Repository navigation
feat: add independent plugin distributions - #105
Conversation
There was a problem hiding this comment.
✅ No new issues found.
Reviewed changes
Reviewed the Claude web plugin package, its archive builder, the landing download page, and the gateway headers for both download names.
- Plugin package — Adds
plugins/exeora-claudewith a root manifest, three skills, a fixedhttps://exeora.dev/mcpHTTP connector, and a listing icon, kept separate from the ChatGPT package. - Archive builder —
plugin:build:claudewrites identical DEFLATE bytes as.pluginand.zip, with filename-specific checksums, and rejects credentials, local MCP, symlinks, and unexpected files. - Landing — Docs, nav, hero, and footer link to the new download and leave the ChatGPT route in place.
- Gateway downloads — Both archive names are served as
application/zipattachments, including conditional 304 responses. - Repository marketplace —
.claude-plugin/marketplace.jsonpoints at./plugins/exeora-claudefor Add marketplace installs.
grok-4.7 | 𝕏
There was a problem hiding this comment.
✅ No new issues found.
Reviewed changes
Reviewed 5db4f11, the commit since the prior review at 9e96cec. It adds three production distributions and a private experimental fixture without changing the Claude or ChatGPT archives.
- Added three packages — GrokBot Cursor, pure Agent Plugin, and GitHub Copilot each ship credential-free remote MCP and three skills, with host-specific catalogs that do not replace the ChatGPT or Claude listings.
- Published five downloads — The landing build emits every production ZIP, checksum, and metadata file, and
/docs/plugins/links to each install guide. - Served the new archives — Gateway headers force
application/zipattachments for the three new ZIPs, including conditional 304 responses. - Corrected ChatGPT web docs — Imported MCP is documented as Desktop only, with publisher submission as the public web path. The shipped ChatGPT archive hash is unchanged.
- Kept the experimental fixture private — Schema checks and allowlists reject extensions, secrets, symlinks, and unexpected files. The mixed ZIP is written only under ignored
.artifacts/and is not a website download.
grok-4.7 | 𝕏
There was a problem hiding this comment.
✅ No new issues found.
Reviewed changes
Reviewed 4ebaa6e and 455a6ac, the commits since the prior review at 5db4f11. They put each client's install limits before the download, and check that order in one frame.
- Added a homepage install section —
#plugin-installationsits directly under the hero, with the ChatGPT Desktop-only notice and each client's steps above its download. - Moved warnings ahead of the files — The ChatGPT web restriction now precedes the ZIP on
/docs/plugin/and the chooser table on/docs/plugins/, and#chatgpt-webstill resolves. - Corrected the hero claim — The hero no longer says any OAuth HTTP client connects, and it links to the new section.
- Stabilized the order check — The layout test reads the notice, steps, and button rectangles in one frame so smooth anchor scrolling cannot split them.
grok-4.7 | 𝕏

Adds independent Exeora downloads for Claude web, GrokBot Cursor, pure Agent Plugins 1.0.0 and GitHub Copilot while preserving the released ChatGPT package. Each has three adapted skills, a credential-free remote MCP connection, deterministic build, SHA-256 sidecar, metadata and installation guide.
/docs/plugins/presents all five distributions. The standard packages validate against pinned official Draft 2020-12 schemas; separate Claude, Cursor and Copilot repository catalogs preserve platform discovery.The landing now shows
/#plugin-installationimmediately after the hero: an explicit remote-MCP Desktop-only warning and public ChatGPT web publication path precede every plugin download, followed by client-specific installation steps before each button. The OpenAI and chooser pages also show limits before download links. Desktop/mobile order assertions and Argent screenshots verify 1280px/390px layouts.The sixth combined fixture is explicitly experimental and generated only under ignored
.artifacts/, outside website and release builds. It shares portable skills and exercises manifest conflicts without claiming universal installation. Its reviewed ZIP was delivered once through the existing verified private Telegram route at the user's explicit request; no delivery configuration, receipt or credentials are committed.Validation (all 13 GitHub checks passed on
455a6ac):bun run cipassed lint, file-length, typecheck and web/extension builds. Its unbounded local test run stalled and was stopped;vitest run --maxWorkers=8passed all 1,895 tests in 183 files. Gateway asset checks also passed (23 tests). The prior-head browser CI timed out in an unrelated simulated MCP relay bootstrap (216/217 passed); the full relay file passed locally. The full local suite now passes all 219 cases, and browser CI passed on final head455a6ac.Verified limits:
com.github.copilotimage metadata.No credentials, authorization grants, persistent tool permissions, managed policies or MCP authentication code changed. No public directory submission or experimental public download is included. Merge remains owned by the single runtime watch after checks/reviews are eligible. The normal existing CI deployment after merge is authorized; manual releases/tags and plugin-account registration, review submission or directory publication are outside this code-shipping scope.