Fresh import of Groupthink-dev/stallari-plugins under the DD-450 freeze; NOT yet cut over. Pending metadata/ref verification and promotion to Stallari/plugins.
  • JavaScript 90.5%
  • TypeScript 7.3%
  • Makefile 2.2%
Find a file
2026-10-01 22:45:52 +00:00
.github ci: Woodpecker validation lane replaces the GitHub Actions validate workflow 2026-10-02 08:40:17 +10:00
.woodpecker ci: Woodpecker validation lane replaces the GitHub Actions validate workflow 2026-10-02 08:40:17 +10:00
assets Brand v2 — README hero: swap stallari-icon for new logo <picture> 2026-05-08 11:10:32 +10:00
data feat(schema)!: mirror pack-spec 4.14.0 fleet-operator → fabric-operator rename 2026-07-02 11:46:02 +10:00
docs DD-338 Phase D.5 — marketplace refresh runbook + automation wrapper 2026-05-24 12:55:57 +10:00
examples/domain-scope-pack DD-333 Phase F.4 — granularity.domain_scope schema + S-DOM-002 procedural gate 2026-05-22 23:10:13 +10:00
plugins Add interactive-brokers community pack (#8) 2026-07-25 16:56:11 +10:00
schemas feat(catalog): enforce add-on admission gate + carry provisions_scopes (#33) 2026-07-25 16:50:08 +10:00
scripts feat(catalog): enforce add-on admission gate + carry provisions_scopes (#33) 2026-07-25 16:50:08 +10:00
worker/src/prompts/generated feat(schema)!: mirror pack-spec 4.14.0 fleet-operator → fabric-operator rename 2026-07-02 11:46:02 +10:00
.brand-version Brand v2 — README hero: swap stallari-icon for new logo <picture> 2026-05-08 11:10:32 +10:00
.gitignore Ignore generated agent shims 2026-06-08 10:37:44 +10:00
CONTRIBUTING.md feat(schema)!: mirror pack-spec 4.14.0 fleet-operator → fabric-operator rename 2026-07-02 11:46:02 +10:00
LICENSE Initial commit: plugin and pack manifests, schemas, validation tooling 2026-04-06 14:26:04 +10:00
Makefile fix: tighten catalog entry schema (#37) 2026-07-16 22:56:14 +10:00
package-lock.json DD-333 Phase D — granularity required-not-optional in catalog schema 2026-05-21 19:46:52 +10:00
package.json DD-333 Phase A.1 + A.6 — catalog schema + AJV gate + fixtures 2026-05-21 13:02:51 +10:00
PACKS_SHA feat(catalog): DD-346 Phase E — single-source catalog from canonical stallari-packs 2026-06-04 18:37:12 +10:00
README.md docs: refresh public-safe README 2026-07-01 22:31:24 +10:00

Stallari

Stallari Plugins

marketplace.stallari.app Discussions Developer Preview Apache 2.0

stallari-plugins is the public catalog metadata repository for the Stallari Marketplace. It describes the artifacts the registry and app can list, validate, install, and present: MCP plugins, packs, add-ons, and bundles.

The schemas and vocabulary in this repo are synchronized from stallari-pack-spec; treat that sibling repo as the source of truth for schema evolution.

Catalog Shape

Artifact Directory Purpose
MCP plugins plugins/tools/*.json Tool/provider catalog entries, install instructions, contracts, tools, trust/readiness metadata
Packs plugins/packs/ Marketplace metadata for workflow packs; first-party pack content lives in stallari-packs
Add-ons plugins/add-ons/ UI reveal and scoped credential provisioning artifacts
Bundles plugins/bundles/ Install/remove/version units that couple related packs, plugins, and add-ons
Scan exceptions plugins/scan-exceptions/ Reviewed catalog scanner exceptions
Schemas schemas/ Synced schema and vocabulary artifacts consumed by catalog build tooling

Current catalog state includes dozens of MCP provider manifests across email, calendar, tasks, vault, DNS, storage, billing, home, travel, gaming, network, infrastructure, and other service domains.

Contracts, Trust, And Readiness

Plugins may implement versioned service contracts such as email-v1, calendar-v1, vault-v1, billing-v1, home-v1, gpu-inference-v1, or dns-authoritative-v1. Contracts let packs ask for an abstract service operation while the runtime resolves an installed provider.

Catalog metadata also carries:

  • trust tier: certified, verified, or community
  • readiness/certification signals for marketplace presentation
  • per-tool risk class and granularity declarations
  • domain-scope and non-conformance rationale where applicable
  • install runtime/package metadata
  • vendor/repository/setup links

Local Development

npm ci
make validate-all
make build-api
make test
make contracts

Run validation before opening catalog PRs. Validation covers JSON/YAML parsing, schema conformance, contract metadata, catalog build scripts, and scanner checks where configured.

Privacy, Secrets, And PII

Catalog entries and examples must never include real API keys, tokens, account IDs, email addresses, customer names, hostnames, vault paths, diagnostic payloads, or user data. Use placeholders and setup guidance instead. If a provider requires credentials, document the credential label and minimum scope, not the credential value.

Repo Role
stallari-pack-spec Schema, vocabulary, service contracts, add-on/bundle definitions
stallari-packs First-party pack content and tarball publish source
stallari-registry-infra Registry API, marketplace site, sealed pack verification, and public catalog deploy
stallari-harness Runtime consumer of catalog, pack install API, local tool and add-on behaviour

License

Apache 2.0 - use freely with attribution.