Doramagic.ai Chinese

MCP Tool Integration · Public

claude-plugins-validation

MCP tool integration project for safely connecting external tools, services, or data sources to an AI host.

MCPTool callingHost configurationPermission boundariesAcceptance checks

Last verification date: 2026-07-28 Verification method: source evidence, semantic profile, public page gate, and static build acceptance.

Publication status · 2026-07-28

What is claude-plugins-validation?

01

Quick decision

Use this section to decide whether the project is worth a deeper read.
Best forDevelopers who need Claude, Cursor, Codex, or another MCP-capable AI host to call external tools safely.

Match the project to your task before installing it.

CapabilityMCP setup guidance, host configuration checks, tool permission boundaries, recovery steps, and acceptance checks

MCP tool integration project for safely connecting external tools, services, or data sources to an AI host.

RepositoryEmasoft/claude-plugins-validation

4 stars · 0 forks

02

What it can do

Translate the upstream project into concrete capabilities the user can judge before installing.
1

Overview and Getting Started

Related topics: Core Validation Features and Security Scanning, Architecture and Internal Components

Source: https://github.com/Emasoft/claude-plugins-validation / Human Manual
2

Core Validation Features and Security Scanning

Related topics: Overview and Getting Started, Architecture and Internal Components, Operations, Workflows, and Common Failure Modes

Source: https://github.com/Emasoft/claude-plugins-validation / Human Manual
3

Architecture and Internal Components

Related topics: Core Validation Features and Security Scanning, Operations, Workflows, and Common Failure Modes

Source: https://github.com/Emasoft/claude-plugins-validation / Human Manual
4

Operations, Workflows, and Common Failure Modes

Related topics: Core Validation Features and Security Scanning, Architecture and Internal Components

Source: https://github.com/Emasoft/claude-plugins-validation / Human Manual
5

Doramagic Pitfall Log

Source-linked risks stay visible on the manual page so the preview does not read like a recommendation.

Source: Doramagic discovery, validation, and Project Pack records

Sources: https://github.com/Emasoft/claude-plugins-validation, Human Manual, Project Pack evidence, and downstream validation signals.

03

Community Discussion Evidence

Project-level external discussion stays visible on the detail page, not only inside the manual.
Stars4 stars
Forks0 forks
Contributors2 contributors
Licenseunknown

04

How to start

Only source-backed commands are shown here. Verify them in an isolated environment first.
1

Try the prompt first

Test the workflow without installing the upstream project.

preview
2

Read the Human Manual

Understand inputs, outputs, limits, and failure modes.

manual
3

Take context to your AI host

Use the compiled assets in your preferred AI environment.

context
4

Run sandbox verification

Confirm install commands and rollback before using a primary environment.

verify
plugin install claude-plugins-validation@emasoft-plugins

Official start command · https://github.com/Emasoft/claude-plugins-validation#readme · verified: yes

05

Human Manual

The English page must expose the real manual, not a short placeholder.

8+ sections · Human Manual

claude-plugins-validation Manual

Comprehensive validation suite for Claude Code plugins, marketplaces, hooks, skills, and MCP servers

Open the full manual
  1. https://github.com/Emasoft/claude-plugins-validation Project Manual
  2. Table of Contents
  3. Overview and Getting Started
  4. Related Pages
  5. What CPV Does
  6. Installation
  7. then add it as a plugin in Claude Code, or invoke the CLI directly:
  8. Basic Usage
1

Overview and Getting Started

Related topics: Core Validation Features and Security Scanning, Architecture and Internal Components

Source: https://github.com/Emasoft/claude-plugins-validation / Human Manual
2

Core Validation Features and Security Scanning

Related topics: Overview and Getting Started, Architecture and Internal Components, Operations, Workflows, and Common Failure Modes

Source: https://github.com/Emasoft/claude-plugins-validation / Human Manual
3

Architecture and Internal Components

Related topics: Core Validation Features and Security Scanning, Operations, Workflows, and Common Failure Modes

Source: https://github.com/Emasoft/claude-plugins-validation / Human Manual
4

Operations, Workflows, and Common Failure Modes

Related topics: Core Validation Features and Security Scanning, Architecture and Internal Components

Source: https://github.com/Emasoft/claude-plugins-validation / Human Manual
5

Doramagic Pitfall Log

Source-linked risks stay visible on the manual page so the preview does not read like a recommendation.

Source: Doramagic discovery, validation, and Project Pack records

06

AI Context Pack and portable assets

After deciding to continue, take the project context into your own AI host.

Complete pack plus user-owned assets

These files are planning and verification assets for Claude Code, Codex, Gemini, Cursor, ChatGPT, and other AI hosts.

07

Preflight checks

Treat this page as a planning asset, not proof that your local environment is ready.

08

Pitfall Log and verification risks

Doramagic surfaces high-risk items before users treat a candidate capability as verified.
high

Security or permission risk requires verification

Developers may expose sensitive permissions or credentials: Canonical pre-push hook: strict publish-ancestry gate forbids ALL branch sharing — allow non-default-branch pushes after secret scan (fleet-stall root cause)

high

Security or permission risk requires verification

Developers may expose sensitive permissions or credentials: skillaudit:agent_manipulation MCP_SCHEMA_POISON false-positive on wikimem memory-note description: PROSE (same class as #177 / #156)

high

Security or permission risk requires verification

Developers may expose sensitive permissions or credentials: standardize still strips documented linter suppressions (MD010, CKV_DOCKER_2) — #145 fixed only MD025; and canon publish.py never creates the {name}--v{version} resolver tag

high

Security or permission risk requires verification

May increase setup, validation, or first-run risk for the user.

medium

Installation risk requires verification

Developers may fail before the first successful local run: Canonical-pipeline validate step hangs ~30 min AFTER CPV builds (4s) — not #114's cold-build cause; timed-out release shipped with no assets

medium

Installation risk requires verification

Developers may fail before the first successful local run: Scan dependencies (not just the plugin tree) for agent-context writers, and score capability vs live separately

medium

Installation risk requires verification

Developers may fail before the first successful local run: feat(canonical-pipeline): gate Rust + shell when a plugin ships them (regen drops them silently)

medium

Installation risk requires verification

Developers may fail before the first successful local run: skillaudit:filesystem FS_WRITE false-positive on install-doc PROSE (bash comment naming ~/.zshrc)