plugin-review

bởi base

Xác thực và xem xét các tệp plugin Base MCP theo Đặc tả Plugin. Sử dụng khi viết plugin mới, chuẩn bị PR plugin để gửi, tự kiểm tra…

npx skills add https://github.com/base/skills --skill plugin-review

Plugin Review

Validate Base MCP plugin files against the current Plugin Specification. Produces a conformance report with actionable findings.

Works for both authors (self-check before submitting a PR) and reviewers (evaluate an incoming PR).

Workflow

  1. Fetch the current spec (it changes — never rely on a stale copy):

    curl -s https://raw.githubusercontent.com/base/skills/master/skills/base-mcp/references/plugin-spec.md
    

    Related docs worth reading: references/custom-plugins.md, references/approval-mode.md, references/batch-calls.md, and SKILL.md (the root skill). Existing native plugins under skills/base-mcp/plugins/ are the precedent for conventions.

  2. Read the plugin file in full. If reviewing a PR:

    gh pr view <n> --repo base/skills --json title,body,number,headRefName,files,additions,deletions
    gh pr diff <n> --repo base/skills
    # raw plugin file (diff may be truncated):
    gh api "repos/base/skills/pulls/<n>/files" --jq '.[] | select(.filename|endswith(".md")) | .raw_url'
    
  3. Static conformance evaluation — assess against every dimension in references/evaluation-criteria.md (includes compliance/language checks and high-risk category gates). Write the report using references/report-template.md.

  4. (Optional) Live API / SDK verification — exercise the documented endpoints/SDK/contracts with read-only calls. See references/live-testing.md. For perps/prediction-market/gambling plugins, also run the geoblock verification (compare frontend vs API access restrictions). Append a ## Live API / SDK Verification section to the report. This routinely overturns doc claims (fabricated/locked endpoints, broken hosts, wrong response shapes).

  5. Save the report. If reviewing a PR and asked to comment, draft a PR comment from the report using references/comment-guidelines.md and post with: gh pr comment <n> --repo base/skills --body-file <comment-file>.

Multiple PRs

Evaluate PRs in parallel by spinning up one sub-agent per PR (each writes its own report + returns a short verdict summary). Hand each sub-agent: the spec (or its raw URL), the PR number, the evaluation criteria, the report template, and the comment guidelines.

Critical gotchas

These recur and are easy to get wrong — full detail in references/evaluation-criteria.md:

  • Smart-account signatures break naive signing. The default Base MCP wallet is a smart contract; sign returns a variable-length ERC-1271/6492 signature (>200 bytes), not a 65-byte EOA sig. Any plugin that splices a signature into a fixed-width calldata slot, or bakes an off-chain EIP-712 signature into calldata (e.g. Permit2 buildCallWithPermit2), is broken for that wallet. Correct pattern: onchain allowance grants.
  • irreversible risk is NOT for every onchain write. The spec says "flag when worth emphasizing." Pure swaps use slippage (precedent: Uniswap, Aerodrome carry [slippage], not irreversible). Reserve irreversible for asymmetric/severe cases (perps/liquidation, token launches/rug). Do not demand it on swaps.
  • Don't self-register. A plugin PR must NOT edit the SKILL.md plugins table, the Integration Types "Examples" cell, or the "Existing Plugin Conformance" table — those are maintainer-managed (codified in plugin-spec.md "Contribution Scope"). The only sanctioned shared-file edit is appending a genuinely net-new tag to the vocabulary list. Limit the diff to plugins/<slug>.md (+ that tag line).
  • version is the plugin-doc version — not the npm/package version and not a global spec version. The spec mandates no specific starting number.
  • Verify claims, don't trust them. Auth models, allowlist completeness, response shapes, and contract addresses are frequently wrong in the doc. Probe them (live testing).
  • Reference links from a plugin file must use ../references/... (plugin files live in plugins/, refs in references/).
  • Neutral language is mandatory. No yield/rate/performance claims, no "you should buy X", no "always deposit here", no defaulting to specific tokens. Steering language is a blocker.
  • Perps, prediction markets, and privacy plugins need legal review before inclusion as native plugins. Flag this as a pre-merge process gate in the report.
  • API geoblock parity. If the protocol's frontend geoblocks US IPs (or others), the API must enforce equivalent restrictions. If it doesn't, Base MCP risks being a circumvention tool — flag as a blocker.

Thêm skills từ base

adding-builder-codes
base
Tích hợp Base Builder Codes (ERC-8021) vào các ứng dụng web3 để ghi nhận giao dịch trên chuỗi và kiếm phí giới thiệu. Sử dụng khi một dự án cần thêm…
official
base-mcp
base
Base MCP — cung cấp cho trợ lý AI của bạn quyền truy cập vào Tài khoản Base thông qua máy chủ Base MCP (mcp.base.org). Ví, danh mục đầu tư, gửi, hoán đổi, ký, x402…
official
build-on-base
base
Sổ tay phát triển Base hoàn chỉnh. Bao gồm: (1) Mạng — URL RPC của Base, ID chuỗi (8453/84532), cấu hình explorer, thiết lập testnet, kết nối với Base, Base Sepolia;…
official
building-with-base-account
base
Tích hợp Base Account SDK để xác thực và thanh toán. Bao gồm Sign in with Base (SIWB), Base Pay, Paymasters, Sub Accounts, Spend Permissions, Prolinks,…
official
connecting-to-base-network
base
Cung cấp cấu hình mạng Base bao gồm các điểm cuối RPC, ID chuỗi và URL trình khám phá. Sử dụng khi kết nối ví, cấu hình môi trường phát triển,…
official
deploying-contracts-on-base
base
Triển khai hợp đồng thông minh lên Base bằng Foundry. Bao gồm các lệnh forge create, xác minh hợp đồng, thiết lập vòi testnet qua CDP và khóa API BaseScan…
official
migrating-an-onchainkit-app
base
Di chuyển ứng dụng từ @coinbase/onchainkit sang các thành phần wagmi / viem độc lập mà không phụ thuộc vào OnchainKit.
official
plugin-review
base
Validate and review Base MCP plugin files against the Plugin Specification. Use when writing a new plugin, preparing a plugin PR for submission, self-checking…
official