Extending an AI Agent Safely: A Walkthrough of the aiFetchly Plugin Manager

How aiFetchly's Plugin Manager bundles skills, subagents, hooks and MCP servers, with six install sources and risk flags.

aiFetchly is a desktop AI business agent, and its Plugin Manager is where all of its extension points come together. A plugin is one package that bundles AI Skills, Subagents, slash Commands, Hooks and MCP servers under one manifest, one install path and one ownership record. Install it and everything it bundles registers; uninstall it and everything goes away as a unit.

Four tabs

  • Installed – every plugin on your machine, with version, source (Built-in / Marketplace / Local), counts of subagents, skills, hooks and MCP servers, a health status, an enable/disable switch and an uninstall button.
  • Discover – search and filter marketplace catalogs, open Details for author, resolved source and risk flags.
  • Marketplaces – add an owner/repo, git URL, local folder or marketplace.json URL, optionally pinned to a branch, tag or commit; refresh or remove sources.
  • Errors – marketplaces that failed to load, with details.

Six install sources

Local Zip, Local Folder (copied, your folder is never modified), Git (HTTPS/SSH, using your SSH agent and credential helper), GitHub (repo, release asset or releases/latest), npm (public or scoped registries; tokens go in a 0600 .npmrc and are never stored) and URL (auto-detected).

Security guarantees on every install

  • Size limits: 50 MB compressed / 250 MB extracted / 5,000 files.
  • No plugin code runs during install – no npm install, no pip install, no lifecycle scripts; npm pack uses --ignore-scripts.
  • 60-second timeout on every spawned git/npm/tar process.
  • HTTPS only, at most 5 redirects.

Risk flags before marketplace installs

aiFetchly flags plugins that start MCP servers, declare hooks, declare monitors, install from npm, or are not pinned to a commit. If any flag is present, you must tick “I understand the risks and want to install” before Install is enabled.

Why it matters

Extensions are where AI tools get dangerous. Packaging skills, agents, commands, hooks and MCP servers as one auditable unit – with no install-time code execution and explicit risk prompts – makes it practical to extend an AI agent without losing track of what you added.

Docs: https://docs.aifetchly.com/docs/ai-outreach/plugin-manager/
Website: https://www.aifetchly.com


If you try it, start with a commit-pinned marketplace and read the risk flags.


Write a comment