{
  "markdown": "# Veris plugins\n\nVeris runs stateful twins of the external services an application calls. An\n**environment** names a set of those services; a **sandbox** is one running\ndeployment of it. The `veris` CLI signs in, defines environments, starts\nsandboxes, seeds them, and runs the application's own tests through them:\n`veris run` reroutes the code's outbound HTTP(S) into a sandbox from outside the\nprocess, so the code under test keeps its production hostnames, credentials and\nclient stack, and every run ends with a **receipt** of what the sandbox received.\n\nFor a CLI-owned workflow, install the CLI once on the controlling machine:\n\n```\ncurl -LsSf https://raw.githubusercontent.com/veris-ai/veris-cli/main/scripts/install.sh | sh\nveris login\n```\n\nAn OpenCode sandbox plugin can instead own the session and its attached twin.\nThe same skills then use its remote application tools and current-run evidence;\nlocal CLI installation and Docker are not prerequisites for that session path.\nSee the OpenCode configuration below.\n\n## veris\n\nThree commands an engineer invokes with a task. The skills use Veris during normal\ndevelopment across CLI-owned and plugin-managed execution. A relevant application\ntest and its existing receipt can establish the change; there is no fixed run quota\nor separate proof phase.\n\n| command | what it does | completion |\n|---|---|---|\n| `setup` | verifies the current session or wires a CLI-owned workflow, identifies vendors, and proves one application run reaches the twin | evidence attributable to that run shows the required vendor calls and expected responses/state |\n| `build <issue link \\| prompt>` | answers relevant service questions and tests the new application behavior | applicable assertions pass through the intended caller, with current-run twin evidence and a concise result |\n| `fix <issue link \\| prompt>` | investigates the reported defect and tests the changed application behavior | applicable assertions pass through the affected caller, with current-run twin evidence and a concise result |\n\nThe reference set lives once in `veris/skills/veris-reference/`. Claude and Codex\nship that canonical tree; the OpenCode npm package bundles it and exposes its\nfiles through `verisSkill`. References are loaded when a command needs them.\n\n### Install\n\nClaude Code:\n\n```\n/plugin marketplace add veris-ai/plugins\n/plugin install veris@veris\n```\n\nThen, in a repository:\n\n```\n/veris:setup\n/veris:build https://github.com/org/repo/issues/42\n/veris:fix   \"create_invoice duplicates the invoice when the response is lost\"\n```\n\nCodex reads the same marketplace:\n\n```\ncodex plugin marketplace add veris-ai/plugins\ncodex plugin add veris@veris\n```\n\nCodex names plugin commands after the plugin: `$veris:setup`,\n`$veris:build <issue link or prompt>`, `$veris:fix <issue link or prompt>`.\n\nFor a CLI-owned container workflow, commands use `veris`, Docker and the control\nplane from the shell. Codex's default sandbox has neither network nor the Docker socket, so start it with\n`codex -s danger-full-access -a never` (or pre-approve `veris` and `docker` prefix\nrules). Otherwise every command waits on an approval.\n\nOpenCode uses the Veris skills package plus one selected sandbox plugin\n(the renamed skills package needs its first release):\n\n```json\n{\n  \"$schema\": \"https://opencode.ai/config.json\",\n  \"plugin\": [\n    \"@veris-ai/veris-opencode@latest\",\n    \"@veris-ai/daytona-opencode@latest\"\n  ]\n}\n```\n\nFor E2B replace the second entry with `@veris-ai/e2b-opencode@latest`. These are\nOpenCode plugins configured in `opencode.json`, not `npx` commands. Set the\nprovider's host credentials and environment, restart OpenCode, then run\n`/veris:setup`, `/veris:build` or `/veris:fix`. Setup verifies the attached session\nbefore local CLI/Docker checks; the provider owns its twin and cleanup. Changes\nreturn through `gitSync` to a local `opencode/N` branch; ignored evidence needs an\nexplicit handoff. Record the resolved published versions for reproducibility.\n\nSee [OpenCode installation and release prerequisites](veris/.opencode-plugin/README.md)\nand the [provider differences](veris/skills/veris-reference/opencode.md). The\npublished `@veris-ai/veris-sim-opencode` 0.7.0 release predates this session path.\nThe next release uses `@veris-ai/veris-opencode`, matching the `veris` name in\nClaude and Codex, with `veris/skills` as its canonical content. After that release,\nreplace the old package entry in your OpenCode config with the new one; install\nonly one skills package. It can also be installed alone for a CLI-owned workflow.\n\nAny other agent, through the `skills` CLI:\n\n```\nnpx skills add veris-ai/plugins --all\n```\n\n### The credential\n\nIn a plugin-managed OpenCode session, use the provider host variables described\n[here](veris/skills/veris-reference/opencode.md#discovery-and-control-access).\nThe following login applies to CLI-owned workflows.\n\n`veris login` pairs the machine once: it prints a code and a link, you approve in\nthe studio, and the key is saved under `~/.veris` with owner-only permissions. The\nskills never see or print it. In CI, set `VERIS_API_KEY` instead; it beats the\nsaved profile on every command.\n\n### Hosted execution\n\nThe hosted tier has provider recipes for\n[Daytona](veris/skills/veris-reference/daytona.md) and\n[E2B](veris/skills/veris-reference/e2b.md), with selection and evidence rules in\n[hosted.md](veris/skills/veris-reference/hosted.md). Both use the provider's\npublished SDK as shipped — `@veris-ai/daytona`, a drop-in for `@daytona/sdk`,\nand `@veris-ai/e2b` — through a task-local script: attach a separate\napplication-test box to the task's existing twin\n(`create({ veris: { attachSandboxId } })`), upload the code, install\ndependencies, run commands with the trust environment applied, and read the\nreceipt since a baseline. Neither package ships a CLI the skills depend on.\nEach task resolves `latest` itself and lets `--save-exact` and the lockfile hold\nit for that run, so a recorded version describes the evidence instead of\ndictating the next run; `tests/skill_version_claims.sh` fails a skill document\nthat pins a specifier, records what `latest` resolved to, or names the removed\n`veris-daytona` executable. A Daytona box running a Node application needs Node\n24 or newer in the image: the SDK's proxy routing rests on `NODE_USE_ENV_PROXY`\nand an `Agent` `proxyEnv` that Node 20 ignores, so there the canary and `curl`\nstill pass while every Node client fails DNS. The Daytona recipe spells out what the SDK sets for the\nproxy and for trust, and what a Node process needs on top; provider-specific\nsetup and limits are in each recipe. OpenCode provider configuration and\nsession-owned sandboxes are a separate workflow.\n\n### Versions\n\nThese entries describe the source plugin history. The old\n`@veris-ai/veris-sim-opencode` npm 0.7.0 tarball predates the CLI migration below;\nmatching version numbers across that old distribution and this source do not\nestablish matching content.\n\n0.8.1 — a twin's control URL is keyed. On current sandboxes `control_url` is a\nseparate address that requires the Veris API key (`X-API-Key`), and `/veris/*` at the\ndata URL or an intercepted vendor hostname is the vendor's own 404. The references no\nlonger curl a control URL: data paging, files, a per-twin reset and the operations list\ngo through `veris sandbox data get --all`, `files import`, `reset <twin>` and\n`services operations`, which send the key from the login profile, so the key is never\nexported or printed. The OpenCode fallback no longer probes `/veris/*` at a vendor\nhostname, and `setup` requires CLI 0.19.0 or newer.\n\n0.8.0 — use Veris in the normal development loop. `build` and `fix` reuse a\nrelevant application test and its receipt instead of requiring a separate proof\nphase. Extra probes, fault cases and repeated calls answer task-specific questions;\nthere is no mandatory two-run check, per-measurement falsifier or prompt hook.\nRecord/ledger helpers remain available for requested investigations, with the\nexisting full-SHA `--base` interface; optional recorded runs gain a timestamp.\nSetup no longer requires staging those helpers, preserves artifact preferences,\nand reuses an execution of the exact saved command. Provider identity, routing,\ntrust and current-run evidence requirements remain. Reduced instruction overhead\ndoes not by itself establish faster tasks or unchanged correctness.\n\n0.7.4 (unreleased) — the Daytona recipe is written around the `@veris-ai/daytona`\nSDK as shipped (0.3.1 and later): the run is a sequence of SDK calls the\nagent's own task-local script makes (attach to the task's twin, upload, install,\npatch bundled CAs, baseline, run with the trust environment, receipt, delete),\nwith the SDK's README and typings as the reference rather than a reprinted script. It states what the SDK sets\nfor egress and trust and what a Node process needs beyond it: `NODE_USE_ENV_PROXY`,\n`--use-openssl-ca`, and the Agent proxy preload for SDKs that build their own\n`https.Agent` (stripe-node measured). Also: one organisation for the CLI and the SDK, `COPYFILE_DISABLE`\non macOS uploads, workspace packages staged as a copy, and the application's own\ndatabase inside the box until data planes are carried through. Run against a live\nbox on 2026-09-08 (Medusa's payment module through the Stripe provider).\n\n0.7.3 (unreleased) — OpenCode commands load skills from the installed package in\nDaytona and E2B sessions, reuse the attached twin, and require evidence attributable to each\napplication run. The plugin owns lifecycle; generated changes use its git sync.\n\n0.7.2 — a hosted tier, with a Daytona provider recipe. `setup` can run tests remotely\nwhen requested, or when the code needs redirection and Docker is unavailable.\n`veris-reference/hosted.md` describes selection, remote workload preparation, trace\nevidence, project notes and cleanup; `veris-reference/daytona.md` holds the commands\nand provider limits. The flow is `veris up`, then `provision`, `push`, `exec` and\n`teardown` through `veris-daytona`, with the twin's trace as the receipt. `build` and\n`fix` reuse the recorded commands. The runner uses an exact published version through\n`npx`; setup checks that release contains all four CLI verbs before creating resources.\nEarlier Node/Stripe and Python/Stripe trials informed the guidance; these\ndocumentation changes were not run against a live box.\n\n0.7.1 — the skills adapters retired their MCP registration, alongside the\nfirst-run lessons of two measured sessions. At that release they registered\ncommands only: `.mcp.json`, `.codex-mcp.json` and the OpenCode plugin's\ninjected server are gone, since every mechanism is a `veris` command and a machine\nsigned in with `veris login` has no `VERIS_API_KEY` for them to send. `record.sh` runs\nthe command after `--` as argv, never through `sh -c`, and treats a command that cannot\nstart as an error rather than a verdict; `ledger.sh` requires state read back on a\n`REPOSITORY` row and refuses one that cites a stub. `setup` adopts only an environment\nthat is the project's, reads the twin's published key instead of inventing one, fixes\nthe image rather than the run line, and recognises the two `doctor` lines that mean\nthe agent is in a sandbox of its own.\n\n0.7.0 — CLI-first. Most mechanisms formerly spelled out as HTTP calls, MCP tools\nand shell scripts moved to `veris` commands: `login`, `doctor`, `services`,\n`env create`, `up`, `sandbox data add|schema|get`, `sandbox services manual`,\n`sandbox trace`, `sandbox clock`, `run`, `snapshot`, `baseline`, `down`. The skills\nkeep the gates and the judgment, in plain language: measure before designing,\nreproduce before fixing, prove with a receipt. `preflight.sh` and `.veris/run.sh`\nwere retired; CLI environment configuration lives in `.veris/twin.yaml`, written by `veris env create`. Current setup also\nwrites `.veris/setup.json` for source/build facts and artifact policy, and keeps\nthe direct-tier reference. The container tier with\n`--patch-bundled-cas` is the default for code under test.\n\n0.6.9 — the clock is sandbox state, not a service choice.\n\n0.6.8 — the coverage catalogue is the first door, not the last.\n\n0.6.7 — the word *world* is gone: `veris-reference/worlds.md` is `state.md`.\n\n0.6.5 — files: bytes go in through the twin's upload route, rows first, files second;\n`setup` gains the files step.\n\n0.6.4 — the manual is not a coverage catalogue; discovery runs cheapest-first.\n\n0.4.3 — `build` and `fix` seed the world before they measure.\n\n0.4.2 — Codex fixes measured in a clean box.\n\n0.4.1 — `test` removed.\n\n0.4.0 — `setup --direct`: a direct-connection tier for applications whose config\nreads each service base URL from its `env_hint` variable.\n\n0.3.0 — `test`: run one named test through the proxy with a per-test verdict.\n\n0.2.1 — `setup` names the services it inferred when asking to create an environment.\n\n0.2.0 — three commands (`setup`, `build`, `fix`) replace the 0.1 skills.\n",
  "bytes": 12953,
  "sha": "930a6a45824b03db24c4e8cc5bb1fa8daac5a57cbaab1c0e3f871e22d3001320",
  "repo_slug": "veris-ai/plugins",
  "fonte": "repo",
  "truncated": false,
  "api": "https://api.agentalog.com/api/listings/skl_veris_ai_plugins_fix_084bb619/readme"
}