctions of your plugin that the platform asks before and after tool calls and at the start and end of a job; they answer allow, deny, modify or escalateWorks today (tool calls of Pydantic AI agents, and every job)
FlowsDeclarative steps in YAML that chain tools, agents, conditions and approvalsWorks today
EvalsTest cases for agents and flows, run with plugin test and recorded model answers, and on a test node before a new version reaches the fleetWorks today

What happens when you install one

The edge locks it to a commit

It resolves the ref you give (or the latest vX.Y.Z tag) to a commit and stores that commit with the plugin.

The edge checks and packs it

The same checks as plugin lint, then a packed artifact, stored by its sha256: digest. Unpinned packages are pinned to the version the registry has now.

A version with evals passes them first

One node of the tenant runs the new version's evals against your models; a version that does worse is stopped, and the fleet keeps the one it has. See Quality gates.

Every node of the tenant gets it from the edge

Nodes never reach Git. Each node that matches the plugin's selector downloads the artifact from the edge, checks its digest and unpacks it.

The node builds its environment and starts it

uv builds a Python environment from the plugin's lock file, packages get their own environments, and the MCP servers start. The node reports the functions it found.

A failed update keeps the previous version running and reports the failure. Plugins of different tenants never mix.

Trust

Plugins run as processes with the node's permissions. There is no sandbox, so install only plugins you trust and run nodes as a user without root.

Next

Copyright © 2026