Skip to content

Add origin-apps plugin: build on the Origin API, port a GitHub App - #423

Open
anikser wants to merge 24 commits into
cursor:mainfrom
anikser:ali/cursor/origin-apps-plugin-05cb
Open

anikser wants to merge 24 commits into
cursor:mainfrom
anikser:ali/cursor/origin-apps-plugin-05cb

Conversation

@anikser

@anikser anikser commented Sep 23, 2026 •

Copy link
Copy Markdown

This adds an Origin plugin with two skills. origin-api points an agent at
the right part of the Origin API docs and lists the handful of rules people
get wrong at first (mirrored repositories, event subscriptions, webhook
verification, scopes). port-github-app-to-origin runs inside an existing
GitHub App and writes a plan for moving it to Origin, including feedback the
team can send to Cursor. It is for developers building Origin Apps, with or
without a GitHub App to start from.

Low risk: it only adds the origin-apps/ folder, the two marketplace
entries, and a README row. No new dependencies, no scripts, and validate
is green.

To try it before merge, copy origin-apps/skills/* into a .cursor/skills/
folder (or point Claude Code at the origin-apps/ folder) and ask about the
Origin API. Once merged and listed, it installs from the Cursor Marketplace.


Note

Low Risk
Additive documentation and agent skills only; marketplace manifest and README listing changes with no impact on existing plugins or build/runtime behavior.

Overview
Introduces the origin-apps marketplace plugin (v0.1.0): skills-only guidance for Cursor Origin, listed in .cursor-plugin/marketplace.json, the new .claude-plugin/marketplace.json, and the root plugin table.

origin-api tells agents to use the live Origin docs (llms.txt, openapi.yaml) instead of memorized endpoints, with a routing table and five “rules to check first” (native vs mirrored repos, event subscriptions, webhook verify/dedupe/ack, scopes from spec, opaque IDs/pagination).

port-github-app-to-origin is planning-only: run in a GitHub App repo, inventory webhooks/API/auth from code, map to the fetched spec, and emit ORIGIN-PORTING-BRIEF.md plus optional ORIGIN-FEEDBACK.md using the templates in references/brief.md (gaps, workarounds, GitHub→Origin feature mapping).

Packaging matches other plugins: .cursor-plugin / .claude-plugin / agent-plugins plugin.json, MIT license, README, and CHANGELOG. No runtime code or new dependencies in the repo.

Reviewed by Cursor Bugbot for commit 5dda504. Bugbot is set up for automated code reviews on this repo. Configure here.

Adds the Origin Apps plugin with one skill, port-github-app-to-origin, which
discovers a GitHub App's surface from its codebase, maps it onto the live
Origin OpenAPI spec (x-origin-scopes / x-origin-webhook-events), and writes a
porting brief. Planning only; it writes no code.

Dual-layout packaging so partners can use it outside Cursor: root plugin.json
(Agent Plugins 1.0), .cursor-plugin/plugin.json (Cursor Marketplace), and
.claude-plugin/plugin.json (Claude Code). Adds a root
.claude-plugin/marketplace.json so `/plugin marketplace add cursor/plugins`
works in Claude Code; it lists only this plugin.
@anikser
anikser force-pushed the ali/cursor/origin-apps-plugin-05cb branch from 94b0440 to 9a9ea84 Compare September 23, 2026 21:34

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

Comment thread origin-apps/.cursor-plugin/plugin.json Outdated
origin-api is the general skill for anyone building on the Origin API:
it points at the live docs and OpenAPI spec first and carries only the
practices that hold across spec versions (credentials and token minting,
minimal scopes from x-origin-scopes, webhook subscription, v1ed
verification, idempotent handling and delivery behavior, opaque page
tokens, TypeIDs, error envelope, rate limits, deliberate differences from
GitHub). port-github-app-to-origin now defers to it for fundamentals and
keeps only discovery, mapping, brief, and gap cards.

Manifests, marketplace entries, README row, and CHANGELOG describe both
skills with one identical description string.

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>
@anikser anikser changed the title Add origin-apps plugin: port a GitHub App to an Origin App Add origin-apps plugin: build on the Origin API, port a GitHub App Sep 23, 2026
cursoragent and others added 2 commits September 23, 2026 22:16
origin-api becomes a fetch-first source list plus a gotcha checklist
(173 -> 80 lines). The porting skill keeps the discover -> fetch -> map ->
brief workflow and the gap-card rules; references drop ecosystem grep
lists, path examples, calibration examples, and everything that restated
the spec or origin-api. origin-isms is now a classification table
(GitHub surface -> label -> Origin idiom). 1231 -> 567 prose lines.

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>
Wording only. Removes em dashes, connector colons, semicolon chains, and
passive voice; replaces "surface" with the concrete noun; one thought per
sentence. Rules and content unchanged. Plugin description is one new
identical string across the three manifests, both marketplace entries,
and the README row.

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>
@anikser anikser changed the title Add origin-apps plugin: build on the Origin API, port a GitHub App Add origin-apps plugin: two skills for building on the Origin API and porting a GitHub App Sep 24, 2026
Porting skill gains step 6, a copyable check-and-fix list run before the
brief is declared done. Both descriptions are third person. The porting
reference table names the origin-api skill instead of a relative path.
brief-template gets a contents line. gap-bar drops "today". "PR" becomes
"pull request" in prose.

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

Comment thread origin-apps/skills/port-github-app-to-origin/SKILL.md Outdated
cursoragent and others added 4 commits September 24, 2026 16:46
index-origin-spec.py drops the ops and scopes modes, which two rg
one-liners cover, and keeps events and schema (payload fields with $ref
resolution). Constants are named; missing file, invalid YAML, and
non-Origin specs exit with a message instead of a traceback.

Prose loses process history and internal justifications: the validation
run note in step 6, "Cursor owns the shape", the manifests paragraph in
the README, and the CHANGELOG iteration notes.

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>
origin-api becomes a fetch-first list, a where-to-look table of
llms-full.txt anchors, four priority rules, and a short coming-from-GitHub
list for facts the docs do not carry yet. origin-isms rows point at docs
anchors instead of restating the idiom. spec-mapping drops copied paths
and slugs and the x-origin-webhook-resource extension, which the current
spec does not have; x-cursor-visibility is corrected to a field badge.
brief-template's mirror rule and hello-world mechanics defer to the docs.
gap-bar and README drop a feedback address the docs do not name.

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>
The docs now carry coming-from-github, ids, preview, and the x-origin-*
summary, so the in-skill Coming from GitHub list becomes a pointer, ID
form points at #ids, PREVIEW points at #preview without claiming where the
badge appears, and the subscription and pageSize rules defer to #events
and #pagination.

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>
The docs will not carry a coming-from-github section, so origin-api
points at the porting skill in one line and origin-isms rows name the
Origin answer or its docs anchor directly. The payload-field rule lives in
the porting mapping step and points at the per-field notes under
#event-payloads.

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>
@anikser anikser changed the title Add origin-apps plugin: two skills for building on the Origin API and porting a GitHub App Add origin-apps plugin: build on the Origin API, port a GitHub App Sep 24, 2026
cursoragent and others added 2 commits September 24, 2026 20:31
origin-isms rows are reshaped where the docs give a path and
not-available where the current spec has nothing; not-available always
carries a question and goes through the gap bar. Rows now cite documented
limitations instead of asserting intent, and two factual fixes land:
reviewer identifiers resolve by email or group slug, and app-level event
subscriptions are the documented webhook path. Related sentences in the
porting SKILL, gap-bar, brief-template, spec-mapping, README, and
origin-api drop "deliberate", "on purpose", and "never a gap".

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>
The docs render every webhook payload family and every endpoint's
response fields with nested objects expanded to dotted paths, deeper
than the script's two-level expansion, so the script and its PyYAML
requirement go. spec-mapping points the REST and payload-field steps at
the matching llms-full.txt headings. origin-api gains a lookup-order rule
(llms.txt first, one section for a narrow question, full files only for
broad work); the porting skill inherits it.

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

Comment thread origin-apps/skills/port-github-app-to-origin/references/spec-mapping.md Outdated
Comment thread origin-apps/plugin.json Outdated
cursoragent and others added 3 commits September 24, 2026 21:09
gap-bar opens with the ask to raise anything that blocks, costs, or would
help the team; the bar orders cards versus questions rather than deciding
whether to speak up. Drops the product-area examples for undocumented
concepts, softens "never about search" and "fails the bar", and closes by
encouraging the team to send cards and questions. The same tone sweep
touches the porting SKILL, spec-mapping, origin-isms, brief-template, and
README.

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>
Manifests lose the porting and integration keywords and tags.
spec-mapping's payload outcomes now include "present in the envelope" so
GitHub's action field maps to event.type instead of falling through to
the gap bar, matching the brief template's five How values. The porting
skill's out-of-scope line says the team sends the cards.

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>
The brief's section is Feedback for Cursor with Feedback: entries; the
reference is the feedback bar and format. The gap parity label stays: a
gap row produces a feedback entry. Section 7 is scoped to decisions the
team must make so it does not duplicate section 6.

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>
@anikser
anikser marked this pull request as ready for review September 24, 2026 21:20
cursoragent and others added 7 commits September 24, 2026 23:48
Feedback for Cursor now carries only the use case and the API gap in
Origin terms, with no file paths, module names, framework internals, or
repository names; the team strips internals before forwarding. The
porting skill states it does not write or change code without an explicit
ask, its procedure is guidance with a short self-check, and the brief is a
default template whose Feedback section is the part to keep exact.
origin-api is a router: docs pointers and five rules, triggered by Origin
mentions only. Capability tables and payload maps use neutral "today"
framing instead of GitHub-versus-Origin.

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>
brief-template.md describes what a good brief does and offers a default
outline the agent adapts or skips, with a small app's brief fitting one
screen. Fixed question lists, column counts, and boilerplate sections are
gone; what remains is what makes the brief trustworthy: evidence for app
claims, Origin claims resolved against the fetched docs, feedback free of
partner internals. unknown folds into not-available; same and reshaped
fold into maps; the four marks are optional vocabulary. Feedback for
Cursor stays last and is also written to ORIGIN-FEEDBACK.md when there is
at least one entry.

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>
Every docs pointer becomes reference/<anchor>.md under the Origin docs
base URL. origin-api's lookup rule is llms.txt first, then the one page;
llms-full.txt and openapi.yaml stay for broad work. The field-map steps
fetch the endpoint's or payload family's own page, with rg over
llms-full.txt kept as the broad-run fallback.

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>
Pointers become quoted section headings resolved through llms.txt at run
time, so the skill does not depend on a docs deploy order and survives
renamed anchors. The base URL stays for llms.txt, llms-full.txt, and
openapi.yaml.

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>
Folds discovery, spec-mapping, gap-bar, origin-isms, and brief-template
into the porting SKILL.md plus one reference (brief, feedback bar, crib);
the eval scored this shape level with the longer one. Also from the eval:
the mirror rule states facts (merging and default-branch changes are
native-only; on a GitHub-sourced mirror every event except
repository.pushed arrives and calls beyond metadata and contents reads
return 403); brevity is structural (list only what does not map straight
across, payload fields only when absent or a follow-up read, a word
budget by app size); a three-line filter sits before feedback; the stale
user-OAuth item points at "Acting on behalf of users" and names the
user-token permission probe as a workaround; ORIGIN-FEEDBACK.md carries no
license header, repo or product name, or other forge, and docs
contradictions go to Cursor.

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>
Wording only. "Crib" becomes "Where GitHub features live on Origin";
"the bar", "first-run path", "marks", "provenance", "fan-out", "rows",
"call families", and "payload family" become ordinary words; native
repositories and stable outbound mirrors are explained once in plain terms;
optional table labels are plain words. Rules, eval fixes, and the
section-name pointers are unchanged.

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>
openapi.yaml and llms-full.txt are about 870 KB and 575 KB, roughly 350k
tokens together, more than a context window holds. Both skills now say to
curl them to disk and rg them, reading only the matching sections. Narrow
questions still go through llms.txt to the one section.

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>
Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

Bugbot Autofix is ON, but it could not run because the branch was deleted or merged before autofix could start.

Reviewed by Cursor Bugbot for commit 7624c3f. Configure here.

Comment thread origin-apps/skills/port-github-app-to-origin/SKILL.md Outdated
cursoragent and others added 2 commits September 29, 2026 00:20
…ge targets

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>
Replaces the curl and rg commands with tool-neutral intent (save locally,
search for the heading or annotation, read the matching part) and keeps
the concrete search targets. Saved copies go in a temporary location
outside the app's repository, so a download cannot overwrite or litter the
working tree.

Co-authored-by: ali.nikseresht <ali.nikseresht@anysphere.co>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants