chore(21st): drop magic MCP residue

The magic MCP wiring left with BDR-093; this removes the prose that still
described it: gitleaks allowlist note, Step 8.7 header, plugins.lock note,
profile.sh comments and the usage() NOTE that still claimed `set` toggles
"the magic MCP", the managed-set test header, README (one history sentence
kept; MCP-era risk paragraph and the retired bashrc wrapper claim dropped).
.env.example carries the same scrub in the working tree; staging it is
denied to the agent (`git add .env*`), the user stages it.
This commit is contained in:
bastien
2026-09-25 16:06:20 +02:00
parent b40dc1e8d4
commit e1963284d2
6 changed files with 28 additions and 40 deletions
-2
View File
@@ -68,8 +68,6 @@ regexes = [
'''X-Amz-Credential=AKIA[0-9A-Z]{16}''',
'''private-user-images\.githubusercontent\.com/[^"]*\?jwt=''',
# Docs/test example — base64 of the "the ..." ASCII sample text, never a key.
# (The MAGIC_API_KEY=abc123 placeholder that sat here went with the magic
# MCP, removed 2026-09-22 when 21st.dev moved to a CLI with no API key.)
'''clientKey = 'dGhlIH[A-Za-z0-9+/=]*'''',
]
+12 -19
View File
@@ -263,15 +263,12 @@ claude mcp add <name> --scope user --env 'API_KEY=${SOME_API_KEY}' -- <command>
The var still has to exist in the **environment of the process that starts
`claude`** — sourcing `~/.claude/.env` into your everyday interactive shell
would defeat the point (every subprocess, every stray `env`/`printenv`, would
then see it). This repo's `~/.bashrc` instead wraps the `claude` command
itself: a `claude()` shell function sources `~/.claude/.env` into a subshell
and `exec`s the real binary, so the var reaches `claude` and its children only
— never the ambient shell.
then see it). Wrap the `claude` command instead: a `claude()` shell function
that sources `~/.claude/.env` into a subshell and `exec`s the real binary, so
the var reaches `claude` and its children only, never the ambient shell.
This config currently registers no MCP server at all. The one it used to
carry, `@21st-dev/magic`, is gone: 21st.dev replaced it with a plain CLI (see
below), so there is no key left to protect by reference. The pattern stays
documented for the next MCP server that needs a secret.
This config registers no MCP server today. The pattern stays documented for
the next one that needs a secret.
There is no `claude mcp add` flag that writes the reference form for you —
the `${VAR}` syntax has to be typed by hand (or via a wrapper script), same as
@@ -297,11 +294,12 @@ Then run the one-time consent flow: `make seo-connect` (per-label token
store, multi-site safe). Missing credentials never break an audit — `/seo`
degrades gracefully to anonymous PageSpeed lab data.
### 21st.dev CLI (replaces the magic MCP)
### 21st.dev CLI
`@21st-dev/cli` (bin `21st`) supersedes the `@21st-dev/magic` MCP server that
this config used to register. Same endpoint, one browser login, no API key,
and nothing loaded into a session that isn't using it:
`@21st-dev/cli` (bin `21st`) is the 21st.dev integration; it replaced the
former Magic MCP server this config used to register. Same endpoint, one
browser login, no API key, and nothing loaded into a session that isn't using
it:
```bash
npm i -g @21st-dev/cli
@@ -312,8 +310,8 @@ npm i -g @21st-dev/cli
an interactive terminal) and installs the skill pack that drives it:
`21st-ui-build`, `-ui-explore`, `-ui-review`, `-cli-use`, `-ai`, plus the two
publishing skills `-registry` and `-design-sync`. The pack is disabled by
default, the same policy the MCP had. `/profile design` turns on the five
design skills; `bash lib/toggle-external.sh enable 21st` turns on all seven.
default. `/profile design` turns on the five design skills;
`bash lib/toggle-external.sh enable 21st` turns on all seven.
The pack is machine-owned and gitignored. It cannot be installed the way
upstream documents it (`21st install-skill`, i.e. `21st skills install
@@ -323,11 +321,6 @@ symlink to this repo's `skills/`. So the install runs under a throwaway `HOME`
and the result is moved into `skills-external/21st-*`, where
`toggle-external.sh` and `profile.sh` symlink it in on demand.
Two risks from the MCP era go away with it. The unauthenticated local callback
server `21st_magic_component_builder` opened (`127.0.0.1:9221+`, CORS `*`, a
10-minute local prompt-injection window, job8 audit / LRN-110). And the API
key that `claude mcp add --env` materialized into `~/.claude.json`.
The permission gate is now one `autoMode.soft_deny` entry covering the
outward-facing verbs (`21st publish*`, `submit`, `edit`, `delete`,
`remove-from-catalog`, `profile set|upload`), because publishing a component
+3 -3
View File
@@ -954,9 +954,9 @@ echo ""
# ============================================================
# STEP 8.7 — 21ST.DEV CLI + SKILL PACK — installed but DISABLED by default
# ============================================================
# `@21st-dev/cli` (bin `21st`) supersedes the `@21st-dev/magic` MCP server:
# same endpoint, one browser login (`21st login`, token in ~/.config/21st),
# no API key, no MCP process loaded into every session. It ships a pack of
# `@21st-dev/cli` (bin `21st`): one browser login (`21st login`, token in
# ~/.config/21st), no API key, no MCP process loaded into every session. It
# ships a pack of
# verified skills (21st-ui-build / -explore / -review / -cli-use / -ai /
# -registry / -design-sync) that drive the CLI from Claude Code.
#
+9 -11
View File
@@ -81,9 +81,8 @@ MANAGED_EXTERNALS=(
# MCP servers that are toggle-managed by `set`, both ways (enable AND
# disable), delegated to lib/toggle-external.sh. Same allowlist doctrine.
# Empty since 2026-09-22: `magic` was the only entry and 21st.dev replaced
# its MCP server with a CLI + skill pack (the 5 design skills are managed as
# externals above). The `mcp` type itself stays supported — a profile can
# Empty: no MCP server is managed today (the 21st design skills are managed
# as externals above). The `mcp` type itself stays supported — a profile can
# still list an MCP, it is then advisory rather than auto-toggled.
MANAGED_MCPS=()
@@ -330,10 +329,8 @@ enable_skill() {
fi
;;
mcp)
# Advisory only. The delegation branch that lived here served `magic`,
# the single managed MCP; 21st.dev replaced it with a CLI (BDR-093), so
# MANAGED_MCPS is empty and nothing is auto-registered. Re-add a branch
# here the day a profile owns an MCP server again.
# Advisory only: MANAGED_MCPS is empty, nothing is auto-registered.
# Re-add a delegation branch here the day a profile owns an MCP server.
if [ "$(skill_status "$skill" mcp)" = "enabled" ]; then
: # already on
else
@@ -579,7 +576,7 @@ cmd_set() {
# Symmetry (BDR-079): a profile switch also parks the managed external
# packs and unregisters the managed MCPs the new profile does not need —
# design leftovers (emil, magic…) no longer survive a `set backend`.
# design leftovers (emil, the 21st pack…) no longer survive a `set backend`.
disable_externals_not_in "$prof"
disable_mcps_not_in "$prof"
@@ -739,9 +736,10 @@ EXAMPLES:
NOTE:
"set" toggles the MANAGED items automatically, both ways: plugins
(ui-ux-pro-max, plugin-dev, pr-review-toolkit), external packs
(emil-design-eng, frontend-design, design-motion-principles, impeccable)
and the magic MCP. Anything outside those allowlists stays advisory —
run "claude plugin enable|disable" or "claude mcp add|remove" yourself.
(emil-design-eng, frontend-design, design-motion-principles, impeccable,
the five 21st design skills). Anything outside those allowlists stays
advisory — run "claude plugin enable|disable" or
"bash lib/toggle-external.sh enable|disable <tool>" yourself.
EOF
}
+3 -4
View File
@@ -1,9 +1,8 @@
#!/usr/bin/env bash
# lib/tests/profile-set-managed.test.sh — `set` symmetry on managed
# externals, gstack on-demand, external from-source (BDR-079). The MCP
# assertions went with `magic` (2026-09-22): MANAGED_MCPS is empty now, the
# 21st skills that replaced it are managed as externals, so the pack's
# park/restore round-trip is what this covers on that side.
# externals, gstack on-demand, external from-source (BDR-079). No MCP is
# managed (MANAGED_MCPS is empty): the 21st skills are managed as externals,
# so the pack's park/restore round-trip is what this covers on that side.
# Hermetic: fixture repo via *_REPO_OVERRIDE + fake `claude` on PATH.
set -u
ROOT="$(cd "$(dirname "$0")/../.." && pwd)"
+1 -1
View File
@@ -23,7 +23,7 @@
"21st": {
"source": "npm:@21st-dev/cli",
"version": "latest",
"note": "21st.dev CLI (bin `21st`) — supersedes the @21st-dev/magic MCP server (2026-09-22). Standalone CLI + a pack of 7 skills, no MCP, no API key: auth is `21st login` (browser token in ~/.config/21st). Install: npm install -g @21st-dev/cli. The skill pack is staged-installed into skills-external/21st-* by install-plugins.sh Step 8.7 — `21st skills install` refuses to write through the ~/.claude/skills symlink."
"note": "21st.dev CLI (bin `21st`) — standalone CLI + a pack of 7 skills, no MCP, no API key: auth is `21st login` (browser token in ~/.config/21st). Install: npm install -g @21st-dev/cli. The skill pack is staged-installed into skills-external/21st-* by install-plugins.sh Step 8.7 — `21st skills install` refuses to write through the ~/.claude/skills symlink."
},
"graphifyy": {
"source": "pypi:graphifyy",