Contributing Clanker
Portable OSS contribution workflow with separated audit, preparation, and human-approved publishing authority
- Type
- Plugin
- Repository
- jeremylongshore/tons-of-skills-marketplace
- GitHub stars
- 2.8k
- License
- MIT
- Repo last updated
- Sep 27, 2026
- Version
- 0.9.0
- Author
- Jeremy Longshore
What Contributing Clanker is
Contributing Clanker is a plugin published in the jeremylongshore/tons-of-skills-marketplace repository on GitHub, which has about 2.8k stars. The repository describes itself as: “Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.”
A plugin is a package that bundles skills, slash commands, subagents, hooks, and MCP connectors so they install together. Plugins are plain files with a manifest at .claude-plugin/plugin.json, and they work in both Claude Code and Claude Cowork.
Installing Contributing Clanker adds everything it ships in one step. Connectors inside a plugin still need to be connected separately, and hooks and subagents only run in Cowork and Claude Code, not in regular chat.
How to install Contributing Clanker
Claude Code
- Add the repository as a plugin marketplace: claude plugin marketplace add jeremylongshore/tons-of-skills-marketplace
- Install the plugin: claude plugin install contributing-clanker@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json.
- Restart the session if the new skills or commands don't appear straight away.
Claude Cowork
- Open Customize → Plugins and choose Add marketplace.
- Enter jeremylongshore/tons-of-skills-marketplace (the owner/repo shorthand works for GitHub).
- Find Contributing Clanker in the list, click Install, then connect any connectors it needs from its Connectors tab.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from plugins/community/contributing-clanker/.claude-plugin/plugin.json, shared under the repository's MIT license. Read the full file on GitHub.
> Portable, least-authority workflow for respectful AI-assisted OSS contributions.
contributing-clanker helps contributors check upstream policy, avoid duplicate work, prepare evidence, and publish only what a human has reviewed. It is model-agnostic: Claude-specific helper agents are optional adapters, not runtime requirements.
Trust model at a glance
The plugin exposes three separately invoked skills:
Installing the plugin creates no state, clones, hooks, credentials, background jobs, or GitHub objects. Invoking contribute also performs no writes.
Distribution boundary
The canonical source for the public package is this tracked marketplace directory. A maintainer's personal checkout, installed-skill symlink, and CONTRIBUTE_STATE_DIR are private runtime inputs, not publication sources.
- Do not mirror or bulk-copy a personal contributing-clanker checkout into this directory.
- Do not package candidate records, dossiers, logs, credentials, worktrees, or user-authored gates.
- Do not add install/uninstall hooks that create, migrate, or synchronize local state.
- Port changes deliberately, review the marketplace diff, and run the portability regression tests before publication.
Catalog and website projections are generated only from this tracked directory. They do not read the maintainer's home directory or configured runtime state.
Thirty-second start
Start with the safe audit:
/contribute qualify owner/repository#123The result is ready-to-prepare, needs-information, wait, or skip, with evidence and the next safe action.
If preparation is appropriate, choose two absolute paths inside your own profile or workspace and initialize them explicitly:
export CONTRIBUTE_STATE_DIR=/your/profile/state/contributing-clanker
export CONTRIBUTE_WORKSPACE_DIR=/your/profile/worktrees/contributions
bash <contribute-prepare-skill-dir>/scripts/setup.sh \
--state-dir "$CONTRIBUTE_STATE_DIR" \
--workspace-dir "$CONTRIBUTE_WORKSPACE_DIR"Then invoke contribute-prepare. It produces a review packet and states that no external action occurred. Invoke contribute-publish separately only when you want to review and approve a specific GitHub action.
Why the split exists
Community skill installers should not inherit another operator's home layout, persistent state, agents, credentials, or approval identity. The split makes the authority boundary visible and enforceable:
- audit works without persistent state;
- preparation has no default paths and no GitHub mutation authority;
- publication cannot install dependencies or write local tracking state;
- authentication proves identity but never substitutes for approval; and
- repository instruction files apply only inside that repository.
The design responds directly to the Hermes interoperability report in issue #1321.
Local preparation model
After explicit setup, the chosen state directory contains:
candidates/ Markdown records for selected issues
research/ Cached repository-policy dossiers
user-gates/ Optional user-authored deterministic gates
check-runs/ Gate evidence
test-logs/ Local test output
profile.md User-selected languages and constraints
log.jsonl Append-only local workflow eventsThe chosen workspace directory contains only repositories the user explicitly selected. Bundled gates are read from the installed skill package; they are not copied into a hidden home directory.
Publication boundary
Before any comment, issue, branch push, or pull request, contribute-publish must show:
- exact repository and target;
- complete content or refspec;
- commit SHA and changed files;
- tests, linters, and gate evidence; and
- CLA/DCO, AI disclosure, warnings, and overrides.
Fresh approval applies to that exact action only. The skill does not merge, force-push, approve reviews, bypass repository rules, or delete branches without a separate explicit review and approval.
Requirements
- git
- jq
- GitHub CLI (gh) authenticated through the user's normal credential store
- Bash for the optional deterministic preparation scripts
- the target repository's own build/test dependencies, only when preparation is explicitly requested
No token value should be placed in plugin state or prompts.
Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Contributing Clanker?
Contributing Clanker is a plugin for Claude Code and Claude Cowork from the jeremylongshore/tons-of-skills-marketplace repository on GitHub. Portable OSS contribution workflow with separated audit, preparation, and human-approved publishing authority
How do I install Contributing Clanker in Claude Code?
Add the repository as a plugin marketplace: claude plugin marketplace add jeremylongshore/tons-of-skills-marketplace Install the plugin: claude plugin install contributing-clanker@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json. Restart the session if the new skills or commands don't appear straight away.
Can I use Contributing Clanker in Claude Cowork?
Open Customize → Plugins and choose Add marketplace. Enter jeremylongshore/tons-of-skills-marketplace (the owner/repo shorthand works for GitHub). Find Contributing Clanker in the list, click Install, then connect any connectors it needs from its Connectors tab.
Is Contributing Clanker safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- Geepers Orchestrator Corpus Coordinates corpus linguistics agents (linguistics expert, KWIC/concordance UI, database performance) for building and optimizing language corpus tools. Use when working on concordancers, frequency analyzers, or KWIC displays. Trigger with \"build a corpus feature\", \"optimize corpus queries\". Subagent · jeremylongshore/tons-of-skills-marketplace
- Geepers Orchestrator Deploy Orchestrates safe service deployments by sequencing pre-validation, Caddy route configuration, service lifecycle management, and post-deploy health checks with rollback on failure. Use when deploying a new service or changing infrastructure routing. Trigger with \"deploy this service\", \"add a Caddy route\". Subagent · jeremylongshore/tons-of-skills-marketplace
- Geepers Orchestrator Games Coordinates game development agents (design, gamification, React/web or Godot implementation) to build or enhance interactive games and gamification features. Use when creating a new game or adding achievement systems to an app. Trigger with \"build a game\", \"add gamification to this app\". Subagent · jeremylongshore/tons-of-skills-marketplace
- Geepers Janitor Hunts and eliminates project cruft — auto-removes cache/build artifacts, archives unused files with a manifest, flags dead code and stale dependencies. Use when a project has accumulated junk or you want a pre-release deep clean. Trigger with \"clean up this project\", \"run the janitor\". Subagent · jeremylongshore/tons-of-skills-marketplace
- Conversational Api Debugger Debug REST API failures using OpenAPI specs and HTTP logs. Analyzes errors, suggests fixes, and generates test commands. Plugin · jeremylongshore/tons-of-skills-marketplace
- Contract Test Validator API contract testing with Pact, OpenAPI validation, and consumer-driven contract verification Plugin · jeremylongshore/tons-of-skills-marketplace
- Coreweave Pack Claude Code skill pack for CoreWeave (23 skills). Community-contributed; not affiliated with, endorsed by, or sponsored by CoreWeave, Inc. CoreWeave is a registered trademark of CoreWeave, Inc. Plugin · jeremylongshore/tons-of-skills-marketplace
- Container Security Scanner Scan containers for vulnerabilities using Trivy, Snyk, and other security tools Plugin · jeremylongshore/tons-of-skills-marketplace