Skip to content

feat(plugins): cursor & refactor - #7

Merged
minhthanhdang merged 23 commits into
mainfrom
minh/plugin-structure-stacked
Sep 17, 2026
Merged

minhthanhdang merged 23 commits into
mainfrom
minh/plugin-structure-stacked

Conversation

@minhthanhdang

@minhthanhdang minhthanhdang commented Sep 15, 2026 •

Copy link
Copy Markdown
Collaborator

🧰 Changes

The repo root was three things at once: a Cursor plugin, an Agent Plugins package, and a marketplace. That overlap let the manifests drift. Root is now only a marketplace, and each client has its own directory.

  • One Cursor MCP server definition, not two that disagree.
  • All three plugins ship anonymous. Nothing asks for an API key on install, and write access is opt-in.
  • Skills live in one place and generate the per-client copies. CI fails on drift.
  • Restores type: http and the /add-plugin readme install step that fix: remove unsupported MCP transport type #6 removed.
  • Codex declares Write, since execute-request acts on the user's project once a key is registered.

🧬 QA & Testing

🤖 Generated with Claude Code

@greptile-apps

greptile-apps Bot commented Sep 15, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

The PR appears safe to merge, with no outstanding or newly introduced actionable defects.

Findings

  1. P1 Missing key response unhandled ▶

Reviews (16) · Last reviewed commit: "ci: only run the push job on main"

greptile-apps[bot]
greptile-apps Bot previously approved these changes Sep 15, 2026
@minhthanhdang
minhthanhdang force-pushed the minh/plugin-structure-stacked branch from 339390a to 6c110ad Compare September 15, 2026 04:53
@greptile-apps
greptile-apps Bot dismissed their stale review September 15, 2026 04:53

Dismissed because a newer commit was pushed; Greptile will re-review the current head.

@minhthanhdang
minhthanhdang force-pushed the minh/plugin-structure-stacked branch from 6c110ad to 29a8de4 Compare September 15, 2026 04:54
greptile-apps[bot]
greptile-apps Bot previously approved these changes Sep 15, 2026
@minhthanhdang
minhthanhdang force-pushed the minh/plugin-structure-stacked branch from 29a8de4 to 77b1cb7 Compare September 15, 2026 04:58
@greptile-apps
greptile-apps Bot dismissed their stale review September 15, 2026 04:58

Dismissed because a newer commit was pushed; Greptile will re-review the current head.

greptile-apps[bot]
greptile-apps Bot previously approved these changes Sep 15, 2026
@greptile-apps
greptile-apps Bot dismissed their stale review September 16, 2026 01:56

Dismissed because a newer commit was pushed; Greptile will re-review the current head.

@minhthanhdang
minhthanhdang force-pushed the minh/plugin-structure-stacked branch from fb14c95 to 2c5bd6f Compare September 16, 2026 01:56
greptile-apps[bot]
greptile-apps Bot previously approved these changes Sep 16, 2026
@minhthanhdang
minhthanhdang force-pushed the minh/plugin-structure-stacked branch from 2c5bd6f to 2e86d0c Compare September 16, 2026 01:59
@greptile-apps
greptile-apps Bot dismissed their stale review September 16, 2026 01:59

Dismissed because a newer commit was pushed; Greptile will re-review the current head.

greptile-apps[bot]
greptile-apps Bot previously approved these changes Sep 16, 2026
@minhthanhdang
minhthanhdang force-pushed the minh/plugin-structure-stacked branch from 2e86d0c to d69ca49 Compare September 16, 2026 02:01
@greptile-apps
greptile-apps Bot dismissed their stale review September 16, 2026 02:01

Dismissed because a newer commit was pushed; Greptile will re-review the current head.

@minhthanhdang
minhthanhdang force-pushed the minh/plugin-structure-stacked branch from d69ca49 to 17735d8 Compare September 16, 2026 02:01
Comment thread cursor/skills/mcp-server/SKILL.md Outdated
greptile-apps[bot]
greptile-apps Bot previously approved these changes Sep 16, 2026
@greptile-apps
greptile-apps Bot dismissed their stale review September 16, 2026 02:14

Dismissed because a newer commit was pushed; Greptile will re-review the current head.

greptile-apps[bot]
greptile-apps Bot previously approved these changes Sep 16, 2026
Comment thread cursor/README.md
```

Put that in `~/.cursor/mcp.json` for every project, or `.cursor/mcp.json` for one. Create the key
under **Account Settings → API Keys** in ReadMe and export it as `README_API_KEY` rather than

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
under **Account Settings → API Keys** in ReadMe and export it as `README_API_KEY` rather than
under **Settings → API Keys** in ReadMe and export it as `README_API_KEY` rather than

Comment thread cursor/README.md
Put that in `~/.cursor/mcp.json` for every project, or `.cursor/mcp.json` for one. Create the key
under **Account Settings → API Keys** in ReadMe and export it as `README_API_KEY` rather than
committing it. The key decides which project the agent reaches, and grants read and write access to
it. Rotate it from Account Settings if it is ever exposed.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
it. Rotate it from Account Settings if it is ever exposed.
it. Rotate it from the API Keys page if it is ever exposed.

minhthanhdang and others added 7 commits September 17, 2026 13:03
Root was a Cursor plugin, an Agent Plugins package, and a marketplace
host for claude/ and codex/ at the same time. That left two MCP
definitions that disagreed and a root manifest duplicating codex/.

Root is now only a marketplace, with one directory per client.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The MCP server is bound to one project by its hostname, so search and
fetch read ReadMe's own documentation while only execute-request, with
the user's key, reaches theirs. Agents cannot tell these apart from the
tool names, and the README was promising that search covered the user's
own guides.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The agent had no way to tell an anonymous server from a keyed one, so it
asked for a key it sometimes already had, and answered from ReadMe's own
docs when no project was named.

Adds a probe against /projects/me that distinguishes the two, and names
the Missing Security Schemes error that an unexpanded ${README_API_KEY}
placeholder produces.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The skill described a protocol without demonstrating it, so the agent
had to infer the shape of every call. It now carries the probe and the
keyed variant as worked examples, including the required title argument
that fails with an unhelpful validation error when omitted.

Also resolves the project once per session rather than per turn, states
that step 3 only applies to an anonymous server, and folds the routing
list into the tool table so one decision is described once.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…copies

Five canonical skills live in skills/ and are the only ones to edit. Each
client directory gets a byte-identical generated copy, since every marketplace
submission reads only its own directory.

Host-specific instructions moved inside the shared files as per-client tables:
registering the key, driving a browser, and installing the plugin by hand. Tool
names are bare, with no namespace prefix.

scripts/sync-skills.mjs regenerates the copies and --check fails on drift.
scripts/validate-skills.mjs checks frontmatter and the 20,000-char limit. CI
runs both plus claude plugin validate.
…not say

readme-api and developer-metrics-api were hand-copied route tables. The server
returns the same map from list-endpoints for 2.6KB against the 8.8KB skill, and
get-endpoint already carries the Refactored-only notices, the category.uri
pattern and prefer: handling=strict. Duplicating a spec that moves is how the
skills go stale.

The facts no endpoint listing can produce move into mcp-server: the paging
response shape, child projects needing their own key, Enterprise gating on
metrics reads, basic auth on the metrics spec, the SDK packages, and which
dashboard metrics have no route at all.

Fixes the metrics auth in the spec table, which said bearer where the
definition says basic.
@minhthanhdang
minhthanhdang force-pushed the minh/plugin-structure-stacked branch from 445ed59 to db8fd22 Compare September 17, 2026 03:03
@greptile-apps
greptile-apps Bot dismissed their stale review September 17, 2026 03:03

Dismissed because a newer commit was pushed; Greptile will re-review the current head.

greptile-apps[bot]
greptile-apps Bot previously approved these changes Sep 17, 2026
@minhthanhdang
minhthanhdang changed the base branch from minh/rm-18419 to main September 17, 2026 03:19
main built claude/ and codex/ in parallel with this branch, so both sides
created the same directories. Resolved in favour of this branch everywhere
except the Codex manifest.

- codex/plugin.json takes main's version: the plugin does write, through
  execute-request once a key is registered, so the directory listing has to
  say so. That also keeps the icons main added, which nothing referenced
  otherwise.
- The two validate workflows become one. main's was the only thing running
  claude plugin validate; this branch's was the only thing checking the
  generated skills match skills/, and its validate step never ran because
  the CLI was never installed. validate.yml now does both, strict.
- Everything else keeps this branch's text. main's inline mcp add snippets
  survive in the mcp-auth registration table.
@greptile-apps
greptile-apps Bot dismissed their stale review September 17, 2026 03:26

Dismissed because a newer commit was pushed; Greptile will re-review the current head.

A PR push was triggering the suite twice, once for push and once for
pull_request.
@minhthanhdang
minhthanhdang merged commit 0dce0b3 into main Sep 17, 2026
2 checks passed
runnabro added a commit that referenced this pull request Sep 18, 2026
Co-authored-by: Cursor <cursoragent@cursor.com>

#7 moved the Agent Plugins manifest into cursor/ and dropped variables, which removed Cursor's only install-time key prompt. Put README_API_KEY back on the Cursor plugin MCP server.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants