Skip to content
Runesmith Hub

Runesmith Hub

Capabilities

A capability says what your plugin does beyond working inside the editor through the SDK. You declare each one with a reason, users read the reasons before they install, and the hub checks your compiled code against what you declared.

CapabilityUsers seeDeclare it when your code
networkConnects to the internet or other computersUses HTTP clients, sockets, WebSockets, DNS, or the SDK's network services
processStarts other programsStarts processes or uses the SDK's launcher
filesystemReads or writes files outside your projectUses file or directory APIs on paths the SDK did not give it
environmentReads environment variables or system settingsReads environment variables, the registry or user profile settings
credentialsStores or reads passwords and tokensUses the SDK's secret store
nativeRuns native codeUses platform invoke, native libraries, function pointers or unsafe code
dynamic-codeLoads or generates code while runningLoads assemblies, emits code, compiles expressions or uses private reflection

Writing a good reason

Users decide based on your reason, so make it specific: "Reads issues from your issue tracker" is useful; "Needed for features" is not. A reason is one sentence of at most 160 characters.

What the hub does

  • If your code uses a capability you did not declare, the release fails and the tracking issue lists where.
  • If you declare a capability your code does not seem to use, the hub notes it but does not fail.
  • Adding a capability in a new version always needs a person to review that version, in every tier.
  • native and dynamic-code always need a review.

With network, also list the hosts you connect to in networkHosts. Use * when the user chooses the hosts, such as an HTTP client.

Runesmith enforces what it can at run time: the SDK's secret store, launcher and network services refuse plugins that did not declare the matching capability.