Address two issues flagged in PR review:
1. Validate pluginRoot and source with isSafeRelativePath before using
them in path.resolve. Without this, absolute paths or .. traversals
in marketplace.json would pass validation silently.
2. Error when the per-plugin .cursor-plugin/plugin.json is missing
instead of silently skipping it. A missing manifest would prevent
the plugin from loading, so the validator should catch it.
Made-with: Cursor
The pre-commit validator previously required a root plugin.json and
would fail when only marketplace.json was present.
Refactor the validator to check for marketplace.json first, falling
back to root plugin.json for single-plugin repos. For marketplace
repos, validate the marketplace manifest (name, owner, plugins array),
resolve each plugin directory using pluginRoot + source, and validate
per-plugin manifests with paths relative to the plugin directory.
Made-with: Cursor