Repository navigation
Conversation
|
Macroscope has since reviewed this pull request. An earlier review was skipped by a cost limit; a review has now completed, so that notice no longer applies. |
ApprovabilityVerdict: Not approved Macroscope's review found this PR not approvable — This PR introduces a broad trusted-plugin platform spanning server execution, npm installation, secrets, MCP tools, isolated views, persistence, authorization, and multiple clients, while also enabling related capabilities by default and adding static-analysis suppressions. An unresolved High-severity source-integrity concern remains in the plugin digest path, so the changes require human review. Not approved because:
Adjust the Minimum Blocking Severity for this repo — including turning it Off — in Settings. You can add or adjust custom eligibility rules. Learn more. |
📝 Walkthrough
|
Stacked on #16057 (and #15010). Review only the top commit: 2e1d06e.
Problem
When a user reviews a plugin before approving it, the Plugins page shows only bare capability names such as
actionsortools. It does not say what those let the plugin do, or what the plugin actually adds: which actions and where they appear, which tools agents can call, which settings it asks for, which events it receives. A user approving trusted local code has to read its manifest to find out.Also, when an environment's plugins declare more actions than the per-environment limit, the plugins that do not fit are left out whole, and nothing tells the user which ones.
This PR lists each plugin's declared contributions and a plain meaning for each capability in the review and details, on web, desktop and mobile.
Why this qualifies
This is the proposal route in CONTRIBUTING, and no maintainer has agreed to it yet. It needs the plugin-system approval on #6714 / #6837, like the plugin PRs below it.
It stacks on the npm install UI PR (its update section also lists what a downloaded version contributes). It adds no RPC and no scope. Its one server change makes a downloaded npm update use the catalogue's manifest summary, so that section is complete. If the answer is no, we close this with the plugin PRs around it. Previous PR in this stack: feat(web,mobile): install and update plugins from npm in Settings (#16057).
Fix
Shared client state (
packages/client-runtime/state/pluginContributions):describePluginContributionsturns the manifest summary the catalogue already sends into groups: actions (title, target, placements,/namefor the composer), tools (title or name, side effect, open world, description), settings (label, type, description), and events (what is delivered). Nothing here starts the plugin.describePluginCapabilitiesgives a plain meaning to each capability the server implements (actions, tools, views, settings, events). Any other name is shown as declared, without a meaning: the server refuses to load a plugin that declares one, so there is no behaviour to describe.Web and desktop: the review/details dialog shows each capability with its meaning, and a Contributes field. A downloaded npm update shows what the new version contributes before it is applied.
Server: a downloaded npm update is now summarized by the catalogue's own summary function (
summarizePluginManifest, exported fromPluginCatalog.ts) instead of the npm install PR's narrower copy, which left out tools, settings and actions. The update's Contributes therefore lists the same things the plugin will list once applied. An update downloaded by a server without this change still has no tools, settings or actions in its summary, so an empty Contributes for a download reads "Nothing listed", not "Nothing declared".Mobile (read-only, like the rest of its Plugins screens): the plugin screen shows capabilities with meanings and a Contributes section. There is no npm update section on mobile, so nothing lists a downloaded version's contributions there.
The action and view snapshots are subscribed only for an enabled installation on servers that report
pluginActions/pluginViews. Like other environment subscriptions, one stays open for up to five idle minutes after the details close, then ends; there is one per environment, not one per plugin. Web reuses the view host's session-bound views hook; mobile gets the environment's views subscription back in shared state (it hosts no views; it reads titles for details).Docs:
docs/user/plugins.mdsays the review lists contributions and capability meanings without starting the plugin, and that a plugin left out by the action limit says so in its details.Size: 16 files, +879 / −32. About 0.33k of the added lines are tests.
Evidence
Environment: macOS arm64; this PR on top of the npm install UI PR.
How to exercise it: use an isolated
vp run dev. Add a scratch plugin whose manifest declares an action (thread menu and/placement), a tool, a secret and a boolean setting, andevents; open its review before approving, then approve and open its details. For the limit, enable eight scratch plugins with 16 actions each before it.Captures (isolated dev server on fresh state, web in Chromium, the built desktop app, and one
vp run dev --shareremote browser; the environment label is a neutral "Proof server"). The scratch plugin declares exactly the five supported capabilities: an action (thread menu and/summarize), a read-only tool, a secret and a boolean setting, events, and a view.Before: bare capability badges, no Contributes. After (video): each capability with its meaning, and Contributes lists Actions ("Summarize thread · Runs on a thread · Thread menu, /summarize"), Tools for agents, Views ("Their titles show here while the plugin is enabled"), Settings ("Service key · Secret, kept on the server", "Notifications · On or off") and Events ("Finished runs"). Once enabled, Views lists "Proof overview · Side panel on web and desktop".
--share).npm update section (this head; video): an installed 1.0.0 (settings, events) downloads 1.2.0, which adds a tool, an action and a second setting. Before, the update shows its capabilities with "New: tools, actions" but no Contributes. After, the download's Contributes lists every declaration: Actions "Summarize thread · Runs on a thread · Thread menu, /summarize", Tools for agents "Thread summary · Reads only", Settings "Notifications · On or off" and "Region · Text", and Events "Finished runs".
--share)Android (this head, an emulator with a standard pairing; mobile has no update section): before, the plugin screen lists capability names only; after, each capability has its meaning and a read-only Contributes section lists Actions, Tools for agents, Views ("Proof overview · Side panel on web and desktop"), Settings and Events, above the view-only notice.
Remote (
vp run dev --share, its own pairing link, fresh browser profiles): admin and standard details render the same as local, and at this head a download staged over the remote origin lists the same Contributes as locally.The review, enabled, action-limit, stopped and standard-pairing captures above were taken on an earlier revision of this PR that differs from this head outside mobile only in the Remove confirmation's wording (not shown in them), the npm update summary, and the empty-list wording of a download. The npm update section and Android were captured at this head.
Checks at this head (
73fc7d0873), re-run 2026-10-05 (vp test run,CI=true, all exit 0):state/pluginContributions,state/pluginViews,state/pluginNpm,state/pluginNpmPresentation,state/pluginPresentation,state/plugins: 6 files, 83 tests pass. The contributions tests cover the declared groups and their details, the action-limit notice (shown only for an installation the server counts; not for quarantined, incompatible, disabled, unapproved or non-actionsplugins), views listed from an already-filtered snapshot with problems, and the capability meanings: the five supported capabilities have one, while names the server refuses (transforms,approvals,status,notifications), unknown names andconstructorhave none. The views subscription's lifecycle itself is not covered by a test here.PluginNpm.test.ts: 1 file, 22 tests pass (withPluginCatalog.test.ts, 2 files and 35 tests passed on an earlier revision with an identical patch). A realPluginNpm.stageUpdateof a version whose manifest declares a tool, a setting and an action returns a reply that, encoded and decoded with the wire schema, carries all three; once applied, the catalogue lists exactly the manifest that was reviewed. With the npm install PR's summary function, this test fails (the staged summary has no tools, settings or actions; recorded during development).PluginsSettings.npm.test.tsx,PluginsSettings.test.tsx,PluginSettingsForm.test.tsxand the plugin view panel tests: 5 files, 24 tests pass; the mounted npm update review shows "Nothing declared" for the installed version and "Nothing listed" for the download with no declarations. mobiledependency-graph: 3 pass. On an earlier revision with an identical patch, the same web set plusPluginsSettings.catalog.test.tsx(6 files, 27 tests) and mobiledependency-graphplus plugin settings values (2 files, 6 tests) also passed.vp run --filtertypecheck for contracts, server, client-runtime, web and mobile;vp lint --report-unused-disable-directivesandvp fmt --checkon the added and modified files (no warnings);vp run knip:check;vp run lint:mobile;vp run --filter @t3tools/web build;vp run build:desktop;node scripts/release-smoke.ts.Surfaces
PluginActionDeclarationtype is exported for the contributions list.docs/user/plugins.mdrewritten. No internals doc.Not verified
Claude Opus 5.5 (build), GPT-6.1 Sol (review) and GPT-6 Astra (captures) via T3 Code
🤖 Generated with Claude Code