Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions .cursor-plugin/marketplace.json
Original file line number Diff line number Diff line change
@@ -1,18 +1,18 @@
{
"name": "graphify",
"owner": {
"name": "Graphify",
"name": "Graphify Labs",
"email": "founders@graphify.com"
},
"metadata": {
"description": "Ground your coding agent in your codebase's knowledge graph.",
"version": "0.1.0"
"version": "0.1.1"
},
"plugins": [
{
"name": "graphify",
"source": "./plugins/graphify",
"description": "Query your codebase's knowledge graph over MCP: entities, relationships, grounded paths, and the conventions a module actually follows."
"description": "Search indexed code, trace dependencies, assess change impact, and retrieve repository memory through Graphify's authenticated MCP server."
}
]
}
20 changes: 20 additions & 0 deletions .github/workflows/validate.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
name: Validate plugin

on:
pull_request:
push:
branches: [main]
workflow_dispatch:

permissions:
contents: read

jobs:
validate:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: '22'
- run: node scripts/validate-template.mjs
33 changes: 20 additions & 13 deletions README.md
Original file line number Diff line number Diff line change
@@ -1,24 +1,31 @@
# Graphify Cursor plugin

The official [Graphify](https://graphify.com) plugin for the Cursor Marketplace.
The official [Graphify](https://graphify.com) plugin source for Cursor. It connects
Cursor to Graphify's authenticated MCP server and supplies a rule for using
indexed code and repository memory with appropriate scope and citations.

Graphify indexes your repositories into a knowledge graph of entities and relationships.
This plugin points your coding agent at the Graphify MCP server so it can query that
graph directly instead of inferring structure from whatever files are open.

## Plugins in this repo

| Plugin | Description |
| Plugin | Contents |
| --- | --- |
| [`graphify`](./plugins/graphify) | Query your codebase's knowledge graph over MCP: entities, relationships, grounded paths, and module conventions. |
| [`graphify`](./plugins/graphify) | Remote MCP connection and a code investigation rule |

## Develop
See the [plugin guide](./plugins/graphify/README.md) for setup, available tools,
data handling, limitations, and troubleshooting. A Graphify account with an
indexed repository is required. Marketplace availability depends on Cursor's
review; local testing and manual MCP configuration are available now.

Validate before submitting:
## Validate and publish

Run from the repository root with Node.js 22 or later:

```bash
node scripts/validate-template.mjs
```

See each plugin's own README for setup and the tool surface. Publishing is handled
through the [Cursor Marketplace](https://cursor.com) publisher application.
CI runs the same package checks. The [submission guide](./docs/cursor-submission.md)
contains the local smoke test, prepared listing copy, evidence, and the remaining
publisher steps. Submit the public repository through the
[Cursor publisher application](https://cursor.com/marketplace/publish).

The plugin package is [MIT licensed](./LICENSE). Use of the hosted Graphify service
is governed by its [terms](https://graphify.com/terms) and
[privacy policy](https://graphify.com/privacy).
146 changes: 146 additions & 0 deletions docs/cursor-submission.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,146 @@
# Cursor marketplace submission

Prepared on 2026-09-30 for Graphify 0.1.1. This is submission preparation, not a
claim of approval or an existing public listing.

## Current status

- Public repository and MIT license: present.
- Native Cursor manifest, committed logo, remote MCP configuration, and rule:
present; the nested package is listed in the root marketplace manifest.
- Plugin instructions now use the server's real tool names and disclose memory
writes, optional trail capture, workspace changes, and indexed-data limitations.
- Metadata, local configuration, and component checks pass locally. CI runs
`node scripts/validate-template.mjs` on pull requests and pushes to `main`.
- Live unauthenticated checks on 2026-09-30: `GET /mcp` returned 401 with a
`WWW-Authenticate` link to protected-resource metadata; both discovery documents
returned 200. Metadata advertises dynamic client registration, authorization
code and refresh-token grants, and PKCE S256.
- Backend source already allows Cursor's desktop loopback, native URI scheme, and
documented web callback. No backend patch was needed for these checks.
- **Still required:** local Cursor loading and an authenticated end-to-end smoke
test. The desktop controller became unavailable before discovery could be
verified; the public HTTP checks do not prove tool calls or OAuth completion.
- **Still required:** publisher sign-in and submission. The application page
displayed "Sign in to apply"; account-specific fields, existing applications,
publisher verification, and any additional requirements were not visible.

## Prepared listing copy

Use this copy in the corresponding fields the signed-in application presents.
Field names and additional requirements may differ.

| Item | Value |
| --- | --- |
| Plugin name / identifier | Graphify / `graphify` |
| Publisher | Graphify Labs |
| Public repository | https://github.com/Graphify-Labs/graphify-cursor-plugin |
| Default branch | `main` (merge the preparation PR before submission) |
| Package directory | `plugins/graphify` |
| Marketplace manifest | `.cursor-plugin/marketplace.json` |
| Plugin manifest | `plugins/graphify/.cursor-plugin/plugin.json` |
| Version | `0.1.1` |
| Website | https://graphify.com |
| Support | founders@graphify.com |
| Issue tracker | https://github.com/Graphify-Labs/graphify-cursor-plugin/issues |
| Privacy policy | https://graphify.com/privacy |
| Terms | https://graphify.com/terms |
| Source license | MIT |
| Logo | `plugins/graphify/assets/logo.png` |
| MCP endpoint | `https://api.graphify.com/mcp` |
| Authentication | Browser-based OAuth with dynamic registration and PKCE; no bundled API key |
| Suggested category | Developer tools / code intelligence, if offered |

**Short description**

Search indexed code, trace dependencies, assess change impact, and retrieve
repository memory through Graphify's authenticated MCP server.

**Long description**

Graphify connects Cursor to a knowledge graph of your indexed repositories.
Find symbols and callers, trace dependency paths, explore potential change impact,
locate linked tests, and retrieve saved repository decisions with source context.
The included rule guides repository selection, evidence-based answers, and checks
against local files before edits.

A Graphify account and an indexed repository are required. Sign in through OAuth
and choose an authorized workspace and repository. Results reflect the indexed
snapshot; graph analysis does not run tests or prove runtime behavior. Some tools
persist repository memory, optional query trails, or workspace preferences, as
described in their live schemas and the plugin README.

**Release notes**

Updated the plugin for the current Graphify MCP tools. Added workspace-selection
guidance, accurate persistence disclosures, installation and troubleshooting
instructions, publisher links, and automated package validation.

## Local smoke test

Use an account with a small, indexed repository containing no sensitive reviewer
data. Keep Cursor's normal approval prompts enabled. Run from this repository's
root on macOS/Linux:

```bash
node scripts/validate-template.mjs
plugin_dest="$HOME/.cursor/plugins/local/graphify"
if [ -e "$plugin_dest" ] || [ -L "$plugin_dest" ]; then
echo "Existing local Graphify plugin found; inspect it before replacing it."
else
mkdir -p "$HOME/.cursor/plugins/local"
cp -R plugins/graphify "$plugin_dest"
fi
```

Copy the actual package, including its hidden `.cursor-plugin` directory. Do not
symlink to a directory outside the plugin folder. Reload Cursor, then inspect
Customize for the Graphify rule and MCP server. An installed marketplace version
with the same name may take precedence; managed accounts may restrict local imports.

Record the Cursor version, tested commit, workspace/repository used privately,
and pass/fail results:

| Check | Steps and expected result |
| --- | --- |
| Package loading | Reload Cursor; Graphify's rule and MCP connection appear without parse errors. |
| OAuth | Connect Graphify from MCP settings; complete sign-in and return to Cursor; tools become available. |
| Repository scope | Ask "List my Graphify workspaces and indexed repositories." Confirm only authorized scope is returned and choose the intended repository. |
| Code evidence | Ask "Using Graphify, locate a known symbol in this repository and cite its file." Check the answer against an actual indexed file. |
| Dependencies | Ask for callers or a path between two known connected symbols. Confirm the returned direction and evidence. |
| Limitations | Ask for a deliberately nonexistent symbol. The agent reports missing evidence without inventing a result. |
| Memory and approvals | Read existing repository memory. Only test `remember` if intentionally saving a test note; verify the returned save/review status. Do not change workspace unless intended. |

Do not claim these authenticated tests passed until they have been performed.
Keep private repository IDs, query results, tokens, and reviewer credentials out
of public issues, screenshots, and this repository.

## Final publisher steps

1. Merge the preparation PR after reviewing its changes and CI result.
2. Complete the local smoke test above, fixing any authentication or discovery
issue before submitting.
3. Sign in at [Cursor's publisher application](https://cursor.com/marketplace/publish).
Confirm whether Graphify already has an application before creating another.
Submit this public repository URL and use the listing copy above where relevant.
The root marketplace manifest identifies the nested plugin package.
4. Complete any publisher verification, terms, or reviewer access requests shown
in the portal. If a demo or test account is requested, provide it through
Cursor's private review channel; do not commit credentials. A short recording
of connection, repository selection, and one cited answer is useful preparation,
but was not confirmed as a mandatory form field.
5. Retain the submission reference and track review in the publisher account.
Public availability depends on Cursor review; pushing or merging alone does
not publish a listing.

## Sources

- [Cursor plugin reference](https://cursor.com/docs/reference/plugins): manifests,
component paths, multi-plugin repositories, and submission checklist.
- [Cursor plugin setup](https://cursor.com/docs/plugins): local loading and installation.
- [Cursor MCP documentation](https://cursor.com/docs/mcp): remote HTTP and OAuth.
- [Cursor marketplace security](https://cursor.com/help/security-and-privacy/marketplace-security):
public source, licensing, and review.
- [Graphify protected-resource metadata](https://api.graphify.com/.well-known/oauth-protected-resource)
and [authorization-server metadata](https://api.graphify.com/.well-known/oauth-authorization-server):
public discovery checks.
8 changes: 5 additions & 3 deletions plugins/graphify/.cursor-plugin/plugin.json
Original file line number Diff line number Diff line change
@@ -1,12 +1,14 @@
{
"name": "graphify",
"displayName": "Graphify",
"version": "0.1.0",
"description": "Ground your coding agent in your codebase's knowledge graph. Query entities and relationships, trace grounded paths, and read the conventions a module actually follows, all over MCP.",
"version": "0.1.1",
"description": "Search indexed code, trace dependencies, assess change impact, and retrieve repository memory through Graphify's authenticated MCP server.",
"author": {
"name": "Graphify",
"name": "Graphify Labs",
"email": "founders@graphify.com"
},
"homepage": "https://graphify.com",
"repository": "https://github.com/Graphify-Labs/graphify-cursor-plugin",
"license": "MIT",
"keywords": [
"graphify",
Expand Down
126 changes: 86 additions & 40 deletions plugins/graphify/README.md
Original file line number Diff line number Diff line change
@@ -1,43 +1,76 @@
# Graphify for Cursor

Ground your coding agent in your codebase's knowledge graph.
Search indexed code, trace dependencies, assess change impact, and retrieve
repository memory through Graphify's authenticated MCP server.

Graphify indexes your repositories into a graph of entities and relationships. This
plugin points Cursor at the Graphify MCP server so the agent can query that graph
directly: find how things connect, trace grounded paths, and read the conventions a
module actually follows, instead of inferring from whatever files happen to be open.

## What it adds

- **MCP server** at `https://api.graphify.com/mcp` (Streamable HTTP).
- **A rule** that tells the agent when to reach for the graph.

## Tools (all read-only)

| Tool | What it does |
| --- | --- |
| `query_graph` | Search entities and relationships across the indexed graph. |
| `get_node` | Fetch one node with its edges, file span, and confidence tags. |
| `path` | Trace the grounded path between two entities. |
| `explain_style` | Summarize the conventions a module actually follows. |

Nothing on this list can modify code, the graph, or your account.
The package includes a remote MCP connection at `https://api.graphify.com/mcp`
(Streamable HTTP) and a rule for investigating code. It has no local executable,
install script, hook, bundled credential, or runtime dependency to install.

## Setup

1. Install the plugin from the Cursor Marketplace.
2. On first use, Cursor runs a one-time sign-in (OAuth 2.1 via Auth0). There is no
API key to paste and nothing to configure.
3. Ask the agent about your codebase. It will call the Graphify tools when a question
is about structure, dependencies, or conventions.

You need a Graphify account with at least one indexed repository. Sign up and connect
a repo at [graphify.com](https://graphify.com).

## Manual configuration

If you prefer to wire the server yourself instead of installing the plugin, add this
to `~/.cursor/mcp.json` (global) or `.cursor/mcp.json` (per repo):
1. Sign in to [Graphify](https://app.graphify.com), connect a repository you are
authorized to use, and wait for indexing to complete.
2. Install Graphify from Cursor's marketplace once its listing is approved.
Before approval, use the [local test guide](../../docs/cursor-submission.md#local-smoke-test)
or the manual MCP configuration below.
3. Open Cursor's MCP settings and use the Graphify server's sign-in/connect
action. Complete the Graphify OAuth flow in your browser and return to Cursor.
No API key or client secret is included in this plugin; reauthentication may
be required when a session expires or access changes.
4. Ask Cursor to list your Graphify workspaces and repositories, then identify
the repository to investigate. If it needs to change workspace, confirm the
choice: `set_workspace` also changes your account's default workspace.

For example: "Using Graphify, find where authentication is implemented in
`my-repository` and cite the relevant files." Other useful requests are "Trace
the callers of this symbol" and "Which linked tests should I inspect before
changing this function?" Use real repository and symbol names from your index.

## Main tools

The connected server supplies the authoritative schemas, descriptions, and
approval annotations. Availability can vary with server configuration and access.

| Tools | Purpose |
| --- | --- |
| `list_workspaces`, `list_repositories` | Discover accessible scope and repository IDs. |
| `set_workspace` | Select the active workspace and update the account's default workspace. |
| `query_graph`, `graphify_find`, `graphify_node` | Search indexed code and inspect symbols. |
| `graphify_callers`, `graphify_callees`, `graphify_trace` | Investigate directed call relationships. |
| `shortest_path` | Find a connecting graph path, which need not be a directed call chain. |
| `graphify_impact`, `impact_and_risk`, `graphify_tests_for` | Explore potential change impact and linked tests. These do not execute tests. |
| `recall`, `memories_about` | Retrieve saved repository context. |
| `remember` | Save durable repository memory; the result may require review. |

## Data handling and limitations

Tool arguments are sent to Graphify's hosted service under your authenticated
workspace permissions, and returned code context becomes available to the Cursor
agent. Do not put secrets or unrelated private information in queries.

The MCP tools do not edit source files. They are **not all read-only**:
`remember` persists memory and `set_workspace` changes account scope. When trail
capture is enabled for a workspace, `query_graph`, `graphify_trace`,
`graphify_find`, and `graphify_rank_files` may save query/search context as
repository memory; `recall` may record an unanswered memory query. Follow the
live tool annotations and Cursor's approval prompts.

Results describe an indexed snapshot, not necessarily the current branch or
uncommitted edits. Inspect local code before changing it. Static graph analysis
does not prove runtime behavior, security, or exhaustive test coverage. Saved
memories may contain historical or unverified statements.

See Graphify's [privacy policy](https://graphify.com/privacy) for processing,
retention, and subprocessors, and its [terms](https://graphify.com/terms) for
service conditions. Plugin source licensing does not confer hosted service access.

## Manual MCP configuration

As an alternative to the plugin, merge this server entry into `~/.cursor/mcp.json`
(global) or `.cursor/mcp.json` (project). Preserve existing entries. This connects
the MCP server but does not install the plugin's rule. Avoid configuring the same
server both manually and through the plugin.

```json
{
Expand All @@ -49,9 +82,22 @@ to `~/.cursor/mcp.json` (global) or `.cursor/mcp.json` (per repo):
}
```

Cursor shows "Needs login" until you finish the one-time sign-in.

## Links

- Website: https://graphify.com
- Connect other agents (Claude Code, Codex, VS Code, and more): your Graphify dashboard, Integrations tab
## Troubleshooting

- **Needs login / unauthorized:** complete or renew the Graphify OAuth sign-in
from Cursor's MCP settings. Do not paste tokens into the repository.
- **No repository or empty results:** verify the selected workspace, repository
permissions, and completed indexing in Graphify. Use `list_repositories` to
obtain the current ID instead of guessing one.
- **Stale answers:** compare the indexed snapshot with the branch and local files
being edited; reindex through Graphify as needed.
- **Duplicate servers:** keep one Graphify connection. A local plugin, marketplace
install, and manual MCP entry can otherwise overlap.
- **Local plugin missing:** copy the plugin directory with its hidden manifest,
reload Cursor, and check Customize. Managed accounts may restrict local imports.

## Support

- [Graphify website](https://graphify.com) · [Documentation](https://docs.graphify.com)
- [Plugin issues](https://github.com/Graphify-Labs/graphify-cursor-plugin/issues)
- [Contact Graphify](https://graphify.com/contact) · [founders@graphify.com](mailto:founders@graphify.com)
Loading
Loading