Both vendors ship official first-party remote MCP servers over Streamable
HTTP with OAuth 2.0 and no API key, so each plugin is a URL-only mcp.json
with no variables block.
Named the Apollo plugin apollo-io to avoid colliding with Apollo GraphOS,
which ships an unrelated self-hosted MCP server. Both vendors prohibit AI
model training on data pulled through MCP, so both READMEs call that out.
Co-authored-by: Sam Sokolin <SamSokolin@users.noreply.github.com>
* Add Playwright and GitHub third-party MCP plugins
Wire Microsoft's local Playwright MCP (npx stdio) and GitHub's remote
MCP server (PAT auth) into the marketplace, matching existing third_party
plugin layout and manifests.
Co-authored-by: Sam Sokolin <SamSokolin@users.noreply.github.com>
* Pass -y to npx for Playwright MCP
Avoid first-launch hangs when npx would otherwise prompt for
install confirmation over non-interactive MCP stdio.
Co-authored-by: Sam Sokolin <SamSokolin@users.noreply.github.com>
---------
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Sam Sokolin <SamSokolin@users.noreply.github.com>
Both mcp.json files declared $schema: https://cursor.com/schemas/mcp.json.
parsePluginMcpConfig treats any $schema outside SUPPORTED_SCHEMA_IDS (the two
agent-plugins.org 1.0.0 ids) as unsupported and returns null, so indexing found
zero MCP servers and both plugins registered with no components.
The Google plugins omit $schema entirely, which is why they were unaffected.
Removing the key restores discovery.
Co-authored-by: Cursor <cursoragent@cursor.com>
The cloud mark is opaque, so a transparent canvas reads correctly on both
light and dark backgrounds. Geometry is unchanged.
Co-authored-by: Cursor <cursoragent@cursor.com>
Gong uses its official 180x180 apple-touch icon as-is; it already ships a
purple ground and rounded corners.
Salesforce publishes no square icon larger than a 32px favicon, so the logo
is built from their official cloud mark (vector, 262x184) centered on a
192x192 white tile with padding — same treatment as the Google plugins.
Co-authored-by: Cursor <cursoragent@cursor.com>
Completes the third_party grouping so all vendor MCP integrations live in
one place. Updates marketplace source paths, root README links, and the
tree/main homepage URLs in each manifest.
Safe for already-published plugins: the indexer keys plugin identity on
(marketplaceId, name), so a re-index updates gitPath in place rather than
creating a new row, and deprecation is name-based too. Logos stay relative
to the plugin root and re-resolve against the new basePath.
Co-authored-by: Cursor <cursoragent@cursor.com>
Moves gong/ and salesforce/ to third_party/ and points their marketplace
`source` paths at the new location. Nested source paths resolve fine:
resolvePluginSourcePath treats source as a relative path and only strips a
leading ./
Co-authored-by: Cursor <cursoragent@cursor.com>
Adds two MCP integration plugins to the public marketplace and extends the
plugin schema with a `variables` block so manifests can declare
user-configured values.
Gong forwards CLIENT_ID/CLIENT_SECRET into MCP auth. Salesforce Hosted MCP
is a PKCE public client, so it takes a consumer key with no secret, pins the
mcp_api and refresh_token scopes, and templates the whole server URL because
it varies by org type (production vs sandbox) and server kind
(platform vs custom).
Co-authored-by: Cursor <cursoragent@cursor.com>
Drop the three Workspace MCP plugins from the marketplace and delete their plugin directories. Gmail, Drive, and Calendar stay.
Co-authored-by: Alex Vandak Maloney <maloney.a12@gmail.com>
<!-- CURSOR_AGENT_PR_BODY_BEGIN -->
All six Google plugin logos (Gmail, Calendar, Docs, Drive, Sheets, Slides) were transparent-background SVGs whose artwork ran to within 8px of the 192px canvas edge. Against Cursor's dark UI chrome that reads as loose colored marks with no tile, and the glyphs crowd whatever container the client draws around them.
Each logo now gets:
- a full-bleed white `<rect>` behind the artwork, so the icon reads as an app tile in both light and dark themes;
- the original Google artwork inset by 12px — a `translate(12 12) scale(0.875)` group around the existing content — which leaves roughly 19px (10%) of white between the glyph and the tile edge;
- a `viewBox="0 0 192 192"` on the four logos that previously declared only `width`/`height`, so they scale cleanly at any render size.
The artwork itself is untouched: same paths, gradients, masks, and filters from the official 2026 product logos, just uniformly scaled. Applying one scale factor to all six preserves the relative optical sizing Google designed into the family rather than normalizing each glyph's bounding box independently.
READMEs and changelog entries note that the shipped asset is the official icon on a padded white tile.
Rendered with headless Chrome at 24/32/48/96px on a dark background, with rounded-corner masking to approximate how the client is likely to clip them:

`node scripts/validate-plugins.mjs` passes.
<!-- CURSOR_AGENT_PR_BODY_END -->
<div><a href="https://cursor.com/agents/bc-cc691b8a-1190-47ae-a8e4-58fa8e2fcb7b?cursor_ref=pr_footer&cursor_cta=open_in_web"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/open-in-web-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/open-in-web-light.png"><img alt="Open in Web" width="114" height="28" src="https://cursor.com/assets/images/open-in-web-dark.png"></picture></a> <a href="https://cursor.com/background-agent?bcId=bc-cc691b8a-1190-47ae-a8e4-58fa8e2fcb7b&cursor_ref=pr_footer&cursor_cta=open_in_cursor"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/open-in-cursor-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/open-in-cursor-light.png"><img alt="Open in Cursor" width="131" height="28" src="https://cursor.com/assets/images/open-in-cursor-dark.png"></picture></a> </div>
Each of the six Google plugin logos was a transparent-background SVG whose
artwork ran to within 8px of the 192px canvas, which reads poorly against
Cursor's dark UI chrome. Add a full-bleed white backdrop, inset the artwork
by 12px (0.875 scale about center), and add the missing viewBox to the four
logos that only declared width/height.
Co-authored-by: Alex Vandak Maloney <maloney.a12@gmail.com>
* docs(pstack): complete the poteto-mode route map
The guide's route paragraph predates the autopilot playbooks, so a
reader browsing routes never learns a PR queue can run on autopilot.
Add that route, and give worktree cleanup a prompt in the section
that tells readers to fan out worktrees in the first place.
Co-authored-by: lauren <poteto@users.noreply.github.com>
* docs(pstack): teach /no-comments and Comment Sicko in the cleanup chapter
The cleanup habit covered /deslop and /unslop but not the comment
pass, so readers never met Comment Sicko or the constraint-encoding
offer. Add the before-review step and state the deslop / unslop /
no-comments division of labor.
Co-authored-by: lauren <poteto@users.noreply.github.com>
* docs(pstack): cover Babysit and Shipping after the PR opens
The chapter ended at opening the PR and a note claiming pstack
bundles no PR monitoring. That note is stale: Babysit ships with the
watch-pr watcher and Shipping lands verified stacks through Graphite
merge-when-ready. Replace it with the two playbooks, their prompts,
and the merge-ready versus land distinction.
Co-authored-by: lauren <poteto@users.noreply.github.com>
* docs(pstack): teach the autopilots and orchestrate in the overnight chapter
The chapter covered one task per night and nothing bigger, so the
queue and program playbooks had no home in the guide. Add
autopilot-full, autopilot-stack, and orchestrate with prompts and
the rule for choosing between them.
Co-authored-by: lauren <poteto@users.noreply.github.com>
* docs(pstack): introduce /technical-writing and /bro in the later chapters
Both skills shipped without a guide mention. /technical-writing sits
with skill authoring, where readers already write prose that agents
and humans consume. /bro joins the recipes as the one-word prompt for
a jargon-free restatement.
Co-authored-by: lauren <poteto@users.noreply.github.com>
* docs(pstack): technical-writing pass over the new guide prose
Fixes traced to the skill's rules. Split sentences carrying two or
three thoughts (STE). Moved 'only' next to what it changes and gave
the merge-ready heading a real subject instead of 'it' (Global
English). One name per thing: uncommitted work, Autopilot-full,
verdict instead of say-so. Replaced unglossed jargon with plain
words: 'drains completions' and 'merge frontier' now say what the
coordinator does, 'the real surface' is now 'proves the behavior
live'.
Co-authored-by: lauren <poteto@users.noreply.github.com>
---------
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
* pstack: add /bro, restate the last message in plain language
* poteto-mode: add babysit, shipping, orchestrate, and worktree-cleanup playbooks
Ships the watch-pr status watcher, the orch coordinator CLI, and
worktree-audit.sh under scripts/, plus a Bugbot triage rubric under
references/. Wires the new playbooks into the mode's triggers and
catalog, and repoints autopilot babysit references at the bundled
playbooks.
* pstack: catch-up edits to unslop, automate-me, type-system-discipline, poteto-agent
unslop gains the cross-project swap test, more banned metaphor nouns,
and plainer rule titles. automate-me learns nested personal-category
mode skills. principle-type-system-discipline states the define-errors-
out-of-existence rule. poteto-agent defaults to background execution.
* pstack 0.14.0: README and guide updates for the new skill and playbooks
* fix(pstack): queued babysit stops on WAITING/merge-queue, not READY
Queued watch-pr never emits READY; a green frontier is non-terminal
WAITING with reason merge-queue. The playbook wrongly told agents to
wait for READY, which hangs drive with the default timeout.
* Port Comment Sicko foreign-gotcha tip and no-comments step 5
Catch up to the merged tip: our-code surprises die with MUST KILL
reshape, foreign/unowned keeps survive, step 5 simplified. Sanitize
how/why and principle paths for the public plugin.
* Fix capitalization after principle path sanitize
---------
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
* pstack: add autopilot and writing workflows
Co-authored-by: lauren <poteto@users.noreply.github.com>
* pstack: tighten autopilot handoff rules
Co-authored-by: lauren <poteto@users.noreply.github.com>
* pstack: restore tip-faithful Sicko/no-comments and full autopilot ports
Prior commit reconstructed these from secondary metadata. Restore from
the real tip/main sources with only public-path edits.
* pstack: fix Comment Sicko spawn path and add /no-comments to Opening a PR
Spawn Comment Sicko by subagent_type alone; the hardcoded
.cursor/agents/ path does not exist on plugin installs. Add the
/no-comments pass to the Opening a PR playbook so the Before review
trigger holds outside the autopilot playbooks.
---------
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Set displayName to Gmail / Google Drive / Calendar / Docs / Sheets /
Slides and replace placeholder icons with Google's productlogos SVGs
from gstatic.
Co-authored-by: Cursor <cursoragent@cursor.com>
<!-- CURSOR_AGENT_PR_BODY_BEGIN -->
## What
Model routing behavior is unchanged; the prose shrinks to the places that define it.
- `setup-pstack` keeps the `inherit-parent` / `auto` definition (steps 1, 3, 4) and writes it into the generated rule's header comment; the five-line resolution block collapses to one definition line.
- `poteto-mode` keeps one alias clause at the end of the Task-call defaults paragraph.
- `how`, `why`, `arena`, `architect`, `reflect`, and `interrogate` drop their per-call-site resolution instructions ("pass a real slug / omit `model` for `inherit-parent`/`auto` / if the role line is absent...") and return to compact configured-role pointers. All current model defaults stay exactly as they are.
- `interrogate` gains configurable reviewer counts: the `interrogate reviewers` list sets the panel size, the Reviewer A/B/C labels extend or shrink to the configured entry count, and a default table keeps the current panel.
## Why
Call-mechanics instructions in skill prose do not change agent behavior; the subagent tool schema (model optional, omitted inherits the parent) governs. Prose that defines what a config value means is what earns its place. Verified with blinded behavioral runs on this tree: a mixed config planted (aliases on panel roles, real slugs elsewhere, one role line deleted), multiple parent model families, spawn calls graded mechanically from transcripts. One blinded run showed a config-misread unrelated to this change (that agent never opened the skill file this change edits for that path); the fan-out and alias invariants held across all runs.
## Version
0.11.7 -> 0.11.8 (skill-content change, per repo convention).
<!-- CURSOR_AGENT_PR_BODY_END -->
<div><a href="https://cursor.com/agents/bc-12823923-1f75-47d8-81ba-e78099b4add8"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/open-in-web-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/open-in-web-light.png"><img alt="Open in Web" width="114" height="28" src="https://cursor.com/assets/images/open-in-web-dark.png"></picture></a> <a href="https://cursor.com/background-agent?bcId=bc-12823923-1f75-47d8-81ba-e78099b4add8"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/open-in-cursor-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/open-in-cursor-light.png"><img alt="Open in Cursor" width="131" height="28" src="https://cursor.com/assets/images/open-in-cursor-dark.png"></picture></a> </div>
* pstack: add public usage tutorial
Co-authored-by: lauren <poteto@users.noreply.github.com>
* pstack: document verification skill workflows
Co-authored-by: lauren <poteto@users.noreply.github.com>
* pstack: mention verification setup offer
Co-authored-by: lauren <poteto@users.noreply.github.com>
* pstack: clarify optional verification setup
Co-authored-by: lauren <poteto@users.noreply.github.com>
* pstack: rewrite tutorial prompts to match real usage
The example prompts read like specs. Real prompts are short, informal,
and goal-first, so every example now uses that register. The prose
reshapes around them: friendly second-person tutorial voice, goals
before mechanics, pitfalls where readers actually trip, and the
playbook reference table replaced with prompts in context. Every
skill claim re-checked against the skill files at this commit.
* pstack: make the README guide link an invitation
Point new readers at what the guide walks them through instead of
listing its topics.
* pstack: drop the version bump
This PR only adds documentation, so the plugin manifest stays at
main's 0.11.7.
* pstack: add illustrations to the guide
One hero image per major guide page (routing, understanding, design,
verification, overnight runs, recipes), 1200px JPEGs under
docs/guide/images/.
---------
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
1. hillclimb.md: port steps 1-2 (workload grounding before choosing the
ruler; harness sensitivity proof before freezing), fold the how-skill
grounding into step 1 and rewrite step 4 to reference it.
2. refactoring.md: insert missing step 2 (name the structure the code is
missing per principle-model-the-domain), renumber 3-8, and restore the
"safety net" framing sentence in the intro.
3. feature.md + poteto-mode SKILL.md: expand the delegation scope and the
any-code trigger to choose the organizing structure per
principle-model-the-domain.
4. typescript-best-practices: restore the dropped "Real tests" and
"Structured telemetry" rules in generic form.
5. poteto-mode Subagents: add the difficulty tiering criteria (judgment vs
precisely specified vs trivial mechanical) and the setup-pstack rule
override semantics.
6. One-liner tells ported verbatim into bug-fix, runtime-forensics,
session-pickup, autonomous-run, and authoring-a-skill.
7. Bug fix: interrogate is "(multi-model adversarial)", not four-model;
the default panel is three models.
8. Leak fix: drop the dangling databricks-use-dbt-models skill reference
in why/references/sources/databricks.md.
Plus: arena cross-judge pool role line in setup-pstack, version bump to
0.11.3.
* maintain-verification-skill: cleanup granularity, re-doctor, evidence checks
Follow-up to the four bugbot comments that landed on #150 seconds
before merge: failed-drive cleanup now matches the granularity of what
failed (never tearing down a shared instance mid-pass), a failed drive
on a long-lived instance triggers re-doctor before the next feature,
the doctor-drift retry includes cleanup and relaunch, and every cleanup
is followed by an evidence-survival check.
* State the live-pass recovery rules as invariants, not enumerated procedures
* Restore the per-session doctor check inside invariant 1
* pstack: add create-verification-skill and maintain-verification-skill
Generalizes the control-glass approach (feature map, doctor, proof
standards, harness-first) for any language or platform. The generator
interviews the repo, writes a project-local verify skill + seeded
feature map, and must prove its own output by running it once. The
maintainer is the upkeep loop: source wave per feature, one live pass,
at most one PR. setup-pstack gains an optional final step offering the
generator. Validated by 4 cloud agents generating against real repos
(go TUI, node CLI, HTTP service, full-stack web app) - all four proof
runs passed, and their friction reports drove 6 revisions.
* Address bugbot: frontmatter spec, teardown, launch-model deference, target discovery
* Rewrite live pass: per-session health checks, doctor-drift retry, per-failure cleanup, teardown after re-proof
* pstack: lead the README with the two-step quickstart
* Keep version at 0.10.4; README-only change
* README: no version bump, reorder for first-time readers, collapse long blocks
make-it-yours and automations move below the reference sections; the
sixteen-playbook table and the examples block collapse behind <details>
so the top of the page is install -> get started -> usage.
* README: collapse the skills table too, keep four examples visible
* README: link every skill, playbook, and principle to its file; split examples by section
* README: visible examples are bare copy-paste prompts
* README: link every prose skill mention and the playbooks dir
* README: visible example prompts wrap at 100 chars and lead their sections
* README: principles as a collapsible table