Skip to content

feat: add independent plugin distributions - #105

Merged
leynier merged 4 commits into
mainfrom
feat/exeora-claude-web-plugin
Oct 11, 2026
Merged

leynier merged 4 commits into
mainfrom
feat/exeora-claude-web-plugin

Conversation

@leynier

@leynier leynier commented Oct 11, 2026 •

Copy link
Copy Markdown
Owner

Adds independent Exeora downloads for Claude web, GrokBot Cursor, pure Agent Plugins 1.0.0 and GitHub Copilot while preserving the released ChatGPT package. Each has three adapted skills, a credential-free remote MCP connection, deterministic build, SHA-256 sidecar, metadata and installation guide. /docs/plugins/ presents all five distributions. The standard packages validate against pinned official Draft 2020-12 schemas; separate Claude, Cursor and Copilot repository catalogs preserve platform discovery.

The landing now shows /#plugin-installation immediately after the hero: an explicit remote-MCP Desktop-only warning and public ChatGPT web publication path precede every plugin download, followed by client-specific installation steps before each button. The OpenAI and chooser pages also show limits before download links. Desktop/mobile order assertions and Argent screenshots verify 1280px/390px layouts.

The sixth combined fixture is explicitly experimental and generated only under ignored .artifacts/, outside website and release builds. It shares portable skills and exercises manifest conflicts without claiming universal installation. Its reviewed ZIP was delivered once through the existing verified private Telegram route at the user's explicit request; no delivery configuration, receipt or credentials are committed.

Validation (all 13 GitHub checks passed on 455a6ac):

  • bun run ci passed lint, file-length, typecheck and web/extension builds. Its unbounded local test run stalled and was stopped; vitest run --maxWorkers=8 passed all 1,895 tests in 183 files. Gateway asset checks also passed (23 tests). The prior-head browser CI timed out in an unrelated simulated MCP relay bootstrap (216/217 passed); the full relay file passed locally. The full local suite now passes all 219 cases, and browser CI passed on final head 455a6ac.
  • The full Chromium/mobile suite passed: 219 tests, including downloads/checksums/archive manifests and compatibility-before-download order at 1280px/390px. Anchor movement is handled by atomic geometry measurement; screenshots were inspected with Argent.
  • Official Agent Plugins schema validation and 35 package/preparation tests, including exact ChatGPT/Claude preservation and rejection of provider extensions in the pure distribution.
  • Strict Claude Code plugin/marketplace validation, Cursor official template validation, locked Bun 1.3.14 install and high-severity dependency audit.
  • Read-only Copilot 1.0.95 external inventory probes: root metadata selected ahead of a distinct Claude marker; inventory also lists an unsupported schema, so this is not full runtime validation.

Verified limits:

  • Claude web upload/connector connection is separate from CLI syntax; no real host installation or OAuth performed.
  • Cursor supports extracted local folders/repository marketplaces. Grok Bot documents catalog add/auth, without custom ZIP or arbitrary-repository ingestion; availability and skills remain unverified.
  • Agent Plugin is pure 1.0.0 with no extensions/provider metadata/assets; authentication and installation are client-defined.
  • GitHub Copilot app, CLI and VS Code have documented plugin paths. No reviewed contract defines a plugin logo/interface field; the image is a README/web asset only, with no invented com.github.copilot image metadata.
  • The user reports preliminary Claude web import/use for one unidentified experimental ZIP; no categorical mixed-manifest rejection claim is retained. This is not complete OAuth evidence.
  • OpenAI marks any imported MCP plugin Desktop only, including remote HTTPS. The sent combined ZIP and the unchanged separate package both declare MCP. Public-user web distribution requires the publisher portal connection/domain verification, scans, review, approval and publication; private app references do not provide universal access and are excluded from public submissions. Added local preflight and corrected web/docs instructions without altering the preserved archive.
  • Experimental v2 corrects documentation only and uses versioned private output; no speculative replacement was sent.

No credentials, authorization grants, persistent tool permissions, managed policies or MCP authentication code changed. No public directory submission or experimental public download is included. Merge remains owned by the single runtime watch after checks/reviews are eligible. The normal existing CI deployment after merge is authorized; manual releases/tags and plugin-account registration, review submission or directory publication are outside this code-shipping scope.

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ No new issues found.

Reviewed changes

Reviewed the Claude web plugin package, its archive builder, the landing download page, and the gateway headers for both download names.

  • Plugin package — Adds plugins/exeora-claude with a root manifest, three skills, a fixed https://exeora.dev/mcp HTTP connector, and a listing icon, kept separate from the ChatGPT package.
  • Archive builder — plugin:build:claude writes identical DEFLATE bytes as .plugin and .zip, with filename-specific checksums, and rejects credentials, local MCP, symlinks, and unexpected files.
  • Landing — Docs, nav, hero, and footer link to the new download and leave the ChatGPT route in place.
  • Gateway downloads — Both archive names are served as application/zip attachments, including conditional 304 responses.
  • Repository marketplace — .claude-plugin/marketplace.json points at ./plugins/exeora-claude for Add marketplace installs.

Pullfrog  | View workflow run | Using grok-4.7 | 𝕏

@leynier leynier changed the title feat: add claude web plugin downloads feat: add independent plugin distributions Oct 11, 2026

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ No new issues found.

Reviewed changes

Reviewed 5db4f11, the commit since the prior review at 9e96cec. It adds three production distributions and a private experimental fixture without changing the Claude or ChatGPT archives.

  • Added three packages — GrokBot Cursor, pure Agent Plugin, and GitHub Copilot each ship credential-free remote MCP and three skills, with host-specific catalogs that do not replace the ChatGPT or Claude listings.
  • Published five downloads — The landing build emits every production ZIP, checksum, and metadata file, and /docs/plugins/ links to each install guide.
  • Served the new archives — Gateway headers force application/zip attachments for the three new ZIPs, including conditional 304 responses.
  • Corrected ChatGPT web docs — Imported MCP is documented as Desktop only, with publisher submission as the public web path. The shipped ChatGPT archive hash is unchanged.
  • Kept the experimental fixture private — Schema checks and allowlists reject extensions, secrets, symlinks, and unexpected files. The mixed ZIP is written only under ignored .artifacts/ and is not a website download.

Pullfrog  | View workflow run | Using grok-4.7 | 𝕏

@leynier
leynier merged commit 6b0418d into main Oct 11, 2026
13 checks passed
@leynier
leynier deleted the feat/exeora-claude-web-plugin branch October 11, 2026 04:16

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ No new issues found.

Reviewed changes

Reviewed 4ebaa6e and 455a6ac, the commits since the prior review at 5db4f11. They put each client's install limits before the download, and check that order in one frame.

  • Added a homepage install section — #plugin-installation sits directly under the hero, with the ChatGPT Desktop-only notice and each client's steps above its download.
  • Moved warnings ahead of the files — The ChatGPT web restriction now precedes the ZIP on /docs/plugin/ and the chooser table on /docs/plugins/, and #chatgpt-web still resolves.
  • Corrected the hero claim — The hero no longer says any OAuth HTTP client connects, and it links to the new section.
  • Stabilized the order check — The layout test reads the notice, steps, and button rectangles in one frame so smooth anchor scrolling cannot split them.

Pullfrog  | View workflow run | Using grok-4.7 | 𝕏

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant