Marketplace: review a plugin's catalog entry and confirm what it runs (PR review #3, #4)

A plugin's update diff now includes its marketplace.json entry as a
pretty-printed "marketplace.json entry" file, so inline hooks, MCP servers
and commands are reviewed like any file. CatalogItem gains
plugin_components (entry / plugin.json runnable keys, hooks/hooks.json,
.mcp.json, commands/), and installing a plugin now goes through
PluginConfirmModal listing them. The import-preview warnings describe
that confirmation accurately.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
2026-09-27 13:08:15 -07:00
co-authored by Claude Opus 5.5
parent d51b54774b
commit da65d51f09
11 changed files with 365 additions and 38 deletions
@@ -19,6 +19,7 @@ const it_ = (kind: CatalogItem["kind"], key: string, patch: Partial<CatalogItem>
path: key,
invalid: null,
hook_commands: [],
plugin_components: [],
preview: `${key} preview body`,
...patch,
});