Skip to content

Prepare Graphify Cursor plugin for marketplace review - #1

Merged
raihankhan-rk merged 1 commit into
mainfrom
codex/cursor-marketplace-readiness
Sep 30, 2026
Merged

raihankhan-rk merged 1 commit into
mainfrom
codex/cursor-marketplace-readiness

Conversation

@raihankhan-rk

Copy link
Copy Markdown
Collaborator

The plugin currently directs Cursor to obsolete tool names (get_node, path, and explain_style) and incorrectly describes the entire MCP server as read-only. Version 0.1.1 aligns the rule and documentation with the current tool surface, including repository selection, memory persistence, optional trail capture, workspace changes, and indexed-snapshot limitations.

Adds publisher metadata, setup/troubleshooting and privacy/support links, prepared listing copy, and a local review checklist. Package validation now rejects invalid component paths, malformed or missing MCP configuration, embedded credentials, unexpected endpoints, and manifest connection overrides; CI runs validation on PRs and main.

Validation:

  • Package validation and syntax/whitespace checks passed with Node 22.17.0.
  • Eleven temporary-fixture checks passed (valid package plus invalid configuration/path cases).
  • Documented tool names were checked against query-service/backend source; relative documentation links resolve.
  • Production MCP returns the expected 401 authentication challenge; OAuth discovery returns 200 and advertises dynamic registration and PKCE S256. Backend source already permits Cursor callbacks.

Before marketplace submission: complete local Cursor discovery and an authenticated smoke test, then sign into the publisher application and submit the public repository after merging. The desktop controller became unavailable before loading could be verified, and the publisher form was behind sign-in. Neither authenticated operation nor marketplace approval is claimed. Full handoff: docs/cursor-submission.md.

@graphify-labs graphify-labs Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).

Formal verification. 1 change(s) tested, no difference found (not proven).


Graphify review — findings

Prepares Graphify 0.1.1 for Cursor Marketplace submission by bumping the version, crediting "Graphify Labs" as owner, and rewriting the listing description around the real MCP capabilities (code search, dependency tracing, change impact, repository memory). Adds a CI workflow that runs node scripts/validate-template.mjs on PRs and pushes to main, checking manifests, frontmatter, and referenced paths so a broken package fails before submission. Adds docs/cursor-submission.md with prepared listing copy, a local smoke-test procedure, and the remaining publisher steps; it records that authenticated end-to-end testing and publisher sign-in are still outstanding.

No blocking issues surfaced. 4 lower-confidence candidates did not survive cross-model review.

Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 39 functions depend on the 39 functions this change touches.

Health — this change adds coupling hotspots:

  • new: main() — 1 callers, 10 callees

Verification — 39 functions in the blast radius were not formally verified this run (proofs are advisory here).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 39 function(s) in the blast radius were not formally verified this run

Test selection

Test selection

0 test file(s) selected via static blast radius.

Escalated to a full run for safety — the selection is not trustworthy on its own (see below). CI should run the whole suite.

non-code file(s) changed (.cursor-plugin/marketplace.json, .github/workflows/validate.yml, README.md, docs/cursor-submission.md, plugins/graphify/.cursor-plugin/plugin.json …) → running the full suite for safety (a code graph can't see config/fixture/data deps)

changed code file(s) with no mapped test (.github/workflows/validate.yml, README.md, docs/cursor-submission.md, plugins/graphify/README.md, scripts/validate-template.mjs) — a coverage gap or a missing link — running the full suite rather than only the selected tests

Selection is safe under the controlled-regression assumption; always-run tests + a periodic full run are the backstops. Advisory — it never changes the check verdict.

Formal verification

No difference found (not proven): No behavior difference found in isSafeRelativePath (not a proof).

The verifier ran both versions of isSafeRelativePath on many inputs and saw identical behavior every time. Strong evidence the change is safe, but evidence, not a proof.

Guarantee: Empirical: the property-js tier. A divergence on an untested input remains possible, so this is 'no counterexample found', not 'proven equivalent'.

Note: An input the sampler did not try could still differ.

Could not verify: Could not verify main.

The verifier did not have enough to check main, so it is saying so rather than guessing. No false assurance is the whole point.

Guarantee: No guarantee either way, this is an honest abstention, not a pass.

Note: Reason: not verifiable: all 1 sampled inputs raised on both versions — the function never executed, so 'no divergence' would be vacuous

Could not verify: Could not verify readJsonFile.

The verifier did not have enough to check readJsonFile, so it is saying so rather than guessing. No false assurance is the whole point.

Guarantee: No guarantee either way, this is an honest abstention, not a pass.

Note: Reason: not verifiable: all 23 sampled inputs raised on both versions — the function never executed, so 'no divergence' would be vacuous

Could not verify: Could not verify summarizeAndExit.

The verifier did not have enough to check summarizeAndExit, so it is saying so rather than guessing. No false assurance is the whole point.

Guarantee: No guarantee either way, this is an honest abstention, not a pass.

Note: Reason: not verifiable: all 1 sampled inputs raised on both versions — the function never executed, so 'no divergence' would be vacuous

Could not verify: Could not verify validateReferencedPath.

The verifier did not have enough to check validateReferencedPath, so it is saying so rather than guessing. No false assurance is the whole point.

Guarantee: No guarantee either way, this is an honest abstention, not a pass.

Note: Reason: not verifiable: all 23 sampled inputs raised on both versions — the function never executed, so 'no divergence' would be vacuous

· 1 more finding(s) on lines outside this diff (see the check run).

@safishamsi safishamsi left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — marketplace metadata, docs and validation workflow look good.

@raihankhan-rk
raihankhan-rk merged commit fe567e0 into main Sep 30, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants