plugin-review

작성자: base

Base MCP 플러그인 파일을 플러그인 사양에 따라 검증하고 검토합니다. 새 플러그인을 작성하거나, 플러그인 PR을 제출하기 위해 준비하거나, 자체 점검할 때 사용합니다.

npx skills add https://github.com/base/skills --skill plugin-review

Plugin Review

Validate Base MCP plugin files against the current Plugin Specification. Produces a conformance report with actionable findings.

Works for both authors (self-check before submitting a PR) and reviewers (evaluate an incoming PR).

Workflow

  1. Fetch the current spec (it changes — never rely on a stale copy):

    curl -s https://raw.githubusercontent.com/base/skills/master/skills/base-mcp/references/plugin-spec.md
    

    Related docs worth reading: references/custom-plugins.md, references/approval-mode.md, references/batch-calls.md, and SKILL.md (the root skill). Existing native plugins under skills/base-mcp/plugins/ are the precedent for conventions.

  2. Read the plugin file in full. If reviewing a PR:

    gh pr view <n> --repo base/skills --json title,body,number,headRefName,files,additions,deletions
    gh pr diff <n> --repo base/skills
    # raw plugin file (diff may be truncated):
    gh api "repos/base/skills/pulls/<n>/files" --jq '.[] | select(.filename|endswith(".md")) | .raw_url'
    
  3. Static conformance evaluation — assess against every dimension in references/evaluation-criteria.md (includes compliance/language checks and high-risk category gates). Write the report using references/report-template.md.

  4. (Optional) Live API / SDK verification — exercise the documented endpoints/SDK/contracts with read-only calls. See references/live-testing.md. For perps/prediction-market/gambling plugins, also run the geoblock verification (compare frontend vs API access restrictions). Append a ## Live API / SDK Verification section to the report. This routinely overturns doc claims (fabricated/locked endpoints, broken hosts, wrong response shapes).

  5. Save the report. If reviewing a PR and asked to comment, draft a PR comment from the report using references/comment-guidelines.md and post with: gh pr comment <n> --repo base/skills --body-file <comment-file>.

Multiple PRs

Evaluate PRs in parallel by spinning up one sub-agent per PR (each writes its own report + returns a short verdict summary). Hand each sub-agent: the spec (or its raw URL), the PR number, the evaluation criteria, the report template, and the comment guidelines.

Critical gotchas

These recur and are easy to get wrong — full detail in references/evaluation-criteria.md:

  • Smart-account signatures break naive signing. The default Base MCP wallet is a smart contract; sign returns a variable-length ERC-1271/6492 signature (>200 bytes), not a 65-byte EOA sig. Any plugin that splices a signature into a fixed-width calldata slot, or bakes an off-chain EIP-712 signature into calldata (e.g. Permit2 buildCallWithPermit2), is broken for that wallet. Correct pattern: onchain allowance grants.
  • irreversible risk is NOT for every onchain write. The spec says "flag when worth emphasizing." Pure swaps use slippage (precedent: Uniswap, Aerodrome carry [slippage], not irreversible). Reserve irreversible for asymmetric/severe cases (perps/liquidation, token launches/rug). Do not demand it on swaps.
  • Don't self-register. A plugin PR must NOT edit the SKILL.md plugins table, the Integration Types "Examples" cell, or the "Existing Plugin Conformance" table — those are maintainer-managed (codified in plugin-spec.md "Contribution Scope"). The only sanctioned shared-file edit is appending a genuinely net-new tag to the vocabulary list. Limit the diff to plugins/<slug>.md (+ that tag line).
  • version is the plugin-doc version — not the npm/package version and not a global spec version. The spec mandates no specific starting number.
  • Verify claims, don't trust them. Auth models, allowlist completeness, response shapes, and contract addresses are frequently wrong in the doc. Probe them (live testing).
  • Reference links from a plugin file must use ../references/... (plugin files live in plugins/, refs in references/).
  • Neutral language is mandatory. No yield/rate/performance claims, no "you should buy X", no "always deposit here", no defaulting to specific tokens. Steering language is a blocker.
  • Perps, prediction markets, and privacy plugins need legal review before inclusion as native plugins. Flag this as a pre-merge process gate in the report.
  • API geoblock parity. If the protocol's frontend geoblocks US IPs (or others), the API must enforce equivalent restrictions. If it doesn't, Base MCP risks being a circumvention tool — flag as a blocker.

base의 다른 스킬

adding-builder-codes
base
웹3 애플리케이션에 Base Builder Codes(ERC-8021)를 통합하여 온체인 트랜잭션 속성 추적 및 추천 수수료 수익을 얻습니다. 프로젝트가 추가해야 할 때 사용합니다.
official
base-mcp
base
Base MCP — Base MCP 서버(mcp.base.org)를 통해 AI 어시스턴트가 Base 계정에 접근할 수 있도록 합니다. 지갑, 포트폴리오, 전송, 스왑, 서명, x402…
official
build-on-base
base
완전한 Base 개발 플레이북. 포함 내용: (1) 네트워크 — Base RPC URL, 체인 ID(8453/84532), 탐색기 설정, 테스트넷 설정, Base 연결, Base Sepolia;…
official
building-with-base-account
base
Base Account SDK를 통합하여 인증 및 결제를 처리합니다. Base 로그인(SIWB), Base Pay, Paymasters, 서브 계정, 지출 권한, Prolinks 등을 다룹니다.
official
connecting-to-base-network
base
Base 네트워크 구성(RPC 엔드포인트, 체인 ID, 탐색기 URL 포함)을 제공합니다. 지갑 연결, 개발 환경 구성 시 사용하세요.
official
deploying-contracts-on-base
base
Foundry를 사용하여 Base에 스마트 계약을 배포합니다. forge create 명령어, 계약 검증, CDP를 통한 테스트넷 faucet 설정, BaseScan API 키 등을 다룹니다…
official
migrating-an-onchainkit-app
base
@coinbase/onchainkit에서 독립형 wagmi/viem 컴포넌트로 앱을 마이그레이션하여 OnchainKit 의존성을 완전히 제거합니다.
official
plugin-review
base
Validate and review Base MCP plugin files against the Plugin Specification. Use when writing a new plugin, preparing a plugin PR for submission, self-checking…
official