Generates the skeleton for a new mob plugin under plugins/<name>/.
mix mob.new_plugin <name> [--tier <0|1|2|3|4>] [--dest <DIR>]Tiers (per MOB_PLUGINS.md):
0(default) — pure-Elixir helpers. No manifest, no native code.1— native NIF + Elixir wrapper. Manifest with:nifs; ships an Erlang NIF stub and the matching C source. Wired into the build byMobDev.Plugin.Merge.nifs/1+ the build.zig-Dplugin_c_nifsarg.2— native UI component viaMob.UI.native_view+Mob.Component. Manifest with:ui_components; ships an ElixirMob.Componentmodule, the matching Kotlin Composable, and a Swift View placeholder.3— multi-screen plugin. Manifest with:screens+:migrations(and optionally:assets); ships twoMob.Screenmodules and an Ecto migration the host applies on device.4— embedded sub-app. Manifest with:lifecycle+:settings+:notifications; ships a lifecycle module, a supervised worker, a notification handler, and a settings editor screen.
Signing (tiers 1–4)
A plugin with a manifest is verified by every host before its native build
uses it: priv/mob_plugin.sig must be a v2 signature over every file the
build reads (MobDev.Plugin.Sign.build_inputs/2), made with the key whose
public half is priv/mob_plugin.pub, and the host must trust that key. So
tiers 1–4 also get:
.gitignoreignoringpriv/mob_plugin.sig(priv/mob_plugin.pubis committed);mix.exswith Hex package metadata (package files:ship all ofpriv/; set@source_urlto the plugin's repository) and a dev-only:mob_devdep for the signing tasks, plus aREADME.mdand theCHANGELOG.mdthe release notes are taken from;.github/workflows/release.yml: on aversion:bump inmix.exsit tags, creates the GitHub Release, checks that theMOB_PLUGIN_SIGN_KEYsecret derives the committed public key, runsmix mob.validate_pluginandmix mob.plugin.sign, thenmix hex.publish. The published package therefore carries a fresh signature over exactly what ships.
One-time setup, in the plugin directory:
mix deps.get
mix mob.plugin.keygen # priv/mob_plugin.pub + ~/.mob/keys/<name>.priv
gh secret set MOB_PLUGIN_SIGN_KEY < ~/.mob/keys/<name>.priv
gh secret set HEX_API_KEYmix mob.plugin.sign signs locally for testing; a host records trust with
mix mob.plugin.trust <name>. Tier 0 has no manifest and nothing to sign.
Options
--tier <0|1|2|3|4>— plugin tier; defaults to0.--dest <DIR>— destination directory; defaults toplugins/<name>relative to the current working directory.