diff --git a/.cursor-plugin/marketplace.json b/.cursor-plugin/marketplace.json index bc8e9af..af52b7f 100644 --- a/.cursor-plugin/marketplace.json +++ b/.cursor-plugin/marketplace.json @@ -6,7 +6,7 @@ }, "metadata": { "description": "Ground your coding agent in your codebase's knowledge graph.", - "version": "0.1.1" + "version": "0.1.2" }, "plugins": [ { diff --git a/docs/cursor-submission.md b/docs/cursor-submission.md index fee7962..3578b47 100644 --- a/docs/cursor-submission.md +++ b/docs/cursor-submission.md @@ -1,6 +1,6 @@ # Cursor marketplace submission -Prepared on 2026-09-30 for Graphify 0.1.1. This is submission preparation, not a +Prepared on 2026-09-30 for Graphify 0.1.2. This is submission preparation, not a claim of approval or an existing public listing. ## Current status @@ -18,9 +18,19 @@ claim of approval or an existing public listing. code and refresh-token grants, and PKCE S256. - Backend source already allows Cursor's desktop loopback, native URI scheme, and documented web callback. No backend patch was needed for these checks. -- **Still required:** local Cursor loading and an authenticated end-to-end smoke - test. The desktop controller became unavailable before discovery could be - verified; the public HTTP checks do not prove tool calls or OAuth completion. +- Local smoke testing completed on 2026-09-30 in Cursor 3.21.18 against plugin + 0.1.1, commit `fe567e0`: the plugin loaded with one rule and one MCP server, + 24 tools became available, workspace/repository discovery succeeded, and a + known function resolved exactly to a file/line verified against public source. + Version 0.1.2 adds guidance about the observed lookup limitations; its MCP + connection configuration is identical. The revised guidance was statically + reviewed and package-validated, not separately tested in an agent conversation. +- Missing-symbol behavior: `graphify_node` returned a different symbol marked + `resolved: semantic`. The agent correctly reported the substitution. The rule + and README now explicitly require treating such results as suggestions. +- Remaining test coverage: caller queries succeeded with empty lists; a nonempty + call path, memory writes, fresh OAuth consent, and token refresh were not + separately demonstrated. These results do not establish exhaustive graph coverage. - **Still required:** publisher sign-in and submission. The application page displayed "Sign in to apply"; account-specific fields, existing applications, publisher verification, and any additional requirements were not visible. @@ -39,7 +49,7 @@ Field names and additional requirements may differ. | Package directory | `plugins/graphify` | | Marketplace manifest | `.cursor-plugin/marketplace.json` | | Plugin manifest | `plugins/graphify/.cursor-plugin/plugin.json` | -| Version | `0.1.1` | +| Version | `0.1.2` | | Website | https://graphify.com | | Support | founders@graphify.com | | Issue tracker | https://github.com/Graphify-Labs/graphify-cursor-plugin/issues | @@ -68,13 +78,16 @@ A Graphify account and an indexed repository are required. Sign in through OAuth and choose an authorized workspace and repository. Results reflect the indexed snapshot; graph analysis does not run tests or prove runtime behavior. Some tools persist repository memory, optional query trails, or workspace preferences, as -described in their live schemas and the plugin README. +described in their live schemas and the plugin README. Symbol lookup may return +a labelled semantic suggestion when no exact match is available; verify the +returned symbol and file before relying on it. **Release notes** -Updated the plugin for the current Graphify MCP tools. Added workspace-selection -guidance, accurate persistence disclosures, installation and troubleshooting -instructions, publisher links, and automated package validation. +Updated the bundled Graphify logo. Clarified semantic symbol suggestions and empty +caller results in the agent rule and usage guide. Recorded successful local loading, +authenticated discovery, and exact code lookup, with the remaining test coverage +stated explicitly. ## Local smoke test @@ -108,7 +121,7 @@ and pass/fail results: | Repository scope | Ask "List my Graphify workspaces and indexed repositories." Confirm only authorized scope is returned and choose the intended repository. | | Code evidence | Ask "Using Graphify, locate a known symbol in this repository and cite its file." Check the answer against an actual indexed file. | | Dependencies | Ask for callers or a path between two known connected symbols. Confirm the returned direction and evidence. | -| Limitations | Ask for a deliberately nonexistent symbol. The agent reports missing evidence without inventing a result. | +| Limitations | Ask for a deliberately nonexistent symbol. Inspect `resolved` and the returned symbol/file. A semantic fallback must be disclosed as a suggestion, not presented as proof that the requested exact symbol exists. | | Memory and approvals | Read existing repository memory. Only test `remember` if intentionally saving a test note; verify the returned save/review status. Do not change workspace unless intended. | Do not claim these authenticated tests passed until they have been performed. @@ -117,9 +130,9 @@ of public issues, screenshots, and this repository. ## Final publisher steps -1. Merge the preparation PR after reviewing its changes and CI result. -2. Complete the local smoke test above, fixing any authentication or discovery - issue before submitting. +1. Merge the 0.1.2 guidance update after reviewing its changes and CI result. +2. Review the recorded smoke-test results and coverage above. Rerun applicable + checks if the connection configuration or server behavior changes. 3. Sign in at [Cursor's publisher application](https://cursor.com/marketplace/publish). Confirm whether Graphify already has an application before creating another. Submit this public repository URL and use the listing copy above where relevant. diff --git a/plugins/graphify/.cursor-plugin/plugin.json b/plugins/graphify/.cursor-plugin/plugin.json index e15ae94..dae6cf2 100644 --- a/plugins/graphify/.cursor-plugin/plugin.json +++ b/plugins/graphify/.cursor-plugin/plugin.json @@ -1,7 +1,7 @@ { "name": "graphify", "displayName": "Graphify", - "version": "0.1.1", + "version": "0.1.2", "description": "Search indexed code, trace dependencies, assess change impact, and retrieve repository memory through Graphify's authenticated MCP server.", "author": { "name": "Graphify Labs", diff --git a/plugins/graphify/README.md b/plugins/graphify/README.md index 5b5385f..429d6fc 100644 --- a/plugins/graphify/README.md +++ b/plugins/graphify/README.md @@ -61,6 +61,12 @@ uncommitted edits. Inspect local code before changing it. Static graph analysis does not prove runtime behavior, security, or exhaustive test coverage. Saved memories may contain historical or unverified statements. +Symbol lookup can use semantic fallback. If `graphify_node` cannot resolve an +exact match, it may return a different symbol with `resolved: semantic`, including +for a nonexistent name. Treat it as a suggestion and verify the returned symbol +and file before relying on it. An empty caller list means no matching indexed +callers were returned; it is not proof that a function is unused. + See Graphify's [privacy policy](https://graphify.com/privacy) for processing, retention, and subprocessors, and its [terms](https://graphify.com/terms) for service conditions. Plugin source licensing does not confer hosted service access. diff --git a/plugins/graphify/assets/logo.png b/plugins/graphify/assets/logo.png index abc79e4..19d64ad 100644 Binary files a/plugins/graphify/assets/logo.png and b/plugins/graphify/assets/logo.png differ diff --git a/plugins/graphify/rules/graphify.mdc b/plugins/graphify/rules/graphify.mdc index 3496dad..486d049 100644 --- a/plugins/graphify/rules/graphify.mdc +++ b/plugins/graphify/rules/graphify.mdc @@ -16,6 +16,13 @@ server's current tool schemas and follow their required inputs and annotations. `graphify_node` to inspect one. Use `graphify_callers`, `graphify_callees`, or `graphify_trace` for directed call relationships; use `shortest_path` for a connection that need not be a directed call chain. +- Check the returned symbol, file, and `resolved` value before citing a lookup. + `graphify_node` can return `resolved: semantic` and a different symbol when no + exact match exists. Treat that result as a suggestion: say the requested exact + symbol was not resolved, disclose the substituted symbol, and verify it before + answering or editing. A successful tool call alone does not establish a match. + An empty caller list means no matching callers were returned from the index; + it does not prove that the symbol is unused. - Use `graphify_impact` or `impact_and_risk` for graph-based change analysis and `graphify_tests_for` to locate linked tests. These do not run tests or prove runtime behavior or complete test coverage.