What a plugin is
A plugin is a Git repository with an oz0-plugin.yaml at its root. It is how anything specific gets into Orchestrator Zero: your tools, your agents, your skills. The core stays the same, and the building blocks official plugins use are the same ones you get.
The building blocks
| Block | What you write | Status |
|---|---|---|
| Tools | An MCP server: your own code, an existing PyPI or npm package, or a remote server | Works today |
| Agents | A YAML file: instructions, model, tools, contracts, limits, delegation | Works today (Pydantic AI) |
| Skills | Folders with a SKILL.md in the Agent Skills format | Works today |
| Harnesses | A command that runs one session of an agent harness, such as the Claude Agent SDK, per job | Works today |
| Hooks | Functions of your plugin that the platform asks before and after tool calls and at the start and end of a job; they answer allow, deny, modify or escalate | Works today (tool calls of Pydantic AI agents, and every job) |
| Flows | Declarative steps in YAML that chain tools, agents, conditions and approvals | Works today |
| Evals | Test cases for agents and flows, run with plugin test and recorded model answers, and on a test node before a new version reaches the fleet | Works today |
What happens when you install one
The edge locks it to a commit
It resolves the ref you give (or the latest vX.Y.Z tag) to a commit and stores that commit with the plugin.
The edge checks and packs it
The same checks as plugin lint, then a packed artifact, stored by its sha256: digest. Unpinned packages are pinned to the version the registry has now.
A version with evals passes them first
One node of the tenant runs the new version's evals against your models; a version that does worse is stopped, and the fleet keeps the one it has. See Quality gates.
Every node of the tenant gets it from the edge
Nodes never reach Git. Each node that matches the plugin's selector downloads the artifact from the edge, checks its digest and unpacks it.
The node builds its environment and starts it
uv builds a Python environment from the plugin's lock file, packages get their own environments, and the MCP servers start. The node reports the functions it found.
A failed update keeps the previous version running and reports the failure. Plugins of different tenants never mix.
Trust
Plugins run as processes with the node's permissions. There is no sandbox, so install only plugins you trust and run nodes as a user without root.