Skip to main content
Mibyan ships a small set of plugins bundled with the repository. They live under <repo>/plugins/<name>/ and load automatically alongside user-installed plugins in ~/.mibyan/plugins/. They use the same plugin surface as third-party plugins — hooks, tools, slash commands — just maintained in-tree. See the Plugins page for the general plugin system, and Build a Mibyan Plugin to write your own.

How discovery works

The PluginManager scans four sources, in order:
  1. Bundled — <repo>/plugins/<name>/ (what this page documents)
  2. User — ~/.mibyan/plugins/<name>/
  3. Project — ./.mibyan/plugins/<name>/ (requires mibyan_ENABLE_PROJECT_PLUGINS=1)
  4. Pip entry points — mibyan_agent.plugins
On name collision, later sources win — a user plugin named disk-cleanup would replace the bundled one. plugins/memory/ and plugins/context_engine/ are deliberately excluded from bundled scanning. Those directories use their own discovery paths because memory providers and context engines are single-select providers configured through mibyan memory setup / context.engine in config.

Bundled plugins are opt-in

Bundled plugins ship disabled. Discovery finds them (they appear in mibyan plugins list and the interactive mibyan plugins UI), but none load until you explicitly enable them:
Or via ~/.mibyan/config.yaml:
This is the same mechanism user-installed plugins use. Bundled plugins are never auto-enabled — not on fresh install, not for existing users upgrading to a newer Mibyan. You always opt in explicitly. To turn a bundled plugin off again:

Currently shipped

The repo ships these bundled plugins under plugins/. All are opt-in — enable them via mibyan plugins enable <name>. Memory providers (plugins/memory/*) and context engines (plugins/context_engine/*) are listed separately on Memory Providers — they’re managed through mibyan memory and mibyan plugins respectively. The full per-plugin detail for the two long-running hooks-based plugins follows.

disk-cleanup

Auto-tracks and removes ephemeral files created during sessions — test scripts, temp outputs, cron logs, stale chrome profiles — without requiring the agent to remember to call a tool. How it works: Deletion rules: Slash command — /disk-cleanup available in both CLI and gateway sessions:
State — everything lives at $mibyan_HOME/disk-cleanup/: Safety — cleanup only ever touches paths under mibyan_HOME or /tmp/mibyan-*. Windows mounts (/mnt/c/...) are rejected. Well-known top-level state dirs (logs/, memories/, sessions/, cron/, cache/, skills/, plugins/, disk-cleanup/ itself) are never removed even when empty — a fresh install does not get gutted on first session end. User project trees (workspace/, projects/, plans/, home/) are never tracked or swept at all: a test_*.py or tmp_* file inside your project is source code, not scratch. kanban/ (task attachments and workspaces) is never tracked either, and a tracked directory under a protected top level such as cache/ is never removed — only the files inside it age out. Enabling: mibyan plugins enable disk-cleanup (or check the box in mibyan plugins). Disabling again: mibyan plugins disable disk-cleanup.

security-guidance

Fast pattern-matched security warnings on file writes. When the agent’s write_file / patch / skill_manage calls carry content matching a known-dangerous code pattern — pickle.load, yaml.load without SafeLoader, eval(, os.system, subprocess(..., shell=True), JS child_process.exec, React dangerouslySetInnerHTML, raw .innerHTML = / .outerHTML = / document.write, Node crypto.createCipher, AES ECB mode, TLS verification disabled, XXE-prone xml.etree / minidom parsers, <script src="//..." > without SRI, torch.load without weights_only=True, GitHub Actions ${{ github.event.* }} injection — the plugin appends a ⚠️ Security guidance block to the tool’s result. The file is still written. The model reads the warning in the next turn’s tool message and can either fix the code or document why the construct is safe in this context. Pattern matching has a non-trivial false-positive rate, which is why warn (not block) is the default. Coverage: 25 rules total, covering unsafe deserialization, command injection, XSS sinks, crypto footguns, XXE, supply-chain (SRI), and CI/CD workflow injection. The pattern data is a verbatim Apache-2.0 fork of Anthropic’s claude-plugins-official — see the plugin’s LICENSE and NOTICE files for attribution. Modes: Enabling: mibyan plugins enable security-guidance (or check the box in mibyan plugins). Disabling again: mibyan plugins disable security-guidance. What it does not do (yet): the upstream Anthropic plugin has two more layers — an LLM diff review on each agent turn that touched files, and an agentic commit-time review that traces data flow across files. Neither is ported. The agent can already run those reviews on demand via delegate_task.

observability/langfuse

Traces Mibyan turns, LLM calls, and tool invocations to Langfuse — an open-source LLM observability platform. One span per turn, one generation per API call, one tool observation per tool call. Usage totals, per-type token counts, and cost estimates come out of Mibyan’ canonical agent.usage_pricing numbers, so the Langfuse dashboard sees the same breakdown (input / output / cache_read_input_tokens / cache_creation_input_tokens / reasoning_tokens) that appears in mibyan logs. The plugin is fail-open: no SDK installed, no credentials, or a transient Langfuse error — all turn into a silent no-op in the hook. The agent loop is never impacted. Setup (interactive — recommended):
The wizard collects your keys, prepares the declared langfuse extra through PM when needed, and enables observability/langfuse. Restart Mibyan and the next turn ships a trace. If preparation fails, retry through mibyan tools; do not install the SDK into the selected environment with pip. Setup (manual): For a source checkout, first follow the PM developer workflow with the intended Mibyan home. Use the checkout’s prepared Python:
Use . .\activate.ps1 for PowerShell activation. Then put the credentials in the active home’s .env ($mibyan_HOME/.env, normally ~/.mibyan/.env):
How it works: Session grouping keys off the Mibyan session ID (or task ID for sub-agents) via langfuse.propagate_attributes, so everything in a single mibyan chat session lives under one Langfuse session. Verify:
Optional tuning (in .env): Mibyan-prefixed and standard SDK env vars (LANGFUSE_PUBLIC_KEY, LANGFUSE_SECRET_KEY, LANGFUSE_BASE_URL) are both accepted — Mibyan-prefixed wins when both are set. Performance: the Langfuse client is cached after the first hook call. If credentials or SDK are missing, that decision is also cached — subsequent hooks fast-return without re-checking env vars or reloading config. Disabling: mibyan plugins disable observability/langfuse. The plugin module is still discovered, but no module code runs until you re-enable.

NeMo Relay native integration (migration note)

NeMo Relay is no longer a bundled Mibyan plugin. Do not run mibyan plugins enable observability/nemo_relay; Mibyan core now owns the Relay session, turn, LLM, and tool lifecycles. Configure Relay middleware or exporters through a standard Relay plugins.toml. Mibyan loads Relay’s user configuration (~/.config/nemo-relay/plugins.toml) and then its machine-wide system configuration (/etc/nemo-relay/plugins.toml, or %ProgramData%\nemo-relay\plugins.toml on Windows). Set mibyan_NEMO_RELAY_PLUGINS_TOML before starting Mibyan only when you want an explicit file to replace the user configuration; the system configuration still has higher precedence. The policy is process-wide for every profile hosted by that Mibyan process. Run mibyan doctor to see which files apply. See the NeMo Relay observability configuration for ATOF, ATIF, and OpenTelemetry options. The old mibyan_NEMO_RELAY_ATOF_* and mibyan_NEMO_RELAY_ATIF_* settings no longer configure exporters. When mibyan_NEMO_RELAY_PLUGINS_TOML is unset, the gateway warns about remaining legacy variables and mibyan doctor reports them. Independently discovered Relay user or system exporters still apply. Automatic migration. mibyan update (and mibyan migrate relay, or mibyan migrate relay --all-profiles for every profile home) converts the legacy variables into <mibyan home>/relay-plugins.toml, sets mibyan_NEMO_RELAY_PLUGINS_TOML in that profile’s .env, and comments the legacy lines out (nothing is deleted). Under a multiplexed gateway every profile home gets its own file. The generated file is validated through Relay before it is written; this is the shape it produces (note the type = "file" sink discriminator — a sink without it is rejected):
Then add mibyan_NEMO_RELAY_PLUGINS_TOML=/home/you/.mibyan/relay-plugins.toml to .env and restart the gateway.

Session-span segmentation (continuous sessions)

Relay exports a span when its scope closes. A continuous gateway session can keep its session span open for days even though each turn span exports normally. Optional segmentation rotates only the session scope at a turn boundary:
Both defaults preserve one session scope for the full session. Rotated spans retain the same session_id and add mibyan.session.segment plus mibyan.session.segment_reason (compaction or max_turns).

google_meet

Lets the agent join, transcribe, and participate in Google Meet calls — take notes on a meeting, summarize the back-and-forth after, follow up on specific points, and (optionally) speak replies back into the call via TTS. What it adds:
  • A headless virtual participant that joins a Meet URL using browser automation
  • Live transcription derived from Meet’s own live captions (the bot never decodes the meeting audio, so no STT billing — and captions are lossy and English-biased)
  • A meet_join / meet_status / meet_transcript / meet_leave / meet_say toolset the agent invokes to join calls, poll the live transcript, and act on what it heard
  • Post-meeting artifacts (transcript, status) saved under ~/.mibyan/workspace/meetings/<meeting_id>/
Setup:
Usage from chat:
“Join meet.google.com/abc-defg-hij and take notes. After the call, send me a summary with action items.”
The agent kicks off the meeting join, streams the transcription back into its context as the call proceeds, and produces a structured summary when the meeting ends (or when you tell it to stop). Realtime mode (mode='realtime') is speak-only on the audio side. The bot’s replies are synthesized by OpenAI Realtime and played into the call through a virtual microphone; what it hears is still the caption stream, not the meeting audio — nothing from the call is sent to the Realtime session. meet_status reports micState (unmuted, unmuted_clicked when the bot had to unmute itself after admission, or unknown when Meet’s toggle was not found) so a silent bot can be diagnosed. When to use it: recurring standups where you want a bot to transcribe + summarize for async attendees; deposition-style interviews where you want structured notes; any case where you’d otherwise need Fireflies / Otter / Grain. When you’d rather not have an AI listening in — don’t enable it. Disabling: mibyan plugins disable google_meet. Any saved transcripts stay in ~/.mibyan/workspace/meetings/ until you remove them.

mibyan-achievements

Adds a Steam-style achievements tab to the dashboard — 60+ collectible, tiered badges generated from your real Mibyan session history. Tool-chain feats, debugging patterns, vibe-coding streaks, skill/memory usage, model/provider variety, lifestyle quirks (weekend and night sessions). Originally authored by @PCinkusz as an external plugin; brought in-tree so it stays in lockstep with Mibyan feature changes. How it works:
  • Scans your entire ~/.mibyan/state.db session history on the dashboard backend
  • Per-session stats are cached by (started_at, last_active) fingerprint, so only new or changed sessions re-analyze on subsequent scans
  • First-ever scan runs in a background thread — the dashboard never blocks waiting for it, even on databases with thousands of sessions
  • Unlock state is persisted to $mibyan_HOME/plugins/mibyan-achievements/state.json
Tier progression: Copper → Silver → Gold → Diamond → Olympian. Each card exposes a “What counts” section listing the exact metric being tracked. Achievement states: API — routes mount under /api/plugins/mibyan-achievements/: State files — live under $mibyan_HOME/plugins/mibyan-achievements/: Performance notes:
  • Cold scan on ~8,000 sessions takes a few minutes. It runs in a background thread on first dashboard request; the UI sees a pending placeholder and polls /scan-status.
  • Incremental results during a cold scan — the scanner publishes a partial snapshot every ~250 sessions so each dashboard refresh shows more badges unlocked as the scan progresses. No minute-long stare at zeros.
  • Warm rescan reuses per-session stats for every session whose started_at + last_active fingerprint matches the checkpoint — completes in seconds even on large histories.
  • The in-memory snapshot TTL is 120s; stale requests serve the old snapshot immediately and kick a background refresh. You never wait on a spinner just because TTL expired.
Enabling: Nothing to enable — mibyan-achievements is a dashboard-only plugin (no lifecycle hooks, no model-visible tools). It auto-registers as a tab in mibyan dashboard on first launch. The plugins.enabled config only gates lifecycle/tool plugins; dashboard plugins are discovered purely via their dashboard/manifest.json. Opting out: Delete or rename plugins/mibyan-achievements/dashboard/manifest.json, or override it with a user plugin of the same name in ~/.mibyan/plugins/mibyan-achievements/ that ships no dashboard. The plugin’s state files under $mibyan_HOME/plugins/mibyan-achievements/ survive — reinstalling preserves your unlock history.

Adding a bundled plugin

Bundled plugins are written exactly like any other Mibyan plugin — see Build a Mibyan Plugin. The only differences are:
  • Directory lives at <repo>/plugins/<name>/ instead of ~/.mibyan/plugins/<name>/
  • Manifest source is reported as bundled in mibyan plugins list
  • User plugins with the same name override the bundled version
A plugin is a good candidate for bundling when:
  • It has no optional dependencies (or they are already in the declared all extra)
  • The behaviour benefits most users and is opt-out rather than opt-in
  • The logic ties into lifecycle hooks that the agent would otherwise have to remember to invoke
  • It complements a core capability without expanding the model-visible tool surface
Counter-examples — things that should stay as user-installable plugins, not bundled: third-party integrations with API keys, niche workflows, large dependency trees, anything that would meaningfully change agent behaviour by default.