lousho add installs a tool, skill, channel, schedule or memory slot into an
agent directory from a registry. A registry is plain
static JSON: an index plus one document per item that carries the file contents.
The files are copied into your project as source you own and can edit. There is
no runtime plugin loader, and nothing from a registry is executed or imported
while adding it.
There is no hosted registry yet. Point lousho add at one with --registry or
the LOUSHO_REGISTRY environment variable; without either it fails with
LOUSHO_CONFIG_INVALID and says how to pass one.
Before it writes anything,
lousho add prints the permission manifest and the
files it will write, then asks [y/N].
Format
The index is{ items: [{ name, type, description, url | path }] }. type is
tool, skill, channel, schedule or memory. url / path locate the
item document; a relative one is resolved against the index’s own location.
Each item document is:
index.json:
name and type must match its index entry, and a
name is letters, digits, ., _ and -. A document that does not match the
format is LOUSHO_REGISTRY_INVALID, with the fields named.
Permission manifest
permissions declares what the item can do, so you can decide before you
install it. All of it is optional; what is missing is shown as “none” / “no”.
The manifest is what the author says the code does. It is not enforced by the
SDK and not a sandbox: read the files it lists (
--dry-run shows them) the way
you would read any dependency before running it.
Safety rules
- Every
files[].pathmust be relative, normalized and forward-slashed: no.., no absolute path, no drive letter (C:), no backslashes, no empty or.segments. After resolving symlinks it must still be inside the agent directory, and a symlink target is never written through. - A file must be inside the folder its item’s type allows:
toolintools/,skillinskills/<name>/,channelinchannels/,scheduleinschedules/,memoryinmemory/. - Existing files are not overwritten without
--overwrite. All files are checked before any is written, so a bad item writes nothing. Each of these failures isLOUSHO_REGISTRY_UNSAFE_PATHorLOUSHO_REGISTRY_FILE_EXISTS. - A file is at most 256 KiB and an item at most 1 MiB; a registry document at most 2 million characters.
- Only
http(s)URLs and local paths are read, with a 15 second timeout per fetch (LOUSHO_REGISTRY_UNREACHABLEotherwise). dependenciesare printed as annpm install ...line for you to run. The command never installs packages.