fix: Resolve Claude plugin directory scanner findings - #181
Merged
Merged
Conversation
- Replace skills/ symlinks with an explicit `skills` array in plugin.json; the validator does not follow symlinks, which caused inventory gaps. - Swap cross-tool `logo` key for `icon` and add `privacyPolicyUrl`. - Stop skills from auto-detecting API tokens in env vars or ~/.claude/config.json; prefer MCP (OAuth) and ask the user for a token when a REST call is unavoidable. - Add a marketplace description. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
nhironaka
approved these changes
Sep 28, 2026
erangeles
enabled auto-merge (squash)
September 28, 2026 20:10
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 689b8ce. Configure here.
erangeles
disabled auto-merge
September 28, 2026 20:11
Skill eval results
Only suites whose source actually changed since their last recorded score were re-run. Soft-failing while we stabilise the baseline. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Summary
Addresses the warnings the Claude plugin directory scanner reported on v1.0.0 (
f1bea2f) and bumps the Claude plugin to 1.0.1.skills/were never read. They're replaced with an explicitskillsarray in.claude-plugin/plugin.jsonthat points at the real skill directories. Verified withclaude --plugin-dir: the same 15 skills load as before.logowithicon: "logo.svg".privacyPolicyUrl: https://launchdarkly.com/policies/privacy/.online-evals,custom-metrics,projectsandconfigs-targetingtold the agent to find API tokens in env vars and~/.claude/config.json. They now say to use the MCP server's OAuth first, and to ask the user for a token only when a REST call is unavoidable. Examples the agent runs directly use an{api_token}placeholder instead of reading env vars.description(validator warning) and a CHANGELOG entry.Intentionally unchanged (notes for directory reviewer)
projects/references/*: this is code written into the user's own app, CI or Terraform. Reading SDK keys and API tokens from env vars or secret stores is the correct practice there.evals/andtests/: dev-only eval and test harness. These files never run in a user's session. They account for thepromptfooconfig.yamlcredential hits and the largepackage-lock.jsonfiles.Testing
claude plugin validate .andclaude plugin validate .claude-plugin/plugin.jsonpass with no warningstests/test_*.pypassscripts/validate_skills.pyvalidates all 49 SKILL.md filesNot tested
.codex-plugin/plugin.jsonstill points at./skills/.🤖 Generated with Claude Code
Note
Overview
Bumps the Claude Code plugin to 1.0.1 and fixes validator warnings from the plugin directory scanner.
Plugin metadata: Adds marketplace
description,privacyPolicyUrl, renameslogo→icon, and registers skills via an explicitskillsarray inplugin.jsoninstead of flatskills/symlinks (which the scanner did not follow). The symlink stubs underskills/are cleared accordingly.Agent skill credential guidance: Several AgentControl skills (
configs-targeting,custom-metrics,online-evals,projects) drop “API key detection” from env vars and~/.claude/config.json. They now tell agents to use LaunchDarkly MCP (OAuth) first and only ask the user for a session token when REST is required; curl/Python examples use{api_token}instead of$LD_API_KEY/os.environ. Related reference docs (configs-create, langchain-tracking, migrate, metrics-api`) are aligned.Docs:
CHANGELOG.mdrecords the 1.0.1 release notes.Reviewed by Cursor Bugbot for commit 689b8ce. Bugbot is set up for automated code reviews on this repo. Configure here.