镜像站点 · 本页由第三方 GitHub 只读镜像提供,非 GitHub 官方站点,不接受任何登录或凭据输入。前往 github.com
Skip to content

validate: parse hooks.json and mcp.json, check skill names against directories, require kebab-case names and semver - #17

Open
deanrie wants to merge 3 commits into
cursor:mainfrom
deanrie:feat/validator-stacked
Open

deanrie wants to merge 3 commits into
cursor:mainfrom
deanrie:feat/validator-stacked

Conversation

@deanrie

@deanrie deanrie commented Oct 9, 2026

Copy link
Copy Markdown

Summary

Stacked on #15 and #16 (their commits are included here; the diff to review is the last commit, scripts/validate-template.mjs only). Merge those two first and this one rebases to the validator change alone.

The validator checked the two manifests, component paths and frontmatter, but not the two files that most often break a plugin in practice. It now also:

  • Parses hooks/hooks.json: valid JSON, version is a positive integer, hooks is an object keyed by known event names (unknown events warn), every definition has a command. For commands that point inside the plugin (${CURSOR_PLUGIN_ROOT}/... or ./...) it checks the script exists, warns when the path is cwd-relative (plugin hooks do not run from the plugin folder; this is what ci: validate the template on every PR; fix hook script paths and permissions; add LICENSE #15 fixed in the starter), and warns when a .sh is not executable and not invoked through bash.
  • Parses mcp.json: valid JSON, non-empty mcpServers, each server has command or url, warns on plain http:// outside localhost and on npx ...@latest, and warns when a ${VAR} placeholder has no matching variables.properties.<VAR> in plugin.json (otherwise users are never prompted for it).
  • Skill name vs directory: warns when SKILL.md name differs from its folder, since slash commands use the folder name.
  • Plugin name and version: name must be kebab-case as the README says (the old pattern allowed .); version warns when not semver.

Run against main before #15/#16 it reports exactly the defects those PRs fix (relative hook paths, non-executable scripts, missing version, undeclared ${POSTGRES_URL}); on this branch it passes with only the two "starter-simple has no hooks/mcp" notes.

Verification

  • node scripts/validate-template.mjs on this branch: Validation passed.
  • Same script against main @ 4621607: 1 error (hooks.json must declare "version"), 7 warnings (3 cwd-relative commands, 3 non-executable scripts, 1 undeclared placeholder), as expected.

…nd address them via CURSOR_PLUGIN_ROOT; add MIT LICENSE
…e/publish; replace the archived postgres MCP example with a pinned maintained server
…rectories, require kebab-case names and semver
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant