Repository navigation
SCR-395: plugin distribution metadata, Cursor/Codex manifests and install-path fixes - #36
Merged
Merged
Conversation
…ires Anthropic's plugin directory moved to the developer portal at claude.ai/directory/manage, whose validator blocks a submission on two things this plugin lacked: a README of at least 40 words in the plugin folder, and a license declared there (a LICENSE file in the folder or `license` in plugin.json). The repository-root LICENSE does not count; people who install the plugin receive only the plugin folder. - plugins/scrapingbee-cli/README.md: the directory shows it as the listing's description. It says what the plugin is for, what is inside, what it needs, and — for the security scan, which checks for undisclosed behaviour — exactly what it runs, sends and fetches: skill text only, no hooks or scripts; the agent runs the scrapingbee CLI or calls the MCP server, which talk to app.scrapingbee.com over HTTPS with the user's own key, and nothing else. - plugins/scrapingbee-cli/LICENSE: copy of the repository's MIT license. - plugin.json: `license`, `homepage` and `repository`, the metadata fields the publishing guide asks for. `claude plugin validate --strict` still passes.
A live Cowork test installed scrapingbee-cli successfully, then reported `scrapingbee: command not found` — pip had put the entrypoint in ~/.local/bin, which that shell does not search. The agent recovered by calling the full path, but nothing in the skill told it to, and an agent that does not work it out will conclude the install failed and reach for another tool. Getting-started now says where the executable is, gives the one-line PATH fix, and names the full-path fallback, with an explicit instruction not to switch tools over it. It also notes that a .env in the working directory is read for the key, which is the cleanest way to hand a sandboxed shell a credential without pasting it anywhere. Applies to any minimal shell, not only Cowork; the eval harness never saw it because it places the shim on PATH itself.
…ATH note Live Cowork test, continued. With the CLI installed and runnable, every API call failed with "Cannot connect to host app.scrapingbee.com:443 ... Temporary failure in name resolution": the sandbox shell reaches PyPI but not the ScrapingBee API, because the org restricts outbound traffic to an allowlist. The MCP connector worked throughout, since connectors bypass the shell's allowlist. SKILL.md's MCP rule now names that case alongside "no shell" and "installation blocked", with the error string an agent will actually see. rules/install.md gains a section on allowlists — an org Owner can add the host (Cowork: Admin settings → Capabilities), or use the MCP connector for single-page work while crawls, batches and file output still need the CLI — and an explicit note not to substitute the host's built-in fetch, which sits behind the same allowlist and cannot render JavaScript or pass anti-bot protection. Also completes the previous commit: install.md's "Command not found" section only covered virtualenvs, not the ~/.local/bin user-install case the Cowork shell hit.
| The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/), | ||
| and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). | ||
|
|
||
| ## [Unreleased] |
Contributor
There was a problem hiding this comment.
placeholder or left like this on purpose? (I mean version number)
marius-nemeiksis-sbee
approved these changes
Oct 7, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
plugins/scrapingbee-cli/now carries its ownREADME.md,LICENSEandlicense/homepage/repositoryfields in the Claude manifest..cursor-plugin/plugin.json(with aSCRAPINGBEE_API_KEYvariable and a rootmcp.jsonthat connects the ScrapingBee MCP server) and.codex-plugin/plugin.json, plusassets/logo.svgandassets/icon.png.rules/install.mdnow say thatuv tool installputsscrapingbeein~/.local/binand how to run it when that directory is not onPATH, and document what a "Temporary failure in name resolution" means in a sandbox with a network allowlist.CONTRIBUTING.mdlists all three plugin manifests in the version-bump checklist;CHANGELOG.mdgets an Unreleased section.Why
skills/. Vendor directories were chosen over the portable rootplugin.jsonbecause Cursor's support for that format has novariablesorlogo, and a root.mcp.jsonfor Codex would also be picked up by Claude Code.codex mcp addsetup instead.~/.local/binonPATH; without the note an agent hit "command not found" after a successful install and fell back to another tool.Verification
claude plugin validate --strictpasses; Claude Code loads the plugin with no MCP server picked up frommcp.json.cursor agent --plugin-dirloads both skills and the bundled MCP server and completes a scrape task.codex plugin addinstalls the plugin from a local marketplace;codex execreads the skill and runsscrapingbee scrape … --render-js false;codex mcp add … --bearer-token-env-varconnects the MCP server authenticated.~/.local/binon PATH): the updated skill installs and runs the CLI without a failed command.scripts/check_examples.pypasses and the host skill copies are in sync.