判断自己是不是目标用户。
MCP 工具接入 · 开源项目
claude-plugins-validation
MCP 工具接入项目,用于把外部工具、服务或数据源安全接入 AI 宿主。
判断自己是不是目标用户。
能做什么MCP 接入说明、宿主配置检查、工具权限边界、失败恢复和验收清单查看可带走的能力路径。
继续前先在非主力宿主配置中验证 MCP server 命令、权限范围和回滚方式。未完成验证前保持审慎。
GitHub 快照4 星标0 分叉 · 2 贡献者
Doramagic.ai 最后验证日期:2026-07-28 验证方法:来源证据、语义档案、公开页面门禁和静态构建验收。
快速判断 · 2026-07-28
claude-plugins-validation 项目 是什么?
- claude-plugins-validation 帮助把外部工具、服务或数据源接入支持 MCP 的 AI 宿主。
- 最适合:需要让 Claude、Cursor、Codex 或其他支持 MCP 的 AI 宿主安全调用外部工具的开发者。
- 不适合:不适合不愿修改宿主配置、无法授予工具权限、或不能隔离网络/文件/凭据访问的用户。
- 它给 AI 增加的能力:MCP 接入说明、宿主配置检查、工具权限边界、失败恢复和验收清单
- 第一步安全验证:先在非主力宿主配置中验证 MCP server 命令、权限范围和回滚方式。
- 当前验证状态:源码、Quick Start 和沙箱安装检查均记录为已通过。
- 最大风险:Developers may expose sensitive permissions or credentials: Canonical pre-push hook: strict publish-ancestry gate forbids ALL branch sharing — allow non-default-branch pushes after secret scan (fleet-stall root cause)
- 证据基础:https://github.com/Emasoft/claude-plugins-validation、https://github.com/Emasoft/claude-plugins-validation#readme、项目说明书、踩坑日志
01
一眼判断
先判断自己是否是目标用户,再决定是否继续。不适合不愿修改宿主配置、无法授予工具权限、或不能隔离网络/文件/凭据访问的用户。
未完成验证前保持审慎。
02
它能做什么
把项目翻译成用户能判断的具体能力,而不是 Doramagic 的使用流程。宿主配置
先在非主力配置中检查 MCP server 命令和宿主配置路径。
host-config权限边界
授予权限前明确文件、网络、工具调用和凭据访问范围。
permissions验收检查
定义一个可回滚的最小工具调用,再进入日常工作流。
acceptance来源:https://github.com/Emasoft/claude-plugins-validation、https://github.com/Emasoft/claude-plugins-validation#readme、项目说明书、踩坑日志。这里只回答“它能帮我做什么”。
03
项目温度与外部声音
站点快照,非实时质量证明;用于开工前背景判断。社区讨论
已收录 12 条来源下面是已采集到的项目级社区讨论来源,来源平台:github。这些外部声音用于帮助判断真实使用反馈,不单独作为质量证明。
-
01
Canonical-pipeline validate step hangs ~30 min AFTER CPV builds (4s) — n
github / github_issue
-
02
canonical publish.py: run() hardcodes timeout=300, making the test gate
github / github_issue
-
03
skillaudit:filesystem FS_WRITE false-positive on install-doc PROSE (bash
github / github_issue
-
04
bug(--strict scope): validates non-shippable tracked content (project-me
github / github_issue
-
05
skillaudit:agent_manipulation MCP_SCHEMA_POISON false-positive on wikime
github / github_issue
-
06
feat(canonical-pipeline): gate Rust + shell when a plugin ships them (re
github / github_issue
-
07
Scan dependencies (not just the plugin tree) for agent-context writers,
github / github_issue
-
08
Recognize CC v2.1.218 skill-frontmatter field 'background' (currently fl
github / github_issue
-
09
skillaudit: defensive anti-injection guardrails flagged as injection (4
github / github_issue
-
10
cpv_validation_common.py trips bandit B108 on its own data constants — b
github / github_issue
-
11
standardize --fix generates a .cspell.json that trips CPV's own skillaud
github / github_issue
-
12
Canonical pre-push hook: strict publish-ancestry gate forbids ALL branch
github / github_issue
04
怎么开始使用
先试、再读项目说明书、再带给 AI,最后按官方quick start验证。先试 Prompt
不安装项目,先体验能力节奏。
预览读项目说明书
理解输入、输出、失败模式和边界。
说明书带给 AI
把上下文交给你的宿主 AI 继续工作。
上下文沙箱验证
进入主力环境前先完成安装入口与风险边界验证。
验证plugin install claude-plugins-validation@emasoft-plugins来源:https://github.com/Emasoft/claude-plugins-validation#readme。验证:已通过。
05
项目说明书
每个项目结构不同,Doramagic 保留原项目解释结构,并补充边界与踩坑日志。草稿 · 项目说明书
claude-plugins-validation 说明书
面向 Claude Code 插件、市场、hooks、skills 与 MCP 服务器的全面校验套件。
打开完整说明书- https://github.com/Emasoft/claude-plugins-validation 项目说明书
- 目录
- 说明书章节
- 相关页面
- 项目概述
- 安装方式
- 两种使用模式
06
带给 AI 的上下文包
决定继续后,把项目上下文带给你的宿主 AI。07
继续前检查
在复制命令、导入 AI、安装插件前,看清还不能相信什么。不要把试用当真实运行
试用 Prompt 只展示流程,不证明项目已安装或运行。
确认宿主兼容
支持 MCP 的 AI 宿主、claude_code、claude
先隔离验证
继续完成沙箱验证和证据复核
- 先在非主力宿主配置中验证 MCP server 命令、权限范围和回滚方式。
08
踩坑日志与复核重点
Doramagic 记录的高风险项优先显示,避免用户把候选能力当成已验证能力。失败模式:security_permissions: Canonical pre-push hook: strict publish-ancestry gate forbids ALL branch sharing — allow non-...
需要继续复核。
Developers may expose sensitive permissions or credentials: Canonical pre-push hook: strict publish-ancestry gate forbids ALL branch sharing — allow non-default-branch pushes after secret scan (fleet-stall root cause)
失败模式:security_permissions: skillaudit:agent_manipulation MCP_SCHEMA_POISON false-positive on wikimem memory-note descrip...
需要继续复核。
Developers may expose sensitive permissions or credentials: skillaudit:agent_manipulation MCP_SCHEMA_POISON false-positive on wikimem memory-note description: PROSE (same class as #177 / #156)
失败模式:security_permissions: standardize still strips documented linter suppressions (MD010、CKV_DOCKER_2) — #145 fixed on...
需要继续复核。
Developers may expose sensitive permissions or credentials: standardize still strips documented linter suppressions (MD010、CKV_DOCKER_2) — #145 fixed only MD025; and canon publish.py never creates the {name}--v{version} resolver tag
来源证据:Canonical-pipeline validate step hangs ~30 min AFTER CPV builds (4s) — not #114's cold-build cause; timed-out release s…
GitHub 社区证据显示该项目存在一个安全/权限相关的待验证问题:Canonical-pipeline validate step hangs ~30 min AFTER CPV builds (4s) — not #114's cold-build cause; timed-out release shipped with no assets
可能影响授权、密钥配置或安全边界。
失败模式:installation: Canonical-pipeline validate step hangs ~30 min AFTER CPV builds (4s) — not #114's cold-build...
需要继续复核。
Developers may fail before the first successful local run: Canonical-pipeline validate step hangs ~30 min AFTER CPV builds (4s) — not #114's cold-build cause; timed-out release shipped with no assets
失败模式:installation: Scan dependencies (not just the plugin tree) for agent-context writers、and score capability...
需要继续复核。
Developers may fail before the first successful local run: Scan dependencies (not just the plugin tree) for agent-context writers、and score capability vs live separately
失败模式:installation: feat(canonical-pipeline): gate Rust + shell when a plugin ships them (regen drops them silently)
需要继续复核。
Developers may fail before the first successful local run: feat(canonical-pipeline): gate Rust + shell when a plugin ships them (regen drops them silently)
失败模式:installation: skillaudit:filesystem FS_WRITE false-positive on install-doc PROSE (bash comment naming ~/.zs...
需要继续复核。
Developers may fail before the first successful local run: skillaudit:filesystem FS_WRITE false-positive on install-doc PROSE (bash comment naming ~/.zshrc)
失败模式:installation: v2.158.0: the #165 resolver-tag migration SILENTLY skips 6/13 fleet plugins (anchor regex mis...
需要继续复核。
Developers may fail before the first successful local run: v2.158.0: the #165 resolver-tag migration SILENTLY skips 6/13 fleet plugins (anchor regex misses the two-call push shape); residual signal is a non-blocking WARNING; its remedia...
可能修改宿主 AI 配置
项目面向 Claude/Cursor/Codex/Gemini/OpenCode 等宿主,或安装命令涉及用户配置目录。
安装可能改变本机 AI 工具行为,用户需要知道写入位置和回滚方法。
失败模式:configuration: CC v2.1.207 spec drift: ${user_config.*} in shell-form commands is now REJECTED、and plugin o...
需要继续复核。
Developers may misconfigure credentials、environment、or host setup: CC v2.1.207 spec drift: ${user_config.*} in shell-form commands is now REJECTED、and plugin options are no longer read from project settings.json — CPV has no rule for either
失败模式:configuration: RC-DEP-TAG-PIPELINE false-positives on a correct (manifest-derived) resolver tag — the litera...
需要继续复核。
Developers may misconfigure credentials、environment、or host setup: RC-DEP-TAG-PIPELINE false-positives on a correct (manifest-derived) resolver tag — the literal never appears in publish.py
下一步:先在非主力宿主配置中验证 MCP server 命令、权限范围和回滚方式。。