Add the root Cursor marketplace manifest so the plugin can be ingested [sc-143999] - #5
Conversation
…43999] Cursor's marketplace reviewer could not ingest the plugin: this repo uses the multi-plugin layout (plugins/<name>/.cursor-plugin/plugin.json) but had no .cursor-plugin/marketplace.json at the root, which is the file Cursor's ingester reads to find plugins in that layout. - Add .cursor-plugin/marketplace.json listing the ifttt plugin with source "plugins/ifttt", shaped per cursor/plugins' marketplace.schema.json. - Rename plugins/ifttt/.mcp.json to mcp.json, the name Cursor discovers by default and the one the Agent Plugins layout expects; repoint the manifest's mcpServers field and every doc reference. Keep "type": "http", the value used by every ingested Cursor plugin. - Keep category, tags, and displayName: Cursor's plugin.schema.json lists them even though the prose docs' field table omits them. - Teach scripts/validate.mjs to require the marketplace manifest, check that plugin names are unique and match each target plugin.json, that each source resolves to a directory with .cursor-plugin/plugin.json, that every plugins/<name>/ is listed, and that plugin.json uses no fields outside Cursor's schema (which sets additionalProperties: false). - Widen the CI JSON-parse glob and update README, AGENTS.md, CONTRIBUTING, llms.txt, and the plugin README to describe the real layout. An Agent Plugins root plugin.json was deliberately not added: Cursor's docs say that format loads only skills and MCP servers (no rules), document no precedence when both manifests exist, and its mcp.json schema requires "type": "streamable-http" plus a $schema key that no ingested Cursor plugin uses, so a single mcp.json cannot satisfy both.
|
Understand this PR’s impact Explore downstream dependencies and potential security impact with Blast Radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: IFTTT/coderabbit/.coderabbit.yaml Review profile: CHILL Plan: Essentials Run ID: 📒 Files selected for processing (12)
Included review availability: 4 reviews are currently available. Your included PR review attempts over the past 7 days set your current allowance at 5 reviews per hour. 📝 WalkthroughWalkthroughThe repository adds a root Cursor marketplace manifest for the IFTTT plugin, changes the MCP configuration path to ChangesCursor marketplace integration
Priority: ⬇️ Low Estimated code review effort: 3 (Moderate) | ~25 minutes Change: Feature 🚥 Pre-merge checks | ✅ 4✅ Passed checks (4 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
Unblocks Cursor's marketplace review of this repo. [sc-143999]
Why
Cursor's reviewer came back on our resubmission saying the plugin is "missing some metadata we need" to properly ingest it, and pointed at their plugin spec.
Nothing was wrong inside
plugins/ifttt/— the gap is one level up. This repo uses the multi-plugin layout, so the plugin manifest lives atplugins/ifttt/.cursor-plugin/plugin.json. Cursor's ingester looks at the repo root for one of.cursor-plugin/plugin.json,.cursor-plugin/marketplace.json, or an Agent Pluginsplugin.json, and we shipped none of them. Their submission checklist spells out the requirement: "Multi-plugin repos have.cursor-plugin/marketplace.jsonwith unique names."What changed
.cursor-plugin/marketplace.json(new, repo root) — the actual fix. Lists the oneiftttplugin withsource: "plugins/ifttt", owned byIFTTT <channels+cursor@ifttt.com>(the submission account). Field shape mirrors Cursor's own live marketplace manifest and validates against theirmarketplace.schema.json, wheresourceis a marketplace-root-relative directory — nested sources likethird_party/gmailare already ingested in their repo today.plugins/ifttt/.mcp.json→plugins/ifttt/mcp.json— every official Cursor plugin uses this filename, and it's both the documented auto-discovery path and what the Agent Plugins standard expects; no dot-prefixed variant exists anywhere incursor/plugins. Contents unchanged (type: http,https://ifttt.com/mcp); the manifest now points at./mcp.json. All prose references updated across the repo.scripts/validate.mjs— new marketplace checks so this can't regress: the root manifest must exist and parse; each entry needs a unique kebab-casenamematching the targetplugin.jsonname; eachsourcemust resolve to a directory containing.cursor-plugin/plugin.json; and noplugins/<name>/directory may go unlisted. Also added an allow-list of Cursor's schema fields that errors on unknown top-level keys, since both of their schemas areadditionalProperties: false..github/workflows/validate.yml— JSON-parse glob covers the new paths.README.md,AGENTS.md,CONTRIBUTING.md,llms.txt, the plugin README, the setup skill, and the lifecycle rule.Notes for review
category,tags, anddisplayName;plugin.schema.jsonallows all three and all 83 official manifests use them. Our existing manifest fields were already correct, soplugin.jsonchanges by one line.plugin.json. The reviewer offered it as an alternative, but that format loads only skills + MCP servers — it would droprules/ifttt-lifecycle.mdc— Cursor documents no precedence when both manifests exist, and onemcp.jsoncan't satisfy both schemas (Agent Plugins requirestype: "streamable-http"plus a$schema; all 65 ingested Cursor configs usetype: "http"). The Cursor-format path answers the request on its own and is the well-trodden one.Verification
node scripts/validate.mjspasses. Both manifests were also checked withajvagainst the real schemas pulled fromcursor/plugins, and the new guards were confirmed to fail as intended on a scratch copy (missing manifest, unknown field, name mismatch, badsource, duplicate names, unlisted plugin dir,..traversal).Follow-up after merge
Cursor ingests from the default branch, so once this is on
mainwe reply on the existing review thread asking them to re-ingest, rather than filing a fresh submission.🤖 Generated with Claude Code
Summary by CodeRabbit
New Features
Documentation
Validation