Skip to content

feat(plugins): add Agent Plugins compiler and native import - #113

Merged
gricha merged 61 commits into
mainfrom
codex/add-plugin-support
Aug 9, 2026
Merged

gricha merged 61 commits into
mainfrom
codex/add-plugin-support

Conversation

@dcramer

@dcramer dcramer commented Jun 12, 2026 •

Copy link
Copy Markdown
Member

Adds project-scoped plugin dependencies to dotagents with an explicit compiler/importer contract.

[[plugins]]
name = "review-tools"
source = "getsentry/agent-plugins"
path = "plugins/review-tools"
targets = ["claude", "cursor", "codex", "grok", "opencode", "pi"]

install resolves the source using the existing trust and minimum-release-age policies, stages the bundle under .agents/plugins/<name>/, records the resolved source in agents.lock, and reconciles the selected client harnesses. Plugins participate in install, offline sync, list, remove, doctor, lockfile updates, and selective gitignore generation.

Forward compilation: Agent Plugins → client harness

The portable input is Agent Plugins v1: required plugin.json, optional skills/, optional mcp.json, and reverse-domain extension directories. Portable source files are preserved unchanged.

Each target adapter owns an exact filesystem contract:

Target Generated output
Claude Code Project marketplace plus a Claude-native manifest inside the installed bundle
Cursor Project marketplace plus a Cursor-native manifest inside the installed bundle
Codex Repo-scoped marketplace plus a Codex-native manifest inside the installed bundle
Grok Build Sanitized managed copy of the portable bundle
OpenCode Supported Agent Skill symlinks only; this is resource projection, not plugin installation
Pi Agent Skill symlinks in the shared .agents/skills/ directory

Target JSON remains client-native. Dotagents ownership is recorded in adjacent .dotagents-managed sidecars, so native validators do not receive dotagents-only fields. Legacy metadata-marked output is still recognized for migration.

Standard bundles reject legacy root agents, commands, rules, hooks, and native MCP files. Client-owned content must live in reverse-domain extension directories and is not guessed or translated into another client. Pi is the explicit isolation exception: targeting Pi projects skills into the shared .agents/skills/ surface, making them visible to other clients that consume that directory.

Portable MCP validation covers stdio, streamable HTTP, and SSE transports, safe command/cwd rules, reserved runtime variables, and per-server recovery. A malformed server is omitted while valid siblings are emitted into a sanitized target-owned MCP adapter. Valid source MCP remains untouched.

Reverse import: native bundle → portable intersection

Native Claude, Cursor, and Codex bundles remain discoverable. Dotagents preserves the owning native manifest and resources, records native provenance in a managed marker, and exposes only the portable intersection—core metadata and valid Agent Skills—to other selected clients.

Native commands, agents, rules, hooks, apps, and MCP references are never cross-translated. Grok receives a sanitized Agent Plugins core rather than another client’s native directories. Native MCP-to-portable conversion remains explicit future importer work rather than an inferred transformation.

Exact integration contract

The main integration contract is one table-driven test definition run in six isolated projects—Claude, Cursor, Codex, Grok, OpenCode, and Pi. Each case enumerates the complete expected file/symlink inventory and validates every file’s full semantic contents and every symlink target. This prevents one harness, especially Pi’s shared skill projection, from making another harness pass accidentally.

The fixture includes a contained linked skills/ directory, client-extension files, a stdio MCP server using PLUGIN_ROOT/PLUGIN_DATA, and a streamable HTTP MCP server. A separate reverse-import case proves native provenance survives sync and native components do not leak into Cursor, OpenCode, or Grok.

Ownership and safety

  • Canonical and referenced paths are checked using resolved filesystem paths.
  • Broken or escaping symlinks are rejected; contained relative symlinks survive staging and target copies verbatim.
  • Existing plugin destinations require the on-disk managed marker; lockfile state alone never authorizes replacement.
  • Source-supplied dotagents ownership markers are stripped before installation.
  • Unmanaged marketplaces, manifests, projections, and skill links are preserved and reported.
  • Replacement uses staged and backup directories, retaining recoverable state after failure.
  • Obsolete native adapters are pruned before dependent copies are refreshed.

Review order

  1. specs/plugins.md for forward/reverse invariants and explicit gaps.
  2. plugins/schema.ts and plugins/store.ts for portable parsing, native discovery, provenance, containment, and installation.
  3. plugins/runtime/ for target manifests, marketplaces, MCP recovery, projection, ownership, pruning, and verification.
  4. CLI lifecycle integration and diagnostics.
  5. The isolated harness integration table and skills/dotagents-qa client proofs.

Validation includes the full repository suite, install/sync repair QA, clean Claude validation plus actual marketplace add/install/details with one skill and two MCP servers, and Codex marketplace add/install/list with the installed non-empty MCP file inspected. Cursor remains deterministic-contract-only because its desktop CLI exposes no plugin validation command; Grok client proof runs when its CLI is available.

@vercel

vercel Bot commented Jun 12, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
dotagents Ready Ready Preview Aug 9, 2026 7:58am

Request Review

Comment thread packages/dotagents/src/agents/plugin-writer.ts Outdated
Comment thread packages/dotagents/src/cli/commands/sync.ts
Comment thread packages/dotagents/src/agents/plugin-writer.ts Outdated
Comment thread packages/dotagents/src/cli/commands/doctor.ts
Comment thread packages/dotagents/src/plugins/store.ts
Comment thread packages/dotagents/src/cli/commands/install.ts Outdated
Comment thread packages/dotagents/src/cli/commands/sync.ts
Comment thread packages/dotagents/src/agents/plugin-store.ts Outdated
Comment thread packages/dotagents/src/plugins/store.ts Outdated
Comment thread packages/dotagents/src/cli/commands/install.ts Outdated
Comment thread packages/dotagents/src/cli/commands/sync.ts
Comment thread packages/dotagents/src/agents/plugin-writer.ts Outdated
Comment thread packages/dotagents/src/cli/commands/install.ts Outdated
Comment thread packages/dotagents/src/cli/commands/sync.ts
Comment thread packages/dotagents/src/plugins/store.ts
Comment thread packages/dotagents/src/cli/commands/sync.ts
Comment thread packages/dotagents/src/cli/commands/doctor.ts
Comment thread packages/dotagents/src/plugins/store.ts Outdated
Comment thread packages/dotagents/src/cli/commands/sync.ts
Comment thread packages/dotagents/src/plugins/store.ts
Comment thread packages/dotagents/src/cli/commands/install.ts Outdated
Comment thread packages/dotagents/src/plugins/runtime/writer.ts
Comment thread packages/dotagents/src/plugins/runtime/writer.ts
Comment thread packages/dotagents/src/plugins/runtime/writer.ts Outdated
Comment thread packages/dotagents/src/plugins/runtime/writer.ts
Comment thread packages/dotagents/src/cli/commands/install.ts Outdated
Comment thread packages/dotagents/src/cli/commands/remove.ts
Comment thread packages/dotagents/src/config/loader.ts
Comment thread packages/dotagents/src/plugins/runtime/manifest-values.ts Outdated
Comment thread packages/dotagents/src/plugins/runtime/manifests.ts Outdated
Comment thread packages/dotagents/src/plugins/store.ts Outdated
Comment thread packages/dotagents/src/cli/commands/remove.ts
Comment thread packages/dotagents/src/plugins/runtime/writer.ts
Comment thread packages/dotagents/src/plugins/runtime/writer.ts
Comment thread packages/dotagents/src/cli/commands/remove.ts
Comment thread packages/dotagents/src/plugins/runtime/manifests.ts
Comment thread packages/dotagents/src/plugins/store.ts
Comment thread packages/dotagents/src/plugins/schema.ts Outdated
Comment thread packages/dotagents/src/plugins/store.ts

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

There are 2 total unresolved issues (including 1 from previous review).

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 09a84dd. Configure here.

? value as Record<string, unknown>
: null;
const schemaValue = recordValue?.["$schema"];
const normalizedSchemaValue = typeof schemaValue === "string"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

MCP schema case folding gap

Low Severity

parsePluginManifest now treats Agent Plugins schema origins as case-insensitive and canonicalizes them, but parsePluginMcpBestEffort still requires an exact AGENT_PLUGIN_MCP_SCHEMA literal. A standard bundle whose mcp.json uses the same case-folded origin is classified as standard, then drops portable MCP after envelope validation fails.

Additional Locations (1)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 09a84dd. Configure here.

Comment thread packages/dotagents/src/plugins/runtime/writer.ts Outdated
Comment thread packages/dotagents/src/plugins/schema.ts
Comment thread packages/dotagents/src/plugins/store.ts
Comment thread packages/dotagents/src/cli/commands/install/plugins.ts
Comment thread packages/dotagents/src/cli/commands/remove.ts
Comment thread packages/dotagents/src/plugins/runtime/writer.ts
Comment thread packages/dotagents/src/plugins/schema.ts
Comment thread packages/dotagents/src/plugins/store.ts

This branch was successfully deployed

1 active deployment
Preview — d102b3ef Deployed Aug 9, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

risk: high PR risk score: high

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants