Skip to content

feat: curate the initial company plugin batch - #3645

Open
Patrick-Erichsen wants to merge 2 commits into
codex/claw-723-plugin-syncfrom
codex/claw-723-plugin-batch
Open

feat: curate the initial company plugin batch#3645
Patrick-Erichsen wants to merge 2 commits into
codex/claw-723-plugin-syncfrom
codex/claw-723-plugin-batch

Conversation

@Patrick-Erichsen

@Patrick-Erichsen Patrick-Erichsen commented Sep 9, 2026

Copy link
Copy Markdown
Collaborator

Proposes the first curated company-plugin batch across 426 current registry candidates: Arize from its company repository, Intercom under Cursor, and Zoom under Cursor. All source approvals remain disabled until maintainer acceptance.

The decision record preserves snapshot commits, source/license hashes, target publishers, supported capabilities, omitted components and winner/exclusion reasons. The richer OpenAI Zoom candidate is withheld because its normalized 5,431,663-byte artifact exceeds the normal 4 MiB multipart upload limit; the smaller Cursor MCP wrapper passes the normal publisher dry run, and meeting knowledge remains distinct from OpenClaw's Zoom meeting-participant plugin. OpenClaw Slack suppresses the equivalent wrapper. Granola and both Notion sources remain withheld for missing complete MIT licensing. Existing community plugins remain untouched.

The allowlist also records current published and bundled OpenClaw identities, including catalog parity observations. The complete inventory and separate informational permission-needed report are attached to the tracking issue; no company was contacted and no production artifact was published.

The acceptance test now runs in the regular local-auth CI matrix. Verified company adoption also exercises the existing profile workflow and confirms that package identity, release metadata, exact downloaded file bytes and canonical alias redirects remain unchanged after custody transfers.

Validation: ci:static, ci:unit (6,547 passed, 3 skipped), Convex TypeScript, the targeted adoption test, existing CI-workflow regressions and strict manifest parsing pass. Each of the three real pinned source artifacts passes the normal CLI dry run with exact upload-inventory digest verification. The parent synchronization layer passes ci:types-build, ci:packages, ci:e2e-http, public browser smoke (17 passed), and the real local-auth catalog/download acceptance seam with four direct OpenClaw 2026.9.3 installs in a disposable OCM environment. GitHub CI also passed the new company-plugin-sync shard before the final adoption-test checkpoint. The initial batch and adoption regression each passed autoreview; the final required fixture field was manually reviewed and retested.

Real browser and API/install proof covers immutable updates, deduplication, withheld artifacts and canonical replacement. Security verdicts in the acceptance seam use controlled worker fixtures, not live-provider certification. Initial production publication and scheduled activation remain disabled pending maintainer review.

@clawsweeper

clawsweeper Bot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

ClawSweeper review complete

ClawSweeper finished reviewing this revision. The review result is being finalized.

View the workflow run.

@vercel

vercel Bot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
clawhub Ready Ready Preview Sep 9, 2026 4:09am UTC

Request Review

@clawsweeper

clawsweeper Bot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

Codex review: blocked before merge. Reviewed September 9, 2026, 8:32 AM ET / 12:32 UTC (Revision 4).

ClawSweeper review

What this changes

Proposes three initial company-plugin imports with recorded exclusions, adds synchronization acceptance coverage to CI, and verifies that company adoption preserves existing package history and downloads.

Merge readiness

Blocked before merge - 2 items remain

This remains a distinct, useful batch proposal absent from current main. No blocking defect was found in the introduced changes; batch acceptance remains a curator decision, separate from production activation.

Priority: P2
Reviewed head: 5126e46e763099d79d256ea0646c20f2b183468d
Owner decision: Required. See Decision needed.

Review scores

Measure Result What it means
Overall readiness 🐚 platinum hermit (4/6) A focused proposal with useful acceptance evidence and regression coverage, no blocking findings, and a separate curator acceptance decision.
Proof confidence 🐚 platinum hermit (4/6) Not applicable: The collaborator-authored proposal does not trigger mandatory external-contributor proof or change production authority. Inspected local Convex/API and OpenClaw installation traces support the parent acceptance scenario added to CI; the adoption extension is supplemental regression coverage, and proposed-source production publication remains unproven and disabled.
Patch quality 🐚 platinum hermit (4/6) No actionable review findings were identified.

Verification

Check Result Evidence
Real behavior Not applicable Not applicable: The collaborator-authored proposal does not trigger mandatory external-contributor proof or change production authority. Inspected local Convex/API and OpenClaw installation traces support the parent acceptance scenario added to CI; the adoption extension is supplemental regression coverage, and proposed-source production publication remains unproven and disabled.
Evidence reviewed 9 items Verified introduced scope: The pinned base-to-head delta contains exactly five files: CI configuration, one existing runtime test, the operator README, source proposals, and the decision record. It introduces no production function, schema, dependency, permission, or authorization change.
Dormant source proposals and bounded preparation: Read both JSON files fully. All seven source approvals are false; three candidates have initial content hashes. The decision record preserves exclusions, existing-package comparisons, three dry-run inventories, and a prepared digest without claiming production publication.
Existing importer gates remain authoritative: Read the manifest contract, reconciliation, CLI, import publisher, and synchronization specs. Scheduled reconciliation excludes unapproved entries; manual application requires the reviewed digest; publication uses normal prepublication checks. The unchanged scheduled workflow additionally requires explicit repository activation and a Production staff token.
Findings None None.
Security None None.

How this fits together

ClawHub’s curated importer turns reviewed upstream plugin sources into scanned, immutable packages. This proposal supplies its initial source inventory while leaving scheduled publication approvals disabled.

flowchart TD
  A[Upstream plugin sources] --> B[Recorded candidates and exclusions]
  B --> C[Curator acceptance]
  C --> D[Digest-bound import plan]
  D --> E[Normal publication and security checks]
  E --> F[Immutable catalog packages]
  G[Explicit scheduling approval] --> D
Loading

Decision needed

Question Recommendation
Should Arize’s company source and Cursor’s Intercom and Zoom wrappers be accepted as the initial proposed batch, with the recorded exclusions retained? Accept the dormant batch proposal: Accept these three candidates and recorded exclusions while keeping publication and scheduling approval separate.

Why: The implementation preserves existing gates, but technical validation cannot choose which company representations ClawHub should curate; the decision record explicitly leaves acceptance pending.

Before merge

  • Complete next step (P2) - Confirm or narrow the three proposed candidates and recorded exclusions, keeping production publication and scheduling authorization separate.
  • Resolve maintainer decision - Resolve the maintainer decision shown above before merge.
Agent review details

Security

None.

Review metrics

Metric Value Why it matters
Introduced scope +750/-4 across 5 files Most additions are reviewable source inventory and decision data.
Net line growth production runtime +0; tests +66; configuration, data, and docs +680 The branch expands batch records and coverage without duplicating the importer implementation.
Activation 3 selected candidates; 0 of 7 sources approved Landing this proposal does not enable scheduled publication.

Technical review

Best possible solution:

Retain one reviewed, dormant source manifest with explicit exclusions, and authorize any later publication through the existing digest, custody, and scan gates.

Do we have a high-confidence way to reproduce the issue?

Not applicable: this is a curated batch proposal and coverage extension, not a reported existing-behavior defect.

Is this the best way to solve the issue?

Yes: populating the existing importer’s reviewed manifest is the narrowest implementation path; a separate publisher or relaxed upload limits would duplicate or weaken established behavior.

AGENTS.md: found and applied where relevant.

Codex review notes: model internal, reasoning medium; reviewed against 6b25e866fb91.

Labels

Label justifications:

  • P2: This is a bounded catalog-curation improvement with useful regression coverage and no demonstrated urgent user failure.
  • rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🐚 platinum hermit and patch quality is 🐚 platinum hermit.
  • status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Not applicable: The collaborator-authored proposal does not trigger mandatory external-contributor proof or change production authority. Inspected local Convex/API and OpenClaw installation traces support the parent acceptance scenario added to CI; the adoption extension is supplemental regression coverage, and proposed-source production publication remains unproven and disabled.

Evidence

What I checked:

  • Verified introduced scope: The pinned base-to-head delta contains exactly five files: CI configuration, one existing runtime test, the operator README, source proposals, and the decision record. It introduces no production function, schema, dependency, permission, or authorization change. (5126e46e7630)
  • Dormant source proposals and bounded preparation: Read both JSON files fully. All seven source approvals are false; three candidates have initial content hashes. The decision record preserves exclusions, existing-package comparisons, three dry-run inventories, and a prepared digest without claiming production publication. (scripts/company-plugins/sources.json:35, 5126e46e7630)
  • Existing importer gates remain authoritative: Read the manifest contract, reconciliation, CLI, import publisher, and synchronization specs. Scheduled reconciliation excludes unapproved entries; manual application requires the reviewed digest; publication uses normal prepublication checks. The unchanged scheduled workflow additionally requires explicit repository activation and a Production staff token. (scripts/company-plugins/reconcile.ts:42, 5126e46e7630)
  • Adoption regression matches the existing contract: The extended test checks unchanged package, release, alias, and downloaded bytes after verified company adoption, plus the existing canonical redirect. The underlying profile mutation and custody rules are parent-branch behavior, not introduced authority changes. (convex/curatedPlugins.runtime.test.ts:175, 5126e46e7630)
  • Still necessary on main and latest release: The curated importer directory and adoption test are absent from the fetched main tree; the importer directory is also absent from v0.23.3. Live REST metadata confirms the parent synchronization PR remains open: feat: synchronize immutable curated plugin releases #3644. No merged replacement establishing this batch was identified. (6b25e866fb91)
  • Linked real acceptance evidence inspected: Inspected the linked report and summary at https://github.com/openclaw/clawhub/tree/qa-artifacts/clawhub-ui-proof/pr-3644/immutable-company-plugin-sync. Report blob 33115097914b24b2793fa99ca41d128e9feb7d78 records local Convex/dev-auth, immutable update results, a 307 canonical replacement, and four successful OpenClaw 2026.9.3 fixture installations. It identifies validated revision ad61c85 and controlled scanner verdicts. This supports the parent acceptance scenario added to CI; it does not establish production scans or live service operation for the three proposed sources. (clawhub-ui-proof/pr-3644/immutable-company-plugin-sync/report.md:1, 6b25e866fb91)

Likely related people:

  • Patrick-Erichsen: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)
  • steipete: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)

Rating scale

Score Internal tier Crab rank Meaning
6/6 S 🦀 challenger crab Exceptional readiness
5/6 A 🦞 diamond lobster Very strong readiness
4/6 B 🐚 platinum hermit Good normal PR; ordinary maintainer review
3/6 C 🦐 gold shrimp Useful, but confidence is limited
2/6 D 🦪 silver shellfish Proof or implementation needs work
1/6 F 🧂 unranked krab Not merge-ready
N/A NA 🌊 off-meta tidepool Rating does not apply

Overall follows the weaker of proof and patch quality.
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

Workflow

  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

History

Review history (3 earlier review cycles)
  • reviewed 2026-09-09T03:24:24.004Z sha a4157b2 :: needs changes before merge. :: none
  • reviewed 2026-09-09T03:33:25.827Z sha b4f3883 :: needs maintainer review before merge. :: none
  • reviewed 2026-09-09T04:10:48.121Z sha 5126e46 :: blocked before merge. :: none

@clawsweeper clawsweeper Bot added P2 Normal backlog priority with limited blast radius. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. labels Sep 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

P2 Normal backlog priority with limited blast radius. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant