Default the homepage Plugins catalog to Featured when switching from the Skills-only Trending tab, while preserving explicit valid plugin tabs and existing Skills behavior.\n\nCloses #3433
Restores homepage search and category discovery while preserving the canonical Trending feed contract. Adds the responsive control-group divider and closes#3417.
Remove Skill listing icons across discovery, retain Plugin recognition icons on desktop, and collapse both icon columns at the existing mobile breakpoints. Keep loading skeletons aligned with settled rows and cards.
Closes#3425.
Co-authored-by: Vyctor H. Brzezowski <krzyszchweski@gmail.com>
Constrain the mobile app-category strip to the available content width while preserving internal horizontal scrolling. Scope the CSS regression contract to the exact nested mobile rule.
Auto-populate the publish form short summary from SKILL.md frontmatter
description (metadata or top-level), with a dismissible in-field banner
that nudges authors toward discovery-friendly copy. Reset prefill state
on re-upload, measure banner height for textarea padding, and raise the
summary limit to 300 characters.
Run oxfmt across touched UI files, stop exporting the unused inline-code
summary segment type, and type the malformed-topic hook test so types-build
passes.
Keep GitHub-backed pending verification visible in browse/search, hide only
first-publish hosted pending skills synchronously, and require a listable
approved version before showing hosted skills still under review.
Tighten publicBrowse test fixtures for Convex Id/license types, drop
moderationSourceVersionId from digest picks, and apply pending-review
filtering to listPublicApiPageV1 entries.
Stop default recommended browse from falling back to updated ordering when
scores are missing, and exclude pending-review items from public browse/search
while preserving the last approved version for established skills.
* Improve skill publish metadata layout and copy.
Reorganize categories/topics into their own card, add short summary on publish, align catalog fields, and clarify publishing-as owner labels.
* Rename publish tags label and fix related tests.
Use Release tags on the publish form, align publishing-as aria labels, and replace the invisible catalog toolbar mirror with a height spacer.
* Cap publish summary at 200 chars and polish PR assets.
Limit the publish-form short summary to 200 characters, tighten publish-only backend validation, simplify owner option labels, and drop the broken in-repo PR screenshot.
* feat(ui): move creator into skill and plugin detail hero
Show publisher name, handle, and official badge below the summary in the
shared detail hero, remove the sidebar Creator row, and resolve official
status from backend publisher data plus client fallback lookup.
* fix(ui): avoid extra official publisher detail reads
* fix(ui): align creator hero types with package API
* fix(og): render org profile images in publisher OG cards
Pass publisher avatar, kind, and installs into OG meta URLs and allow
safely fetching public HTTPS org logos when generating profile images.
* fix: render org profile images in publisher OG cards
Org logos use public HTTPS URLs outside the GitHub/gravatar allowlist, so OG
generation fell back to the default mark. Allow SSRF-safe public fetches for
publisher profile avatars and embed avatar/kind metadata in OG URLs.
* fix(og): show Downloads instead of Installs on OG cards
Switch skill, plugin, and publisher OG image generators to read and
label download counts, with legacy installs query param fallback.
* fix(og): type skill API payload for canonical stat reads
Export SkillStatReadable so fetchSkillOgMeta can pass API skill stats
through readCanonicalStat without a TypeScript error.
* fix(og): format compact downloads in OG cards
Query-param download counts were rendered as raw integers on publisher
OG images. Reuse formatCompactStat, add download icon + lowercase label,
bump layout versions, and refresh org profile visual proof.
* fix(og): use Downloads label without icon on OG cards
Remove the download SVG from OG stat blocks and show only a muted
"Downloads" label above compact values. Bump skill/plugin/publisher
layout versions to bust cached social previews.
* fix(web): align publisher grouped All tab with catalog total
The grouped All chip was summing only paginated items while the Skills/Plugins tab showed the publisher total, causing mismatches like Plugins 59 vs All 12 on large profiles.
* docs(proof): add post-fix publisher All tab screenshot
* fix(web): restore full-color round user avatars in Cmd+K typeahead
Keep org avatars square and muted in the navbar search dropdown while showing user profile photos in full color with circular framing.
* fix(web): limit typeahead user color restore to profile photos
Keep muted glyph fallbacks for users without avatars while preserving full-color circular photos and explicit muted square org treatment.
* fix(web): compact CLI/Prompt toggle on skill install card
Replace pill tablist with a flat text toggle for CLI vs Prompt install
options, with matching skeleton and styles.
* chore: add UI proof screenshot for install toggle PR
* feat(profile): polish publisher detail hero, catalog, and members layout
Refine the publisher profile page with a full-width hero, larger avatar,
Links/Members side-by-side details, chip-based catalog filters, and
segmented Skills/Plugins tabs while extracting profile styles into a
dedicated stylesheet.
* feat(profile): polish catalog grouping, members UI, and chrome layout
Checkpoint before moving publisher stats into the profile header actions slot.
* feat(profile): default catalog tab, plugin links, and visual proof
Open the plugins tab when a publisher has no skills, preserve scoped
plugin detail hrefs on profile rows, and keep catalog pagination active
during search. Includes publisher profile polish follow-ups and UI proof
screenshots for the PR.
* fix(profile): clear lint issues in publisher profile route
* fix(profile): polish avatar/badge details and refresh UI proof
Square org avatars, show icon-only official badge on mobile handles, and
match member placeholder size to photo avatars. Regenerate publisher
profile Playwright screenshots for PR proof.
* test(e2e): assert publisher catalog region on profile smoke
Match the publisher profile catalog landmark after the profile polish
removed the visible "Publisher catalog" heading.
* test(e2e): stabilize org delete profile catalog waits
Wait for the publisher profile heading and catalog region before asserting
seeded skill visibility, matching the async catalog load on the polished
profile page.
* test(e2e): assert publisher catalog skills by slug link
Profile catalog rows truncate display names to 40 chars, so deletion
proofs should wait for the skill detail href instead of the full seed
label text.
* fix(test): add skillSlug to AccountDeletionFixture type
Unblocks types-build after the publisher profile e2e assertion started
reading fixture.skillSlug for the catalog link check.
* Polish skill header visibility alert and CLI install command styling.
Move staff moderation notes into the management toolbar and highlight install command targets with muted verb and emphasized slug.
* Polish plugin validation findings as a hero section above detail tabs.
Move validation outputs out of the tab bar into a persistent findings region with richer cards, CLI/agent copy actions, and updated unit and e2e coverage.
* Polish plugin validation fix guide header layout.
Stack the remediation copy on its own line and pin the fix guide link to the top-right beside the How to fix label.
* Polish plugin validation fix guide link column and color.
Move the fix guide CTA into a right column centered against the copy block and set the link color to #0099FF.
* Polish plugin validation panel header, actions, and findings list.
Tighten validation overview hierarchy with neutral stats, summary hint,
CLI validate block, and Copy instructions tooltip; align action heights,
collapse findings by default, and update unit/e2e assertions for the new copy.
* feat(web): rename publishers browse to Creators
Align /publishers page heading and filter tabs with clearer creator-focused copy, move Official after All, and show full org labels on desktop only.
* test(e2e): align local-auth flows with owner-qualified routes
Update playwright local-auth helpers and specs for canonical profile, skill, and plugin URLs after the main branch routing migration.
* fix(test): export plugin validation href helper for e2e typecheck
* chore: format local-auth helpers import
* chore: retrigger CI after flaky local-auth shards
* feat(web): move publishers browse to /creators route
Keep /publishers and /users as legacy redirects with search preserved, and align registry copy, tests, and reserved slugs with the new path.
* fix(web): drop unused OpenClaw slug re-export after schema move
* chore: format openClawExtensionSlugs re-export cleanup
* fix(web): show only downloads in plugin browse listings
Plugin list rows and cards on /plugins and the home Plugins tab no longer surface star counts.
* docs: add UI proof screenshots for plugin listing change
* fix: recall publishers outside top install window in search
Publisher search only scanned the top 500 by installs and dropped empty
profiles, so handles like vincentkoc never appeared even when the user
profile was public.
* test: cover publisher search recall for low-install handles
Add regression coverage for publishers with published skills that fall
outside the top install browse window, matching the vyctorbrzezowski case.
* test: align publisher search mocks with downloads browse indexes
* chore: add production publisher search proof for PR 2790
* test: drop invalid publisher list stats assertion
Remove stats.skills expectation from listPublicPage search recall test;
public list items only expose downloads and installs counts.
* chore: retrigger CI after delete-account flake
* fix: polish skill detail hero metadata
* fix: improve skill readme presentation
* chore: outline skill detail structure
* fix: narrow detail page container
* fix: compact skill sidebar on detail pages
* fix: use body font for install switcher
* fix: align plugin detail sidebar
* fix: shorten skill readme preview
* fix: soften related skills heading
* fix: remove duplicate stars metadata
* fix: remove related skill hover underline
* chore: remove detail debug outlines
* fix: align hero with content column
* fix: rename summary disclosure action
* fix: wrap tab content in contrast panel
* fix: restore full width hero layout
* fix: refine skill detail surfaces
* fix: soften skill readme body copy
* fix: hide skill detail breadcrumbs
* fix: place skill taxonomy above title
* fix: reduce skill detail title size
* fix: add skill hero top spacing
* fix: standardize skill markdown formatting
* fix: refine related skills navigation
* fix: align plugin detail hero with skills
* fix: increase hero taxonomy spacing
* fix: mark official plugin owners
* fix: tune detail sidebar labels
* fix: restyle install tab switcher
* fix: add subtle skill detail wash
* fix: horizontalize skill versions panel
* fix: animate install tab switcher
* fix: align plugin versions layout
* fix: improve tab markdown surface contrast
* fix: separate detail categories with commas
* fix: remove detail tab underline bars
* fix: bleed skill wash behind header
* fix: polish detail versions changelog
* fix: add file tree to skill files view
* fix: anchor skill wash to page top
* fix: restore plugin version download actions
* fix: align detail sidebar top spacing
* fix: restore active detail tab bar
* fix: collapse detail version changelogs
* fix: clarify version changelog toggles
* fix: tune detail tab and install polish
* fix: polish markdown code blocks
* fix: refine markdown code wrap control
* docs: capture detail polish direction
* fix: refine release history layout
* feat: simplify detail file navigation
* fix: align detail hero sidebar patterns
* fix: unify plugin and skill detail polish
* fix: refine detail hero and release rows
* fix: move related skills below detail content
* fix: align detail hero title with main content column
Keep the hero wash full width while constraining taxonomy, title, and
summary to the same grid column as install and tab content on desktop.
* fix: increase star count badge font to 14px
Make the sidebar star action count easier to read on detail pages.
* fix: align shiki code block surfaces with detail markdown
Override Shiki's inline pre background so fenced blocks use the shared
markdown-code-block surface on skill and plugin README tabs.
* fix: remove code wrap toggle blur flicker
Drop the wrap-state blur reveal so toggling nowrap/wrap keeps the code
DOM stable without flashing highlighted tokens.
* fix: contain detail markdown overflow in tab bodies
Keep README and SKILL surfaces clipped to the tab column while preserving
horizontal scroll only inside code blocks and tables.
* fix: use neutral hover border on detail sidebar actions
Override the accent outline hover on Star, Share, and Download sidebar
buttons so detail pages keep a quieter action treatment.
* fix: tighten release row checks and download actions
Keep scan badges on one horizontal row, left-align package actions with
the column header, and show an icon-only download control.
* fix: collapse long plugin README previews like SKILL.md
Reuse the skill readme preview limiter with Read more/Show less on plugin
README.md tabs so long documentation stays scannable by default.
* fix: match activity metric info icon to security audit
Reuse the quiet sidebar info button styling so download labels no longer
show a circular hover treatment on the help icon.
* chore: remove unused activity metric info button styles
* fix: use neutral colors for download trend sparklines
Keep sidebar activity graphs muted with ink-soft tones instead of accent
red on skill and plugin detail pages.
* fix(ui): style related skills category link as outline button
Give the compact hero "More in …" footer full-width outline button affordance with neutral hover, matching sidebar secondary actions.
Co-authored-by: Cursor <cursoragent@cursor.com>
* fix(ui): compact skill/plugin detail hero on mobile
Tighten vertical rhythm below 1100px: side-by-side Star/Share, smaller
action buttons, denser metadata rows, shorter download sparkline, and
reduced gaps between hero, sidebar, and install sections.
Co-authored-by: Cursor <cursoragent@cursor.com>
* fix(ui): reduce sidebar action count font to 13px
Co-authored-by: Cursor <cursoragent@cursor.com>
* fix(ui): reduce sidebar action count font to 13px
Co-authored-by: Cursor <cursoragent@cursor.com>
* fix(ui): shrink sidebar star count badge height
Lower the action-count pill so Star and Share buttons align at the same height.
Co-authored-by: Cursor <cursoragent@cursor.com>
* fix(ui): restore markdown ordered and bullet list markers
Tailwind preflight strips list-style from ol/ul; re-apply disc and decimal
markers inside .markdown so SKILL.md and plugin README numbering renders.
Co-authored-by: Cursor <cursoragent@cursor.com>
* feat: add download period tabs to detail sidebar
Replace the static 30-day downloads row with All time, 30d, and 7d tabs
that update the sparkline and total on skill and plugin detail pages.
Co-authored-by: Cursor <cursoragent@cursor.com>
* fix(ui): polish audit sidebar, badges, and chart theme tokens
Make creator badges fully clickable, collapse Latest audit to one inline row,
and tune download sparkline colors per theme with softer blue tones.
Co-authored-by: Cursor <cursoragent@cursor.com>
* fix: make creator user badges fully clickable
Use fallbackHandle for profile links, pass plugin ownerHandle when the
owner record omits it, and add sidebar hover affordance on the whole badge.
Co-authored-by: Cursor <cursoragent@cursor.com>
* fix(ui): tighten audit sidebar and related skills footer
Center the category footer action, remove the secondary-actions negative
margin hack, and keep Latest audit on one compact inline row.
Co-authored-by: Cursor <cursoragent@cursor.com>
* fix(ui): refine downloads tabs, report row, and related summaries
Move download period tabs inline with the Downloads label using listing-style
underline tabs, drop the Report block top border, and cap related skill
descriptions at 80 characters.
Co-authored-by: Cursor <cursoragent@cursor.com>
* feat: polish skill and plugin detail pages
* feat: add diff viewer skeleton
* fix: retain diff skeleton while versions load
* feat: restructure skill card review layout
* feat: add category icons to related skills
* fix: keep primary skill file first
* fix: keep skill card context expanded
* fix: refine skill card overview and risk contrast
* fix: show stars in related skill rows
* fix: refine install requirement tabs
* fix: join skill card risk rail
* fix: align plugin versions panel behavior
* fix: polish plugin repository and requirement panels
* fix: stabilize detail page skeleton layouts
* fix: resolve detail hydration gaps and finish polish pass
Keep mobile/desktop detail markup stable for SSR hydration, sync Shiki
theme selection with useSyncExternalStore, and complete tabpanel ARIA for
Files and Versions. Also lands remaining plugin categorize, install, and
metadata dialog polish from the detail-page iteration.
Co-authored-by: Cursor <cursoragent@cursor.com>
* fix: stabilize detail page CI contracts
* feat(web): polish detail install shell and checkpoint branch WIP
Add subtle terminal $ prompt to skill/plugin install commands with
vertical alignment and descender-safe line height. Bundle remaining
detail-page polish, dialog tweaks, and local PR proof artifacts as a
restore point before further agent work.
* fix(web): polish plugin sidebar download and detail hero alignment
Move plugin download inline with the downloads count when no activity graph
is shown, and to the sidebar footer when a graph is present. Align skill/plugin
hero summary rows, compact management toolbar actions, and plugin mobile
About/Stats tabs. Remove accidental local proof artifacts from the branch.
* fix(web): stabilize detail page CI
---------
Co-authored-by: Cursor <cursoragent@cursor.com>
* fix: restrict membership management to org publishers
* fix(api): ignore stale personal publisher memberships
* fix(api): reject stale personal publisher publish targets
* fix(api): reject stale personal publisher memberships
* fix(api): use personal publisher links for package access
* fix(api): guard personal publisher owner scopes
* fix: enforce publisher ownership for skill reads
* fix: narrow personal publisher dashboard owner
* fix: ignore stale personal package memberships
* fix: allow own legacy personal skill destination
* fix: preserve legacy personal package dashboards
* fix: preserve legacy personal skill dashboards
* fix: avoid redundant personal publisher boolean coercion
* fix: preserve legacy personal publisher access
* fix: include legacy direct packages in personal dashboard
* fix: close stale personal publisher ownership gaps
---------
Co-authored-by: Patrick Erichsen <patrick.a.erichsen@gmail.com>
* fix: hide package resources when owners are banned
* fix(api): attribute unban package restores to moderator
* fix(web): clarify package effects in ban confirmations
* fix(api): continue package ban batches during in-flight bans
* fix: keep package unban restore scoped to ban batch
* fix: retimestamp package releases during repeated bans
* fix: start package ban batches after user ban commit
* fix: preserve manual package moderation after unban
* fix: cover personal publisher package sanctions
* fix: restore personal publisher packages in autoban remediation
* fix: bound package publish token revocation batches
* fix: clear package ban reason during remediation restore
* fix: block direct package ban restores
* fix: scan linked personal publisher packages during sanctions
* fix: tighten package sanction restore batches
* fix: block personal publisher publishes after owner ban
* fix: allow initial package ban cleanup before commit
---------
Co-authored-by: Patrick Erichsen <patrick.a.erichsen@gmail.com>
* fix: block direct skill transfers under moderation
* fix(api): block accepted transfers for moderated skills
* fix(api): block malware-flagged skill transfers
* fix: cover moderated skill transfer bypasses
* test: support ownership heal transfer sync
* fix: close moderated transfer backfill gaps
* fix: block soft-deleted transfer guard state
---------
Co-authored-by: Patrick Erichsen <patrick.a.erichsen@gmail.com>
Replace ad-hoc sign-in UI on /settings, /dashboard, /import, /stars,
/cli/auth and /docs/auth with a single SignInPrompt component that
mirrors the polished /settings design (gradient backdrop, blur, card
with shadow, LockKeyhole icon, styled GitHub sign-in button).
Also replaces inline 'Sign in to comment.' text in SoulDetailPage and
SkillCommentsPanel with a compact SignInButton size='sm'.
Adds SignInPrompt.test.tsx with 8 unit tests and -stars.test.tsx with
6 route-level tests.
Fixes stars.tsx loading logic so unauthenticated users see the prompt
immediately instead of a skeleton.
- bun run build: pass
- bun run format:check: pass
- bun run lint: pass
- bun run test: 1,758 tests pass
Co-authored-by: Patrick Erichsen <patrick.a.erichsen@gmail.com>
* fix: prevent skill transfer acceptance after requester is banned
The acceptTransferInternal mutation did not verify whether the transfer
requester (fromUser) was banned or deactivated when the skill still
belonged to that user. This created a race condition where a pending
transfer could be accepted after the requester was banned, allowing
the skill to escape the ban batch and remain alive under a new owner.
This change moves the requester validity check before the ownership
branch, so it is evaluated unconditionally for all transfers.
Fixes a security vulnerability where banned users' skills could
survive moderation actions via pending transfers.
* fix: harden skill transfer acceptance
Co-authored-by: vyctorbrzezowski <krzyszchweski@gmail.com>
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com>
Redesign Settings into focused account, organization, API token, and account deletion views.
Follow-up verification:
- restored the Separator primitive usage so the Radix dependency remains active and static checks pass
- gated the organization member query to the organizations view with a selected org
- added focused settings coverage for default account rendering, organizations navigation/member loading, and legacy hash migration
Validation:
- bun install --frozen-lockfile
- bun run test -- src/routes/-settings.test.tsx src/__tests__/header.test.tsx
- bun run test:ui-contract
- bun run ci:static
- bunx tsc --noEmit
- bunx tsc -p packages/schema/tsconfig.json --noEmit
- bunx tsc -p packages/clawhub/tsconfig.json --noEmit
- VITE_CONVEX_URL=https://example.invalid bun run build
- GitHub repo-owned PR checks passed on verified signed head 7abd808fd4
Vercel fork authorization remained a non-code failure; authenticated local visual proof was blocked by missing GitHub login credentials, while signed-out settings route dev QA rendered without framework overlay.
Align signed-in header avatar controls across desktop and mobile so the menu trigger keeps consistent sizing, truncation, and dropdown styling.\n\nCo-authored-by: vyctorbrzezowski <krzyszchweski@gmail.com>
Add the publishers discovery/profile surface and harden the landing fixups for existing publisher aggregate rows and scoped plugin links.
Co-authored-by: Vyctor Huggo Przozwski <krzyszchweski@gmail.com>
Co-authored-by: Peter Steinberger <peter@steipete.com>
Clean stale seed lookup/badge rows during repeated local Convex dev seed resets, and delete package fixtures in an order that avoids the package-release trigger fallback query limit.\n\nTests:\n- bun run test -- convex/devSeed.rescanFixtures.test.ts\n- bun run format:check\n- bun run lint\n- bunx tsc --noEmit\n- bunx tsc -p packages/schema/tsconfig.json --noEmit\n- bunx tsc -p packages/clawhub/tsconfig.json --noEmit\n- git diff --check origin/main...HEAD\n\nCo-authored-by: vyctorbrzezowski <krzyszchweski@gmail.com>
Document local Convex HTTP route usage through the site proxy port and make setup-worktree reject local site URL misconfigurations that point browser/auth routes at the function port.\n\nTests:\n- bun run test -- scripts/setup-worktree.test.ts\n- bun run format:check\n- bun run lint\n- bunx tsc --noEmit\n- bunx tsc -p packages/schema/tsconfig.json --noEmit\n- bunx tsc -p packages/clawhub/tsconfig.json --noEmit\n- git diff --check origin/main...HEAD\n\nCo-authored-by: vyctorbrzezowski <krzyszchweski@gmail.com>