Plugin Capability Card
When a marketplace plugin can be driven by AI, a one-line Capability Card appears at the top of that plugin's Sessions pane saying so. It is read-only, dismissible per plugin, and never runs an action itself — anything sensitive still pauses in your inbox for your approval.
What it is
Status: shipped (always on, landed 2026-08-06). The card shows for any marketplace plugin that declares AI-callable actions in its manifest, on every installation — there is no separate toggle for the card itself, and nothing to enable.
When a marketplace plugin can be driven by AI (it declares AI-callable actions in its manifest), the Plugin Capability Card tells you so, right where you'd notice it: a single line at the top of that plugin's Sessions pane.
It is a read-only disclosure. It tells you the plugin's AI can take actions; it never runs one itself, and there is nothing on it to click besides dismissing it. Actions that actually change things still go through the normal approval flow (they pause in your inbox for you to approve) no matter what.
The card reads: "{Plugin name} can take actions for you with AI. Anything sensitive asks your approval first." A small ✕ next to it dismisses the card for that plugin, permanently: open a different AI-capable plugin later and you will see the card there, but this plugin stays quiet from then on.
Where to find it
There is no menu entry or setting for the card — it appears by itself. Open a marketplace plugin that declares AI actions, and look at the top of its Sessions pane, the pane that mounts beside the plugin's own screen; the card is that single line. It appears nowhere else in the app.
The plugins themselves are browsed, installed and removed from the Plugin Marketplace, described in plugin-marketplace.md.
How it behaves
- Nothing to enable — the card ships always-on (it landed with the
plugin-ai-native-clifeature on 2026-08-06). - Open a plugin that declares AI actions (its manifest lists
cli.endpoints). Its Sessions pane appears beside the plugin. - At the top of that pane you will see the one-line Capability Card. Read only, nothing to expand.
- Don't want the reminder for this plugin anymore? Click the ✕. It will not come back for that plugin (other AI-capable plugins you open still show it until you dismiss each one).
- To actually have the plugin's AI do something, ask it in a session; anything that changes data still pauses in your inbox for your approval first.
For agents
- Component: PluginCapabilityCard.tsx — presentational, props
{ pluginName: string, onDismiss: () => void }(noendpointsprop; it renders no per-action detail). Sparkles icon + one line of copy + a dismiss button. - Visibility is a pure function, compute-plugin-capability-card-visible.ts: shown iff the active plugin manifest declares at least one
cli.endpointAND that plugin has not been dismissed (the feature-reveal condition is always true now thatplugin-ai-native-cliships). There is no dedicated Lab flag for the card — the oldplugin-capability-cardflag and itspluginCapabilityCardEnabledsetting are gone; the card rides onplugin-ai-native-clionly. - Rendered by PluginSessionsPane.tsx, which also owns dismissal: clicking ✕ appends the plugin id to the
dismissedPluginCapabilityCardssetting (string[], default[]) — permanent and per-plugin; dismissing one plugin never hides the card for another. - DISPLAY-ONLY: the card adds no execute path. A plugin action still runs only through the existing confirm/approve/execute route (cli-server-plugins-routes.ts to plugin-cli-dispatch-handler.ts) — DF-0005, untouched by this card.
- It is the human-facing counterpart to the AI-facing capability block session-context/plugin-provider.ts
buildAiActionsBlockfolds into every plugin AI session; that briefing still lists individual actions for the AI, but the human card no longer mirrors that detail line-for-line — it just states the fact that AI actions exist here. - Contract + invariants: plugin-capability-card-contract.md. AI-pointable anchor
plugin-capability-cardin plugin-sessions.ui-anchors.ts.
Related
The experience the card sits inside is plugin-ai-native-sessions.md, which covers the Sessions pane, the suggested-prompt chips and the auto-context briefing the agent receives. Where the card is the human-facing one-liner, the AI-facing list of callable actions comes from the same plugin manifest, and a session that has to discover a plugin by name is plugin-cli-discovery.md. Installing, consenting to and removing the plugins themselves is plugin-marketplace.md.
Last verified 2026-09-23