What is Cursor Plugins? A catalogue for agent extensions
Cursor Plugins source-code walkthrough: what validation checks
Read the schema and validator before relying on a green package check
What you will learn
- Locate the validator
- Understand the schema boundary
- Follow one real package
Before you start
- A disposable client profile
- One selected plugin
- The pinned repository revision
Turn a promising catalogue entry into a repeatable team decision
Key takeaways
- Ajv validates structured metadata.
- The validator checks source existence and matching names.
- Runtime effects still need a separate audit.
Locate the validator
`scripts/validate-plugins.mjs` loads the marketplace schema and plugin schema with Ajv. It validates the root marketplace, then walks each listed source directory.
For each entry it checks that the directory and `.cursor-plugin/plugin.json` exist, validates the manifest, and compares the marketplace name with the plugin name. It exits nonzero after collecting errors.
Understand the schema boundary
The marketplace schema constrains entry shape and source fields; the plugin schema constrains names, metadata and component-reference fields. This catches malformed packaging before submission.
A valid path string is not proof that a hook is harmless, an MCP server is trustworthy or a requested token has narrow scopes. The validator does not run the plugin or model.
Follow one real package
The create-plugin manifest declares `./skills/`, `./rules/` and `./agents/`. The GitHub manifest instead declares a variable and `./mcp.json`; its MCP file contains an HTTP URL and authorization placeholder.
When debugging an install, start with the entry name and source, compare manifest values and then open the referenced component. This review inspected those files but did not execute the validator on the upstream checkout.
Decision guide
| Criterion | Option A | Option B |
|---|---|---|
| Best when | You need predictable behavior and easy auditing | You need adaptive optimization and have reliable telemetry |
| Main risk | May leave performance on the table | Can become difficult to explain or debug |
Implementation steps
- 1
Read marketplace.json and its schema together.
- 2
Trace one entry into plugin.json and referenced files.
- 3
Treat a green schema result as packaging evidence only.
Copy-ready example
validate(marketplaceSchema)
for entry in marketplace.plugins:
check source and plugin.json
validate(pluginSchema); compare namesFrequently asked questions
Does validation test remote MCP permissions?
No. The inspected script performs schema and local path checks, not a live authorization test.
Why can an entry pass but still fail at runtime?
External services, client versions or referenced scripts may fail after packaging validation.
Sources
- Cursor Plugins / scripts/validate-plugins.mjsSource checked 2026-10-08
- Cursor Plugins / schemas/marketplace.schema.jsonSource checked 2026-10-08
- Cursor Plugins / schemas/plugin.schema.jsonSource checked 2026-10-08
- Cursor Plugins / create-plugin/.cursor-plugin/plugin.jsonSource checked 2026-10-08
- Cursor Plugins / third_party/github/.cursor-plugin/plugin.jsonSource checked 2026-10-08
- Cursor Plugins / third_party/github/mcp.jsonSource checked 2026-10-08