feat(plugins): cursor & refactor - #7
Conversation
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01KDoRbmzuRVJ6Ev9MPEmLm5
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01KDoRbmzuRVJ6Ev9MPEmLm5
|
339390a to
6c110ad
Compare
Dismissed because a newer commit was pushed; Greptile will re-review the current head.
6c110ad to
29a8de4
Compare
29a8de4 to
77b1cb7
Compare
Dismissed because a newer commit was pushed; Greptile will re-review the current head.
Dismissed because a newer commit was pushed; Greptile will re-review the current head.
fb14c95 to
2c5bd6f
Compare
2c5bd6f to
2e86d0c
Compare
Dismissed because a newer commit was pushed; Greptile will re-review the current head.
2e86d0c to
d69ca49
Compare
Dismissed because a newer commit was pushed; Greptile will re-review the current head.
d69ca49 to
17735d8
Compare
Dismissed because a newer commit was pushed; Greptile will re-review the current head.
b45f3bc to
445ed59
Compare
dec3597 to
006a1e8
Compare
| ``` | ||
|
|
||
| Put that in `~/.cursor/mcp.json` for every project, or `.cursor/mcp.json` for one. Create the key | ||
| under **Account Settings → API Keys** in ReadMe and export it as `README_API_KEY` rather than |
There was a problem hiding this comment.
| under **Account Settings → API Keys** in ReadMe and export it as `README_API_KEY` rather than | |
| under **Settings → API Keys** in ReadMe and export it as `README_API_KEY` rather than |
| Put that in `~/.cursor/mcp.json` for every project, or `.cursor/mcp.json` for one. Create the key | ||
| under **Account Settings → API Keys** in ReadMe and export it as `README_API_KEY` rather than | ||
| committing it. The key decides which project the agent reaches, and grants read and write access to | ||
| it. Rotate it from Account Settings if it is ever exposed. |
There was a problem hiding this comment.
| it. Rotate it from Account Settings if it is ever exposed. | |
| it. Rotate it from the API Keys page if it is ever exposed. |
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01KDoRbmzuRVJ6Ev9MPEmLm5
006a1e8 to
40f94d9
Compare
Root was a Cursor plugin, an Agent Plugins package, and a marketplace host for claude/ and codex/ at the same time. That left two MCP definitions that disagreed and a root manifest duplicating codex/. Root is now only a marketplace, with one directory per client. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The MCP server is bound to one project by its hostname, so search and fetch read ReadMe's own documentation while only execute-request, with the user's key, reaches theirs. Agents cannot tell these apart from the tool names, and the README was promising that search covered the user's own guides. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The agent had no way to tell an anonymous server from a keyed one, so it
asked for a key it sometimes already had, and answered from ReadMe's own
docs when no project was named.
Adds a probe against /projects/me that distinguishes the two, and names
the Missing Security Schemes error that an unexpanded ${README_API_KEY}
placeholder produces.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The skill described a protocol without demonstrating it, so the agent had to infer the shape of every call. It now carries the probe and the keyed variant as worked examples, including the required title argument that fails with an unhelpful validation error when omitted. Also resolves the project once per session rather than per turn, states that step 3 only applies to an anonymous server, and folds the routing list into the tool table so one decision is described once. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…copies Five canonical skills live in skills/ and are the only ones to edit. Each client directory gets a byte-identical generated copy, since every marketplace submission reads only its own directory. Host-specific instructions moved inside the shared files as per-client tables: registering the key, driving a browser, and installing the plugin by hand. Tool names are bare, with no namespace prefix. scripts/sync-skills.mjs regenerates the copies and --check fails on drift. scripts/validate-skills.mjs checks frontmatter and the 20,000-char limit. CI runs both plus claude plugin validate.
…not say readme-api and developer-metrics-api were hand-copied route tables. The server returns the same map from list-endpoints for 2.6KB against the 8.8KB skill, and get-endpoint already carries the Refactored-only notices, the category.uri pattern and prefer: handling=strict. Duplicating a spec that moves is how the skills go stale. The facts no endpoint listing can produce move into mcp-server: the paging response shape, child projects needing their own key, Enterprise gating on metrics reads, basic auth on the metrics spec, the SDK packages, and which dashboard metrics have no route at all. Fixes the metrics auth in the spec table, which said bearer where the definition says basic.
445ed59 to
db8fd22
Compare
Dismissed because a newer commit was pushed; Greptile will re-review the current head.
main built claude/ and codex/ in parallel with this branch, so both sides created the same directories. Resolved in favour of this branch everywhere except the Codex manifest. - codex/plugin.json takes main's version: the plugin does write, through execute-request once a key is registered, so the directory listing has to say so. That also keeps the icons main added, which nothing referenced otherwise. - The two validate workflows become one. main's was the only thing running claude plugin validate; this branch's was the only thing checking the generated skills match skills/, and its validate step never ran because the CLI was never installed. validate.yml now does both, strict. - Everything else keeps this branch's text. main's inline mcp add snippets survive in the mcp-auth registration table.
Dismissed because a newer commit was pushed; Greptile will re-review the current head.
A PR push was triggering the suite twice, once for push and once for pull_request.
Co-authored-by: Cursor <cursoragent@cursor.com> #7 moved the Agent Plugins manifest into cursor/ and dropped variables, which removed Cursor's only install-time key prompt. Put README_API_KEY back on the Cursor plugin MCP server.
🧰 Changes
The repo root was three things at once: a Cursor plugin, an Agent Plugins package, and a marketplace. That overlap let the manifests drift. Root is now only a marketplace, and each client has its own directory.
type: httpand the/add-plugin readmeinstall step that fix: remove unsupported MCP transport type #6 removed.execute-requestacts on the user's project once a key is registered.🧬 QA & Testing
🤖 Generated with Claude Code