chore(21st): drop magic MCP residue
The magic MCP wiring left with BDR-093; this removes the prose that still described it: gitleaks allowlist note, Step 8.7 header, plugins.lock note, profile.sh comments and the usage() NOTE that still claimed `set` toggles "the magic MCP", the managed-set test header, README (one history sentence kept; MCP-era risk paragraph and the retired bashrc wrapper claim dropped). .env.example carries the same scrub in the working tree; staging it is denied to the agent (`git add .env*`), the user stages it.
This commit is contained in:
@@ -68,8 +68,6 @@ regexes = [
|
|||||||
'''X-Amz-Credential=AKIA[0-9A-Z]{16}''',
|
'''X-Amz-Credential=AKIA[0-9A-Z]{16}''',
|
||||||
'''private-user-images\.githubusercontent\.com/[^"]*\?jwt=''',
|
'''private-user-images\.githubusercontent\.com/[^"]*\?jwt=''',
|
||||||
# Docs/test example — base64 of the "the ..." ASCII sample text, never a key.
|
# Docs/test example — base64 of the "the ..." ASCII sample text, never a key.
|
||||||
# (The MAGIC_API_KEY=abc123 placeholder that sat here went with the magic
|
|
||||||
# MCP, removed 2026-09-22 when 21st.dev moved to a CLI with no API key.)
|
|
||||||
'''clientKey = 'dGhlIH[A-Za-z0-9+/=]*'''',
|
'''clientKey = 'dGhlIH[A-Za-z0-9+/=]*'''',
|
||||||
]
|
]
|
||||||
|
|
||||||
|
|||||||
@@ -263,15 +263,12 @@ claude mcp add <name> --scope user --env 'API_KEY=${SOME_API_KEY}' -- <command>
|
|||||||
The var still has to exist in the **environment of the process that starts
|
The var still has to exist in the **environment of the process that starts
|
||||||
`claude`** — sourcing `~/.claude/.env` into your everyday interactive shell
|
`claude`** — sourcing `~/.claude/.env` into your everyday interactive shell
|
||||||
would defeat the point (every subprocess, every stray `env`/`printenv`, would
|
would defeat the point (every subprocess, every stray `env`/`printenv`, would
|
||||||
then see it). This repo's `~/.bashrc` instead wraps the `claude` command
|
then see it). Wrap the `claude` command instead: a `claude()` shell function
|
||||||
itself: a `claude()` shell function sources `~/.claude/.env` into a subshell
|
that sources `~/.claude/.env` into a subshell and `exec`s the real binary, so
|
||||||
and `exec`s the real binary, so the var reaches `claude` and its children only
|
the var reaches `claude` and its children only, never the ambient shell.
|
||||||
— never the ambient shell.
|
|
||||||
|
|
||||||
This config currently registers no MCP server at all. The one it used to
|
This config registers no MCP server today. The pattern stays documented for
|
||||||
carry, `@21st-dev/magic`, is gone: 21st.dev replaced it with a plain CLI (see
|
the next one that needs a secret.
|
||||||
below), so there is no key left to protect by reference. The pattern stays
|
|
||||||
documented for the next MCP server that needs a secret.
|
|
||||||
|
|
||||||
There is no `claude mcp add` flag that writes the reference form for you —
|
There is no `claude mcp add` flag that writes the reference form for you —
|
||||||
the `${VAR}` syntax has to be typed by hand (or via a wrapper script), same as
|
the `${VAR}` syntax has to be typed by hand (or via a wrapper script), same as
|
||||||
@@ -297,11 +294,12 @@ Then run the one-time consent flow: `make seo-connect` (per-label token
|
|||||||
store, multi-site safe). Missing credentials never break an audit — `/seo`
|
store, multi-site safe). Missing credentials never break an audit — `/seo`
|
||||||
degrades gracefully to anonymous PageSpeed lab data.
|
degrades gracefully to anonymous PageSpeed lab data.
|
||||||
|
|
||||||
### 21st.dev CLI (replaces the magic MCP)
|
### 21st.dev CLI
|
||||||
|
|
||||||
`@21st-dev/cli` (bin `21st`) supersedes the `@21st-dev/magic` MCP server that
|
`@21st-dev/cli` (bin `21st`) is the 21st.dev integration; it replaced the
|
||||||
this config used to register. Same endpoint, one browser login, no API key,
|
former Magic MCP server this config used to register. Same endpoint, one
|
||||||
and nothing loaded into a session that isn't using it:
|
browser login, no API key, and nothing loaded into a session that isn't using
|
||||||
|
it:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
npm i -g @21st-dev/cli
|
npm i -g @21st-dev/cli
|
||||||
@@ -312,8 +310,8 @@ npm i -g @21st-dev/cli
|
|||||||
an interactive terminal) and installs the skill pack that drives it:
|
an interactive terminal) and installs the skill pack that drives it:
|
||||||
`21st-ui-build`, `-ui-explore`, `-ui-review`, `-cli-use`, `-ai`, plus the two
|
`21st-ui-build`, `-ui-explore`, `-ui-review`, `-cli-use`, `-ai`, plus the two
|
||||||
publishing skills `-registry` and `-design-sync`. The pack is disabled by
|
publishing skills `-registry` and `-design-sync`. The pack is disabled by
|
||||||
default, the same policy the MCP had. `/profile design` turns on the five
|
default. `/profile design` turns on the five design skills;
|
||||||
design skills; `bash lib/toggle-external.sh enable 21st` turns on all seven.
|
`bash lib/toggle-external.sh enable 21st` turns on all seven.
|
||||||
|
|
||||||
The pack is machine-owned and gitignored. It cannot be installed the way
|
The pack is machine-owned and gitignored. It cannot be installed the way
|
||||||
upstream documents it (`21st install-skill`, i.e. `21st skills install
|
upstream documents it (`21st install-skill`, i.e. `21st skills install
|
||||||
@@ -323,11 +321,6 @@ symlink to this repo's `skills/`. So the install runs under a throwaway `HOME`
|
|||||||
and the result is moved into `skills-external/21st-*`, where
|
and the result is moved into `skills-external/21st-*`, where
|
||||||
`toggle-external.sh` and `profile.sh` symlink it in on demand.
|
`toggle-external.sh` and `profile.sh` symlink it in on demand.
|
||||||
|
|
||||||
Two risks from the MCP era go away with it. The unauthenticated local callback
|
|
||||||
server `21st_magic_component_builder` opened (`127.0.0.1:9221+`, CORS `*`, a
|
|
||||||
10-minute local prompt-injection window, job8 audit / LRN-110). And the API
|
|
||||||
key that `claude mcp add --env` materialized into `~/.claude.json`.
|
|
||||||
|
|
||||||
The permission gate is now one `autoMode.soft_deny` entry covering the
|
The permission gate is now one `autoMode.soft_deny` entry covering the
|
||||||
outward-facing verbs (`21st publish*`, `submit`, `edit`, `delete`,
|
outward-facing verbs (`21st publish*`, `submit`, `edit`, `delete`,
|
||||||
`remove-from-catalog`, `profile set|upload`), because publishing a component
|
`remove-from-catalog`, `profile set|upload`), because publishing a component
|
||||||
|
|||||||
+3
-3
@@ -954,9 +954,9 @@ echo ""
|
|||||||
# ============================================================
|
# ============================================================
|
||||||
# STEP 8.7 — 21ST.DEV CLI + SKILL PACK — installed but DISABLED by default
|
# STEP 8.7 — 21ST.DEV CLI + SKILL PACK — installed but DISABLED by default
|
||||||
# ============================================================
|
# ============================================================
|
||||||
# `@21st-dev/cli` (bin `21st`) supersedes the `@21st-dev/magic` MCP server:
|
# `@21st-dev/cli` (bin `21st`): one browser login (`21st login`, token in
|
||||||
# same endpoint, one browser login (`21st login`, token in ~/.config/21st),
|
# ~/.config/21st), no API key, no MCP process loaded into every session. It
|
||||||
# no API key, no MCP process loaded into every session. It ships a pack of
|
# ships a pack of
|
||||||
# verified skills (21st-ui-build / -explore / -review / -cli-use / -ai /
|
# verified skills (21st-ui-build / -explore / -review / -cli-use / -ai /
|
||||||
# -registry / -design-sync) that drive the CLI from Claude Code.
|
# -registry / -design-sync) that drive the CLI from Claude Code.
|
||||||
#
|
#
|
||||||
|
|||||||
+9
-11
@@ -81,9 +81,8 @@ MANAGED_EXTERNALS=(
|
|||||||
|
|
||||||
# MCP servers that are toggle-managed by `set`, both ways (enable AND
|
# MCP servers that are toggle-managed by `set`, both ways (enable AND
|
||||||
# disable), delegated to lib/toggle-external.sh. Same allowlist doctrine.
|
# disable), delegated to lib/toggle-external.sh. Same allowlist doctrine.
|
||||||
# Empty since 2026-09-22: `magic` was the only entry and 21st.dev replaced
|
# Empty: no MCP server is managed today (the 21st design skills are managed
|
||||||
# its MCP server with a CLI + skill pack (the 5 design skills are managed as
|
# as externals above). The `mcp` type itself stays supported — a profile can
|
||||||
# externals above). The `mcp` type itself stays supported — a profile can
|
|
||||||
# still list an MCP, it is then advisory rather than auto-toggled.
|
# still list an MCP, it is then advisory rather than auto-toggled.
|
||||||
MANAGED_MCPS=()
|
MANAGED_MCPS=()
|
||||||
|
|
||||||
@@ -330,10 +329,8 @@ enable_skill() {
|
|||||||
fi
|
fi
|
||||||
;;
|
;;
|
||||||
mcp)
|
mcp)
|
||||||
# Advisory only. The delegation branch that lived here served `magic`,
|
# Advisory only: MANAGED_MCPS is empty, nothing is auto-registered.
|
||||||
# the single managed MCP; 21st.dev replaced it with a CLI (BDR-093), so
|
# Re-add a delegation branch here the day a profile owns an MCP server.
|
||||||
# MANAGED_MCPS is empty and nothing is auto-registered. Re-add a branch
|
|
||||||
# here the day a profile owns an MCP server again.
|
|
||||||
if [ "$(skill_status "$skill" mcp)" = "enabled" ]; then
|
if [ "$(skill_status "$skill" mcp)" = "enabled" ]; then
|
||||||
: # already on
|
: # already on
|
||||||
else
|
else
|
||||||
@@ -579,7 +576,7 @@ cmd_set() {
|
|||||||
|
|
||||||
# Symmetry (BDR-079): a profile switch also parks the managed external
|
# Symmetry (BDR-079): a profile switch also parks the managed external
|
||||||
# packs and unregisters the managed MCPs the new profile does not need —
|
# packs and unregisters the managed MCPs the new profile does not need —
|
||||||
# design leftovers (emil, magic…) no longer survive a `set backend`.
|
# design leftovers (emil, the 21st pack…) no longer survive a `set backend`.
|
||||||
disable_externals_not_in "$prof"
|
disable_externals_not_in "$prof"
|
||||||
disable_mcps_not_in "$prof"
|
disable_mcps_not_in "$prof"
|
||||||
|
|
||||||
@@ -739,9 +736,10 @@ EXAMPLES:
|
|||||||
NOTE:
|
NOTE:
|
||||||
"set" toggles the MANAGED items automatically, both ways: plugins
|
"set" toggles the MANAGED items automatically, both ways: plugins
|
||||||
(ui-ux-pro-max, plugin-dev, pr-review-toolkit), external packs
|
(ui-ux-pro-max, plugin-dev, pr-review-toolkit), external packs
|
||||||
(emil-design-eng, frontend-design, design-motion-principles, impeccable)
|
(emil-design-eng, frontend-design, design-motion-principles, impeccable,
|
||||||
and the magic MCP. Anything outside those allowlists stays advisory —
|
the five 21st design skills). Anything outside those allowlists stays
|
||||||
run "claude plugin enable|disable" or "claude mcp add|remove" yourself.
|
advisory — run "claude plugin enable|disable" or
|
||||||
|
"bash lib/toggle-external.sh enable|disable <tool>" yourself.
|
||||||
EOF
|
EOF
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -1,9 +1,8 @@
|
|||||||
#!/usr/bin/env bash
|
#!/usr/bin/env bash
|
||||||
# lib/tests/profile-set-managed.test.sh — `set` symmetry on managed
|
# lib/tests/profile-set-managed.test.sh — `set` symmetry on managed
|
||||||
# externals, gstack on-demand, external from-source (BDR-079). The MCP
|
# externals, gstack on-demand, external from-source (BDR-079). No MCP is
|
||||||
# assertions went with `magic` (2026-09-22): MANAGED_MCPS is empty now, the
|
# managed (MANAGED_MCPS is empty): the 21st skills are managed as externals,
|
||||||
# 21st skills that replaced it are managed as externals, so the pack's
|
# so the pack's park/restore round-trip is what this covers on that side.
|
||||||
# park/restore round-trip is what this covers on that side.
|
|
||||||
# Hermetic: fixture repo via *_REPO_OVERRIDE + fake `claude` on PATH.
|
# Hermetic: fixture repo via *_REPO_OVERRIDE + fake `claude` on PATH.
|
||||||
set -u
|
set -u
|
||||||
ROOT="$(cd "$(dirname "$0")/../.." && pwd)"
|
ROOT="$(cd "$(dirname "$0")/../.." && pwd)"
|
||||||
|
|||||||
+1
-1
@@ -23,7 +23,7 @@
|
|||||||
"21st": {
|
"21st": {
|
||||||
"source": "npm:@21st-dev/cli",
|
"source": "npm:@21st-dev/cli",
|
||||||
"version": "latest",
|
"version": "latest",
|
||||||
"note": "21st.dev CLI (bin `21st`) — supersedes the @21st-dev/magic MCP server (2026-09-22). Standalone CLI + a pack of 7 skills, no MCP, no API key: auth is `21st login` (browser token in ~/.config/21st). Install: npm install -g @21st-dev/cli. The skill pack is staged-installed into skills-external/21st-* by install-plugins.sh Step 8.7 — `21st skills install` refuses to write through the ~/.claude/skills symlink."
|
"note": "21st.dev CLI (bin `21st`) — standalone CLI + a pack of 7 skills, no MCP, no API key: auth is `21st login` (browser token in ~/.config/21st). Install: npm install -g @21st-dev/cli. The skill pack is staged-installed into skills-external/21st-* by install-plugins.sh Step 8.7 — `21st skills install` refuses to write through the ~/.claude/skills symlink."
|
||||||
},
|
},
|
||||||
"graphifyy": {
|
"graphifyy": {
|
||||||
"source": "pypi:graphifyy",
|
"source": "pypi:graphifyy",
|
||||||
|
|||||||
Reference in New Issue
Block a user