fix(plugin): respect marketplace component boundaries - #443
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Skills-only repositories no longer leak their development hooks, GitHub configuration, or MCP servers into consumer workspaces. AllAgents now reads both Copilot and Claude marketplace manifests and honors the component kinds declared by a
strict: falseentry, including when the repository is installed directly or fetched through another marketplace.Before this change,
source: "./"made the whole repository look like plugin content, so.github/hookscould be interpreted as distributable configuration. After this change, a root source can remain a plugin whileskills: ["./skills/"]is the only exposed component; top-levelhooks/remains available to conventional or explicitly hook-bearing plugins.The boundary is enforced in the normal file copier, Codex hook aggregation, MCP discovery, skill scanning, and legacy user-hook relocation. Custom marketplace component paths are parsed but not remapped yet; this PR applies the declared component-kind boundary to AllAgents' conventional root directories.
Related: WiseTechGlobal/mcp-ediprod#448
Validation
bun run buildbun run typecheckbun run lintbun test— 1,347 passed, 5 skippedbun run test:e2e— 117 passed, 4 skippedManual E2E:
WiseTechGlobal/mcp-ediprodinto a temporary directory.strict: falsewithskills: ["./skills/"].dist/index.js update..github/skills, while.github/hooks,.github/plugin, and.copilot/mcp-config.jsonwere absent.