Skip to content

Contrib-First Module Evaluation Playbook

Classification: PROCEDURE. Not authority; the governing standard below owns the rules.
Authority: contrib-first-policy


1. The Contrib-First Mandate

"ALWAYS, THE RULE IS CONTRIB FIRST. CUSTOM CODE IS THE LAST RESORT, ONLY WHEN YOU CAN PROVE THAT CONTRIB, CORE, CONFIG, OTHER OPEN SOURCE AND OTHER UPSTREAMS CAN'T SOLVE FIRST. WE REUSE, NEVER BUILD, AND NEVER ADD MORE TECH DEBT."


2. Contrib Evaluation Rubric

Before proposing or writing any custom module or PHP class, complete this evaluation:

Criterion Green (Proceed with Contrib) Yellow (Evaluate Carefully) Red (Avoid / Do Not Use)
Drupal 10/11 Compatibility Explicit ^10.3 or ^11 release on Packagist Requires lenient composer plugin No D10/11 release, abandoned
Security Coverage Green Shield icon (Security covered) Beta/RC with active maintainer Known unpatched CVEs
Maintenance Activity Commit in last 90 days, responsive issues Commit in last 12 months 2+ years without commit
Ecosystem Usage 1,000+ active installs reported 100+ active installs 0-10 installs, unvetted
Upstream Documentation Comprehensive guide, clear API docs README only No documentation

3. Proven Contrib Stack for Bluefly Rigs

Requirement Contrib Module Why Chosen
Agent Context & Memory drupal/ai_context (CCC) Native ai_context_item entity, token budgeting, prompt injection
Short-term Dialog History drupal/ai_agent_memory Decorates agent runner, handles tempstore message buffer
Core Action Tools drupal/tool_belt 43 atomic tools (CRUD entities, fields, users, workspaces)
External REST Integration drupal/api_orchestrator Config-driven endpoints, automatic retry/backoff, request logging
Event Automation drupal/eca + drupal/ai_integration_eca No-code visual event handling, auto-embeddings, moderation
Inbound Webhooks drupal/webhooks Ingests GitLab CI/MR notifications, dispatches Symfony events
Secret Management drupal/key Stores tokens via 1Password Connect, zero plain text in config
Asynchronous Queues drupal/advancedqueue Reliable background processing with retry policies