
Security News
When Autonomous Agents Escape: Why Socket Signed the Cyber Defense Open Letter
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.
@timps-ai/plugin-sdk
Advanced tools
TIMPS plugin SDK — formal interface for extending TIMPS agents with custom commands, tools, and lifecycle hooks. Build plugins for AI coding workflows.
Formal interface for extending TIMPS agents with custom commands, tools, and lifecycle hooks.
npm install @timps-ai/plugin-sdk
import { PluginRegistry, loadPlugin } from '@timps-ai/plugin-sdk'
import type { Plugin } from '@timps-ai/plugin-sdk'
const registry = new PluginRegistry()
// Register a plugin with manifest + handler maps
const myPlugin: Plugin = {
manifest: {
name: 'my-plugin',
version: '1.0.0',
description: 'Custom commands for my workflow',
commands: [{ name: 'hello', description: 'Say hello', usage: '/hello <name>' }],
tools: [{
name: 'greet',
description: 'Greet someone',
parameters: { type: 'object', properties: { name: { type: 'string' } }, required: ['name'] }
}],
hooks: ['before:run', 'after:run'],
},
commands: {
hello: async (args, ctx) => `Hello, ${args[0] || 'world'}!`
},
tools: {
greet: async (params, ctx) => ({ output: `Hello, ${params.name}!` })
},
hooks: {
'before:run': async (event, payload, ctx) => { console.log('Starting run...') },
'after:run': async (event, payload, ctx) => { console.log('Run complete') }
},
setup: async (ctx) => { console.log('Plugin initialized') },
teardown: async (ctx) => { console.log('Plugin cleaned up') },
}
registry.register(myPlugin)
// List registered plugins
console.log(registry.list())
// Resolve a command handler
const handlers = registry.resolveCommand('hello')
console.log(handlers[0].plugin.manifest.name)
// Get all tool specs + handlers
console.log(registry.allTools().length, 'tools registered')
// Load a plugin from a file (default export must be a Plugin object)
const filePlugin = await loadPlugin('./path/to/plugin.js')
registry.register(filePlugin)
| Property | Type | Required | Description |
|---|---|---|---|
manifest | PluginManifest | ✅ | Static metadata (name, version, description, commands, tools, hooks) |
commands | Record<string, CommandHandler> | ❌ | Command name → handler mapping |
tools | Record<string, ToolHandler> | ❌ | Tool name → handler mapping |
hooks | Partial<Record<HookName, HookHandler>> | ❌ | Lifecycle hooks |
setup | (ctx: PluginContext) => Promise<void> | ❌ | Called once on activation |
teardown | (ctx: PluginContext) => Promise<void> | ❌ | Called once on deactivation |
type CommandHandler = (args: string[], ctx: PluginContext) => Promise<string>
type ToolHandler = (params: Record<string, unknown>, ctx: PluginContext) => Promise<{ output: string; error?: string }>
type HookHandler = (event: HookName, payload: unknown, ctx: PluginContext) => Promise<void>
The PluginContext.memory property provides access to the host agent's memory. This is a dependency-injected interface — plugin authors must test within a host that provides MemoryAPI.
interface MemoryAPI {
loadSemantic(projectPath: string): Promise<SemanticEntry[]>
saveSemantic(projectPath: string, entries: SemanticEntry[]): Promise<void>
loadEpisodes(projectPath: string, count?: number): Promise<EpisodicEntry[]>
appendEpisode(projectPath: string, entry: EpisodicEntry): Promise<void>
}
FAQs
TIMPS plugin SDK — formal interface for extending TIMPS agents with custom commands, tools, and lifecycle hooks. Build plugins for AI coding workflows.
The npm package @timps-ai/plugin-sdk receives a total of 4 weekly downloads. As such, @timps-ai/plugin-sdk popularity was classified as not popular.
We found that @timps-ai/plugin-sdk demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.

Research
/Security News
Socket researchers found 18 Chrome extensions and one Edge extension delivering a wallet drainer, credential theft, and other malicious payloads.