Commit Graph

10 Commits

Author SHA1 Message Date
Stefan Broenner 3ad8ca3831 Verify plugin runtime downloads (#813)
Publish SHA-256 checksums for Windows runtime archives and require both plugin bootstraps to verify fresh and cached downloads before extraction.

Co-authored-by: Stefan Broenner <stbrnner@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
2026-08-24 19:42:27 +02:00
Stefan Broenner d43a165f85 Preserve Agent Plugins 1.0 source fixes (#811)
* fix(plugin): preserve Agent Plugins 1.0 source

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* docs(plugin): define publication source of truth

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Stefan Broenner <stbrnner@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
2026-08-24 15:40:28 +02:00
Stefan Broenner 4e670445f7 Fix generated skill version validation (#803)
* Fix generated skill version metadata

Require explicit package versions and stamp generated skill outputs across plugin, ZIP, and VS Code distributions.

Tests: Skill version integration tests; plugin packaging tests; Release solution build; VS Code package build.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Restrict VS Code skill copy target

Remove the caller-controlled deletion path so the packaging script only replaces its fixed generated extension directory.

Tests: CopyVscodeSkills_CleansOutputAndStampsExtensionVersion.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
2026-08-20 14:10:35 +02:00
Stefan Broenner b2eab4ca91 Migrate plugins to Agent Plugins 1.0 (#776)
Build plugins from canonical source templates, validate portable manifests and MCP configuration, synchronize complete Agent Skill directories, and scope Excel E2E to runtime-impacting changes.

Tests: 23 targeted SkillGeneration tests passed; Release build completed with 0 warnings and 0 errors; Excel E2E path classification passed for 12 cases; MCPB and Agent Skills packaging passed.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Co-authored-by: Stefan Brönner <sbroenne@openclaw.fritz.box>
Copilot-Session: 858e5fa0-f0ef-490f-a154-00c470943904
2026-08-16 10:11:38 +02:00
github-actions[bot] 352b1da895 Revert: remove RELEASE_PAT verification scratch file [skip ci]
Reverts the scratch verification commit; confirms PAT push authentication
and ruleset bypass work end-to-end for the release-automation fix.
2026-07-23 09:40:03 +02:00
github-actions[bot] f1d85698f3 test: verify RELEASE_PAT can push directly to protected main [skip ci]
This is a scratch verification commit for the release-automation fix in
PR #739 (direct changelog push using RELEASE_PAT as a ruleset bypass
actor). It will be reverted immediately by a follow-up commit.
2026-07-23 09:39:47 +02:00
Stefan Broenner bef84d9184 docs: comprehensive documentation audit and fact-check pass (#703)
* Restore Excel green branding and shrink docs hero

Fix two visual regressions on the MkDocs site plus a stray heading bug:

- Color: palette was set to Material teal; restore the Excel brand green
  (#217346 primary, #107c41 accent, #217346->#33a85c hero gradient) via
  custom Material color variables in extra.css, with lifted variants for
  dark mode.
- Hero size: reduce .mcp-hero padding (3rem->1.8rem), icon (96->72px),
  title (2.6->2.1rem) and margins so the header box is less oversized.
- Stray "Home" heading: home.html had a literal {{ super() }} inside an
  HTML comment, which Jinja still evaluated and re-rendered Material's
  auto-injected page title. Render {{ page.content }} directly instead;
  the hero already provides the page's single h1.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Redesign docs landing page for clarity and consistency

Rework the homepage so it routes visitors instead of dumping the whole
manual on one long scroll:

- Remove the triple-represented feature content; keep one consistent
  "Key features" grid (uniform .lg .middle icons + dividers on every card).
- Trim the redundant "Documentation" grid into a consistent "Explore the
  docs" section with matching card styling and call-to-action links.
- Keep the count line ("26 tools and 232 operations") exactly once, so the
  doc-count guard still has its anchor.
- Move the internal architecture detail off the landing page into a new
  architecture.md page, replacing the dated ASCII diagram with a Mermaid
  flowchart (superfences custom_fence added to mkdocs.yml).
- Move author-portfolio "Related projects" into its own related-projects.md
  page under the More nav section.
- Restructure nav: keep Home/Features/Installation/MCP Server/CLI as top
  tabs; group Agent Skills, Architecture, Changelog and the rest under More.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* docs: reframe value prop and critically review all READMEs

Landing page:
- Lead with capability-first "real Excel engine" differentiator (names
  openpyxl / Anthropic xlsx skill as the file-parser contrast)
- Hero H1: "Automate real Excel with AI"
- Add transparent-background nav logo

READMEs (critical review against actual repo):
- Reframe "100% Safe / Zero corruption risk" overclaims to "real Excel engine"
- tests: fix VBA test folder (Vba/), real filenames, drop non-existent trait
- examples: replace non-existent session-demo scripts with inline commands
- infrastructure/azure: fix cost contradiction ($30 -> $61 24/7)
- skills: fix plugin install syntax (@mcp-server-excel-plugins), bash->powershell,
  weak /releases links -> SKILL.md, reorder Goose row
- CLI: convert GitHub Actions bash step to PowerShell (shell: pwsh)
- vscode: add missing Calculation Mode feature, fix broken Troubleshooting heading
- docs proposal: fix plugin install syntax

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* docs: align vscode README with landing page and unify doc links

- Reword landing-page differentiator in plain language (drop
  "re-serialized/approximated" jargon; name the concrete consequence)
- Mirror the reworded value prop and curated "Key features" themes in the
  VS Code marketplace README so it matches excelmcpserver.dev
- Point all documentation links to excelmcpserver.dev (replace stale
  sbroenne.github.io URLs) across vscode, McpServer, CLI, and plugin READMEs;
  keep source-file/issue/badge links on GitHub

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* docs: comprehensive documentation audit and fact-check pass

Full review of all Markdown documentation for accuracy, consistency, and staleness:

- FEATURES.md: fixed verb tense inconsistencies, a nested-list rendering bug
  (Conditional Formatting/Screenshot sections rendering flat instead of nested),
  un-backticked references, removed redundant summary sections.
- Removed the defunct HeyGen MCP server reference and fixed stale tool/operation
  counts across docs.
- SECURITY.md: replaced a stale Supported Versions table (1.6.x/1.7.x) with an
  accurate latest release only policy, and fixed a Version History date error
  (1.0.0 mis-dated 2024 instead of 2025).
- PRIVACY.md: clarified that telemetry is collected by the MCP Server only -
  verified via code search that the CLI has zero telemetry code.
- docs/CONTRIBUTING.md: rewrote the technical sections to describe the actual
  current 5-layer architecture (ComInterop/Core/Service/CLI/McpServer) and
  workflow, replacing a defunct flat-command-registration description.
- CHANGELOG.md: fixed a confirmed year typo - 8 entries (v1.5.0-v1.5.14) were
  dated 2025-01/02 instead of 2026-01/02, verified against actual PR merge
  commit dates, which had broken chronological ordering.
- gh-pages/overrides/main.html: removed a stale hardcoded JSON-LD software
  version with no build-time injection mechanism.
- Reviewed and fixed installation guides, VS Code extension docs, Agent Skills
  docs, and GitHub Copilot plugin READMEs:
  - .github/plugins/excel-mcp/README.md: restored a missing Python in Excel
    (2 ops) row so the category list sums to the advertised 232 operations.
  - skills/README.md and docs/INSTALLATION-MCP-SERVER.md: corrected false
    claims that the VS Code extension auto-installs both the excel-mcp and
    excel-cli skills - it only registers excel-mcp via chatSkills.
  - docs/INSTALLATION.md: corrected a misleading tip claiming the VS Code
    extension bundles the CLI alongside the MCP Server.
- Reviewed MkDocs navigation structure and all site pages for correctness.

Verified: scripts/check-doc-counts.ps1 passes (26 tools / 232 operations),
mkdocs build --strict --clean passes with 0 errors.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* docs: fix remaining VS Code extension / CLI bundling inaccuracies

- docs/INSTALLATION-MCP-SERVER.md: the VS Code extension bundles the MCP
  server only, not the CLI - fixed a claim saying it bundles both.
- docs/INSTALLATION-CLI.md: the excel-cli Copilot plugin bootstraps/downloads
  excelcli.exe on first use rather than bundling it, and the VS Code
  extension does not include the CLI at all - fixed a claim saying the CLI
  is "already included" via either path.
- docs/INSTALLATION.md: clarified the VS Code extension only auto-installs
  the excel-mcp skill (not excel-cli).

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Stefan Broenner <stbrnner@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
2026-07-09 15:51:41 +02:00
Stefan Broenner 3b54044d39 Ship plugin bootstrap runtime wrappers and packaging validation
## Summary
- Ship bootstrap-only Copilot CLI plugin packages for Excel CLI and MCP runtime launchers.
- Auto-download the latest self-contained Windows runtime on first invocation and refresh through wrapper scripts.
- Keep public skills concise by moving detailed CLI command guidance into references/cli-commands.md.
- Add packaging regressions for plugin bootstrap assets and CLI command reference inclusion.

## Validation
- dotnet test tests\ExcelMcp.SkillGeneration.Tests\ExcelMcp.SkillGeneration.Tests.csproj --filter "FullyQualifiedName~PluginBootstrapBuildTests|Feature=SkillGeneration" --blame-hang-timeout 5m --no-restore

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-04-27 13:35:17 +02:00
Stefan Broenner 9924234aec chore: harden release workflows and extension packaging
- fix publish-plugins tag resolution for annotated release tags
- remove retired workflow/package distribution surfaces and align docs
- switch vscode-extension packaging to @vscode/vsce 2.25.0 to clear the unpatchable Dependabot uuid chain

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-04-25 16:25:56 +02:00
Stefan Broenner cb14f2eb5b Add Copilot CLI plugin publish flow and Squad cleanup (#608)
* chore(squad): plan refinement after rubber-duck review — added Phase -1 spike

- Accept all 4 critical + 4 moderate findings from rubber-duck critique
- User approved Phase -1 spike to validate {pluginDir} placeholder before Phase 0
- Incorporate wrapper script design, GitHub App auth, SHA256 verification
- Answer all 5 open questions (Q1–Q5)
- Document decisions in .squad/decisions.md (merged from inbox, deduplicated)
- Update Kelso agent history with session context
- Created orchestration logs and session log for audit trail

Critical fixes ready for Phase -1 execution:
1. Wrapper script (bin/start-mcp.ps1) for missing-binary detection
2. Phase -1 spike to prove {pluginDir} placeholder works
3. GitHub App replacing PAT in release workflow (Phase 4)
4. SHA256 checksum verification in download.ps1 (Phase 4)
5. Version skew detection (version.txt + wrapper validation)
6. Workflow atomicity (concurrency control, single commit)
7. CLI discovery without agent (skill-driven)
8. Drop non-spec frontmatter fields

Next: Execute Phase -1 spike, await Phase 0 GO/NO-GO decision.

* Add plugin publish pipeline

Add Copilot CLI plugin publish automation and supporting docs for syncing
excel-mcp and excel-cli artifacts to the published plugin repository.

Refs #606

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Update Squad governance and remove workflows

Add Kelso to the Squad roster, save the default GPT-5.4 model preference,
remove unused Squad GitHub workflows, and align the active agent guidance
with workflow-free operation.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* docs: Plugin release path audit and documentation sync

Agents: Kelso (Plugin Release), Trejo (Documentation)

## Orchestration

- Kelso: Validated GitHub Copilot CLI plugin publishing workflow; added
  preflight validation; identified PLUGINS_REPO_TOKEN as required secret
- Trejo: Aligned install docs and release strategy with two-plugin flow;
  removed CLI-exclusive wording; clarified plugin support across surfaces

## Changes

### Release Automation
- `.github/workflows/publish-plugins.yml`: Added preflight job that fails
  fast when PLUGINS_REPO_TOKEN is missing (better UX than generic auth error)
- `docs/RELEASE-STRATEGY.md`: Treats plugin publish as required follow-on
  step; added surface-neutral wording for release artifacts

### Documentation Updates
- `README.md`: Two-plugin install flow (marketplace registration + dual install)
- `docs/INSTALLATION.md`: Clarified plugin surface support (Copilot CLI, VS
  Code, Claude); removed CLI-exclusive language
- `gh-pages/index.md`: Updated landing content to reflect multi-surface plugin
  support
- `docs/publish-plugins-setup.md`: Separated artifact publication from
  client-specific install UX

## Decisions Merged

- 2026-04-24: Plugin release preflight and verification (Kelso)
- 2026-04-24: Plugin release wording should be surface-neutral (Kelso)
- 2026-04-24: Plugin install and release sync (Trejo)
- 2026-04-24: Plugin wording must separate concept from install path (Trejo)

## Session Logs

- `.squad/orchestration-log/2026-04-24T10-36-50Z-kelso.md`
- `.squad/orchestration-log/2026-04-24T10-36-50Z-trejo.md`
- `.squad/log/2026-04-24T10-36-50Z-release-plugin-audit.md`

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* chore: revert plugin publish auth from GitHub App to stored PAT

Switches publish-plugins.yml from GitHub App auth (PLUGINS_PUBLISH_APP_ID + PLUGINS_PUBLISH_APP_PRIVATE_KEY) back to a single stored cross-repo token (PLUGINS_REPO_TOKEN) while preserving all operational hardening (preflight gate, sync gate, version guards, manual re-sync path).

WORKFLOW CHANGES:

- Removed GitHub App token minting steps

- Replaced app-id/private-key refs with PLUGINS_REPO_TOKEN secret

- Kept preflight validation (fails fast if token missing/unreachable)

- Kept all guards: downgrade, tag mismatch, duplicate skip, manual override

- Changed commit identity from app bot to github-actions[bot]

DOCS UPDATED:

- publish-plugins-setup.md: PAT setup instructions (removed App sections)

- RELEASE-STRATEGY.md: Updated secrets table, troubleshooting

- INSTALLATION.md: Changed 'GitHub App auth' to 'stored cross-repo PAT'

- README.md: Updated release strategy reference

- gh-pages/index.md: Aligned with README change

- cross-repo-release-preflight SKILL: Generalized patterns for both PAT and App auth

RATIONALE:

Simpler setup (1 secret vs 1 variable + 1 secret), easier rotation, same security posture for this public-repo use case. Keeps iq-core-style operational hardening intact.

* docs: record plugin auth revert decision and learnings

* Scribe: Orchestrate plugin auth revert session (Kelso + Trejo)

- Merged inbox decision: Revert plugin publish auth from GitHub App to stored PAT (PLUGINS_REPO_TOKEN)
- Kelso verified workflow already token-based; coordinated docs revert
- Trejo aligned all user-facing and maintainer docs to simpler PAT model
- Cross-repo-release-preflight skill generalized to document both PAT and App auth patterns
- Updated agent history files with session context and coordination notes
- Decision merged to decisions.md; inbox file deleted

Status: Ready for user to store PLUGINS_REPO_TOKEN secret in repo

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix Copilot plugin marketplace layout

Align the source repo with the two-plugin marketplace model and migrate
published marketplace sync toward the canonical manifest layout.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Stefan Broenner <stefan.broenner@microsoft.comm>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-04-25 14:38:47 +02:00