Skip to content

Class 99 · Advanced mastery

Build your own Antigravity plugin

Author, validate, install, test and safely package an Antigravity plugin end-to-end. The manifest snaps into place, components dock onto the core, and live turns execute under measured token constraints.

Start the class

Quick answer

An Antigravity plugin packages skills, rules, lifecycle hooks and MCP servers into one deployable asset, and every plugin needs a plugin.json file at its root. This class builds one end to end: the manifest, a skill, a rule, a hook, an MCP config, and what each costs on the customization meter. Independent class by Design Delight Studio. Not affiliated with or endorsed by Google.

Built with Gemini 3.8 Flash High in Google Antigravity; corrections by Claude Sonnet 5.5 (recorded).

Key takeaways

  1. The root manifest marks the bundle. Every plugin requires a plugin.json file at its root. Its name may contain only letters, digits, hyphens and underscores.
  2. Skills are instructions the agent can follow. Each skill lives in its own subfolder under skills/ with a SKILL.md file. The agent can pick one from context, or you can run it by typing /<skill-name>.
  3. A rule needs a valid trigger. Every rule file in rules/ starts with YAML frontmatter whose trigger is always_on, model_decision, glob or manual. The docs say a rule file in .agents/rules/ with an unrecognized trigger is silently discarded.
  4. Hooks run shell commands. A plugin's hooks.json holds event handlers that execute shell commands before or after tool calls. Read each command before you install a plugin.
  5. Customizations run under budgets. The docs say Antigravity truncates any rule file over 24,000 bytes, and that the 20,000-token rules budget is separate from the customization budget. On our meter, Rules and Other Customizations each showed a 20,000-token ceiling, and installing our example plugin added 89 tokens to Rules.
  6. Share safely with inspected archives. Package plugins as clean directory archives without sensitive credentials or extraneous files, and inspect received plugins before installing them into your workspace.
Module zero · 5 min

What an Antigravity plugin does

A plugin is a directory with a required plugin.json and optional components: skills, agents, rules, hooks and MCP server definitions. You can install, enable, disable and uninstall it as one unit. The measurements on this page come from live testing in Antigravity version 2.19.1.

baseline installed plugins4on the Installed tab before install
plugins active during test5with example plugin loaded
measured rule token delta89tokens added to the Rules line (2 to 3 rules)
measured skill token delta72tokens added to the Skills line (23 to 24 skills)

MeasuredCalculatedn = 1 reading per state, Antigravity 2.19.1 Plugin counts read from the Installed tab; token deltas read from the Customizations token meter. Independent class by Design Delight Studio. Not affiliated with or endorsed by Google.

Directory anatomy

A plugin directory has a required plugin.json at its root. Beside it sit optional components: skills/, agents/, rules/, hooks.json and mcp_config.json.

Antigravity Plugin Directory Anatomy Directory diagram showing root manifest plugin.json, skills, rules, hooks, and MCP server configuration Antigravity Plugin Directory Anatomy Root manifest plus component folders for skills, rules, hooks, and MCP dva-study-helper/ plugin.json Root manifest schema hooks.json Lifecycle audit event mcp_config.json Tool server config skills/study-checklist/ SKILL.md task workflow rules/cite-class-page.md Behavioral boundary constraint Discovery paths: .agents/plugins/ (workspace) and ~/.gemini/config/plugins/ (global)
The main files of our example plugin, dva-study-helper. plugin.json at the root, with hooks.json, mcp_config.json, skills/study-checklist/ and rules/cite-class-page.md.

Quotedn = 1 documentation page Required and optional components quoted from the official plugins documentation at antigravity.google/docs/plugins.

Interactive · Anatomyregion

Anatomy of an Antigravity plugin

Explore the components that make up a standard Antigravity plugin directory.

Root Manifest & ConfigurationInteractive Customizations

Your answers stay in this browser. Nothing is sent anywhere. Reset clears them.

Measured How plugin discovery was verified
Method
Copied the plugin folder into the global and workspace plugin folders, read the Installed tab, ran the skill, and read the Customizations token meter with the plugin installed and uninstalled.
n
4 plugins listed before install and 5 after; 1 meter reading per state.
Source
Antigravity 2.19.1 installed plugins interface and customization token meters.
Excludes
Does not measure third-party marketplace publishing or cloud server synchronization.
Module one · 7 min

The manifest schema and validation

At the heart of every plugin is plugin.json. The docs say it identifies the directory as a plugin and defines its metadata: a name and an optional description. The name is required when you manage plugins from the CLI; in Antigravity 2.0 and the IDE it defaults to the folder name. In the schema published in the docs, name must match ^[a-zA-Z0-9-_]+$: only letters (either case), digits, hyphens and underscores. The same schema sets additionalProperties to false. In our run, a name with spaces and an exclamation mark failed our local checker.

Interactive · Huntround 1 of 2

Find the manifest schema error

Inspect candidate plugin.json snippets to identify syntax and schema errors.

Name pattern validationProperty names and patterns from Google published schema
Identify the invalid manifest property in this plugin definition.

Your answers stay in this browser. Nothing is sent anywhere. Reset clears them.

Measured How manifest schema validation was evaluated
Method
Ran a local checker built from the schema published in the docs on one manifest with an invalid name, then on a valid one, and saved both outputs and exit codes. The checker also accepts a $schema key, which the docs' example manifest uses.
n
2 validation runs: 1 failing run and 1 passing run.
Source
Saved manifest files and validation logs in test environment.
Excludes
Does not evaluate online network validation against the remote schema URI.
Module two · 8 min

Skills and slash commands

A skill is a folder containing a SKILL.md file. Its YAML frontmatter needs a description; name is optional and defaults to the folder name. The agent can pick a relevant skill on its own, or you can type /<skill-name> to invoke one. In our install, the plugin's skill appeared in the slash picker labelled dva-study-helper.

Interactive · Decidercase 1 of 8

Plugin, skill, rule or hook?

Evaluate each proposal. Read PASS as consistent with the Antigravity documentation and FAIL as contradicting it.

You want an agent to turn any input URL into a 5-point study checklist without network calls. Proposal: build it as a skill with a SKILL.md file.

documented: skills page · quoted

Your answers stay in this browser. Nothing is sent anywhere. Reset clears them.

Measured How skill discovery and invocation were verified
Method
Typed /study in the Antigravity prompt box and captured the slash picker, which listed study-checklist with the label dva-study-helper; then ran the skill on a class URL in two conversations. One answer is captured; in the other, the turn stopped at a file search.
n
1 slash-picker capture and 2 skill runs.
Source
Recorded UI frames.
Excludes
Does not test skills that require external network scraping or binary dependencies.
Module three · 8 min

Rules, triggers and citations

Rules are persistent instructions that Antigravity discovers on the filesystem and injects into the agent's context. Every .md file inside rules/ must start with YAML frontmatter declaring a valid trigger: always_on, model_decision, glob or manual. With always_on, the full rule goes into the system prompt on every turn. With model_decision, only the rule's path and description go in up front, and the agent reads the rest on demand. A glob rule activates when the agent touches files matching its globs. A manual rule loads only when you @-mention it. The docs warn that a file in .agents/rules/ with no frontmatter, or with an unrecognized trigger such as camelCase alwaysOn or modelDecision, is silently discarded.

A rule is an instruction, so test what it changes. Our example rule has the trigger always_on and tells the agent to cite the class page URL or a local file path for every claim it makes when discussing academy curriculum, classes, architecture or lessons. In one captured run, the answer's bullets ended with (Citation: <url>), and the URL was the one we had typed into the prompt. That prompt also asked for citations, so the capture does not isolate the rule's effect, and nothing in it shows the cited page was checked.

Interactive · Prompt Diffclause

Rule enforcement: citation form vs truth

Toggle the three parts of our captured run to see what each adds, and what the capture does not show.

as asked
Our captured run: prompt, rule and answer
as specified

Your answers stay in this browser. Nothing is sent anywhere. Reset clears them.

Module four · 8 min

Lifecycle hooks and audit logs

Hooks run custom scripts or shell commands at specific points in Antigravity's execution loop. A plugin's hooks.json maps a hook name to events such as PostToolUse. For PreToolUse and PostToolUse, a matcher says which tools trigger the hook, and each handler has a command. The handler's command is a shell command, so read it before you install the plugin.

Review a hook in this order: first the event and its matcher, for example PostToolUse with a tool matcher; then the command itself, naming every path, program and URL it uses; then whether it makes any network call; then whether it deletes or overwrites files. Stop at the first check that fails, and refuse the plugin.

Our test plugin has one hook: a PostToolUse handler with the matcher view_file whose command appends the line [HOOK] study helper accessed to a local file, hook_audit.log. The command makes no network call. The saved log held 22 such lines when we checked it.

Interactive · Decidercase 1 of 3

Is this lifecycle hook safe to install?

Review each hook command in the order above. PASS means it is safe to install; FAIL means review stops and the plugin is refused.

A plugin's PostToolUse hook runs: echo [AUDIT] Tool invoked >> logs/hook_audit.log. Proposal: install the plugin.

checked against: the four review steps above

Your answers stay in this browser. Nothing is sent anywhere. Reset clears them.

Measured How hook execution was verified
Method
Wrote a PostToolUse hook whose command appends a line to a local log file, ran Antigravity turns that call tools, and saved the log file.
n
1 hook; 22 logged lines in the saved file.
Source
The saved hooks.json and hook_audit.log.
Excludes
Does not execute hooks containing remote network requests or system modifications.
Module five · 7 min

Model Context Protocol structure

A plugin can carry Model Context Protocol (MCP) server definitions in a root mcp_config.json file. The docs describe it as declarations connecting Antigravity to external tool servers.

In our example plugin, mcp_config.json holds an empty mcpServers object, so it declares no tool server.

Module six · 8 min

Customization token budget and resource limits

Settings, then Customizations, shows a Token Usage meter with a Rules line and an Other Customizations line (skills and MCP tools), each against a 20,000-token budget. The meter's own text says that when a budget is exceeded, large rules are demoted to path pointers and large customizations are excluded automatically. The docs add that the 20,000-token rules budget is separate from the customization budget (plugins such as skills and MCP), and that Antigravity truncates any single rule file over 24,000 bytes.

Customization Token Budgets Chart showing measured 20,000-token rules budget and 20,000-token other customizations budget before and after plugin install Customization Token Budgets (Measured & Quoted) Measured in Antigravity 2.19.1 (2026-10-06, n=1) against published documentation Rules: 3,348 / 20,000 tokens (+89 delta) 20,000 limit Other Customizations: 5,866 / 20,000 tokens (+72 delta) 20,000 limit Plugin rule delta: +89 tokens (Rules line) Plugin skill delta: +72 tokens (Skills line) MEASURED (n=1, Antigravity 2.19.1): Rules 20,000; Other Customizations 20,000. QUOTED (docs): Rules budget is separate from customization budget; 24,000 bytes/file limit.
Customization token budgets. Measured limits (n=1, Antigravity 2.19.1, 2026-10-06) showing separate 20,000-token rules budget and 20,000-token other customizations budget before and after plugin installation.

MeasuredQuotedn = 1 measurement, Antigravity 2.19.1, 2026-10-06 Measured via Settings Customizations panel; per-file limits quoted from documentation.

In our live environment audit, the customization token usage meter recorded the following: with the plugin uninstalled, Rules read 3,259 of 20,000 tokens (16.3% of the rules budget across 2 rules). With the plugin installed, Rules read 3,348 of 20,000 tokens (16.7% across 3 rules), an exact difference of 89 tokens, with the rule breakdowns going from 2 to 3. The Other Customizations line read 5,794 of 20,000 tokens uninstalled and 5,866 of 20,000 installed (+72 tokens). The Skills line went from 23 to 24 breakdowns and from 4,979 to 5,051 tokens (+72 tokens) once the plugin was installed.

Interactive · Instrumentlive

Customization budget triage & token limits

Pick how many rules you plan to ship; each is counted at 89 tokens against the 20,000-token rules budget.

Estimated Rule Tokens
—tokens

Your answers stay in this browser. Nothing is sent anywhere. Reset clears them.

Calculated How budget triage estimates were modeled
Method
Multiplied the number of rules by the measured 89-token difference and compared the total with the published 20,000-token rules budget.
n
1 measured rule baseline yielding 89 tokens delta.
Source
Antigravity Customizations Token Usage meter and documentation.
Excludes
Does not model dynamic memory caching or cross-session token compression.
Interactive · Ledgerclaim 1 of 5

Documentation claims against measured evidence

Compare the expected value with what our meter and Installed tab showed in the live test.

Baseline Installed Plugins

Your answers stay in this browser. Nothing is sent anywhere. Reset clears them.

Measured How claims were audited against live evidence
Method
Read the Installed tab before install, with the plugin installed, and after its folders were deleted, and read the token meter with the plugin installed and uninstalled.
n
5 rows: 3 Installed-tab states and 2 meter states.
Source
Live screen captures and recorded environment metrics.
Excludes
Does not cover any budget the meter does not show.
Module seven · 10 min

The plugin workbench

Use this interactive workbench to design, validate, and package an Antigravity plugin. Test plugin names against the published schema pattern, toggle component inclusions, and build a zip of the plugin folder in your browser.

Plugin Workbench: Build, Validate & Package

Assemble an Antigravity plugin manifest, configure component files, validate against published schema rules, and package a downloadable archive.

Components to Package
Manifest Status: Valid The name matches the published pattern ^[a-zA-Z0-9-_]+$.

Customization Budget (Measured & Quoted Limits)

Measured limits (n=1, Antigravity 2.19.1, 2026-10-06): Rules budget 20,000 tokens; Other Customizations budget 20,000 tokens. The docs say Antigravity truncates a rule file over 24,000 bytes, and that the rules budget is separate from the customization budget.

Module eight · 7 min

Sharing and installing plugins safely

A plugin can bundle hooks, which run shell commands, and MCP server declarations. Read both before you install a plugin you did not write. Before extracting an archive into .agents/plugins/ or your global configuration, inspect all scripts and configurations.

Interactive · Setup Checkeryour path

Is this plugin ready to share?

Configure the components included in your plugin to view the mandatory safety preflight checks.

  1. Manifest Schema AuditRun validate_manifest.py: Ensure name conforms to ^[a-zA-Z0-9-_]+$ and no illegal keys exist.
  2. Lifecycle Hook AuditAudit hooks.json: Verify all shell commands run offline without network requests or deletions.
  3. MCP Server AuditAudit mcp_config.json: Ensure external binaries and env tokens are not exposed or executed unexpectedly.
  4. Clean Archive PackagingGenerate zip archive with deterministic checksums and verifiable file inventory.

Your answers stay in this browser. Nothing is sent anywhere. Reset clears them.

Module nine · 5 min

What we did not verify

Our commitment to deterministic evidence requires stating plainly what was not tested or confirmed in this evaluation:

  • Budgets beyond the two meter lines: We read the Rules and Other Customizations lines once (n = 1). We did not push either line past 20,000 tokens, so we did not see demotion or exclusion happen.
  • Public marketplace publishing: We did not test publishing a plugin to the Marketplace. The marketplace docs link an interest form for getting a plugin listed, and we did not use it.
  • Remote schema network resolution: Schema validation was executed using a local checker using the schema published in the docs; the remote schema URL was not fetched over the network. The checker also accepts a $schema key, which the docs' example manifest uses but the published schema does not declare.
  • Cross-platform lifecycle execution: Our hook command uses cmd.exe, so we ran it on Windows only; macOS and Linux were not tested.
  • Whether the rule changed the answer: Our captured run asked for citations in the prompt as well as in the rule, and we have no finished run without the citation request: our second run, with the skill alone, stopped at a file search and gave no checklist.
  • One turn's hook count: We saved the hook log (22 lines) but not a before-and-after count for a single turn.
  • Installing the workbench zip: The zip's contents pass a script check against the docs. We have no frame showing that zip installed in Antigravity.

Questions

What is an Antigravity plugin?

An Antigravity plugin packages reusable skills, rules, lifecycle hooks and MCP servers into a single deployable asset. It is a directory with a required plugin.json at its root.

Where do I place a plugin folder?

For a manual install, the docs say to place the plugin folder in .agents/plugins/ at the root of a workspace (that project only) or in ~/.gemini/config/plugins/ (all workspaces). The CLI's install command stages plugin files under ~/.gemini/antigravity-cli/plugins/ instead.

What fields does plugin.json have?

In the schema published in the docs, plugin.json has a name that must match the pattern ^[a-zA-Z0-9-_]+$ and an optional description. The docs say the name is required for CLI commands and defaults to the folder name in Antigravity 2.0 and the IDE. The docs' example manifest also includes a $schema key for editor autocomplete and validation.

What is the difference between a skill and a rule in an Antigravity plugin?

The docs say to write a rule for constraints and invariants and a skill for multi-step workflows. A skill is a folder with a SKILL.md the agent can follow, and you can invoke it with a slash command named after the skill. A rule is a markdown file in rules/ whose trigger decides when it is injected.

Does a rule check that the model's answer is true?

We have no evidence that it does. A rule is instruction text that Antigravity injects into the agent's context according to its trigger. In our one captured run, the answer's bullets ended with a citation to the URL we had typed into the prompt; the prompt asked for citations too, and nothing in the capture shows the citations were checked.

What are the published resource limits for plugin rules?

The docs say Antigravity truncates any single rule file over 24,000 bytes, and that all active global and always_on rules share a 20,000-token budget that is separate from the customization budget.

How much token budget did our example plugin consume?

In our live measurement, installing the example rule increased measured rule token usage by 89 tokens, while the example skill added 72 tokens to the skills allocation.

What safety checks should I perform before installing a shared plugin?

Audit hooks.json to ensure shell commands perform only safe local operations without unauthorized network requests or file deletions, and review mcp_config.json for unknown binary executions.

Did we test publishing to the Antigravity Marketplace?

No. We did not test publishing. The marketplace docs link an interest form for getting a plugin listed.

Is this class affiliated with Google?

Independent class by Design Delight Studio. Not affiliated with or endorsed by Google.