Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .cursor-plugin/marketplace.json
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@
},
"metadata": {
"description": "Ground your coding agent in your codebase's knowledge graph.",
"version": "0.1.1"
"version": "0.1.2"
},
"plugins": [
{
Expand Down
39 changes: 26 additions & 13 deletions docs/cursor-submission.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# Cursor marketplace submission

Prepared on 2026-09-30 for Graphify 0.1.1. This is submission preparation, not a
Prepared on 2026-09-30 for Graphify 0.1.2. This is submission preparation, not a
claim of approval or an existing public listing.

## Current status
Expand All @@ -18,9 +18,19 @@ claim of approval or an existing public listing.
code and refresh-token grants, and PKCE S256.
- Backend source already allows Cursor's desktop loopback, native URI scheme, and
documented web callback. No backend patch was needed for these checks.
- **Still required:** local Cursor loading and an authenticated end-to-end smoke
test. The desktop controller became unavailable before discovery could be
verified; the public HTTP checks do not prove tool calls or OAuth completion.
- Local smoke testing completed on 2026-09-30 in Cursor 3.21.18 against plugin
0.1.1, commit `fe567e0`: the plugin loaded with one rule and one MCP server,
24 tools became available, workspace/repository discovery succeeded, and a
known function resolved exactly to a file/line verified against public source.
Version 0.1.2 adds guidance about the observed lookup limitations; its MCP
connection configuration is identical. The revised guidance was statically
reviewed and package-validated, not separately tested in an agent conversation.
- Missing-symbol behavior: `graphify_node` returned a different symbol marked
`resolved: semantic`. The agent correctly reported the substitution. The rule
and README now explicitly require treating such results as suggestions.
- Remaining test coverage: caller queries succeeded with empty lists; a nonempty
call path, memory writes, fresh OAuth consent, and token refresh were not
separately demonstrated. These results do not establish exhaustive graph coverage.
- **Still required:** publisher sign-in and submission. The application page
displayed "Sign in to apply"; account-specific fields, existing applications,
publisher verification, and any additional requirements were not visible.
Expand All @@ -39,7 +49,7 @@ Field names and additional requirements may differ.
| Package directory | `plugins/graphify` |
| Marketplace manifest | `.cursor-plugin/marketplace.json` |
| Plugin manifest | `plugins/graphify/.cursor-plugin/plugin.json` |
| Version | `0.1.1` |
| Version | `0.1.2` |
| Website | https://graphify.com |
| Support | founders@graphify.com |
| Issue tracker | https://github.com/Graphify-Labs/graphify-cursor-plugin/issues |
Expand Down Expand Up @@ -68,13 +78,16 @@ A Graphify account and an indexed repository are required. Sign in through OAuth
and choose an authorized workspace and repository. Results reflect the indexed
snapshot; graph analysis does not run tests or prove runtime behavior. Some tools
persist repository memory, optional query trails, or workspace preferences, as
described in their live schemas and the plugin README.
described in their live schemas and the plugin README. Symbol lookup may return
a labelled semantic suggestion when no exact match is available; verify the
returned symbol and file before relying on it.

**Release notes**

Updated the plugin for the current Graphify MCP tools. Added workspace-selection
guidance, accurate persistence disclosures, installation and troubleshooting
instructions, publisher links, and automated package validation.
Updated the bundled Graphify logo. Clarified semantic symbol suggestions and empty
caller results in the agent rule and usage guide. Recorded successful local loading,
authenticated discovery, and exact code lookup, with the remaining test coverage
stated explicitly.

## Local smoke test

Expand Down Expand Up @@ -108,7 +121,7 @@ and pass/fail results:
| Repository scope | Ask "List my Graphify workspaces and indexed repositories." Confirm only authorized scope is returned and choose the intended repository. |
| Code evidence | Ask "Using Graphify, locate a known symbol in this repository and cite its file." Check the answer against an actual indexed file. |
| Dependencies | Ask for callers or a path between two known connected symbols. Confirm the returned direction and evidence. |
| Limitations | Ask for a deliberately nonexistent symbol. The agent reports missing evidence without inventing a result. |
| Limitations | Ask for a deliberately nonexistent symbol. Inspect `resolved` and the returned symbol/file. A semantic fallback must be disclosed as a suggestion, not presented as proof that the requested exact symbol exists. |
| Memory and approvals | Read existing repository memory. Only test `remember` if intentionally saving a test note; verify the returned save/review status. Do not change workspace unless intended. |

Do not claim these authenticated tests passed until they have been performed.
Expand All @@ -117,9 +130,9 @@ of public issues, screenshots, and this repository.

## Final publisher steps

1. Merge the preparation PR after reviewing its changes and CI result.
2. Complete the local smoke test above, fixing any authentication or discovery
issue before submitting.
1. Merge the 0.1.2 guidance update after reviewing its changes and CI result.
2. Review the recorded smoke-test results and coverage above. Rerun applicable
checks if the connection configuration or server behavior changes.
3. Sign in at [Cursor's publisher application](https://cursor.com/marketplace/publish).
Confirm whether Graphify already has an application before creating another.
Submit this public repository URL and use the listing copy above where relevant.
Expand Down
2 changes: 1 addition & 1 deletion plugins/graphify/.cursor-plugin/plugin.json
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"name": "graphify",
"displayName": "Graphify",
"version": "0.1.1",
"version": "0.1.2",
"description": "Search indexed code, trace dependencies, assess change impact, and retrieve repository memory through Graphify's authenticated MCP server.",
"author": {
"name": "Graphify Labs",
Expand Down
6 changes: 6 additions & 0 deletions plugins/graphify/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -61,6 +61,12 @@ uncommitted edits. Inspect local code before changing it. Static graph analysis
does not prove runtime behavior, security, or exhaustive test coverage. Saved
memories may contain historical or unverified statements.

Symbol lookup can use semantic fallback. If `graphify_node` cannot resolve an
exact match, it may return a different symbol with `resolved: semantic`, including
for a nonexistent name. Treat it as a suggestion and verify the returned symbol
and file before relying on it. An empty caller list means no matching indexed
callers were returned; it is not proof that a function is unused.

See Graphify's [privacy policy](https://graphify.com/privacy) for processing,
retention, and subprocessors, and its [terms](https://graphify.com/terms) for
service conditions. Plugin source licensing does not confer hosted service access.
Expand Down
Binary file modified plugins/graphify/assets/logo.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
7 changes: 7 additions & 0 deletions plugins/graphify/rules/graphify.mdc
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,13 @@ server's current tool schemas and follow their required inputs and annotations.
`graphify_node` to inspect one. Use `graphify_callers`, `graphify_callees`, or
`graphify_trace` for directed call relationships; use `shortest_path` for a
connection that need not be a directed call chain.
- Check the returned symbol, file, and `resolved` value before citing a lookup.
`graphify_node` can return `resolved: semantic` and a different symbol when no
exact match exists. Treat that result as a suggestion: say the requested exact
symbol was not resolved, disclose the substituted symbol, and verify it before
answering or editing. A successful tool call alone does not establish a match.
An empty caller list means no matching callers were returned from the index;
it does not prove that the symbol is unused.
- Use `graphify_impact` or `impact_and_risk` for graph-based change analysis and
`graphify_tests_for` to locate linked tests. These do not run tests or prove
runtime behavior or complete test coverage.
Expand Down
Loading