Skip to content

Harden loading for every host - #3

Merged
sasdeployer merged 1 commit into
mainfrom
harden/all-host-loading
Sep 8, 2026
Merged

sasdeployer merged 1 commit into
mainfrom
harden/all-host-loading

Conversation

@sasdeployer

@sasdeployer sasdeployer commented Sep 4, 2026 •

Copy link
Copy Markdown
Contributor

Deep pass of every manifest, hook, and MCP file against each host's primary docs, then verified against Claude Code by real install and a --debug session. Full detail is in the commit body.

Found by installing, not by reading

Finding Effect before Fix
Claude Code reads hooks/hooks.json regardless of the manifest pointer; it held Cursor's schema [WARN] hooks.afterFileEdit: unknown hook event on every session start for every user Shared filename now carries the nested schema Claude Code and Codex share; Cursor gets hooks/cursor.json via its manifest (Cursor's docs say the pointer replaces discovery)
commands/ is deprecated in Claude Code and duplicated the skills' slash names Skills (4) with duplicate names "commands": [] in .claude-plugin/plugin.json → Skills (2)
agentSubagents is not a Devin manifest key Undefined Removed; Devin reads agents/ by convention
Manifest paths without ./ Undefined per host Normalised
allowed-tools: Bash(npx:* docker:* git:*) splits into malformed tokens Spec violation Patch 0004
Codex apply_patch puts the edited path inside patch text Hook never found the file on Codex Regex + cwd resolution; Copilot toolArgs too

Verified

  • Claude Code, from the tree: Skills (2) · Agents (1) · Hooks (1) · MCP servers (1); --debug session WARN count 0; hook loads from hooks/hooks.json.
  • streamable-http accepted by Claude Code and normalised to HTTP.
  • Plugin MCP is suppressed on a dev machine only because the same URL is manually configured — the debug log says so explicitly. Not a load failure.
  • All 11 new validator checks fire when each rule is broken (tested on a git archive copy).
  • Hook: all four host payload shapes resolve; exit 0 on garbage.
  • validate.py, gen-host-components.py --check, claude plugin validate --strict pass.

Not verified

Live Cursor / Devin / VS Code / Grok installs; Windows; sync-from-mcp.sh --check against an upstream clone.

🤖 Generated with Claude Code

@sasdeployer
sasdeployer force-pushed the harden/all-host-loading branch 2 times, most recently from fadfa18 to fe3d664 Compare September 5, 2026 16:45
Deep pass of every manifest, hook, and MCP file against each host's primary
documentation (Claude Code plugins reference, Cursor plugins + hooks reference,
Codex/OpenAI plugins + hooks, Agent Plugins 1.0, Agent Skills spec, Devin CLI
plugins, VS Code agent plugins, Copilot CLI plugin + hooks), then verified
against Claude Code by real install and a --debug session.

Behavior (found by installing, not by reading):
- hooks/hooks.json carried Cursor's flat schema at the default filename. Claude
  Code reads that file regardless of the manifest pointer and emitted
  `[WARN] hooks.afterFileEdit: unknown hook event` on every session start for
  every user. Codex defaults to the same file with the same nested schema
  Claude Code uses. The shared filename now carries the nested schema
  (PostToolUse, matcher Write|Edit|MultiEdit|NotebookEdit|apply_patch,
  ${CLAUDE_PLUGIN_ROOT}); Cursor — the one host whose docs say the manifest
  pointer replaces default discovery — gets hooks/cursor.json. WARN count in a
  live session: 0.
- .claude-plugin/plugin.json: `"commands": []`. commands/ is deprecated in
  Claude Code and each skill is already slash-invocable, so the same-named
  wrappers produced `Skills (4)` with duplicate names. Now `Skills (2)`.
  Dropped the `hooks` and `mcpServers` pointers — Claude Code reads the default
  locations regardless, and a second MCP declaration is at best redundant.
- .devin-plugin/plugin.json: removed `agentSubagents`, which is not a documented
  Devin key; Devin reads agents/ by convention.
- .cursor-plugin/plugin.json: every path ./-prefixed, hooks → ./hooks/cursor.json.
- .codex-plugin/plugin.json: explicit hooks → ./hooks/hooks.json.
- Hook script finds the edited file in Codex apply_patch payloads (path is
  inside patch text, resolved against cwd) and Copilot toolArgs, in addition to
  Claude Code and Cursor. All four shapes tested; exit 0 on garbage.

Verified: Claude Code accepts type streamable-http and normalises to HTTP.
Claude Code suppresses a plugin MCP server that duplicates a manually
configured one by URL — which is why a developer machine never shows the
plugin's copy, and is not a load failure.

Patch 0004: ship-it-nexlayer allowed-tools split into one Tool(pattern) per
token per the Agent Skills spec. Depends on 0003's context; filename order
guarantees application order.

Validator: encodes every rule above — hook schemas per file, per-host wiring,
./ paths, Devin's documented key set, Agent Plugins transport values, Agent
Skills frontmatter shape. All 11 new checks confirmed to fire by breaking each
on a git-archive copy.

Docs: PLATFORMS.md rewritten hooks section, loading-rules table, per-host notes
for Copilot (VS Code namespace holds agents/hooks/commands/rules; Copilot CLI
hook schema recorded, not shipped — no plugin-root variable documented), Devin
(root hooks.json, Windsurf-style rules), transport type, Windows behaviour.
CHANGELOG folded.

Not verified here: live Cursor, Devin, VS Code, Grok installs; Windows;
sync-from-mcp.sh --check against a claudecode-mcp-go clone.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@sasdeployer sasdeployer changed the title Harden loading for every host; add CLAUDE.md project memory Harden loading for every host Sep 8, 2026
@sasdeployer
sasdeployer force-pushed the harden/all-host-loading branch from fe3d664 to 52df1ae Compare September 8, 2026 17:38
@sasdeployer
sasdeployer merged commit f13b3c1 into main Sep 8, 2026
1 check passed
@sasdeployer
sasdeployer deleted the harden/all-host-loading branch September 8, 2026 17:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant