From 0035033302243c06cac518597500ecca9690a45a Mon Sep 17 00:00:00 2001 From: Rajeh Taher Date: Sat, 3 Oct 2026 07:34:34 +0300 Subject: [PATCH 1/3] Declare Streamable HTTP transport in portable MCP manifest --- mcp.json | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/mcp.json b/mcp.json index fd6585f..82e403b 100644 --- a/mcp.json +++ b/mcp.json @@ -2,7 +2,8 @@ "$schema": "https://agent-plugins.org/schemas/1.0.0/mcp.schema.json", "mcpServers": { "polymorfa-docs": { - "url": "https://docs.polymorfa.com/mcp" + "url": "https://docs.polymorfa.com/mcp", + "type": "http" } } } From 5437e16cad0734877de841029753f13c2737c4f1 Mon Sep 17 00:00:00 2001 From: Rajeh Taher Date: Sat, 3 Oct 2026 07:35:07 +0300 Subject: [PATCH 2/3] Validate client-specific transport and component paths --- .cursor-plugin/plugin.json | 2 +- mcp.json | 2 +- scripts/validate.py | 7 +++++++ 3 files changed, 9 insertions(+), 2 deletions(-) diff --git a/.cursor-plugin/plugin.json b/.cursor-plugin/plugin.json index 20875e3..00b3f0b 100644 --- a/.cursor-plugin/plugin.json +++ b/.cursor-plugin/plugin.json @@ -14,5 +14,5 @@ "mcp" ], "skills": "./skills/", - "mcpServers": "./mcp.json" + "mcpServers": "./.mcp.json" } diff --git a/mcp.json b/mcp.json index 82e403b..ff87f2a 100644 --- a/mcp.json +++ b/mcp.json @@ -3,7 +3,7 @@ "mcpServers": { "polymorfa-docs": { "url": "https://docs.polymorfa.com/mcp", - "type": "http" + "type": "streamable-http" } } } diff --git a/scripts/validate.py b/scripts/validate.py index b93573a..50739c6 100644 --- a/scripts/validate.py +++ b/scripts/validate.py @@ -8,3 +8,10 @@ for filename in ("plugin.json", ".claude-plugin/plugin.json", ".cursor-plugin/plugin.json", "gemini-extension.json"): assert json.loads((root / filename).read_text())["version"] == "0.1.0", filename print("Manifests and skills validated") +for filename, transport in [("mcp.json", "streamable-http"), (".mcp.json", "http")]: + servers = json.loads((root / filename).read_text())["mcpServers"] + assert servers == {"polymorfa-docs": {"type": transport, "url": "https://docs.polymorfa.com/mcp"}}, filename +for filename in (".claude-plugin/plugin.json", ".cursor-plugin/plugin.json"): + manifest = json.loads((root / filename).read_text()) + assert (root / manifest["mcpServers"]).is_file(), filename + assert (root / manifest["skills"]).is_dir(), filename From 89170d78ef6c7ce43b9a3010b2a5a16df6717885 Mon Sep 17 00:00:00 2001 From: Rajeh Taher Date: Sat, 3 Oct 2026 07:51:36 +0300 Subject: [PATCH 3/3] Validate plugin component paths stay within repository --- scripts/validate.py | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/scripts/validate.py b/scripts/validate.py index 50739c6..15bff4e 100644 --- a/scripts/validate.py +++ b/scripts/validate.py @@ -13,5 +13,9 @@ assert servers == {"polymorfa-docs": {"type": transport, "url": "https://docs.polymorfa.com/mcp"}}, filename for filename in (".claude-plugin/plugin.json", ".cursor-plugin/plugin.json"): manifest = json.loads((root / filename).read_text()) - assert (root / manifest["mcpServers"]).is_file(), filename - assert (root / manifest["skills"]).is_dir(), filename + for field, kind in (("mcpServers", "file"), ("skills", "directory")): + relative = Path(manifest[field]) + assert not relative.is_absolute() and ".." not in relative.parts, (filename, field) + target = (root / relative).resolve() + assert target.is_relative_to(root), (filename, field) + assert target.is_file() if kind == "file" else target.is_dir(), (filename, field)