Skip to content

Add origin-apps plugin: build on the Origin API, port a GitHub App - #423

Open
anikser wants to merge 26 commits into
cursor:mainfrom
anikser:ali/cursor/origin-apps-plugin-05cb
Open

anikser wants to merge 26 commits into
cursor:mainfrom
anikser:ali/cursor/origin-apps-plugin-05cb

Conversation

@anikser

@anikser anikser commented Sep 23, 2026 •

Copy link
Copy Markdown

Adds a origin-apps plugin with two skills.

  • origin-api points an agent at the right part of the Origin API docs and lists the handful of rules people get wrong at first (mirrored repositories, event subscriptions, webhook verification, scopes).
  • port-github-app-to-origin runs inside an existing GitHub App and writes a plan for moving it to Origin, including feedback the team can send to Cursor. It is for developers building Origin Apps, with or without a GitHub App to start from.

Note

Low Risk
Adds documentation, agent skills, and marketplace manifests only; no application runtime or auth code changes.

Overview
Introduces the origin-apps marketplace plugin (v0.1.0): skills-only guidance for Cursor Origin—registered in .cursor-plugin/marketplace.json, a new .claude-plugin/marketplace.json entry, and the root README plugin table.

origin-api steers agents to live Origin docs (llms.txt, targeted fetches) and enforces “check first” rules (native vs mirrored repos, event subscriptions, webhook verify/dedupe/ack, scopes from the spec, opaque pagination/IDs)—without inventing endpoints from memory.

port-github-app-to-origin is a planning workflow run inside a GitHub App repo: inventory webhooks, API/GraphQL usage, and auth from code; map against the saved spec; emit ORIGIN-PORTING-BRIEF.md and optional ORIGIN-FEEDBACK.md via references/brief.md (gap criteria, GitHub→Origin feature mapping). No code changes unless the user asks after the brief.

Reviewed by Cursor Bugbot for commit 0390402. Bugbot is set up for automated code reviews on this repo. Configure here.

Adds the Origin Apps plugin with one skill, port-github-app-to-origin, which
discovers a GitHub App's surface from its codebase, maps it onto the live
Origin OpenAPI spec (x-origin-scopes / x-origin-webhook-events), and writes a
porting brief. Planning only; it writes no code.

Dual-layout packaging so partners can use it outside Cursor: root plugin.json
(Agent Plugins 1.0), .cursor-plugin/plugin.json (Cursor Marketplace), and
.claude-plugin/plugin.json (Claude Code). Adds a root
.claude-plugin/marketplace.json so `/plugin marketplace add cursor/plugins`
works in Claude Code; it lists only this plugin.
@anikser
anikser force-pushed the ali/cursor/origin-apps-plugin-05cb branch from 94b0440 to 9a9ea84 Compare September 23, 2026 21:34

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

Comment thread origin-apps/.cursor-plugin/plugin.json Outdated
origin-api is the general skill for anyone building on the Origin API:
it points at the live docs and OpenAPI spec first and carries only the
practices that hold across spec versions (credentials and token minting,
minimal scopes from x-origin-scopes, webhook subscription, v1ed
verification, idempotent handling and delivery behavior, opaque page
tokens, TypeIDs, error envelope, rate limits, deliberate differences from
GitHub). port-github-app-to-origin now defers to it for fundamentals and
keeps only discovery, mapping, brief, and gap cards.

Manifests, marketplace entries, README row, and CHANGELOG describe both
skills with one identical description string.

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>
@anikser anikser changed the title Add origin-apps plugin: port a GitHub App to an Origin App Add origin-apps plugin: build on the Origin API, port a GitHub App Sep 23, 2026
cursoragent and others added 2 commits September 23, 2026 22:16
origin-api becomes a fetch-first source list plus a gotcha checklist
(173 -> 80 lines). The porting skill keeps the discover -> fetch -> map ->
brief workflow and the gap-card rules; references drop ecosystem grep
lists, path examples, calibration examples, and everything that restated
the spec or origin-api. origin-isms is now a classification table
(GitHub surface -> label -> Origin idiom). 1231 -> 567 prose lines.

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>
Wording only. Removes em dashes, connector colons, semicolon chains, and
passive voice; replaces "surface" with the concrete noun; one thought per
sentence. Rules and content unchanged. Plugin description is one new
identical string across the three manifests, both marketplace entries,
and the README row.

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>
@anikser anikser changed the title Add origin-apps plugin: build on the Origin API, port a GitHub App Add origin-apps plugin: two skills for building on the Origin API and porting a GitHub App Sep 24, 2026
Porting skill gains step 6, a copyable check-and-fix list run before the
brief is declared done. Both descriptions are third person. The porting
reference table names the origin-api skill instead of a relative path.
brief-template gets a contents line. gap-bar drops "today". "PR" becomes
"pull request" in prose.

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

Comment thread origin-apps/skills/port-github-app-to-origin/SKILL.md Outdated
cursoragent and others added 4 commits September 24, 2026 16:46
index-origin-spec.py drops the ops and scopes modes, which two rg
one-liners cover, and keeps events and schema (payload fields with $ref
resolution). Constants are named; missing file, invalid YAML, and
non-Origin specs exit with a message instead of a traceback.

Prose loses process history and internal justifications: the validation
run note in step 6, "Cursor owns the shape", the manifests paragraph in
the README, and the CHANGELOG iteration notes.

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>
origin-api becomes a fetch-first list, a where-to-look table of
llms-full.txt anchors, four priority rules, and a short coming-from-GitHub
list for facts the docs do not carry yet. origin-isms rows point at docs
anchors instead of restating the idiom. spec-mapping drops copied paths
and slugs and the x-origin-webhook-resource extension, which the current
spec does not have; x-cursor-visibility is corrected to a field badge.
brief-template's mirror rule and hello-world mechanics defer to the docs.
gap-bar and README drop a feedback address the docs do not name.

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>
The docs now carry coming-from-github, ids, preview, and the x-origin-*
summary, so the in-skill Coming from GitHub list becomes a pointer, ID
form points at #ids, PREVIEW points at #preview without claiming where the
badge appears, and the subscription and pageSize rules defer to #events
and #pagination.

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>
The docs will not carry a coming-from-github section, so origin-api
points at the porting skill in one line and origin-isms rows name the
Origin answer or its docs anchor directly. The payload-field rule lives in
the porting mapping step and points at the per-field notes under
#event-payloads.

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>
@anikser anikser changed the title Add origin-apps plugin: two skills for building on the Origin API and porting a GitHub App Add origin-apps plugin: build on the Origin API, port a GitHub App Sep 24, 2026
cursoragent and others added 2 commits September 24, 2026 20:31
origin-isms rows are reshaped where the docs give a path and
not-available where the current spec has nothing; not-available always
carries a question and goes through the gap bar. Rows now cite documented
limitations instead of asserting intent, and two factual fixes land:
reviewer identifiers resolve by email or group slug, and app-level event
subscriptions are the documented webhook path. Related sentences in the
porting SKILL, gap-bar, brief-template, spec-mapping, README, and
origin-api drop "deliberate", "on purpose", and "never a gap".

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>
The docs render every webhook payload family and every endpoint's
response fields with nested objects expanded to dotted paths, deeper
than the script's two-level expansion, so the script and its PyYAML
requirement go. spec-mapping points the REST and payload-field steps at
the matching llms-full.txt headings. origin-api gains a lookup-order rule
(llms.txt first, one section for a narrow question, full files only for
broad work); the porting skill inherits it.

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

Comment thread origin-apps/skills/port-github-app-to-origin/references/spec-mapping.md Outdated
Comment thread origin-apps/plugin.json Outdated
cursoragent and others added 3 commits September 24, 2026 21:09
gap-bar opens with the ask to raise anything that blocks, costs, or would
help the team; the bar orders cards versus questions rather than deciding
whether to speak up. Drops the product-area examples for undocumented
concepts, softens "never about search" and "fails the bar", and closes by
encouraging the team to send cards and questions. The same tone sweep
touches the porting SKILL, spec-mapping, origin-isms, brief-template, and
README.

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>
Manifests lose the porting and integration keywords and tags.
spec-mapping's payload outcomes now include "present in the envelope" so
GitHub's action field maps to event.type instead of falling through to
the gap bar, matching the brief template's five How values. The porting
skill's out-of-scope line says the team sends the cards.

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>
The brief's section is Feedback for Cursor with Feedback: entries; the
reference is the feedback bar and format. The gap parity label stays: a
gap row produces a feedback entry. Section 7 is scoped to decisions the
team must make so it does not duplicate section 6.

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>
@anikser
anikser marked this pull request as ready for review September 24, 2026 21:20
cursoragent and others added 7 commits September 24, 2026 23:48
Feedback for Cursor now carries only the use case and the API gap in
Origin terms, with no file paths, module names, framework internals, or
repository names; the team strips internals before forwarding. The
porting skill states it does not write or change code without an explicit
ask, its procedure is guidance with a short self-check, and the brief is a
default template whose Feedback section is the part to keep exact.
origin-api is a router: docs pointers and five rules, triggered by Origin
mentions only. Capability tables and payload maps use neutral "today"
framing instead of GitHub-versus-Origin.

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>
brief-template.md describes what a good brief does and offers a default
outline the agent adapts or skips, with a small app's brief fitting one
screen. Fixed question lists, column counts, and boilerplate sections are
gone; what remains is what makes the brief trustworthy: evidence for app
claims, Origin claims resolved against the fetched docs, feedback free of
partner internals. unknown folds into not-available; same and reshaped
fold into maps; the four marks are optional vocabulary. Feedback for
Cursor stays last and is also written to ORIGIN-FEEDBACK.md when there is
at least one entry.

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>
Every docs pointer becomes reference/<anchor>.md under the Origin docs
base URL. origin-api's lookup rule is llms.txt first, then the one page;
llms-full.txt and openapi.yaml stay for broad work. The field-map steps
fetch the endpoint's or payload family's own page, with rg over
llms-full.txt kept as the broad-run fallback.

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>
Pointers become quoted section headings resolved through llms.txt at run
time, so the skill does not depend on a docs deploy order and survives
renamed anchors. The base URL stays for llms.txt, llms-full.txt, and
openapi.yaml.

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>
Folds discovery, spec-mapping, gap-bar, origin-isms, and brief-template
into the porting SKILL.md plus one reference (brief, feedback bar, crib);
the eval scored this shape level with the longer one. Also from the eval:
the mirror rule states facts (merging and default-branch changes are
native-only; on a GitHub-sourced mirror every event except
repository.pushed arrives and calls beyond metadata and contents reads
return 403); brevity is structural (list only what does not map straight
across, payload fields only when absent or a follow-up read, a word
budget by app size); a three-line filter sits before feedback; the stale
user-OAuth item points at "Acting on behalf of users" and names the
user-token permission probe as a workaround; ORIGIN-FEEDBACK.md carries no
license header, repo or product name, or other forge, and docs
contradictions go to Cursor.

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>
Wording only. "Crib" becomes "Where GitHub features live on Origin";
"the bar", "first-run path", "marks", "provenance", "fan-out", "rows",
"call families", and "payload family" become ordinary words; native
repositories and stable outbound mirrors are explained once in plain terms;
optional table labels are plain words. Rules, eval fixes, and the
section-name pointers are unchanged.

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>
openapi.yaml and llms-full.txt are about 870 KB and 575 KB, roughly 350k
tokens together, more than a context window holds. Both skills now say to
curl them to disk and rg them, reading only the matching sections. Narrow
questions still go through llms.txt to the one section.

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>
Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

Bugbot Autofix is ON, but it could not run because the branch was deleted or merged before autofix could start.

Reviewed by Cursor Bugbot for commit 7624c3f. Configure here.

Comment thread origin-apps/skills/port-github-app-to-origin/SKILL.md Outdated
cursoragent and others added 4 commits September 29, 2026 00:20
…ge targets

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>
Replaces the curl and rg commands with tool-neutral intent (save locally,
search for the heading or annotation, read the matching part) and keeps
the concrete search targets. Saved copies go in a temporary location
outside the app's repository, so a download cannot overwrite or litter the
working tree.

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>
Every row mapped a question to a section whose title in llms.txt says
the same thing, or to a section a ranked rule already names. The one
mapping the index does not make obvious (stale check-run posts are under
"Ordering writes") stays as a single line.

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>
Outbound mirrors are not externally shipped, so the skills no longer
mention them. Native repositories get full scopes and every write; on a
GitHub mirror every event except repository.pushed arrives, calls beyond
metadata and contents reads return 403, and merge and default-branch
changes are not available.

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants