* fix(cursor-rules): align marketplace.json rule with CONTRIBUTING.md
The rule 'Never modify .claude-plugin/marketplace.json from inside a
plugin PR' contradicted CONTRIBUTING.md step 3 and actual maintainer
practice, causing CodeRabbit to force revert/re-add churn on plugin PRs
(#577, #582, #596, #606). Reword to prohibit hand-editing the generated
registries instead.
* docs: fix stale component counts (194 agents, 106 commands, 158 skills, 44 plugins)
* docs(contributing): add commercial content and disclosure policy
* docs(protect-mcp): remove unverified downloads claim
npm reports ~3.2K monthly downloads, not 10K+; the README already has a
live shields.io downloads badge. Also drop the stale v0.5.5 reference
(see #601).
Add lean, native plugin-install entry points so each harness's own plugin
manager can install this marketplace (mirroring obra/superpowers) — committing
only small JSON registries, not duplicated skill/agent content trees.
- Codex: committed marketplace registry (.agents/plugins/marketplace.json) +
per-plugin manifests (plugins/*/.codex-plugin/plugin.json). Entries point at
source ./plugins/<name>; Codex reads SKILL.md directly. Transformed
.codex/skills|agents stay gitignored.
- Cursor: commit the existing .cursor-plugin/ marketplace + .cursor/rules/
(these already point at source plugins/).
- Gemini: gemini-extension.json already committed (contextFileName: AGENTS.md);
transformed trees stay gitignored (install via clone + make generate).
- OpenCode: unchanged — install via `make install-opencode` (transformed tree
stays gitignored).
- CLAUDE.md is now a symlink to AGENTS.md; Claude-Code addenda moved to
docs/harnesses.md.
- CI: new step fails if `make generate-all` drifts from the committed registries.
Net new committed: ~720 KB of manifests (no skill/agent duplication). Adds
round-trip tests for the new registries + the symlink. Docs updated across
README, docs/harnesses.md, ARCHITECTURE.md, CONTRIBUTING.md, GEMINI.md,
docs/authoring.md, and the PR template.