Skip to content

fix: Resolve Claude plugin directory scanner findings - #181

Merged
erangeles merged 2 commits into
mainfrom
fix/plugin-directory-findings
Sep 28, 2026
Merged

erangeles merged 2 commits into
mainfrom
fix/plugin-directory-findings

Conversation

@erangeles

@erangeles erangeles commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Summary

CleanShot 2026-09-28 at 2 58 58 PM

Addresses the warnings the Claude plugin directory scanner reported on v1.0.0 (f1bea2f) and bumps the Claude plugin to 1.0.1.

  • BINARIES_NOT_INSPECTED / INVENTORY_GAPS: the validator doesn't follow symlinks, so the 14 flat symlinks under skills/ were never read. They're replaced with an explicit skills array in .claude-plugin/plugin.json that points at the real skill directories. Verified with claude --plugin-dir: the same 15 skills load as before.
  • UNKNOWN_KEY_CROSS_TOOL / ICON_MISSING: replaced logo with icon: "logo.svg".
  • PRIVACY_URL_MISSING: added privacyPolicyUrl: https://launchdarkly.com/policies/privacy/.
  • MCP_FORWARDS_CREDENTIAL_ENV: online-evals, custom-metrics, projects and configs-targeting told the agent to find API tokens in env vars and ~/.claude/config.json. They now say to use the MCP server's OAuth first, and to ask the user for a token only when a REST call is unavoidable. Examples the agent runs directly use an {api_token} placeholder instead of reading env vars.
  • Added a marketplace description (validator warning) and a CHANGELOG entry.

Intentionally unchanged (notes for directory reviewer)

  • SDK snippets and projects/references/*: this is code written into the user's own app, CI or Terraform. Reading SDK keys and API tokens from env vars or secret stores is the correct practice there.
  • evals/ and tests/: dev-only eval and test harness. These files never run in a user's session. They account for the promptfooconfig.yaml credential hits and the large package-lock.json files.

Testing

  • claude plugin validate . and claude plugin validate .claude-plugin/plugin.json pass with no warnings
  • tests/test_*.py pass
  • scripts/validate_skills.py validates all 49 SKILL.md files

Not tested

  • Codex plugin skill discovery after removing the symlinks: .codex-plugin/plugin.json still points at ./skills/.

🤖 Generated with Claude Code


Note

Overview
Bumps the Claude Code plugin to 1.0.1 and fixes validator warnings from the plugin directory scanner.

Plugin metadata: Adds marketplace description, privacyPolicyUrl, renames logo → icon, and registers skills via an explicit skills array in plugin.json instead of flat skills/ symlinks (which the scanner did not follow). The symlink stubs under skills/ are cleared accordingly.

Agent skill credential guidance: Several AgentControl skills (configs-targeting, custom-metrics, online-evals, projects) drop “API key detection” from env vars and ~/.claude/config.json. They now tell agents to use LaunchDarkly MCP (OAuth) first and only ask the user for a session token when REST is required; curl/Python examples use {api_token} instead of $LD_API_KEY / os.environ. Related reference docs (configs-create, langchain-tracking, migrate, metrics-api`) are aligned.

Docs: CHANGELOG.md records the 1.0.1 release notes.

Reviewed by Cursor Bugbot for commit 689b8ce. Bugbot is set up for automated code reviews on this repo. Configure here.

- Replace skills/ symlinks with an explicit `skills` array in plugin.json;
  the validator does not follow symlinks, which caused inventory gaps.
- Swap cross-tool `logo` key for `icon` and add `privacyPolicyUrl`.
- Stop skills from auto-detecting API tokens in env vars or
  ~/.claude/config.json; prefer MCP (OAuth) and ask the user for a
  token when a REST call is unavoidable.
- Add a marketplace description.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@erangeles
erangeles requested a review from a team September 28, 2026 20:05
@erangeles
erangeles enabled auto-merge (squash) September 28, 2026 20:10

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 689b8ce. Configure here.

Comment thread .claude-plugin/plugin.json
@erangeles
erangeles disabled auto-merge September 28, 2026 20:11
@github-actions

Copy link
Copy Markdown

Skill eval results

Skill Before After Δ
agentcontrol/configs-create 100/100 (4/4) 75/100 (3/4) -25
agentcontrol/configs-update 80/100 (4/5) 80/100 (4/5) no change
agentcontrol/configs-variations 80/100 (4/5) 80/100 (4/5) no change
agentcontrol/tools 75/100 (3/4) 75/100 (3/4) no change
feature-flags/flag-and-release-change - 100/100 (4/4) new
feature-flags/flag-release - 100/100 (5/5) new
feature-flags/launchdarkly-flag-command - 100/100 (3/3) new
feature-flags/launchdarkly-flag-create 100/100 (3/3) 100/100 (4/4) no change
feature-flags/launchdarkly-flag-drift - 100/100 (4/4) new
feature-flags/should-flag-change - 100/100 (17/17) new
onboarding - 100/100 (4/4) new

Only suites whose source actually changed since their last recorded score were re-run. Soft-failing while we stabilise the baseline.

@erangeles
erangeles merged commit ef54971 into main Sep 28, 2026
19 checks passed
@erangeles
erangeles deleted the fix/plugin-directory-findings branch September 28, 2026 20:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants