diff --git a/.gitleaks.toml b/.gitleaks.toml index 27a5616..b1e0d8f 100644 --- a/.gitleaks.toml +++ b/.gitleaks.toml @@ -68,8 +68,6 @@ regexes = [ '''X-Amz-Credential=AKIA[0-9A-Z]{16}''', '''private-user-images\.githubusercontent\.com/[^"]*\?jwt=''', # Docs/test example — base64 of the "the ..." ASCII sample text, never a key. - # (The MAGIC_API_KEY=abc123 placeholder that sat here went with the magic - # MCP, removed 2026-09-22 when 21st.dev moved to a CLI with no API key.) '''clientKey = 'dGhlIH[A-Za-z0-9+/=]*'''', ] diff --git a/README.md b/README.md index ef213af..2ee2cd5 100644 --- a/README.md +++ b/README.md @@ -263,15 +263,12 @@ claude mcp add --scope user --env 'API_KEY=${SOME_API_KEY}' -- The var still has to exist in the **environment of the process that starts `claude`** — sourcing `~/.claude/.env` into your everyday interactive shell would defeat the point (every subprocess, every stray `env`/`printenv`, would -then see it). This repo's `~/.bashrc` instead wraps the `claude` command -itself: a `claude()` shell function sources `~/.claude/.env` into a subshell -and `exec`s the real binary, so the var reaches `claude` and its children only -— never the ambient shell. +then see it). Wrap the `claude` command instead: a `claude()` shell function +that sources `~/.claude/.env` into a subshell and `exec`s the real binary, so +the var reaches `claude` and its children only, never the ambient shell. -This config currently registers no MCP server at all. The one it used to -carry, `@21st-dev/magic`, is gone: 21st.dev replaced it with a plain CLI (see -below), so there is no key left to protect by reference. The pattern stays -documented for the next MCP server that needs a secret. +This config registers no MCP server today. The pattern stays documented for +the next one that needs a secret. There is no `claude mcp add` flag that writes the reference form for you — the `${VAR}` syntax has to be typed by hand (or via a wrapper script), same as @@ -297,11 +294,12 @@ Then run the one-time consent flow: `make seo-connect` (per-label token store, multi-site safe). Missing credentials never break an audit — `/seo` degrades gracefully to anonymous PageSpeed lab data. -### 21st.dev CLI (replaces the magic MCP) +### 21st.dev CLI -`@21st-dev/cli` (bin `21st`) supersedes the `@21st-dev/magic` MCP server that -this config used to register. Same endpoint, one browser login, no API key, -and nothing loaded into a session that isn't using it: +`@21st-dev/cli` (bin `21st`) is the 21st.dev integration; it replaced the +former Magic MCP server this config used to register. Same endpoint, one +browser login, no API key, and nothing loaded into a session that isn't using +it: ```bash npm i -g @21st-dev/cli @@ -312,8 +310,8 @@ npm i -g @21st-dev/cli an interactive terminal) and installs the skill pack that drives it: `21st-ui-build`, `-ui-explore`, `-ui-review`, `-cli-use`, `-ai`, plus the two publishing skills `-registry` and `-design-sync`. The pack is disabled by -default, the same policy the MCP had. `/profile design` turns on the five -design skills; `bash lib/toggle-external.sh enable 21st` turns on all seven. +default. `/profile design` turns on the five design skills; +`bash lib/toggle-external.sh enable 21st` turns on all seven. The pack is machine-owned and gitignored. It cannot be installed the way upstream documents it (`21st install-skill`, i.e. `21st skills install @@ -323,11 +321,6 @@ symlink to this repo's `skills/`. So the install runs under a throwaway `HOME` and the result is moved into `skills-external/21st-*`, where `toggle-external.sh` and `profile.sh` symlink it in on demand. -Two risks from the MCP era go away with it. The unauthenticated local callback -server `21st_magic_component_builder` opened (`127.0.0.1:9221+`, CORS `*`, a -10-minute local prompt-injection window, job8 audit / LRN-110). And the API -key that `claude mcp add --env` materialized into `~/.claude.json`. - The permission gate is now one `autoMode.soft_deny` entry covering the outward-facing verbs (`21st publish*`, `submit`, `edit`, `delete`, `remove-from-catalog`, `profile set|upload`), because publishing a component diff --git a/install-plugins.sh b/install-plugins.sh index c1b25d3..24e6ce8 100644 --- a/install-plugins.sh +++ b/install-plugins.sh @@ -954,9 +954,9 @@ echo "" # ============================================================ # STEP 8.7 — 21ST.DEV CLI + SKILL PACK — installed but DISABLED by default # ============================================================ -# `@21st-dev/cli` (bin `21st`) supersedes the `@21st-dev/magic` MCP server: -# same endpoint, one browser login (`21st login`, token in ~/.config/21st), -# no API key, no MCP process loaded into every session. It ships a pack of +# `@21st-dev/cli` (bin `21st`): one browser login (`21st login`, token in +# ~/.config/21st), no API key, no MCP process loaded into every session. It +# ships a pack of # verified skills (21st-ui-build / -explore / -review / -cli-use / -ai / # -registry / -design-sync) that drive the CLI from Claude Code. # diff --git a/lib/profile.sh b/lib/profile.sh index a7ba29c..0e1f73b 100755 --- a/lib/profile.sh +++ b/lib/profile.sh @@ -81,9 +81,8 @@ MANAGED_EXTERNALS=( # MCP servers that are toggle-managed by `set`, both ways (enable AND # disable), delegated to lib/toggle-external.sh. Same allowlist doctrine. -# Empty since 2026-09-22: `magic` was the only entry and 21st.dev replaced -# its MCP server with a CLI + skill pack (the 5 design skills are managed as -# externals above). The `mcp` type itself stays supported — a profile can +# Empty: no MCP server is managed today (the 21st design skills are managed +# as externals above). The `mcp` type itself stays supported — a profile can # still list an MCP, it is then advisory rather than auto-toggled. MANAGED_MCPS=() @@ -330,10 +329,8 @@ enable_skill() { fi ;; mcp) - # Advisory only. The delegation branch that lived here served `magic`, - # the single managed MCP; 21st.dev replaced it with a CLI (BDR-093), so - # MANAGED_MCPS is empty and nothing is auto-registered. Re-add a branch - # here the day a profile owns an MCP server again. + # Advisory only: MANAGED_MCPS is empty, nothing is auto-registered. + # Re-add a delegation branch here the day a profile owns an MCP server. if [ "$(skill_status "$skill" mcp)" = "enabled" ]; then : # already on else @@ -579,7 +576,7 @@ cmd_set() { # Symmetry (BDR-079): a profile switch also parks the managed external # packs and unregisters the managed MCPs the new profile does not need — - # design leftovers (emil, magic…) no longer survive a `set backend`. + # design leftovers (emil, the 21st pack…) no longer survive a `set backend`. disable_externals_not_in "$prof" disable_mcps_not_in "$prof" @@ -739,9 +736,10 @@ EXAMPLES: NOTE: "set" toggles the MANAGED items automatically, both ways: plugins (ui-ux-pro-max, plugin-dev, pr-review-toolkit), external packs - (emil-design-eng, frontend-design, design-motion-principles, impeccable) - and the magic MCP. Anything outside those allowlists stays advisory — - run "claude plugin enable|disable" or "claude mcp add|remove" yourself. + (emil-design-eng, frontend-design, design-motion-principles, impeccable, + the five 21st design skills). Anything outside those allowlists stays + advisory — run "claude plugin enable|disable" or + "bash lib/toggle-external.sh enable|disable " yourself. EOF } diff --git a/lib/tests/profile-set-managed.test.sh b/lib/tests/profile-set-managed.test.sh index 934949e..8a4ba37 100644 --- a/lib/tests/profile-set-managed.test.sh +++ b/lib/tests/profile-set-managed.test.sh @@ -1,9 +1,8 @@ #!/usr/bin/env bash # lib/tests/profile-set-managed.test.sh — `set` symmetry on managed -# externals, gstack on-demand, external from-source (BDR-079). The MCP -# assertions went with `magic` (2026-09-22): MANAGED_MCPS is empty now, the -# 21st skills that replaced it are managed as externals, so the pack's -# park/restore round-trip is what this covers on that side. +# externals, gstack on-demand, external from-source (BDR-079). No MCP is +# managed (MANAGED_MCPS is empty): the 21st skills are managed as externals, +# so the pack's park/restore round-trip is what this covers on that side. # Hermetic: fixture repo via *_REPO_OVERRIDE + fake `claude` on PATH. set -u ROOT="$(cd "$(dirname "$0")/../.." && pwd)" diff --git a/plugins.lock.json b/plugins.lock.json index 636f7c5..db20c6f 100644 --- a/plugins.lock.json +++ b/plugins.lock.json @@ -23,7 +23,7 @@ "21st": { "source": "npm:@21st-dev/cli", "version": "latest", - "note": "21st.dev CLI (bin `21st`) — supersedes the @21st-dev/magic MCP server (2026-09-22). Standalone CLI + a pack of 7 skills, no MCP, no API key: auth is `21st login` (browser token in ~/.config/21st). Install: npm install -g @21st-dev/cli. The skill pack is staged-installed into skills-external/21st-* by install-plugins.sh Step 8.7 — `21st skills install` refuses to write through the ~/.claude/skills symlink." + "note": "21st.dev CLI (bin `21st`) — standalone CLI + a pack of 7 skills, no MCP, no API key: auth is `21st login` (browser token in ~/.config/21st). Install: npm install -g @21st-dev/cli. The skill pack is staged-installed into skills-external/21st-* by install-plugins.sh Step 8.7 — `21st skills install` refuses to write through the ~/.claude/skills symlink." }, "graphifyy": { "source": "pypi:graphifyy",