
Product
Introducing Socket Scanning for VS Code Marketplace Extensions
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.
colab-electrobun-demo
Advanced tools
Comprehensive test plugin demonstrating the full Colab plugin API surface - powered by Electrobun!
A comprehensive demo plugin that showcases the full Colab plugin API surface. This plugin is designed for testing, QA, and as a reference implementation for plugin developers.
Colab discovers plugins on npm by searching for packages with the colab-plugin keyword.
test-plugin directoryLocal plugins are symlinked, so changes take effect after restarting Colab.
electrobun.zap - Enable "zapped" modeelectrobun.rest - Disable zapped modeelectrobun.showGitStatus - Display git branch and statuselectrobun.findFiles - Find TypeScript files in workspaceelectrobun.runShell - Execute a shell commandelectrobun.openDocs - Open Electrobun documentationType these in any Colab terminal:
zap [count] - Display zap animationsbunny - Show ASCII bunny artpaths - Show bundled binary paths (bun, git, fd, rg)Cmd+Shift+Z - Trigger the zap commandRight-click in the file tree to see:
The plugin registers a custom file handler for .bunny files featuring:
topIn JavaScript/TypeScript files, type console. to see electrobun-themed completion snippets.
Dynamic status bar item showing plugin state with periodic updates.
Open plugin settings to configure:
This plugin exercises the following API namespaces:
| Namespace | Methods Used |
|---|---|
api.commands | registerCommand, executeCommand |
api.webview | registerPreloadScript |
api.workspace | readFile, writeFile, exists, findFiles, getWorkspaceFolders |
api.editor | registerCompletionProvider |
api.terminal | registerCommand |
api.shell | exec |
api.notifications | showInfo, showWarning, showError |
api.log | debug, info, warn, error |
api.git | getStatus, getBranch |
api.events | onFileChange, onActiveEditorChange |
api.statusBar | createItem |
api.fileDecorations | registerProvider |
api.contextMenu | registerItem |
api.keybindings | register |
api.settings | registerSchema, get, set, onChange |
api.state | get, set, delete, getAll |
api.slates | register, onMount, onUnmount, onEvent, render |
api.paths | bun, git, fd, rg, colabHome, plugins |
api.ui | openUrl |
api.utils | getUniqueNewName |
api.plugin | name, version |
Declared capabilities (informational for user trust):
{
"filesystem": { "read": true, "write": true },
"network": { "internet": true },
"process": { "spawn": true },
"webview": { "scriptInjection": true },
"terminal": { "commands": true },
"ui": { "statusBar": true, "contextMenu": true, "fileDecorations": true, "notifications": true },
"editor": { "completions": true },
"keybindings": { "global": true }
}
This plugin lives in the Colab repository at test-plugin/ and is used for:
To develop locally:
index.tsTo make your plugin discoverable in Colab's plugin browser:
Add the colab-plugin keyword to your package.json:
{
"keywords": ["colab-plugin"]
}
Include the colab-plugin configuration field (see this plugin's package.json for a full example)
Publish to npm:
npm publish
Users can then find and install your plugin directly from Colab's Plugins panel.
Plugin slates can embed a full xterm.js terminal using the <colab-terminal> web component:
<colab-terminal cwd="/path/to/dir" style="width: 100%; height: 300px;"></colab-terminal>
const terminal = document.getElementById('my-terminal');
terminal.run('npm install'); // Run a command
terminal.write('y\n'); // Send raw input
terminal.clear(); // Clear screen
terminal.kill(); // Kill process
MIT
FAQs
Comprehensive test plugin demonstrating the full Colab plugin API surface - powered by Electrobun!
We found that colab-electrobun-demo demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.