Prepare Graphify Cursor plugin for marketplace review - #1
Conversation
There was a problem hiding this comment.
Graphify reviewed this change.
Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).
Formal verification. 1 change(s) tested, no difference found (not proven).
Graphify review — findings
Prepares Graphify 0.1.1 for Cursor Marketplace submission by bumping the version, crediting "Graphify Labs" as owner, and rewriting the listing description around the real MCP capabilities (code search, dependency tracing, change impact, repository memory). Adds a CI workflow that runs node scripts/validate-template.mjs on PRs and pushes to main, checking manifests, frontmatter, and referenced paths so a broken package fails before submission. Adds docs/cursor-submission.md with prepared listing copy, a local smoke-test procedure, and the remaining publisher steps; it records that authenticated end-to-end testing and publisher sign-in are still outstanding.
No blocking issues surfaced. 4 lower-confidence candidates did not survive cross-model review.
Analysis details — impact, health, verification
Impact & health
Graphify review
Impact — 39 functions depend on the 39 functions this change touches.
Health — this change adds coupling hotspots:
- new:
main()— 1 callers, 10 callees
Verification — 39 functions in the blast radius were not formally verified this run (proofs are advisory here).
Gate & verification
graphify gate
PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.
Advisory (not blocking):
- verification_scope: 39 function(s) in the blast radius were not formally verified this run
Test selection
Test selection
0 test file(s) selected via static blast radius.
Escalated to a full run for safety — the selection is not trustworthy on its own (see below). CI should run the whole suite.
non-code file(s) changed (
.cursor-plugin/marketplace.json,.github/workflows/validate.yml,README.md,docs/cursor-submission.md,plugins/graphify/.cursor-plugin/plugin.json…) → running the full suite for safety (a code graph can't see config/fixture/data deps)
changed code file(s) with no mapped test (
.github/workflows/validate.yml,README.md,docs/cursor-submission.md,plugins/graphify/README.md,scripts/validate-template.mjs) — a coverage gap or a missing link — running the full suite rather than only the selected tests
Selection is safe under the controlled-regression assumption; always-run tests + a periodic full run are the backstops. Advisory — it never changes the check verdict.
Formal verification
No difference found (not proven): No behavior difference found in isSafeRelativePath (not a proof).
The verifier ran both versions of isSafeRelativePath on many inputs and saw identical behavior every time. Strong evidence the change is safe, but evidence, not a proof.
Guarantee: Empirical: the property-js tier. A divergence on an untested input remains possible, so this is 'no counterexample found', not 'proven equivalent'.
Note: An input the sampler did not try could still differ.
Could not verify: Could not verify main.
The verifier did not have enough to check main, so it is saying so rather than guessing. No false assurance is the whole point.
Guarantee: No guarantee either way, this is an honest abstention, not a pass.
Note: Reason: not verifiable: all 1 sampled inputs raised on both versions — the function never executed, so 'no divergence' would be vacuous
Could not verify: Could not verify readJsonFile.
The verifier did not have enough to check readJsonFile, so it is saying so rather than guessing. No false assurance is the whole point.
Guarantee: No guarantee either way, this is an honest abstention, not a pass.
Note: Reason: not verifiable: all 23 sampled inputs raised on both versions — the function never executed, so 'no divergence' would be vacuous
Could not verify: Could not verify summarizeAndExit.
The verifier did not have enough to check summarizeAndExit, so it is saying so rather than guessing. No false assurance is the whole point.
Guarantee: No guarantee either way, this is an honest abstention, not a pass.
Note: Reason: not verifiable: all 1 sampled inputs raised on both versions — the function never executed, so 'no divergence' would be vacuous
Could not verify: Could not verify validateReferencedPath.
The verifier did not have enough to check validateReferencedPath, so it is saying so rather than guessing. No false assurance is the whole point.
Guarantee: No guarantee either way, this is an honest abstention, not a pass.
Note: Reason: not verifiable: all 23 sampled inputs raised on both versions — the function never executed, so 'no divergence' would be vacuous
· 1 more finding(s) on lines outside this diff (see the check run).
safishamsi
left a comment
There was a problem hiding this comment.
LGTM — marketplace metadata, docs and validation workflow look good.
The plugin currently directs Cursor to obsolete tool names (
get_node,path, andexplain_style) and incorrectly describes the entire MCP server as read-only. Version 0.1.1 aligns the rule and documentation with the current tool surface, including repository selection, memory persistence, optional trail capture, workspace changes, and indexed-snapshot limitations.Adds publisher metadata, setup/troubleshooting and privacy/support links, prepared listing copy, and a local review checklist. Package validation now rejects invalid component paths, malformed or missing MCP configuration, embedded credentials, unexpected endpoints, and manifest connection overrides; CI runs validation on PRs and main.
Validation:
Before marketplace submission: complete local Cursor discovery and an authenticated smoke test, then sign into the publisher application and submit the public repository after merging. The desktop controller became unavailable before loading could be verified, and the publisher form was behind sign-in. Neither authenticated operation nor marketplace approval is claimed. Full handoff:
docs/cursor-submission.md.