Match the project to your task before installing it.
MCP Tool Integration · Public
claude-plugins-validation
MCP tool integration project for safely connecting external tools, services, or data sources to an AI host.
Check whether this project matches your task before installing it.
What it can doMCP setup guidance, host configuration checks, tool permission boundaries, recovery steps, and acceptance checksReview the portable capability path.
Before continuingVerify in a sandboxDo not treat a preview pack as a proven local install.
GitHub snapshot4 stars0 forks · 2 contributors
Doramagic.ai Last verification date: 2026-07-28 Verification method: source evidence, semantic profile, public page gate, and static build acceptance.
Publication status · 2026-07-28
What is claude-plugins-validation?
- claude-plugins-validation helps connect external tools, services, or data sources to AI hosts that support MCP.
- Best fit: Developers who need Claude, Cursor, Codex, or another MCP-capable AI host to call external tools safely.
- Not for: Not for users who cannot change host configuration, grant tool permissions, or isolate network, file, and credential access.
- Capability added to an AI workflow: MCP setup guidance, host configuration checks, tool permission boundaries, recovery steps, and acceptance checks
- First safe verification step: Verify the MCP server command, permission scope, and rollback path in a non-primary host configuration first.
- Verification state: source, Quick Start, and sandbox install checks are recorded as passed.
- Top risk: Developers may expose sensitive permissions or credentials: Canonical pre-push hook: strict publish-ancestry gate forbids ALL branch sharing — allow non-default-branch pushes after secret scan (fleet-stall root cause)
- Evidence base: https://github.com/Emasoft/claude-plugins-validation, https://github.com/Emasoft/claude-plugins-validation#readme, Human Manual, Pitfall Log
01
Quick decision
Use this section to decide whether the project is worth a deeper read.MCP tool integration project for safely connecting external tools, services, or data sources to an AI host.
4 stars · 0 forks
02
What it can do
Translate the upstream project into concrete capabilities the user can judge before installing.Overview and Getting Started
Related topics: Core Validation Features and Security Scanning, Architecture and Internal Components
Source: https://github.com/Emasoft/claude-plugins-validation / Human Manual
Core Validation Features and Security Scanning
Related topics: Overview and Getting Started, Architecture and Internal Components, Operations, Workflows, and Common Failure Modes
Source: https://github.com/Emasoft/claude-plugins-validation / Human Manual
Architecture and Internal Components
Related topics: Core Validation Features and Security Scanning, Operations, Workflows, and Common Failure Modes
Source: https://github.com/Emasoft/claude-plugins-validation / Human Manual
Operations, Workflows, and Common Failure Modes
Related topics: Core Validation Features and Security Scanning, Architecture and Internal Components
Source: https://github.com/Emasoft/claude-plugins-validation / Human Manual
Doramagic Pitfall Log
Source-linked risks stay visible on the manual page so the preview does not read like a recommendation.
Source: Doramagic discovery, validation, and Project Pack records
Sources: https://github.com/Emasoft/claude-plugins-validation, Human Manual, Project Pack evidence, and downstream validation signals.
03
Community Discussion Evidence
Project-level external discussion stays visible on the detail page, not only inside the manual.Community Discussion Evidence
12 source-linked itemsReview these external discussions before using claude-plugins-validation with real data or production workflows. They are review inputs, not standalone proof that the project is production-ready.
-
01
Canonical-pipeline validate step hangs ~30 min AFTER CPV builds (4s) — n
github / github_issue
-
02
canonical publish.py: run() hardcodes timeout=300, making the test gate
github / github_issue
-
03
skillaudit:filesystem FS_WRITE false-positive on install-doc PROSE (bash
github / github_issue
-
04
bug(--strict scope): validates non-shippable tracked content (project-me
github / github_issue
-
05
skillaudit:agent_manipulation MCP_SCHEMA_POISON false-positive on wikime
github / github_issue
-
06
feat(canonical-pipeline): gate Rust + shell when a plugin ships them (re
github / github_issue
-
07
Scan dependencies (not just the plugin tree) for agent-context writers,
github / github_issue
-
08
Recognize CC v2.1.218 skill-frontmatter field 'background' (currently fl
github / github_issue
-
09
skillaudit: defensive anti-injection guardrails flagged as injection (4
github / github_issue
-
10
cpv_validation_common.py trips bandit B108 on its own data constants — b
github / github_issue
-
11
standardize --fix generates a .cspell.json that trips CPV's own skillaud
github / github_issue
-
12
Canonical pre-push hook: strict publish-ancestry gate forbids ALL branch
github / github_issue
04
How to start
Only source-backed commands are shown here. Verify them in an isolated environment first.Try the prompt first
Test the workflow without installing the upstream project.
previewRead the Human Manual
Understand inputs, outputs, limits, and failure modes.
manualTake context to your AI host
Use the compiled assets in your preferred AI environment.
contextRun sandbox verification
Confirm install commands and rollback before using a primary environment.
verifyplugin install claude-plugins-validation@emasoft-pluginsOfficial start command · https://github.com/Emasoft/claude-plugins-validation#readme · verified: yes
05
Human Manual
The English page must expose the real manual, not a short placeholder.8+ sections · Human Manual
claude-plugins-validation Manual
Comprehensive validation suite for Claude Code plugins, marketplaces, hooks, skills, and MCP servers
Open the full manual- https://github.com/Emasoft/claude-plugins-validation Project Manual
- Table of Contents
- Overview and Getting Started
- Related Pages
- What CPV Does
- Installation
- then add it as a plugin in Claude Code, or invoke the CLI directly:
- Basic Usage
Overview and Getting Started
Related topics: Core Validation Features and Security Scanning, Architecture and Internal Components
Source: https://github.com/Emasoft/claude-plugins-validation / Human Manual
Core Validation Features and Security Scanning
Related topics: Overview and Getting Started, Architecture and Internal Components, Operations, Workflows, and Common Failure Modes
Source: https://github.com/Emasoft/claude-plugins-validation / Human Manual
Architecture and Internal Components
Related topics: Core Validation Features and Security Scanning, Operations, Workflows, and Common Failure Modes
Source: https://github.com/Emasoft/claude-plugins-validation / Human Manual
Operations, Workflows, and Common Failure Modes
Related topics: Core Validation Features and Security Scanning, Architecture and Internal Components
Source: https://github.com/Emasoft/claude-plugins-validation / Human Manual
Doramagic Pitfall Log
Source-linked risks stay visible on the manual page so the preview does not read like a recommendation.
Source: Doramagic discovery, validation, and Project Pack records
06
AI Context Pack and portable assets
After deciding to continue, take the project context into your own AI host.Complete pack plus user-owned assets
These files are planning and verification assets for Claude Code, Codex, Gemini, Cursor, ChatGPT, and other AI hosts.
07
Preflight checks
Treat this page as a planning asset, not proof that your local environment is ready.- The manual is generated from source-linked project files and Doramagic validation signals.
- Community evidence warnings stay visible instead of being converted into marketing claims.
- This English page is indexable because the locale quality gate passed and explicit English index approval is enabled.
- Use the upstream repository as the final authority for installation commands, license, and version-specific behavior.
08
Pitfall Log and verification risks
Doramagic surfaces high-risk items before users treat a candidate capability as verified.Security or permission risk requires verification
Developers may expose sensitive permissions or credentials: Canonical pre-push hook: strict publish-ancestry gate forbids ALL branch sharing — allow non-default-branch pushes after secret scan (fleet-stall root cause)
Security or permission risk requires verification
Developers may expose sensitive permissions or credentials: skillaudit:agent_manipulation MCP_SCHEMA_POISON false-positive on wikimem memory-note description: PROSE (same class as #177 / #156)
Security or permission risk requires verification
Developers may expose sensitive permissions or credentials: standardize still strips documented linter suppressions (MD010, CKV_DOCKER_2) — #145 fixed only MD025; and canon publish.py never creates the {name}--v{version} resolver tag
Security or permission risk requires verification
May increase setup, validation, or first-run risk for the user.
Installation risk requires verification
Developers may fail before the first successful local run: Canonical-pipeline validate step hangs ~30 min AFTER CPV builds (4s) — not #114's cold-build cause; timed-out release shipped with no assets
Installation risk requires verification
Developers may fail before the first successful local run: Scan dependencies (not just the plugin tree) for agent-context writers, and score capability vs live separately
Installation risk requires verification
Developers may fail before the first successful local run: feat(canonical-pipeline): gate Rust + shell when a plugin ships them (regen drops them silently)
Installation risk requires verification
Developers may fail before the first successful local run: skillaudit:filesystem FS_WRITE false-positive on install-doc PROSE (bash comment naming ~/.zshrc)