Harden loading for every host - #3
Merged
Merged
Conversation
sasdeployer
force-pushed
the
harden/all-host-loading
branch
2 times, most recently
from
September 5, 2026 16:45
fadfa18 to
fe3d664
Compare
Deep pass of every manifest, hook, and MCP file against each host's primary
documentation (Claude Code plugins reference, Cursor plugins + hooks reference,
Codex/OpenAI plugins + hooks, Agent Plugins 1.0, Agent Skills spec, Devin CLI
plugins, VS Code agent plugins, Copilot CLI plugin + hooks), then verified
against Claude Code by real install and a --debug session.
Behavior (found by installing, not by reading):
- hooks/hooks.json carried Cursor's flat schema at the default filename. Claude
Code reads that file regardless of the manifest pointer and emitted
`[WARN] hooks.afterFileEdit: unknown hook event` on every session start for
every user. Codex defaults to the same file with the same nested schema
Claude Code uses. The shared filename now carries the nested schema
(PostToolUse, matcher Write|Edit|MultiEdit|NotebookEdit|apply_patch,
${CLAUDE_PLUGIN_ROOT}); Cursor — the one host whose docs say the manifest
pointer replaces default discovery — gets hooks/cursor.json. WARN count in a
live session: 0.
- .claude-plugin/plugin.json: `"commands": []`. commands/ is deprecated in
Claude Code and each skill is already slash-invocable, so the same-named
wrappers produced `Skills (4)` with duplicate names. Now `Skills (2)`.
Dropped the `hooks` and `mcpServers` pointers — Claude Code reads the default
locations regardless, and a second MCP declaration is at best redundant.
- .devin-plugin/plugin.json: removed `agentSubagents`, which is not a documented
Devin key; Devin reads agents/ by convention.
- .cursor-plugin/plugin.json: every path ./-prefixed, hooks → ./hooks/cursor.json.
- .codex-plugin/plugin.json: explicit hooks → ./hooks/hooks.json.
- Hook script finds the edited file in Codex apply_patch payloads (path is
inside patch text, resolved against cwd) and Copilot toolArgs, in addition to
Claude Code and Cursor. All four shapes tested; exit 0 on garbage.
Verified: Claude Code accepts type streamable-http and normalises to HTTP.
Claude Code suppresses a plugin MCP server that duplicates a manually
configured one by URL — which is why a developer machine never shows the
plugin's copy, and is not a load failure.
Patch 0004: ship-it-nexlayer allowed-tools split into one Tool(pattern) per
token per the Agent Skills spec. Depends on 0003's context; filename order
guarantees application order.
Validator: encodes every rule above — hook schemas per file, per-host wiring,
./ paths, Devin's documented key set, Agent Plugins transport values, Agent
Skills frontmatter shape. All 11 new checks confirmed to fire by breaking each
on a git-archive copy.
Docs: PLATFORMS.md rewritten hooks section, loading-rules table, per-host notes
for Copilot (VS Code namespace holds agents/hooks/commands/rules; Copilot CLI
hook schema recorded, not shipped — no plugin-root variable documented), Devin
(root hooks.json, Windsurf-style rules), transport type, Windows behaviour.
CHANGELOG folded.
Not verified here: live Cursor, Devin, VS Code, Grok installs; Windows;
sync-from-mcp.sh --check against a claudecode-mcp-go clone.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
sasdeployer
force-pushed
the
harden/all-host-loading
branch
from
September 8, 2026 17:38
fe3d664 to
52df1ae
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Deep pass of every manifest, hook, and MCP file against each host's primary docs, then verified against Claude Code by real install and a
--debugsession. Full detail is in the commit body.Found by installing, not by reading
hooks/hooks.jsonregardless of the manifest pointer; it held Cursor's schema[WARN] hooks.afterFileEdit: unknown hook eventon every session start for every userhooks/cursor.jsonvia its manifest (Cursor's docs say the pointer replaces discovery)commands/is deprecated in Claude Code and duplicated the skills' slash namesSkills (4)with duplicate names"commands": []in.claude-plugin/plugin.json→Skills (2)agentSubagentsis not a Devin manifest keyagents/by convention./allowed-tools: Bash(npx:* docker:* git:*)splits into malformed tokens0004apply_patchputs the edited path inside patch textcwdresolution; CopilottoolArgstooVerified
Skills (2) · Agents (1) · Hooks (1) · MCP servers (1);--debugsession WARN count 0; hook loads fromhooks/hooks.json.streamable-httpaccepted by Claude Code and normalised to HTTP.git archivecopy).validate.py,gen-host-components.py --check,claude plugin validate --strictpass.Not verified
Live Cursor / Devin / VS Code / Grok installs; Windows;
sync-from-mcp.sh --checkagainst an upstream clone.🤖 Generated with Claude Code