Skip to content

Add plugin installation support via frontmatter with dual-format configuration and cascading token resolution - #14041

Merged
pelikhan merged 8 commits into
mainfrom
copilot/add-plugin-support-frontend
Feb 6, 2026
Merged

Add plugin installation support via frontmatter with dual-format configuration and cascading token resolution#14041
pelikhan merged 8 commits into
mainfrom
copilot/add-plugin-support-frontend

Conversation

CopilotAI commented Feb 6, 2026

Copy link
Copy Markdown
Contributor

Adds plugins frontmatter field supporting both array and object formats for flexible plugin configuration. Compiler generates installation steps using engine-specific CLI commands with intelligent cascading GitHub token authentication.

Implementation

  • Frontmatter parsing: Extract plugins in both array and object formats, validate repo slugs (org/repo pattern)
  • Schema: Added plugins field to main workflow schema with oneOf for dual-format support
    • Array format: ["org/repo1", "org/repo2"]
    • Object format: { repos: ["org/repo1"], github-token: "${{ secrets.TOKEN }}" }
  • Step generation: Created GeneratePluginInstallationSteps() that produces installation steps with:
    • Engine-specific commands: copilot install plugin, claude install plugin, codex install plugin
    • GITHUB_TOKEN environment variable with cascading token resolution
    • Quoted step names to handle special characters in YAML
  • Engine integration: Inserted plugin installation after CLI installation in Copilot, Claude, and Codex engines
  • Token resolution: Implemented getEffectivePluginGitHubToken() with cascading precedence:
    1. Custom plugins.github-token from object format (highest priority, overrides all defaults)
    2. Custom github-token from top-level frontmatter (if specified)
    3. secrets.GH_AW_PLUGINS_TOKEN (dedicated plugin token)
    4. secrets.GH_AW_GITHUB_TOKEN (general gh-aw token)
    5. secrets.GITHUB_TOKEN (default GitHub Actions token)

Testing

  • Unit tests (plugin_installation_test.go): 23 test cases covering step generation, extraction, and token resolution
  • Integration tests (plugin_compilation_test.go): 11 test cases validating end-to-end compilation:
    • Array format with all three engines (Copilot, Claude, Codex)
    • Object format with and without custom token
    • Token precedence hierarchy validation
    • Top-level github-token precedence
    • No plugins scenario
    • Invalid repo format schema rejection

All 34 test cases pass successfully.

Usage

Array format (simple):

---
engine: copilotplugins:
- github/test-plugin
- acme/custom-tools
---

Generates installation steps with cascading token resolution:

- name: 'Install plugin: github/test-plugin'env:
GITHUB_TOKEN: ${{ secrets.GH_AW_PLUGINS_TOKEN || secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }}run: copilot install plugin github/test-plugin

Object format (with custom token override):

---
engine: copilotplugins:
repos:
- github/test-plugin
- acme/custom-toolsgithub-token: ${{ secrets.CUSTOM_PLUGIN_TOKEN }}
---

Generates installation steps with custom token:

- name: 'Install plugin: github/test-plugin'env:
GITHUB_TOKEN: ${{ secrets.CUSTOM_PLUGIN_TOKEN }}run: copilot install plugin github/test-plugin

With top-level github-token:

---
github-token: ${{ secrets.MY_GITHUB_TOKEN }}plugins:
- github/test-plugin
---

Generates:

- name: 'Install plugin: github/test-plugin'env:
GITHUB_TOKEN: ${{ secrets.MY_GITHUB_TOKEN }}run: copilot install plugin github/test-plugin
Original prompt

Add support for specifying plugins in the frontmatter and installing them through the agentic engine commands.

plugins will be a top-level frontmatter field that contains an array of strings. Each string is a repo slug in the form org/repo.

The compiler will take these repos and generate a step that calls the agentic CLI install plugin command for each one. It will generate a step that invokes the appropriate API to install these repos based on the correct syntax from Copilot, Claude, and Codex documentation.

Ensure the github-token is set on the step so the installation can use it to make Git requests.


💡 You can make Copilot smarter by setting up custom instructions, customizing its development environment and configuring Model Context Protocol (MCP) servers. Learn more Copilot coding agent tips in the docs.

CopilotAIand others added 4 commits February 6, 2026 04:19
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
CopilotAI changed the title [WIP] Add support for plugins in frontmatter with agentic installationAdd plugin installation support via frontmatterFeb 6, 2026
CopilotAI requested a review from pelikhanFebruary 6, 2026 04:36
@pelikhan

Copy link
Copy Markdown
Collaborator

Add support for cascading token resolution. The resolution order should be:

  1. gh-aw-plugins-token
  2. gh-aw-github-token
  3. github-token

@copilot

@pelikhan

Copy link
Copy Markdown
Collaborator

Copilot also adds support for an object-type configuration setting for plugins. This configuration includes a repos field, which is a string array of repositories, and a github-token field, which holds a custom token to use. This token overrides the default token resolution chain.

@pelikhan

Copy link
Copy Markdown
Collaborator

@copilot Copilot also adds support for an object-type configuration setting for plugins. This configuration includes a repos field, which is a string array of repositories, and a github-token field, which holds a custom token to use. This token overrides the default token resolution chain.

Added getEffectivePluginGitHubToken function with cascading precedence:
1. Custom token from frontmatter github-token field
2. secrets.GH_AW_PLUGINS_TOKEN
3. secrets.GH_AW_GITHUB_TOKEN
4. secrets.GITHUB_TOKEN
Updated all engine integrations to use cascading resolution and added tests for token resolution behavior.
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>

CopilotAI commented Feb 6, 2026

Copy link
Copy Markdown
ContributorAuthor

Add support for cascading token resolution. The resolution order should be:

  1. gh-aw-plugins-token...

Implemented cascading token resolution with the requested precedence order:

  1. github-token (from frontmatter)
  2. secrets.GH_AW_PLUGINS_TOKEN
  3. secrets.GH_AW_GITHUB_TOKEN
  4. secrets.GITHUB_TOKEN

The implementation follows the same pattern used in github_token.go for other token resolution functions. Users can now configure a dedicated GH_AW_PLUGINS_TOKEN secret for plugin operations, with automatic fallback to general-purpose tokens.

Example output:

- name: 'Install plugin: github/test-plugin'env:
GITHUB_TOKEN: ${{ secrets.GH_AW_PLUGINS_TOKEN || secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }}run: copilot install plugin github/test-plugin

Commit: bcffcfb

CopilotAI changed the title Add plugin installation support via frontmatterAdd plugin installation support via frontmatter with cascading token resolutionFeb 6, 2026
@pelikhan

Copy link
Copy Markdown
Collaborator

@copilot , make sure the main JSON schema is updated with the new frontmatter entries.

- Added PluginsConfig struct to support object format with repos and github-token fields
- Updated schema to accept both array and object formats using oneOf
- Updated extractPluginsFromFrontmatter to return (repos, token) tuple
- Updated engine integrations to use plugin-specific token with precedence:
1. plugins.github-token (custom token in object format)
2. github-token (top-level frontmatter token)
3. Cascading fallback (GH_AW_PLUGINS_TOKEN || GH_AW_GITHUB_TOKEN || GITHUB_TOKEN)
- Added comprehensive tests for object format with custom token override
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>

CopilotAI commented Feb 6, 2026

Copy link
Copy Markdown
ContributorAuthor

Copilot also adds support for an object-type configuration setting for plugins. This configuration includes a repos field, which is a string array of repositories, and a github-token field, which ...

Implemented object-type configuration for plugins with repos array and github-token field. The custom token overrides the cascading resolution chain.

Both formats are now supported:

Array format:

plugins:
- github/example-plugin

Object format:

plugins:
repos:
- github/example-plugingithub-token: ${{ secrets.CUSTOM_PLUGIN_TOKEN }}

Token precedence: plugins.github-tokengithub-tokenGH_AW_PLUGINS_TOKENGH_AW_GITHUB_TOKENGITHUB_TOKEN

Commit: fea000d

@copilot Copilot also adds support for an object-type configuration setting for plugins. This configuration includes a repos field, which is a string array of repositories, and a github-token field, w...

Implemented object-type configuration for plugins with repos array and github-token field. The custom token overrides the cascading resolution chain.

Both formats are now supported:

Array format:

plugins:
- github/example-plugin

Object format:

plugins:
repos:
- github/example-plugingithub-token: ${{ secrets.CUSTOM_PLUGIN_TOKEN }}

Token precedence: plugins.github-tokengithub-tokenGH_AW_PLUGINS_TOKENGH_AW_GITHUB_TOKENGITHUB_TOKEN

Commit: fea000d

CopilotAI changed the title Add plugin installation support via frontmatter with cascading token resolutionAdd plugin installation support via frontmatter with dual-format configuration and cascading token resolutionFeb 6, 2026
@pelikhan

Copy link
Copy Markdown
Collaborator

@copilot add more tests for compilation

CopilotAI commented Feb 6, 2026

Copy link
Copy Markdown
ContributorAuthor

@copilot , make sure the main JSON schema is updated with the new frontmatter entries.

The main JSON schema (pkg/parser/schemas/main_workflow_schema.json) has been updated with the new plugins frontmatter configuration. The schema supports both formats using oneOf:

  1. Array format: ["org/repo1", "org/repo2"]
  2. Object format: { repos: ["org/repo1"], github-token: "${{ secrets.TOKEN }}" }

Schema validation is active and correctly rejects invalid fields while accepting both valid formats.

Updated in commit: fea000d

Added integration tests covering:
- Array format with single and multiple plugins for all engines
- Object format with and without custom token
- Top-level github-token precedence
- Token precedence hierarchy validation
- No plugins scenario
- Invalid repo format schema validation
All 5 test suites with 11 test cases pass successfully.
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>

CopilotAI commented Feb 6, 2026

Copy link
Copy Markdown
ContributorAuthor

@copilot add more tests for compilation

Added comprehensive compilation tests in plugin_compilation_test.go covering:

Test Coverage (5 test suites, 11 test cases):

  • TestPluginCompilationArrayFormat: Array format with single/multiple plugins for Copilot, Claude, Codex
  • TestPluginCompilationObjectFormat: Object format with and without custom token
  • TestPluginCompilationWithTopLevelGitHubToken: Top-level github-token usage
  • TestPluginCompilationTokenPrecedence: Token hierarchy validation (plugins.github-token > github-token > cascading)
  • TestPluginCompilationAllEngines: All engines with quoted step names and proper commands
  • TestPluginCompilationNoPlugins: Verify no steps when plugins not specified
  • TestPluginCompilationInvalidRepoFormat: Schema validation rejection

All tests pass successfully.

Commit: 0daa50e

@pelikhan
pelikhan marked this pull request as ready for review February 6, 2026 05:30
CopilotAI review requested due to automatic review settings February 6, 2026 05:30

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR adds comprehensive plugin installation support to the agentic-workflows compiler, enabling users to specify plugins in the frontmatter that will be automatically installed before workflow execution. The implementation includes dual-format configuration (array and object formats), intelligent cascading GitHub token resolution, and seamless integration with all three supported engines (Copilot, Claude, and Codex).

Changes:

  • Added plugins frontmatter field with dual-format support (array or object with optional custom token)
  • Implemented cascading GitHub token resolution for plugin authentication (custom token → GH_AW_PLUGINS_TOKEN → GH_AW_GITHUB_TOKEN → GITHUB_TOKEN)
  • Integrated plugin installation steps into Copilot, Claude, and Codex engine installation flows

Reviewed changes

Copilot reviewed 158 out of 158 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
pkg/workflow/frontmatter_extraction_metadata.goAdds extractPluginsFromFrontmatter() to parse both array and object plugin formats
pkg/workflow/compiler_types.goAdds Plugins and PluginsToken fields to WorkflowData struct
pkg/workflow/compiler_orchestrator_tools.goIntegrates plugin extraction into tools processing pipeline
pkg/workflow/compiler_orchestrator_workflow.goPasses plugin data to WorkflowData initialization
pkg/workflow/copilot_engine_installation.goAdds plugin installation steps after Copilot CLI installation
pkg/workflow/claude_engine.goAdds plugin installation steps after Claude CLI installation
pkg/workflow/codex_engine.goAdds plugin installation steps after Codex CLI installation
pkg/parser/schemas/main_workflow_schema.jsonDefines plugins field schema with oneOf for dual-format validation
docs/src/content/docs/reference/frontmatter-full.mdDocuments the plugins frontmatter field
.github/workflows/*.lock.ymlRecompiled workflow lock files with updated MCP_GATEWAY_PAYLOAD_DIR configuration

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@pelikhan
pelikhan merged commit 7ec4e03 into mainFeb 6, 2026
133 checks passed
@pelikhan
pelikhan deleted the copilot/add-plugin-support-frontend branch February 6, 2026 05:41
github-actionsBot added a commit that referenced this pull request Feb 6, 2026
Add documentation for two new frontmatter features:
- plugins: Plugin installation support with dual-format config
- payload-dir: MCP gateway payload directory configuration
Related PRs: #14041, #14026
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@pelikhan