Harden ContextStream plugin for Grok Bot marketplace - #2
Conversation
Add source-backed project briefs, decision checks, and approval-gated handoffs. Include a Grok Bot profile, synthetic demo, data-handling documentation, manual acceptance gates, and marketplace launch guidance. Add a dependency-free package validator, 27 regression tests, and CI. Retain the hosted MCP configuration and existing branding. Live Grok compatibility and marketplace approval remain explicitly unverified.
Pre-submission review — hold marketplace submissionI reviewed the package against the public MCP implementation at Candidate improvements
Local results for the candidate, not the current PR
These results do not establish actual Grok installation, browser OAuth, permission enforcement, retrieval quality, or end-to-end behavior. No live client tests were performed. The candidate defines 24 live acceptance scenarios, with 34 trials per client including repeated continuity tests, to be recorded separately for Cursor and Grok. Submission blockersReal client installation/skill discovery, OAuth, cited first answers, cross-session/cross-tool reuse, backend access revocation and write restrictions, approved-save recovery, public-template privacy, and applicable data-retention behavior still require evidence. The existing logo also needs maintainer review before submission. Do not treat a package check or an MCP tools-list response as proof that those journeys work. No marketplace submission, Bot publication, merge, backend change, or customer-data operation was performed. |
Expand ContextStream from three to seven focused marketplace skills, add first-run guidance, capability mapping, evaluation scenarios, a runnable synthetic demo, metadata-only MCP probing, and a fail-closed release evidence gate. Strengthen packaging validation around duplicate JSON keys, unreviewed executable components, skill discovery, size budgets, and scenario coverage. Add broader regression tests and a two-platform CI matrix. Live Grok OAuth, project authorization, marketplace approval, and end-to-end workflow behavior remain release-gated and unverified by this commit.
Summary
Prepare ContextStream's existing marketplace plugin to become a strong shared-context layer for Grok Bot and Cursor while keeping public compatibility claims behind explicit live-validation gates.
Product experience
context-checkproject-briefdecision-checkproject-resumechange-impactproject-handoffmemory-reviewValidation and release hardening
tools/call; protocol success is explicitly not treated as workflow success.Security and trust boundaries
Locally prepared validation
The complete review candidate was exercised locally before this push with package validation, regression/negative tests, protocol fakes, release-gate tests, synthetic exporter tests, Python compilation, and whitespace checks. The earlier review candidate reported 87 regression tests plus 6 synthetic demo tests passing. GitHub-hosted CI for this exact pushed commit must be treated as authoritative for the repository state and is currently running/queued separately.
Required before marketplace submission or public compatibility claims
.mdcbehavior transfers automatically.A merged GitHub PR, Cursor plugin approval, Grok compatibility, a public Bot share link, curated directory inclusion, and featured placement are separate milestones. This PR does not submit to a marketplace or publish a Bot.
Review starting points
skills/*/SKILL.md— seven user workflowsbots/project-brief-handoff.md— proposed Bot behaviordocs/first-run.md— first useful experiencedocs/capability-map.md— mapping to current ContextStream capabilitiesevaluation/scenarios.json— live acceptance catalogscripts/check_release.py— evidence/release gatescripts/probe_mcp.py— metadata-only protocol diagnosticdocs/manual-validation.md— live test recorddocs/marketplace-launch.md— submission and distribution gates