chore(21st): drop magic MCP residue

The magic MCP wiring left with BDR-093; this removes the prose that still
described it: gitleaks allowlist note, Step 8.7 header, plugins.lock note,
profile.sh comments and the usage() NOTE that still claimed `set` toggles
"the magic MCP", the managed-set test header, README (one history sentence
kept; MCP-era risk paragraph and the retired bashrc wrapper claim dropped).
.env.example carries the same scrub in the working tree; staging it is
denied to the agent (`git add .env*`), the user stages it.
This commit is contained in:
bastien
2026-09-25 16:06:20 +02:00
parent b40dc1e8d4
commit e1963284d2
6 changed files with 28 additions and 40 deletions
-2
View File
@@ -68,8 +68,6 @@ regexes = [
'''X-Amz-Credential=AKIA[0-9A-Z]{16}''', '''X-Amz-Credential=AKIA[0-9A-Z]{16}''',
'''private-user-images\.githubusercontent\.com/[^"]*\?jwt=''', '''private-user-images\.githubusercontent\.com/[^"]*\?jwt=''',
# Docs/test example — base64 of the "the ..." ASCII sample text, never a key. # Docs/test example — base64 of the "the ..." ASCII sample text, never a key.
# (The MAGIC_API_KEY=abc123 placeholder that sat here went with the magic
# MCP, removed 2026-09-22 when 21st.dev moved to a CLI with no API key.)
'''clientKey = 'dGhlIH[A-Za-z0-9+/=]*'''', '''clientKey = 'dGhlIH[A-Za-z0-9+/=]*'''',
] ]
+12 -19
View File
@@ -263,15 +263,12 @@ claude mcp add <name> --scope user --env 'API_KEY=${SOME_API_KEY}' -- <command>
The var still has to exist in the **environment of the process that starts The var still has to exist in the **environment of the process that starts
`claude`** — sourcing `~/.claude/.env` into your everyday interactive shell `claude`** — sourcing `~/.claude/.env` into your everyday interactive shell
would defeat the point (every subprocess, every stray `env`/`printenv`, would would defeat the point (every subprocess, every stray `env`/`printenv`, would
then see it). This repo's `~/.bashrc` instead wraps the `claude` command then see it). Wrap the `claude` command instead: a `claude()` shell function
itself: a `claude()` shell function sources `~/.claude/.env` into a subshell that sources `~/.claude/.env` into a subshell and `exec`s the real binary, so
and `exec`s the real binary, so the var reaches `claude` and its children only the var reaches `claude` and its children only, never the ambient shell.
— never the ambient shell.
This config currently registers no MCP server at all. The one it used to This config registers no MCP server today. The pattern stays documented for
carry, `@21st-dev/magic`, is gone: 21st.dev replaced it with a plain CLI (see the next one that needs a secret.
below), so there is no key left to protect by reference. The pattern stays
documented for the next MCP server that needs a secret.
There is no `claude mcp add` flag that writes the reference form for you — There is no `claude mcp add` flag that writes the reference form for you —
the `${VAR}` syntax has to be typed by hand (or via a wrapper script), same as the `${VAR}` syntax has to be typed by hand (or via a wrapper script), same as
@@ -297,11 +294,12 @@ Then run the one-time consent flow: `make seo-connect` (per-label token
store, multi-site safe). Missing credentials never break an audit — `/seo` store, multi-site safe). Missing credentials never break an audit — `/seo`
degrades gracefully to anonymous PageSpeed lab data. degrades gracefully to anonymous PageSpeed lab data.
### 21st.dev CLI (replaces the magic MCP) ### 21st.dev CLI
`@21st-dev/cli` (bin `21st`) supersedes the `@21st-dev/magic` MCP server that `@21st-dev/cli` (bin `21st`) is the 21st.dev integration; it replaced the
this config used to register. Same endpoint, one browser login, no API key, former Magic MCP server this config used to register. Same endpoint, one
and nothing loaded into a session that isn't using it: browser login, no API key, and nothing loaded into a session that isn't using
it:
```bash ```bash
npm i -g @21st-dev/cli npm i -g @21st-dev/cli
@@ -312,8 +310,8 @@ npm i -g @21st-dev/cli
an interactive terminal) and installs the skill pack that drives it: an interactive terminal) and installs the skill pack that drives it:
`21st-ui-build`, `-ui-explore`, `-ui-review`, `-cli-use`, `-ai`, plus the two `21st-ui-build`, `-ui-explore`, `-ui-review`, `-cli-use`, `-ai`, plus the two
publishing skills `-registry` and `-design-sync`. The pack is disabled by publishing skills `-registry` and `-design-sync`. The pack is disabled by
default, the same policy the MCP had. `/profile design` turns on the five default. `/profile design` turns on the five design skills;
design skills; `bash lib/toggle-external.sh enable 21st` turns on all seven. `bash lib/toggle-external.sh enable 21st` turns on all seven.
The pack is machine-owned and gitignored. It cannot be installed the way The pack is machine-owned and gitignored. It cannot be installed the way
upstream documents it (`21st install-skill`, i.e. `21st skills install upstream documents it (`21st install-skill`, i.e. `21st skills install
@@ -323,11 +321,6 @@ symlink to this repo's `skills/`. So the install runs under a throwaway `HOME`
and the result is moved into `skills-external/21st-*`, where and the result is moved into `skills-external/21st-*`, where
`toggle-external.sh` and `profile.sh` symlink it in on demand. `toggle-external.sh` and `profile.sh` symlink it in on demand.
Two risks from the MCP era go away with it. The unauthenticated local callback
server `21st_magic_component_builder` opened (`127.0.0.1:9221+`, CORS `*`, a
10-minute local prompt-injection window, job8 audit / LRN-110). And the API
key that `claude mcp add --env` materialized into `~/.claude.json`.
The permission gate is now one `autoMode.soft_deny` entry covering the The permission gate is now one `autoMode.soft_deny` entry covering the
outward-facing verbs (`21st publish*`, `submit`, `edit`, `delete`, outward-facing verbs (`21st publish*`, `submit`, `edit`, `delete`,
`remove-from-catalog`, `profile set|upload`), because publishing a component `remove-from-catalog`, `profile set|upload`), because publishing a component
+3 -3
View File
@@ -954,9 +954,9 @@ echo ""
# ============================================================ # ============================================================
# STEP 8.7 — 21ST.DEV CLI + SKILL PACK — installed but DISABLED by default # STEP 8.7 — 21ST.DEV CLI + SKILL PACK — installed but DISABLED by default
# ============================================================ # ============================================================
# `@21st-dev/cli` (bin `21st`) supersedes the `@21st-dev/magic` MCP server: # `@21st-dev/cli` (bin `21st`): one browser login (`21st login`, token in
# same endpoint, one browser login (`21st login`, token in ~/.config/21st), # ~/.config/21st), no API key, no MCP process loaded into every session. It
# no API key, no MCP process loaded into every session. It ships a pack of # ships a pack of
# verified skills (21st-ui-build / -explore / -review / -cli-use / -ai / # verified skills (21st-ui-build / -explore / -review / -cli-use / -ai /
# -registry / -design-sync) that drive the CLI from Claude Code. # -registry / -design-sync) that drive the CLI from Claude Code.
# #
+9 -11
View File
@@ -81,9 +81,8 @@ MANAGED_EXTERNALS=(
# MCP servers that are toggle-managed by `set`, both ways (enable AND # MCP servers that are toggle-managed by `set`, both ways (enable AND
# disable), delegated to lib/toggle-external.sh. Same allowlist doctrine. # disable), delegated to lib/toggle-external.sh. Same allowlist doctrine.
# Empty since 2026-09-22: `magic` was the only entry and 21st.dev replaced # Empty: no MCP server is managed today (the 21st design skills are managed
# its MCP server with a CLI + skill pack (the 5 design skills are managed as # as externals above). The `mcp` type itself stays supported — a profile can
# externals above). The `mcp` type itself stays supported — a profile can
# still list an MCP, it is then advisory rather than auto-toggled. # still list an MCP, it is then advisory rather than auto-toggled.
MANAGED_MCPS=() MANAGED_MCPS=()
@@ -330,10 +329,8 @@ enable_skill() {
fi fi
;; ;;
mcp) mcp)
# Advisory only. The delegation branch that lived here served `magic`, # Advisory only: MANAGED_MCPS is empty, nothing is auto-registered.
# the single managed MCP; 21st.dev replaced it with a CLI (BDR-093), so # Re-add a delegation branch here the day a profile owns an MCP server.
# MANAGED_MCPS is empty and nothing is auto-registered. Re-add a branch
# here the day a profile owns an MCP server again.
if [ "$(skill_status "$skill" mcp)" = "enabled" ]; then if [ "$(skill_status "$skill" mcp)" = "enabled" ]; then
: # already on : # already on
else else
@@ -579,7 +576,7 @@ cmd_set() {
# Symmetry (BDR-079): a profile switch also parks the managed external # Symmetry (BDR-079): a profile switch also parks the managed external
# packs and unregisters the managed MCPs the new profile does not need — # packs and unregisters the managed MCPs the new profile does not need —
# design leftovers (emil, magic…) no longer survive a `set backend`. # design leftovers (emil, the 21st pack…) no longer survive a `set backend`.
disable_externals_not_in "$prof" disable_externals_not_in "$prof"
disable_mcps_not_in "$prof" disable_mcps_not_in "$prof"
@@ -739,9 +736,10 @@ EXAMPLES:
NOTE: NOTE:
"set" toggles the MANAGED items automatically, both ways: plugins "set" toggles the MANAGED items automatically, both ways: plugins
(ui-ux-pro-max, plugin-dev, pr-review-toolkit), external packs (ui-ux-pro-max, plugin-dev, pr-review-toolkit), external packs
(emil-design-eng, frontend-design, design-motion-principles, impeccable) (emil-design-eng, frontend-design, design-motion-principles, impeccable,
and the magic MCP. Anything outside those allowlists stays advisory — the five 21st design skills). Anything outside those allowlists stays
run "claude plugin enable|disable" or "claude mcp add|remove" yourself. advisory — run "claude plugin enable|disable" or
"bash lib/toggle-external.sh enable|disable <tool>" yourself.
EOF EOF
} }
+3 -4
View File
@@ -1,9 +1,8 @@
#!/usr/bin/env bash #!/usr/bin/env bash
# lib/tests/profile-set-managed.test.sh — `set` symmetry on managed # lib/tests/profile-set-managed.test.sh — `set` symmetry on managed
# externals, gstack on-demand, external from-source (BDR-079). The MCP # externals, gstack on-demand, external from-source (BDR-079). No MCP is
# assertions went with `magic` (2026-09-22): MANAGED_MCPS is empty now, the # managed (MANAGED_MCPS is empty): the 21st skills are managed as externals,
# 21st skills that replaced it are managed as externals, so the pack's # so the pack's park/restore round-trip is what this covers on that side.
# park/restore round-trip is what this covers on that side.
# Hermetic: fixture repo via *_REPO_OVERRIDE + fake `claude` on PATH. # Hermetic: fixture repo via *_REPO_OVERRIDE + fake `claude` on PATH.
set -u set -u
ROOT="$(cd "$(dirname "$0")/../.." && pwd)" ROOT="$(cd "$(dirname "$0")/../.." && pwd)"
+1 -1
View File
@@ -23,7 +23,7 @@
"21st": { "21st": {
"source": "npm:@21st-dev/cli", "source": "npm:@21st-dev/cli",
"version": "latest", "version": "latest",
"note": "21st.dev CLI (bin `21st`) — supersedes the @21st-dev/magic MCP server (2026-09-22). Standalone CLI + a pack of 7 skills, no MCP, no API key: auth is `21st login` (browser token in ~/.config/21st). Install: npm install -g @21st-dev/cli. The skill pack is staged-installed into skills-external/21st-* by install-plugins.sh Step 8.7 — `21st skills install` refuses to write through the ~/.claude/skills symlink." "note": "21st.dev CLI (bin `21st`) — standalone CLI + a pack of 7 skills, no MCP, no API key: auth is `21st login` (browser token in ~/.config/21st). Install: npm install -g @21st-dev/cli. The skill pack is staged-installed into skills-external/21st-* by install-plugins.sh Step 8.7 — `21st skills install` refuses to write through the ~/.claude/skills symlink."
}, },
"graphifyy": { "graphifyy": {
"source": "pypi:graphifyy", "source": "pypi:graphifyy",