feat(21st): replace the magic MCP with the @21st-dev CLI + skill pack

Upstream supersedes `@21st-dev/magic` with `@21st-dev/cli` (bin `21st`):
same endpoint, `21st login` in place of an API key, no MCP process loaded
into every session.

- install-plugins.sh Step 8.7: `npm i -g @21st-dev/cli` (pinned in
  plugins.lock.json), staged `21st skills install`, TTY-only login offer,
  pack disabled by default. update-all.sh 7.4 refreshes both.
- The documented `21st install-skill` cannot be used: the installer refuses
  to follow a symlink on the target path and `~/.claude/skills` is one. The
  install runs under a throwaway HOME and the result moves into
  skills-external/21st-* (gitignored), symlinked on demand.
- toggle-external.sh manages `21st` as a pack (names globbed from
  skills-external/21st-*, parked under plain names). `magic` is gone.
- The 5 design skills join design/web/web-full/full and MANAGED_EXTERNALS;
  21st-registry and 21st-design-sync stay parked. MANAGED_MCPS is now empty
  and profile.sh's dead magic branches are removed.
- Design gate: GATE-BLOCK gains `21st` (required-manual, magic's old slot)
  and `21st-ui-build`; PATH repair extended to the npm global bin.
- settings.json: the 4 mcp__magic__* ask entries go; the outward-facing
  21st verbs land in autoMode.soft_deny, the tier that holds under auto
  mode (LRN-153).
- Docs: README, CLAUDE.global.md, design-gate.md, profile SKILL.md,
  .env.example, .gitleaks.toml, link.sh. BDR-093, LRN-158.

Tests: profile-set-managed 17/17, make test green except 2 pre-existing
gitflow FAILs (gitleaks binary absent on this host), shellcheck clean.
This commit is contained in:
bastien
2026-09-22 02:53:31 +00:00
parent 413b35a913
commit 7c05f75eab
26 changed files with 515 additions and 195 deletions
+15 -14
View File
@@ -52,8 +52,7 @@ lists items + types:
| `personal` | symlink move skills/ ↔ skills-disabled/\<name\> (no prefix) |
| `external` | symlink move skills/ ↔ skills-disabled/\<name\> |
| `plugin@<marketplace>` | `claude plugin enable\|disable <name>@<marketplace>` (auto) |
| `mcp` (known: magic) | delegate to `lib/toggle-external.sh` (uses `.env`) |
| `mcp` (other) | advisory — prints manual `claude mcp add …` command |
| `mcp` | advisory — prints manual `claude mcp add …` command (no server is managed today: `MANAGED_MCPS` is empty since 21st.dev moved to a CLI) |
| `cli` | advisory only — reports installed/not-installed |
**Always-on plugins** (`security-guidance`, `superpowers`) are
@@ -62,12 +61,14 @@ protected — `set` will refuse to disable them even if the profile omits them.
`ui-ux-pro-max@ui-ux-pro-max-skill`, `plugin-dev@claude-code-plugins`,
`pr-review-toolkit@claude-code-plugins`. Other plugins are never auto-toggled.
**Managed externals** (`emil-design-eng`, `frontend-design`,
`design-motion-principles`, `impeccable`) and **managed MCPs** (`magic`)
follow the same symmetry (BDR-079): `set` enables them when the profile
lists them (from parked state, or from `skills-external/` if the symlink
never existed) and parks/unregisters them when it does not — e.g. `set
backend` after design work turns emil and magic off. `darwin-skill` and any
other unlisted external are never auto-touched. gstack works the same
`design-motion-principles`, `impeccable`, and the five 21st design skills
`21st-ui-build`, `21st-ui-explore`, `21st-ui-review`, `21st-cli-use`,
`21st-ai`) follow the same symmetry (BDR-079): `set` enables them when the
profile lists them (from parked state, or from `skills-external/` if the
symlink never existed) and parks them when it does not — e.g. `set backend`
after design work turns emil and the 21st pack off. `darwin-skill`,
`21st-registry`, `21st-design-sync` and any other unlisted external are never
auto-touched. gstack works the same
all the way down: a profile listing gstack skills while the whole pack is
off (via `toggle-external.sh`) re-enables JUST those skills on demand.
@@ -137,11 +138,11 @@ bash "$HOME/.claude/lib/profile.sh" $ARGUMENTS
update-check, learnings — script doesn't touch that infra. Disabled skills
are just hidden from Claude Code's scanner; the gstack repo stays installed.
- Profile changes DO toggle the managed Claude Code plugins (ui-ux-pro-max,
plugin-dev, pr-review-toolkit), the managed external packs (emil-design-eng,
frontend-design, design-motion-principles, impeccable) and the `magic` MCP —
in BOTH directions: `set` enables what the profile lists and disables the
managed leftovers it doesn't (BDR-008, BDR-079). Anything outside those
allowlists stays manual: `claude plugin enable|disable`, `claude mcp
add|remove`.
plugin-dev, pr-review-toolkit) and the managed external packs
(emil-design-eng, frontend-design, design-motion-principles, impeccable,
the 21st design skills) — in BOTH directions: `set` enables what the profile
lists and disables the managed leftovers it doesn't (BDR-008, BDR-079).
Anything outside those allowlists stays manual: `claude plugin
enable|disable`, `bash lib/toggle-external.sh enable|disable <tool>`.
- `set` is destructive in the sense that it disables non-listed gstack skills.
Use `apply` if the user wants additive behavior.