Commit Graph

20 Commits

Author SHA1 Message Date
Stefan Broenner 09694d8afe Add table-creation range preflight (#844)
* Add table creation preflight

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* fix: preserve sessions during stale cleanup

Wait for the tracked daemon to finish graceful shutdown even when its reply is lost, so pre-build cleanup cannot interrupt session auto-save.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* fix: preserve sessions during stale cleanup

Wait for the tracked daemon to finish graceful shutdown even when its reply is lost, so pre-build cleanup cannot interrupt session auto-save.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Fix quoted formula reference detection

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: ea1cae23-233e-46ce-9cf7-e22fa9f5ac8b

* fix: await tracked Excel shutdown

Treat graceful cleanup as complete only after the exact daemon generation and its tracked Excel processes exit, while retaining the existing bounded forced fallback.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: b07d5dc3-38d8-4d20-9f07-122e079dd612

* fix: stabilize MCPB staging cleanup

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 9b9eefe6-dd82-44e6-abdc-98202899cf32

* Bound merged-range discovery scans

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Bound table preflight heuristics

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Stefan Broenner <stbrnner@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: ea1cae23-233e-46ce-9cf7-e22fa9f5ac8b
Copilot-Session: b07d5dc3-38d8-4d20-9f07-122e079dd612
Copilot-Session: 9b9eefe6-dd82-44e6-abdc-98202899cf32
2026-08-31 17:13:31 +02:00
Stefan Broenner 288ccea074 Audit public docs and tool help (#819)
Audit and correct public documentation, GitHub Pages presentation, tool descriptions, generated CLI help, and documentation validation.
2026-08-27 18:54:10 +02:00
Stefan Broenner 3ad8ca3831 Verify plugin runtime downloads (#813)
Publish SHA-256 checksums for Windows runtime archives and require both plugin bootstraps to verify fresh and cached downloads before extraction.

Co-authored-by: Stefan Broenner <stbrnner@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
2026-08-24 19:42:27 +02:00
Stefan Broenner d43a165f85 Preserve Agent Plugins 1.0 source fixes (#811)
* fix(plugin): preserve Agent Plugins 1.0 source

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* docs(plugin): define publication source of truth

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Stefan Broenner <stbrnner@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
2026-08-24 15:40:28 +02:00
Stefan Broenner f9a25d155f feat!: unify CLI and MCP automation contracts (#807)
* feat!: unify CLI and MCP automation contracts

Implement the seven-layer CLI/MCP remediation stack: safe pipe-owned cleanup, truthful daemon states, strict generated contracts, canonical inputs, exact Power Query identity, compact reads, and a unified file lifecycle.

Fixes #781, #782, #783, #784, #785, #786, #787, #788, #789, #796, #797, #798, #799, #800, #801

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 57225379-2632-4201-98b6-94b43b419f5c

* test: strengthen protocol regression assertions

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 6a90669a-c01e-46be-838f-2a2418e9b788

---------

Copilot-Session: 57225379-2632-4201-98b6-94b43b419f5c
Copilot-Session: 6a90669a-c01e-46be-838f-2a2418e9b788
2026-08-21 16:59:45 +02:00
Stefan Broenner 3aa557cd7f fix(plugins): harden the runtime bootstrap against corrupt caches and races (#790)
Follow-up to the offline-fallback fix. Six independent failure modes, each
reproduced against the real 1.10.7 cache before being fixed.

A truncated archive wedged the plugin permanently: the cached tag still
matched, so no download was attempted, yet extraction failed on every run
thereafter. Presence was being treated as integrity. The archive is now
opened and validated before it is trusted, downloads land in a temp file
that is renamed into place, and a failed install retries once with a fresh
download instead of failing forever.

Extraction deleted the release directory up front. Remove-Item -Recurse
removes every sibling file before it reaches a locked executable and then
fails, which destroyed a working install and left nothing usable behind.
Extraction now stages into a scratch directory and swaps it in, and the
executable is probed for a lock before anything is removed, so a runtime
that is currently running is kept rather than half overwritten.

Concurrent sessions raced on the same archive path and release directory;
installs are now serialized with a named mutex.

Release lookups now send GITHUB_TOKEN or GH_TOKEN when present.
Unauthenticated GitHub API access is 60 requests/hour per source IP, shared
by everyone behind a corporate NAT, and is the usual reason the metadata is
unreachable in the first place.

Outside a Copilot session the session id is the constant "standalone", so
it always equalled the previously recorded one and the freshness check
never fired again. PATH and shim installs were pinned forever to whatever
they first downloaded. Those now re-check on a time window.

The resolved runtime's version is verified from the version stamped into
the file rather than by running it with --version, which performs its own
network update check and would defeat the point of an offline-safe path.

Nine new tests cover these paths; each was mutation-verified to fail
against the unfixed script. The harness now builds real archives so
integrity handling is exercised rather than mocked away, and it scrubs
COPILOT_AGENT_SESSION_ID, GITHUB_TOKEN and GH_TOKEN so an ambient
environment cannot change what the tests actually assert.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: edb4d8c2-36e0-4719-ab55-4d501b7a2462
2026-08-20 04:55:19 +00:00
Stefan Broenner f3f80acbf2 fix(plugins): preserve quoted arguments and survive an unreachable release API (#779)
* fix(plugins): preserve quoted arguments and survive an unreachable release API

Two defects made the published excel-cli and excel-mcp plugins fail in normal use.

Quoted arguments were destroyed in transit. Windows PowerShell rebuilds the command
line when invoking a native executable and drops embedded double quotes, so every
documented inline JSON example arrived as [[Name,Amount]] instead of
[["Name","Amount"]] when run through the plugin wrapper or the generated PATH shim.
Escaping at the call site cannot fix this. start-cli.ps1 now builds the command line
itself using the standard MSVCRT quoting rules and passes it to ProcessStartInfo
verbatim; stdio is inherited, so interactive and piped use are unchanged. The .cmd
shim had a second, independent mangling layer -- powershell -File strips quotes
before the wrapper ever runs -- so it now resolves the executable up front and
invokes it directly, letting cmd forward %* untouched.

The bootstrap also aborted whenever the GitHub release API was unreachable, even
with the correct runtime already downloaded and extracted. A rate limit (60/hr per
IP, shared behind corporate NAT) or an offline machine therefore stopped the MCP
server from starting at all. A failed freshness check now degrades to the cached
runtime and warns on stderr -- never stdout, which carries the resolved path and is
the MCP stdio channel -- and records the attempt so one dead endpoint is not retried
by every command in the session. With no usable cached runtime the failure stays
loud and still points at the release page.

Relatedly, the download was attempted before checking whether a valid runtime was
already present, leaving the early return unreachable. Any cleanup tool that
reclaimed the cached .zip bricked the plugin offline even though the extracted
binary was intact and tag-matched. Resolution now happens first and short-circuits.

The two download.ps1 copies remain byte-identical modulo 13 plugin-specific tokens;
a normalize-and-compare test now enforces that so a fix applied to one and forgotten
in the other fails in CI instead of shipping. Argument escaping is verified by
round-tripping through CommandLineToArgvW, the same parser the CRT uses to split a
process command line, which keeps the assertion independent of the PowerShell
version running the tests.

start-mcp.ps1 shares the wrapper pattern but is deliberately left alone: it never
receives arguments, so the bug cannot manifest there, and it is not worth perturbing
the MCP stdio handshake in a fix release.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: edb4d8c2-36e0-4719-ab55-4d501b7a2462

* fix(plugins): validate download.ps1 before writing excelcli shims

install-global.ps1 generates a .cmd shim that resolves the runtime by
invoking bin\download.ps1, but it only validated that bin\start-cli.ps1
existed. With download.ps1 missing or corrupt the installer reported
success and wrote shims that failed later, at first use, with an opaque
error from cmd rather than a pointer to the real problem.

Guard the dependency up front, alongside the existing wrapper check and
before any shim or PATH mutation, so a broken plugin tree fails fast and
leaves nothing behind.

The new test pins the "leaves nothing behind" half specifically: it runs
the real installer against a sandbox plugin tree with only download.ps1
absent, redirects USERPROFILE so a regression writes into the sandbox,
and asserts both a non-zero exit and that ~/.copilot/bin was never
created. Mutation-verified: removing the guard makes it fail.

excel-mcp's installer has no such dependency, so this is excel-cli only.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: edb4d8c2-36e0-4719-ab55-4d501b7a2462

---------

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: edb4d8c2-36e0-4719-ab55-4d501b7a2462
2026-08-20 04:50:31 +00:00
Stefan Broenner b2eab4ca91 Migrate plugins to Agent Plugins 1.0 (#776)
Build plugins from canonical source templates, validate portable manifests and MCP configuration, synchronize complete Agent Skill directories, and scope Excel E2E to runtime-impacting changes.

Tests: 23 targeted SkillGeneration tests passed; Release build completed with 0 warnings and 0 errors; Excel E2E path classification passed for 12 cases; MCPB and Agent Skills packaging passed.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Co-authored-by: Stefan Brönner <sbroenne@openclaw.fritz.box>
Copilot-Session: 858e5fa0-f0ef-490f-a154-00c470943904
2026-08-16 10:11:38 +02:00
Stefan Broenner 37aa032503 Docs site: task guides, LLM discoverability layer, and published reference corpus (#769)
* docs: improve discovery and documentation UX

Restructure feature documentation around canonical category pages, improve GitHub Pages navigation and SEO, and align contributor guidance with the canonical-first model.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: f3240d8f-e245-4dfb-a1f5-79373ca1ca1f

* docs: add release note

Document the user-visible discovery and documentation navigation improvements.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: f3240d8f-e245-4dfb-a1f5-79373ca1ca1f

* docs: complete site SEO improvements

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: f3240d8f-e245-4dfb-a1f5-79373ca1ca1f

* docs: add task guides, LLM discoverability layer, and skills reference to site

Intent-matching content (docs/guides/):
- Five canonical task guides built from verified material: refresh Power
  Query, automate PivotTables, query the Data Model with DAX, run VBA
  macros, and COM automation vs. file-parser libraries
- Guides hub index, Guides nav section, cross-links from feature docs,
  FEATURES.md, home page and troubleshooting

Machine-readable layer for AI assistants (gh-pages/hooks.py):
- /llms.txt (llmstxt.org format) and /llms-full.txt, generated from the
  resolved MkDocs nav so they cannot go stale
- Markdown mirror of every page, advertised via rel=alternate
- /tools.json derived from canonical feature docs, build fails on count
  mismatch with FEATURES.md
- FAQPage JSON-LD generated from existing question admonitions
- Explicit AI-crawler allow policy in robots.txt

Reference corpus (skills/shared/ -> /reference/):
- Publish all 24 expert files as a nav-grouped Reference section
- Fix stray outer code fences in conditionalformat, pivottable and
  slicer that also rendered wrong inside the shipped skill packages

Distribution metadata:
- Correct stale tool/operation counts in mcpb/manifest.json and the CLI
  package description
- Point NuGet PackageProjectUrl and .mcp/server.json at the docs site
- Extend check-doc-counts.ps1 to guard both, so this cannot recur

Validation:
- New gh-pages/audit_site.py gate (canonicals, metadata completeness,
  single H1, image dimensions, internal links, sitemap, llms outputs,
  mirror cleanliness, tools.json counts, robots policy) wired into the
  Pages deploy workflow, keeping the docs-only pre-commit path fast

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: f3240d8f-e245-4dfb-a1f5-79373ca1ca1f

* docs: fix marketplace extension identifier and security PoC command

The publisher guide linked to itemName=sbroenne.excelmcp, but the
extension is published as sbroenne.excel-mcp (14 other references in
the repo already use the correct form), so both links 404.

The SECURITY.md path-traversal example invoked 'powerquery export',
which is not a command. Replaced with 'powerquery view', which does
take a file path and so actually illustrates the class of issue.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: f3240d8f-e245-4dfb-a1f5-79373ca1ca1f

---------

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: f3240d8f-e245-4dfb-a1f5-79373ca1ca1f
2026-08-15 12:25:52 +02:00
Stefan Broenner 8c34c73d09 Expand Excel COM coverage to 326 operations (#768)
* Add workbook and worksheet COM coverage

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 00044f4a-446d-46de-856c-5effb4268aab

* Add worksheet view and outline APIs

Tests: Release build; 24 targeted CLI, Core Excel, and MCP E2E tests; COM leak, success flag, coverage, and documentation audits.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 00044f4a-446d-46de-856c-5effb4268aab

* Integrate expanded Excel COM coverage

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 00044f4a-446d-46de-856c-5effb4268aab

* Address automated review feedback

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 00044f4a-446d-46de-856c-5effb4268aab

* Harden QueryTable output and Save As tracking

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 00044f4a-446d-46de-856c-5effb4268aab

* Preserve workbook outputs on failed overwrite

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 00044f4a-446d-46de-856c-5effb4268aab

---------

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 00044f4a-446d-46de-856c-5effb4268aab
2026-08-15 08:18:58 +02:00
github-actions[bot] 352b1da895 Revert: remove RELEASE_PAT verification scratch file [skip ci]
Reverts the scratch verification commit; confirms PAT push authentication
and ruleset bypass work end-to-end for the release-automation fix.
2026-07-23 09:40:03 +02:00
github-actions[bot] f1d85698f3 test: verify RELEASE_PAT can push directly to protected main [skip ci]
This is a scratch verification commit for the release-automation fix in
PR #739 (direct changelog push using RELEASE_PAT as a ruleset bypass
actor). It will be reverted immediately by a follow-up commit.
2026-07-23 09:39:47 +02:00
Stefan Broenner 8988f67ac7 Add list-rules and list-worksheet-rules to conditionalformat (#730) (#734)
* Add list-rules and list-worksheet-rules to conditionalformat (#730)

Add two read actions to the conditionalformat tool so existing conditional
formatting rules can be inspected:

- list-rules: reads rules for a range (Range.FormatConditions)
- list-worksheet-rules: reads all rules on a sheet (Worksheet.Cells.FormatConditions)

Both return rule type, operator, formulas, applies-to range, priority, and
formatting (interior/font/borders) with colors as #RRGGBB hex, in priority order.
MCP + CLI parity is generated automatically from IConditionalFormattingCommands.

Adds ConditionalFormatListResult/ConditionalFormatRuleInfo models, reverse
int->string mappers, FormattingHelpers.ColorToHex, and 8 integration tests.
Docs updated (232 -> 234 operations; Conditional Formatting 2 -> 4).

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 941463de-eb97-4c6d-9f06-f2904603293c

* Harden CF rule reads against COM double/DBNull values (#730)

Address Copilot review on PR #734:
- Read interior/font/border numeric COM props via Convert.ToInt32 so values
  surfaced as double no longer throw and silently skip formatting.
- Treat InvalidCastException (DBNull from unset props) as skippable in the
  COM read guard so mixed-formatting worksheet rules read cleanly.
- Strengthen priority-order test to assert every cellValue rule has a priority.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 941463de-eb97-4c6d-9f06-f2904603293c

* Read CF Type/Operator via Convert.ToInt32 for COM double safety (#730)

Address Copilot re-review on PR #734: FormatCondition.Type and .Operator
can surface as double via dynamic; read them with Convert.ToInt32 so valid
rules are not degraded to unknown/null.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 941463de-eb97-4c6d-9f06-f2904603293c

* Rename CF model file to ConditionalFormatTypes.cs; clarify border docs (#730)

Address Copilot re-review on PR #734:
- Rename ConditionalFormatListResult.cs to ConditionalFormatTypes.cs, matching
  the repo convention for multi-type model files (ResultTypes.cs, PivotTableTypes.cs).
- Document that BorderStyle/BorderColor are sourced from the left edge border
  (xlEdgeLeft), matching the read implementation.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 941463de-eb97-4c6d-9f06-f2904603293c

* Read CF borders across all four edges (#730)

Address Copilot re-review on PR #734: border reading previously inspected only
the left edge, so a rule that set only top/bottom/right borders would report no
border. Now scans left/top/bottom/right and uses the first edge that has a
style. Model docs updated to match.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 941463de-eb97-4c6d-9f06-f2904603293c

* Treat Automatic interior color index as no fill (#730)

Address Copilot re-review on PR #734: Interior.ColorIndex can be
xlColorIndexAutomatic (-4105) when no explicit fill is set. Skip it like
xlColorIndexNone so InteriorColor is not populated (e.g. white) for rules
that did not set an interior color, matching the font-color logic.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 941463de-eb97-4c6d-9f06-f2904603293c

* Read formatConditions.Count via Convert.ToInt32 (#730)

Address Copilot re-review on PR #734: the COM collection count can be surfaced
as double via dynamic; read it with Convert.ToInt32 so rule enumeration does
not throw. Completes the COM-numeric-read hardening for the CF read path.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 941463de-eb97-4c6d-9f06-f2904603293c

---------

Co-authored-by: Stefan Broenner <stbrnner@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 941463de-eb97-4c6d-9f06-f2904603293c
2026-07-23 07:04:34 +02:00
Stefan Broenner bef84d9184 docs: comprehensive documentation audit and fact-check pass (#703)
* Restore Excel green branding and shrink docs hero

Fix two visual regressions on the MkDocs site plus a stray heading bug:

- Color: palette was set to Material teal; restore the Excel brand green
  (#217346 primary, #107c41 accent, #217346->#33a85c hero gradient) via
  custom Material color variables in extra.css, with lifted variants for
  dark mode.
- Hero size: reduce .mcp-hero padding (3rem->1.8rem), icon (96->72px),
  title (2.6->2.1rem) and margins so the header box is less oversized.
- Stray "Home" heading: home.html had a literal {{ super() }} inside an
  HTML comment, which Jinja still evaluated and re-rendered Material's
  auto-injected page title. Render {{ page.content }} directly instead;
  the hero already provides the page's single h1.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Redesign docs landing page for clarity and consistency

Rework the homepage so it routes visitors instead of dumping the whole
manual on one long scroll:

- Remove the triple-represented feature content; keep one consistent
  "Key features" grid (uniform .lg .middle icons + dividers on every card).
- Trim the redundant "Documentation" grid into a consistent "Explore the
  docs" section with matching card styling and call-to-action links.
- Keep the count line ("26 tools and 232 operations") exactly once, so the
  doc-count guard still has its anchor.
- Move the internal architecture detail off the landing page into a new
  architecture.md page, replacing the dated ASCII diagram with a Mermaid
  flowchart (superfences custom_fence added to mkdocs.yml).
- Move author-portfolio "Related projects" into its own related-projects.md
  page under the More nav section.
- Restructure nav: keep Home/Features/Installation/MCP Server/CLI as top
  tabs; group Agent Skills, Architecture, Changelog and the rest under More.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* docs: reframe value prop and critically review all READMEs

Landing page:
- Lead with capability-first "real Excel engine" differentiator (names
  openpyxl / Anthropic xlsx skill as the file-parser contrast)
- Hero H1: "Automate real Excel with AI"
- Add transparent-background nav logo

READMEs (critical review against actual repo):
- Reframe "100% Safe / Zero corruption risk" overclaims to "real Excel engine"
- tests: fix VBA test folder (Vba/), real filenames, drop non-existent trait
- examples: replace non-existent session-demo scripts with inline commands
- infrastructure/azure: fix cost contradiction ($30 -> $61 24/7)
- skills: fix plugin install syntax (@mcp-server-excel-plugins), bash->powershell,
  weak /releases links -> SKILL.md, reorder Goose row
- CLI: convert GitHub Actions bash step to PowerShell (shell: pwsh)
- vscode: add missing Calculation Mode feature, fix broken Troubleshooting heading
- docs proposal: fix plugin install syntax

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* docs: align vscode README with landing page and unify doc links

- Reword landing-page differentiator in plain language (drop
  "re-serialized/approximated" jargon; name the concrete consequence)
- Mirror the reworded value prop and curated "Key features" themes in the
  VS Code marketplace README so it matches excelmcpserver.dev
- Point all documentation links to excelmcpserver.dev (replace stale
  sbroenne.github.io URLs) across vscode, McpServer, CLI, and plugin READMEs;
  keep source-file/issue/badge links on GitHub

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* docs: comprehensive documentation audit and fact-check pass

Full review of all Markdown documentation for accuracy, consistency, and staleness:

- FEATURES.md: fixed verb tense inconsistencies, a nested-list rendering bug
  (Conditional Formatting/Screenshot sections rendering flat instead of nested),
  un-backticked references, removed redundant summary sections.
- Removed the defunct HeyGen MCP server reference and fixed stale tool/operation
  counts across docs.
- SECURITY.md: replaced a stale Supported Versions table (1.6.x/1.7.x) with an
  accurate latest release only policy, and fixed a Version History date error
  (1.0.0 mis-dated 2024 instead of 2025).
- PRIVACY.md: clarified that telemetry is collected by the MCP Server only -
  verified via code search that the CLI has zero telemetry code.
- docs/CONTRIBUTING.md: rewrote the technical sections to describe the actual
  current 5-layer architecture (ComInterop/Core/Service/CLI/McpServer) and
  workflow, replacing a defunct flat-command-registration description.
- CHANGELOG.md: fixed a confirmed year typo - 8 entries (v1.5.0-v1.5.14) were
  dated 2025-01/02 instead of 2026-01/02, verified against actual PR merge
  commit dates, which had broken chronological ordering.
- gh-pages/overrides/main.html: removed a stale hardcoded JSON-LD software
  version with no build-time injection mechanism.
- Reviewed and fixed installation guides, VS Code extension docs, Agent Skills
  docs, and GitHub Copilot plugin READMEs:
  - .github/plugins/excel-mcp/README.md: restored a missing Python in Excel
    (2 ops) row so the category list sums to the advertised 232 operations.
  - skills/README.md and docs/INSTALLATION-MCP-SERVER.md: corrected false
    claims that the VS Code extension auto-installs both the excel-mcp and
    excel-cli skills - it only registers excel-mcp via chatSkills.
  - docs/INSTALLATION.md: corrected a misleading tip claiming the VS Code
    extension bundles the CLI alongside the MCP Server.
- Reviewed MkDocs navigation structure and all site pages for correctness.

Verified: scripts/check-doc-counts.ps1 passes (26 tools / 232 operations),
mkdocs build --strict --clean passes with 0 errors.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* docs: fix remaining VS Code extension / CLI bundling inaccuracies

- docs/INSTALLATION-MCP-SERVER.md: the VS Code extension bundles the MCP
  server only, not the CLI - fixed a claim saying it bundles both.
- docs/INSTALLATION-CLI.md: the excel-cli Copilot plugin bootstraps/downloads
  excelcli.exe on first use rather than bundling it, and the VS Code
  extension does not include the CLI at all - fixed a claim saying the CLI
  is "already included" via either path.
- docs/INSTALLATION.md: clarified the VS Code extension only auto-installs
  the excel-mcp skill (not excel-cli).

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Stefan Broenner <stbrnner@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
2026-07-09 15:51:41 +02:00
Stefan Broenner 198b60a385 Restore Excel green branding and shrink docs hero (#697)
* Restore Excel green branding and shrink docs hero

Fix two visual regressions on the MkDocs site plus a stray heading bug:

- Color: palette was set to Material teal; restore the Excel brand green
  (#217346 primary, #107c41 accent, #217346->#33a85c hero gradient) via
  custom Material color variables in extra.css, with lifted variants for
  dark mode.
- Hero size: reduce .mcp-hero padding (3rem->1.8rem), icon (96->72px),
  title (2.6->2.1rem) and margins so the header box is less oversized.
- Stray "Home" heading: home.html had a literal {{ super() }} inside an
  HTML comment, which Jinja still evaluated and re-rendered Material's
  auto-injected page title. Render {{ page.content }} directly instead;
  the hero already provides the page's single h1.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Redesign docs landing page for clarity and consistency

Rework the homepage so it routes visitors instead of dumping the whole
manual on one long scroll:

- Remove the triple-represented feature content; keep one consistent
  "Key features" grid (uniform .lg .middle icons + dividers on every card).
- Trim the redundant "Documentation" grid into a consistent "Explore the
  docs" section with matching card styling and call-to-action links.
- Keep the count line ("26 tools and 232 operations") exactly once, so the
  doc-count guard still has its anchor.
- Move the internal architecture detail off the landing page into a new
  architecture.md page, replacing the dated ASCII diagram with a Mermaid
  flowchart (superfences custom_fence added to mkdocs.yml).
- Move author-portfolio "Related projects" into its own related-projects.md
  page under the More nav section.
- Restructure nav: keep Home/Features/Installation/MCP Server/CLI as top
  tabs; group Agent Skills, Architecture, Changelog and the rest under More.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* docs: reframe value prop and critically review all READMEs

Landing page:
- Lead with capability-first "real Excel engine" differentiator (names
  openpyxl / Anthropic xlsx skill as the file-parser contrast)
- Hero H1: "Automate real Excel with AI"
- Add transparent-background nav logo

READMEs (critical review against actual repo):
- Reframe "100% Safe / Zero corruption risk" overclaims to "real Excel engine"
- tests: fix VBA test folder (Vba/), real filenames, drop non-existent trait
- examples: replace non-existent session-demo scripts with inline commands
- infrastructure/azure: fix cost contradiction ($30 -> $61 24/7)
- skills: fix plugin install syntax (@mcp-server-excel-plugins), bash->powershell,
  weak /releases links -> SKILL.md, reorder Goose row
- CLI: convert GitHub Actions bash step to PowerShell (shell: pwsh)
- vscode: add missing Calculation Mode feature, fix broken Troubleshooting heading
- docs proposal: fix plugin install syntax

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* docs: align vscode README with landing page and unify doc links

- Reword landing-page differentiator in plain language (drop
  "re-serialized/approximated" jargon; name the concrete consequence)
- Mirror the reworded value prop and curated "Key features" themes in the
  VS Code marketplace README so it matches excelmcpserver.dev
- Point all documentation links to excelmcpserver.dev (replace stale
  sbroenne.github.io URLs) across vscode, McpServer, CLI, and plugin READMEs;
  keep source-file/issue/badge links on GitHub

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Stefan Broenner <stbrnner@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
2026-07-08 21:16:19 +02:00
Stefan Broenner 44e3053d5f Add Python in Excel (PY()) support (#692)
* Add Python in Excel (PY()) support (#691)

Adds a new pythoninexcel Core commands / MCP tool / CLI category with
two operations:
- set-formula: writes a =PY(code, returnType) formula via Range.Formula2
- get-result: polls for the cloud-computed result and classifies it as
  a plain value, a Python error, or a rich Python Object

Python code runs in a Microsoft-hosted cloud sandbox with no reliable
COM-level 'computation finished' signal, so get-result polls Value2
until it has read a stable value across several consecutive samples
over a minimum settle window.

Two real bugs were found and fixed while verifying this:
- Range.Text is unreliable in headless/non-visible Excel automation
  (can render inconsistently even after Value2 has converged), so
  stability polling now compares Value2 only.
- Classification of errors vs. Python Object results now parses the
  returnType argument directly out of the formula text via regex and
  checks Value2 against a fixed list of well-known standard Excel
  error codes, instead of trusting Text.

If polling doesn't stabilize before the timeout, get-result reports
failure and asks the caller to retry rather than returning a possibly
stale value.

All 6 Core integration tests pass reliably (Feature=PythonInExcel).

Docs, FEATURES.md, skills, and CHANGELOG updated (26 tools / 232
operations).

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* docs: add Python in Excel feature card to landing page

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Stefan Broenner <stbrnner@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
2026-07-08 09:18:37 +02:00
Stefan Broenner 3b54044d39 Ship plugin bootstrap runtime wrappers and packaging validation
## Summary
- Ship bootstrap-only Copilot CLI plugin packages for Excel CLI and MCP runtime launchers.
- Auto-download the latest self-contained Windows runtime on first invocation and refresh through wrapper scripts.
- Keep public skills concise by moving detailed CLI command guidance into references/cli-commands.md.
- Add packaging regressions for plugin bootstrap assets and CLI command reference inclusion.

## Validation
- dotnet test tests\ExcelMcp.SkillGeneration.Tests\ExcelMcp.SkillGeneration.Tests.csproj --filter "FullyQualifiedName~PluginBootstrapBuildTests|Feature=SkillGeneration" --blame-hang-timeout 5m --no-restore

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-04-27 13:35:17 +02:00
Stefan Broenner 46313bf67b Enrich plugin README overlays (#615)
* Add plugin README validation gate to pre-commit

Adds check-plugin-readmes.ps1 to validate plugin README overlays before commit.

Validation checks:
- Minimum 40 lines (catches stub/thin content)
- Required sections: title, Prerequisites, Installation
- Skips marketplace-repo README (that's repo-level, not plugin docs)

Prevents shipping incomplete plugin documentation to marketplace.

Pre-commit gate #14 (now 15 total gates).

Addresses user feedback: 'the plugin readmes are horrible!!'

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Update Kelso history with plugin README validation work

Documents implementation of check-plugin-readmes.ps1 and pre-commit integration.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Enrich plugin README overlays with full content

- excel-cli: Full installation, features, and examples
- excel-mcp: Complete plugin documentation with 25 tools overview

Passes check-plugin-readmes.ps1 validation gate (80+ lines, all required sections)

---------

Co-authored-by: Stefan Broenner <stefan.broenner@microsoft.comm>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-04-26 06:45:18 +02:00
Stefan Broenner 848f12b9ff fix: publish excel-cli plugin without bundled binary (#613)
Co-authored-by: Stefan Broenner <stefan.broenner@microsoft.comm>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-04-25 17:16:10 +02:00
Stefan Broenner cb14f2eb5b Add Copilot CLI plugin publish flow and Squad cleanup (#608)
* chore(squad): plan refinement after rubber-duck review — added Phase -1 spike

- Accept all 4 critical + 4 moderate findings from rubber-duck critique
- User approved Phase -1 spike to validate {pluginDir} placeholder before Phase 0
- Incorporate wrapper script design, GitHub App auth, SHA256 verification
- Answer all 5 open questions (Q1–Q5)
- Document decisions in .squad/decisions.md (merged from inbox, deduplicated)
- Update Kelso agent history with session context
- Created orchestration logs and session log for audit trail

Critical fixes ready for Phase -1 execution:
1. Wrapper script (bin/start-mcp.ps1) for missing-binary detection
2. Phase -1 spike to prove {pluginDir} placeholder works
3. GitHub App replacing PAT in release workflow (Phase 4)
4. SHA256 checksum verification in download.ps1 (Phase 4)
5. Version skew detection (version.txt + wrapper validation)
6. Workflow atomicity (concurrency control, single commit)
7. CLI discovery without agent (skill-driven)
8. Drop non-spec frontmatter fields

Next: Execute Phase -1 spike, await Phase 0 GO/NO-GO decision.

* Add plugin publish pipeline

Add Copilot CLI plugin publish automation and supporting docs for syncing
excel-mcp and excel-cli artifacts to the published plugin repository.

Refs #606

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Update Squad governance and remove workflows

Add Kelso to the Squad roster, save the default GPT-5.4 model preference,
remove unused Squad GitHub workflows, and align the active agent guidance
with workflow-free operation.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* docs: Plugin release path audit and documentation sync

Agents: Kelso (Plugin Release), Trejo (Documentation)

## Orchestration

- Kelso: Validated GitHub Copilot CLI plugin publishing workflow; added
  preflight validation; identified PLUGINS_REPO_TOKEN as required secret
- Trejo: Aligned install docs and release strategy with two-plugin flow;
  removed CLI-exclusive wording; clarified plugin support across surfaces

## Changes

### Release Automation
- `.github/workflows/publish-plugins.yml`: Added preflight job that fails
  fast when PLUGINS_REPO_TOKEN is missing (better UX than generic auth error)
- `docs/RELEASE-STRATEGY.md`: Treats plugin publish as required follow-on
  step; added surface-neutral wording for release artifacts

### Documentation Updates
- `README.md`: Two-plugin install flow (marketplace registration + dual install)
- `docs/INSTALLATION.md`: Clarified plugin surface support (Copilot CLI, VS
  Code, Claude); removed CLI-exclusive language
- `gh-pages/index.md`: Updated landing content to reflect multi-surface plugin
  support
- `docs/publish-plugins-setup.md`: Separated artifact publication from
  client-specific install UX

## Decisions Merged

- 2026-04-24: Plugin release preflight and verification (Kelso)
- 2026-04-24: Plugin release wording should be surface-neutral (Kelso)
- 2026-04-24: Plugin install and release sync (Trejo)
- 2026-04-24: Plugin wording must separate concept from install path (Trejo)

## Session Logs

- `.squad/orchestration-log/2026-04-24T10-36-50Z-kelso.md`
- `.squad/orchestration-log/2026-04-24T10-36-50Z-trejo.md`
- `.squad/log/2026-04-24T10-36-50Z-release-plugin-audit.md`

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* chore: revert plugin publish auth from GitHub App to stored PAT

Switches publish-plugins.yml from GitHub App auth (PLUGINS_PUBLISH_APP_ID + PLUGINS_PUBLISH_APP_PRIVATE_KEY) back to a single stored cross-repo token (PLUGINS_REPO_TOKEN) while preserving all operational hardening (preflight gate, sync gate, version guards, manual re-sync path).

WORKFLOW CHANGES:

- Removed GitHub App token minting steps

- Replaced app-id/private-key refs with PLUGINS_REPO_TOKEN secret

- Kept preflight validation (fails fast if token missing/unreachable)

- Kept all guards: downgrade, tag mismatch, duplicate skip, manual override

- Changed commit identity from app bot to github-actions[bot]

DOCS UPDATED:

- publish-plugins-setup.md: PAT setup instructions (removed App sections)

- RELEASE-STRATEGY.md: Updated secrets table, troubleshooting

- INSTALLATION.md: Changed 'GitHub App auth' to 'stored cross-repo PAT'

- README.md: Updated release strategy reference

- gh-pages/index.md: Aligned with README change

- cross-repo-release-preflight SKILL: Generalized patterns for both PAT and App auth

RATIONALE:

Simpler setup (1 secret vs 1 variable + 1 secret), easier rotation, same security posture for this public-repo use case. Keeps iq-core-style operational hardening intact.

* docs: record plugin auth revert decision and learnings

* Scribe: Orchestrate plugin auth revert session (Kelso + Trejo)

- Merged inbox decision: Revert plugin publish auth from GitHub App to stored PAT (PLUGINS_REPO_TOKEN)
- Kelso verified workflow already token-based; coordinated docs revert
- Trejo aligned all user-facing and maintainer docs to simpler PAT model
- Cross-repo-release-preflight skill generalized to document both PAT and App auth patterns
- Updated agent history files with session context and coordination notes
- Decision merged to decisions.md; inbox file deleted

Status: Ready for user to store PLUGINS_REPO_TOKEN secret in repo

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix Copilot plugin marketplace layout

Align the source repo with the two-plugin marketplace model and migrate
published marketplace sync toward the canonical manifest layout.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Stefan Broenner <stefan.broenner@microsoft.comm>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-04-25 14:38:47 +02:00