{"version":3,"file":"marketplace.d.ts","sourceRoot":"","sources":["../../../src/extensions/core/marketplace.ts"],"names":[],"mappings":"AAAA;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;GAkCG;AAsCH,OAAO,KAAK,EAAE,YAAY,EAA2B,MAAM,gCAAgC,CAAC;AAyF5F,wBAAgB,gBAAgB,CAAC,GAAG,EAAE,YAAY,GAAG,IAAI,CA6SxD","sourcesContent":["/**\n * /plugin — marketplace add/list + plugin install/list/remove (the human path).\n *\n * `/plugin` installs plugins from marketplaces (a git repo or local dir with a\n * native `.agents-plugin/marketplace.json`, Claude `.claude-plugin/marketplace.json`,\n * or Copilot-style `.github/marketplace.json` index). Installed plugins are placed\n * at the chosen scope — `~/.agents/plugins/<name>` for `user`, or\n * `<cwd>/.agents/plugins/<name>` for `project` — and loaded by the plugin loader\n * after a reload. `install` asks which, since a human is right here to answer;\n * the autonomous tool reads the `pluginInstallScope` setting instead.\n *\n * Adding a marketplace is the human trust boundary and stays here; the shared\n * mechanics (discovery, install, remove, the bundled default marketplace) live in\n * `core/extensions/plugins/install.ts` so this command and the model-facing\n * lifecycle tools never drift.\n *\n *   /plugin marketplace add <git-url|path>\n *   /plugin marketplace list\n *   /plugin marketplace refresh     re-fetch every cached index now\n *   /plugin list                     list available plugins across marketplaces\n *   /plugin install <name> [--scope user|project]\n *   /plugin remove <name>\n *   /plugin trust [list]             allow repo-committed plugins to run code here\n *   /plugin untrust\n *   /plugin publish <name> [--to <marketplace-dir>]\n *\n * `publish` is the human end of the publish lane (§3.2). The model can package a\n * plugin — gates, README, index entry — but never publish it, because an agent\n * that can push executable code into a marketplace other agents install from\n * unattended is a supply-chain compromise primitive. So the last step is a\n * command a person types, and even then it stops at the machine boundary: with\n * `--to` it copies the plugin into a local marketplace checkout and updates that\n * index, leaving an uncommitted diff to review. Committing and opening the PR\n * stay manual.\n */\n\nimport { existsSync, mkdirSync, rmSync } from \"node:fs\";\nimport { join } from \"node:path\";\nimport { getAgentDir } from \"../../config.js\";\nimport { CATEGORY_GLYPH, SEGMENT_SEP } from \"../../core/brand.js\";\nimport { getPlugin } from \"../../core/extensions/plugins/authoring.js\";\nimport {\n\tensureWellKnownMarketplaces,\n\tfindAvailablePlugin,\n\tinstallAvailablePlugin,\n\tlistAvailablePlugins,\n\tlistInstalledPlugins,\n\treadMarketplaceRecords,\n\trefreshMarketplaces,\n\tuninstallPlugin,\n\twellKnownMarketplacesAreStale,\n} from \"../../core/extensions/plugins/install.js\";\nimport { availablePluginGroups } from \"../../core/extensions/plugins/listing.js\";\nimport {\n\tmarketplaceCacheDir,\n\tmarketplaceCacheRoot,\n\tmarketplaceStorePath,\n\ttype PluginInstallScope,\n} from \"../../core/extensions/plugins/locations.js\";\nimport {\n\tparseMarketplaceDir,\n\treadMarketplaceStore,\n\tresolvePluginSource,\n\twriteMarketplaceStore,\n} from \"../../core/extensions/plugins/marketplace.js\";\nimport { entryNeedsSource, packagePlugin, stageIntoMarketplace } from \"../../core/extensions/plugins/packaging.js\";\nimport {\n\tisWorkspaceTrusted,\n\tlistTrustedWorkspaces,\n\ttrustWorkspace,\n\tuntrustWorkspace,\n} from \"../../core/extensions/plugins/trust.js\";\nimport type { ExtensionAPI, ExtensionCommandContext } from \"../../core/extensions/types.js\";\nimport { type ListStyle, plural, renderList } from \"../../core/format-list.js\";\nimport { SettingsManager } from \"../../core/settings-manager.js\";\n\nfunction isGitSource(loc: string): boolean {\n\treturn /^https?:\\/\\//.test(loc) || loc.startsWith(\"git@\") || loc.endsWith(\".git\");\n}\n\nfunction isInstallScope(value: string): value is PluginInstallScope {\n\treturn value === \"user\" || value === \"project\";\n}\n\n/** Labels carry the consequence, since that is the whole content of the choice. */\nconst SCOPE_CHOICES: ReadonlyArray<{ scope: PluginInstallScope; label: string }> = [\n\t{ scope: \"user\", label: \"User — ~/.agents/plugins, available in every project (recommended)\" },\n\t{ scope: \"project\", label: \"Project — <repo>/.agents/plugins, committed and shared with collaborators\" },\n];\n\n/**\n * Ask where the plugin should land. Returns undefined when the user dismisses\n * the selector, which cancels the install rather than guessing.\n *\n * Headless (no UI to ask through) resolves to `fallback` — the standing setting\n * — so a scripted or `--print` run still installs somewhere predictable.\n */\nasync function promptForScope(\n\tctx: ExtensionCommandContext,\n\tfallback: PluginInstallScope,\n): Promise<PluginInstallScope | undefined> {\n\tif (!ctx.hasUI) return fallback;\n\tconst labels = SCOPE_CHOICES.map((c) => c.label);\n\tconst picked = await ctx.ui.select(\"Install scope\", labels);\n\tif (picked === undefined) return undefined;\n\treturn SCOPE_CHOICES.find((c) => c.label === picked)?.scope ?? fallback;\n}\n\n/**\n * Chat styling for a listing.\n *\n * The name stays in the terminal's default foreground and everything else steps\n * down from it, so the column you scan is the brightest thing on the row. Note\n * this only reaches the screen because `showStatus` passes pre-styled messages\n * through instead of wrapping them in a blanket dim.\n */\nfunction listStyle(theme: ExtensionCommandContext[\"ui\"][\"theme\"]): ListStyle {\n\treturn {\n\t\tmarker: (text) => theme.fg(\"success\", text),\n\t\tfacts: (text) => theme.fg(\"muted\", text),\n\t\tdetail: (text) => theme.fg(\"dim\", text),\n\t\ttrailer: (text) => theme.fg(\"dim\", text),\n\t\tgroupTitle: (text) => theme.fg(\"mdLink\", text),\n\t};\n}\n\n/** `⬡ 4 plugins …` — the counted header every listing opens with. */\nfunction listHeader(\n\ttheme: ExtensionCommandContext[\"ui\"][\"theme\"],\n\tglyph: string,\n\tsummary: string,\n\thint?: string,\n): string {\n\tconst head = `${theme.fg(\"accent\", glyph)} ${theme.fg(\"muted\", summary)}`;\n\treturn hint ? `${head}\\n${theme.fg(\"dim\", `  ${hint}`)}` : head;\n}\n\n/**\n * Bring the curated marketplace indices up to date before reading them.\n *\n * `SearchPlugins` (the model's path) has always done this; the human `/plugin`\n * path never did, so a cache could sit stale indefinitely — and a *wrong* cache\n * with it. That is not hypothetical: `awesome-copilot` is pinned to its built\n * distribution branch, and the correction only reaches a cache that something\n * asks to refresh. Someone who only ever types `/plugin install` would have kept\n * installing unbuilt stubs and had no way to know why.\n *\n * TTL-respecting, so it is free when the cache is fresh. The notice is printed\n * only when a fetch will actually happen, because a silent multi-second clone\n * looks like a hang and a line printed every time looks like noise.\n */\nasync function refreshIndices(ctx: ExtensionCommandContext): Promise<void> {\n\tconst agentDir = getAgentDir();\n\tif (wellKnownMarketplacesAreStale(agentDir)) ctx.ui.notify(\"Refreshing marketplace indices…\", \"info\");\n\tconst errors = await ensureWellKnownMarketplaces(agentDir);\n\t// Non-fatal by construction: whatever is already on disk still lists. Worth\n\t// saying though — a retired ref reports here, and its consequence (entries\n\t// that install with no capabilities) is otherwise inexplicable.\n\tif (errors.length > 0) ctx.ui.notify(`Marketplace indices: ${errors.join(\"; \")}`, \"warning\");\n}\n\nexport function setupMarketplace(hoo: ExtensionAPI): void {\n\thoo.registerCommand(\"plugin\", {\n\t\tdescription:\n\t\t\t\"Manage plugin marketplaces. /plugin marketplace add <git-url|path> | /plugin marketplace list | /plugin marketplace refresh | /plugin list | /plugin install <name> [--scope user|project] | /plugin remove <name> | /plugin trust [list] | /plugin untrust | /plugin publish <name> [--to <dir>]\",\n\t\tgetArgumentCompletions: (prefix: string) =>\n\t\t\t[\"marketplace\", \"list\", \"install\", \"remove\", \"refresh\", \"publish\", \"trust\", \"untrust\"]\n\t\t\t\t.filter((s) => s.startsWith(prefix))\n\t\t\t\t.map((s) => ({ value: s, label: s })),\n\t\thandler: async (args: string, ctx: ExtensionCommandContext): Promise<void> => {\n\t\t\tconst trimmed = args.trim();\n\t\t\tconst cwd = ctx.cwd;\n\n\t\t\t// ── marketplace add / list ──────────────────────────────────────────\n\t\t\tif (trimmed.startsWith(\"marketplace\")) {\n\t\t\t\tconst sub = trimmed.slice(\"marketplace\".length).trim();\n\n\t\t\t\tif (sub === \"list\" || sub === \"\") {\n\t\t\t\t\tconst records = readMarketplaceRecords(cwd);\n\t\t\t\t\tif (records.length === 0) {\n\t\t\t\t\t\tctx.ui.notify(\"No marketplaces. Add one with /plugin marketplace add <git-url|path>.\", \"info\");\n\t\t\t\t\t\treturn;\n\t\t\t\t\t}\n\t\t\t\t\tconst theme = ctx.ui.theme;\n\t\t\t\t\tconst rows = records.map((r) => {\n\t\t\t\t\t\tconst market = parseMarketplaceDir(r.dir);\n\t\t\t\t\t\treturn {\n\t\t\t\t\t\t\tname: market?.name ?? r.location,\n\t\t\t\t\t\t\tfacts: [plural(market?.plugins.length ?? 0, \"plugin\"), (market?.supportPlatform ?? []).join(\", \")],\n\t\t\t\t\t\t\t// The location is the longest and least-scanned token on the row;\n\t\t\t\t\t\t\t// on its own line it stops forcing the wrap.\n\t\t\t\t\t\t\ttrailer: r.location,\n\t\t\t\t\t\t};\n\t\t\t\t\t});\n\t\t\t\t\tconst body = renderList([{ rows }], {\n\t\t\t\t\t\tcolumns: ctx.ui.columns,\n\t\t\t\t\t\tindent: 2,\n\t\t\t\t\t\tstyle: listStyle(theme),\n\t\t\t\t\t});\n\t\t\t\t\tconst header = listHeader(theme, CATEGORY_GLYPH.marketplaces, plural(records.length, \"marketplace\"));\n\t\t\t\t\tctx.ui.notify(\n\t\t\t\t\t\t`${header}\\n${body}\\n\\n${theme.fg(\"dim\", \"  /plugin list to see what they offer\")}`,\n\t\t\t\t\t\t\"info\",\n\t\t\t\t\t);\n\t\t\t\t\treturn;\n\t\t\t\t}\n\n\t\t\t\tif (sub.startsWith(\"add\")) {\n\t\t\t\t\tconst loc = sub.slice(\"add\".length).trim();\n\t\t\t\t\tif (!loc) {\n\t\t\t\t\t\tctx.ui.notify(\"Usage: /plugin marketplace add <git-url|path>\", \"warning\");\n\t\t\t\t\t\treturn;\n\t\t\t\t\t}\n\n\t\t\t\t\tlet dir: string;\n\t\t\t\t\tif (isGitSource(loc)) {\n\t\t\t\t\t\tdir = marketplaceCacheDir(loc);\n\t\t\t\t\t\trmSync(dir, { recursive: true, force: true });\n\t\t\t\t\t\tmkdirSync(marketplaceCacheRoot(), { recursive: true });\n\t\t\t\t\t\tconst res = await hoo.exec(\"git\", [\"clone\", \"--depth\", \"1\", loc, dir]);\n\t\t\t\t\t\tif (res.code !== 0) {\n\t\t\t\t\t\t\tctx.ui.notify(`Clone failed: ${res.stderr || res.stdout}`, \"error\");\n\t\t\t\t\t\t\treturn;\n\t\t\t\t\t\t}\n\t\t\t\t\t} else {\n\t\t\t\t\t\tdir = resolvePluginSource(loc, cwd).kind === \"local\" ? join(cwd, loc) : loc;\n\t\t\t\t\t\tif (!existsSync(dir)) {\n\t\t\t\t\t\t\tctx.ui.notify(`Path not found: ${dir}`, \"error\");\n\t\t\t\t\t\t\treturn;\n\t\t\t\t\t\t}\n\t\t\t\t\t}\n\n\t\t\t\t\tconst market = parseMarketplaceDir(dir);\n\t\t\t\t\tif (!market) {\n\t\t\t\t\t\tctx.ui.notify(\n\t\t\t\t\t\t\t\"No marketplace manifest found (.agents-plugin/, .claude-plugin/, or .github/marketplace.json).\",\n\t\t\t\t\t\t\t\"error\",\n\t\t\t\t\t\t);\n\t\t\t\t\t\treturn;\n\t\t\t\t\t}\n\n\t\t\t\t\tconst records = readMarketplaceStore(marketplaceStorePath()).filter((r) => r.location !== loc);\n\t\t\t\t\trecords.push({ location: loc, dir });\n\t\t\t\t\twriteMarketplaceStore(marketplaceStorePath(), records);\n\t\t\t\t\tctx.ui.notify(`Added marketplace \"${market.name}\" (${market.plugins.length} plugin(s)).`, \"info\");\n\t\t\t\t\treturn;\n\t\t\t\t}\n\n\t\t\t\tif (sub === \"refresh\") {\n\t\t\t\t\tctx.ui.notify(\"Refreshing marketplace indices…\", \"info\");\n\t\t\t\t\tconst { refreshed, errors } = await refreshMarketplaces(cwd);\n\t\t\t\t\tconst lines: string[] = [];\n\t\t\t\t\tif (refreshed.length > 0) lines.push(`Refreshed: ${refreshed.join(\", \")}`);\n\t\t\t\t\tif (errors.length > 0) lines.push(`Could not refresh: ${errors.join(\"; \")}`);\n\t\t\t\t\tctx.ui.notify(lines.join(\"\\n\") || \"Nothing to refresh.\", errors.length > 0 ? \"warning\" : \"info\");\n\t\t\t\t\treturn;\n\t\t\t\t}\n\n\t\t\t\tctx.ui.notify(\n\t\t\t\t\t\"Usage: /plugin marketplace add <git-url|path> | /plugin marketplace list | /plugin marketplace refresh\",\n\t\t\t\t\t\"warning\",\n\t\t\t\t);\n\t\t\t\treturn;\n\t\t\t}\n\n\t\t\t// ── list available plugins ──────────────────────────────────────────\n\t\t\tif (trimmed === \"list\" || trimmed === \"\") {\n\t\t\t\tawait refreshIndices(ctx);\n\t\t\t\tconst available = listAvailablePlugins(cwd);\n\t\t\t\tif (available.length === 0) {\n\t\t\t\t\tctx.ui.notify(\"No plugins available. Add a marketplace first.\", \"info\");\n\t\t\t\t\treturn;\n\t\t\t\t}\n\t\t\t\tconst theme = ctx.ui.theme;\n\t\t\t\t// Installed state is the fact the old listing could not answer: without\n\t\t\t\t// it, /plugin install on something already present silently re-clones\n\t\t\t\t// over it, discarding any local edits to the plugin directory.\n\t\t\t\tconst installed = new Set(listInstalledPlugins(cwd).map((p) => p.id));\n\t\t\t\tconst groups = availablePluginGroups(available, { installed });\n\t\t\t\tconst body = renderList(groups, {\n\t\t\t\t\tcolumns: ctx.ui.columns,\n\t\t\t\t\tindent: 2,\n\t\t\t\t\tstyle: listStyle(theme),\n\t\t\t\t});\n\t\t\t\tconst installedCount = available.filter((p) => installed.has(p.name)).length;\n\t\t\t\tconst summary =\n\t\t\t\t\t`${plural(available.length, \"plugin\")} across ${plural(groups.length, \"marketplace\")}` +\n\t\t\t\t\t(installedCount > 0 ? ` ${SEGMENT_SEP} ${installedCount} installed` : \"\");\n\t\t\t\tconst header = listHeader(\n\t\t\t\t\ttheme,\n\t\t\t\t\tCATEGORY_GLYPH.plugins,\n\t\t\t\t\tsummary,\n\t\t\t\t\tinstalledCount > 0 ? \"✓ already installed\" : undefined,\n\t\t\t\t);\n\t\t\t\tctx.ui.notify(`${header}\\n${body}\\n\\n${theme.fg(\"dim\", \"  /plugin install <name> to add one\")}`, \"info\");\n\t\t\t\treturn;\n\t\t\t}\n\n\t\t\t// ── install <name> [--scope user|project] ───────────────────────────\n\t\t\tif (trimmed.startsWith(\"install\")) {\n\t\t\t\tconst rest = trimmed.slice(\"install\".length).trim();\n\t\t\t\tconst scopeMatch = /(?:^|\\s)--scope[= ]\\s*(\\S+)/.exec(rest);\n\t\t\t\tconst name = rest.replace(/(?:^|\\s)--scope[= ]\\s*\\S+/, \"\").trim();\n\t\t\t\tif (!name) {\n\t\t\t\t\tctx.ui.notify(\"Usage: /plugin install <name> [--scope user|project]\", \"warning\");\n\t\t\t\t\treturn;\n\t\t\t\t}\n\t\t\t\tif (scopeMatch && !isInstallScope(scopeMatch[1])) {\n\t\t\t\t\tctx.ui.notify(`Unknown scope \"${scopeMatch[1]}\". Use --scope user or --scope project.`, \"warning\");\n\t\t\t\t\treturn;\n\t\t\t\t}\n\t\t\t\tawait refreshIndices(ctx);\n\t\t\t\tif (!findAvailablePlugin(cwd, name)) {\n\t\t\t\t\tctx.ui.notify(`Plugin \"${name}\" not found in any marketplace.`, \"error\");\n\t\t\t\t\treturn;\n\t\t\t\t}\n\n\t\t\t\t// An explicit --scope wins; otherwise ask, because this is the human\n\t\t\t\t// path and the destination is a real choice (portable vs. committed to\n\t\t\t\t// the repo). With no UI to ask through there is nobody to ask, so it\n\t\t\t\t// falls back to the same setting the autonomous path uses.\n\t\t\t\tconst scope = scopeMatch\n\t\t\t\t\t? (scopeMatch[1] as PluginInstallScope)\n\t\t\t\t\t: await promptForScope(ctx, SettingsManager.create(cwd, getAgentDir()).getPluginInstallScope());\n\t\t\t\tif (!scope) {\n\t\t\t\t\tctx.ui.notify(\"Install cancelled.\", \"info\");\n\t\t\t\t\treturn;\n\t\t\t\t}\n\n\t\t\t\tconst outcome = await installAvailablePlugin(cwd, name, getAgentDir(), { scope });\n\t\t\t\tif (!outcome.installed) {\n\t\t\t\t\tctx.ui.notify(outcome.message, \"error\");\n\t\t\t\t\treturn;\n\t\t\t\t}\n\n\t\t\t\t// A person typing this command in this directory is the human act\n\t\t\t\t// workspace trust asks for, so an explicit project-scope install grants\n\t\t\t\t// it — otherwise the plugin you just chose to install here would load\n\t\t\t\t// with its hooks withheld, which is nobody's idea of what happened.\n\t\t\t\t// The autonomous path deliberately does not do this.\n\t\t\t\tlet trustNote = \"\";\n\t\t\t\tif (scope === \"project\" && !isWorkspaceTrusted(cwd, getAgentDir())) {\n\t\t\t\t\ttrustWorkspace(cwd, getAgentDir());\n\t\t\t\t\ttrustNote = ` Trusted this workspace, so its plugins may run hooks and MCP servers here (\\`/plugin untrust\\` reverses it).`;\n\t\t\t\t}\n\t\t\t\tctx.ui.notify(`${outcome.message}${trustNote} Reloading…`, \"info\");\n\t\t\t\tawait ctx.reload();\n\t\t\t\treturn;\n\t\t\t}\n\n\t\t\t// ── trust / untrust ─────────────────────────────────────────────────\n\t\t\tif (trimmed === \"trust\" || trimmed.startsWith(\"trust \")) {\n\t\t\t\tconst sub = trimmed.slice(\"trust\".length).trim();\n\t\t\t\tif (sub === \"list\") {\n\t\t\t\t\tconst workspaces = listTrustedWorkspaces(getAgentDir());\n\t\t\t\t\tctx.ui.notify(\n\t\t\t\t\t\tworkspaces.length\n\t\t\t\t\t\t\t? `Trusted workspaces:\\n${workspaces.map((w) => `${w.path} (since ${w.at.slice(0, 10)})`).join(\"\\n\")}`\n\t\t\t\t\t\t\t: \"No trusted workspaces. Plugins in a working tree load skills and commands, but not hooks or MCP servers.\",\n\t\t\t\t\t\t\"info\",\n\t\t\t\t\t);\n\t\t\t\t\treturn;\n\t\t\t\t}\n\t\t\t\tif (sub) {\n\t\t\t\t\tctx.ui.notify(\"Usage: /plugin trust | /plugin trust list | /plugin untrust\", \"warning\");\n\t\t\t\t\treturn;\n\t\t\t\t}\n\t\t\t\tif (isWorkspaceTrusted(cwd, getAgentDir())) {\n\t\t\t\t\tctx.ui.notify(`Already trusted: ${cwd}`, \"info\");\n\t\t\t\t\treturn;\n\t\t\t\t}\n\t\t\t\ttrustWorkspace(cwd, getAgentDir());\n\t\t\t\tctx.ui.notify(\n\t\t\t\t\t`Trusted ${cwd}. Plugins committed to this repository may now run hooks and MCP servers here, ` +\n\t\t\t\t\t\t\"including any added by a later pull. Reverse it with /plugin untrust. Reloading…\",\n\t\t\t\t\t\"info\",\n\t\t\t\t);\n\t\t\t\tawait ctx.reload();\n\t\t\t\treturn;\n\t\t\t}\n\n\t\t\tif (trimmed === \"untrust\") {\n\t\t\t\tif (!untrustWorkspace(cwd, getAgentDir())) {\n\t\t\t\t\tctx.ui.notify(`Not trusted: ${cwd}`, \"info\");\n\t\t\t\t\treturn;\n\t\t\t\t}\n\t\t\t\tctx.ui.notify(`Revoked trust for ${cwd}. Reloading…`, \"info\");\n\t\t\t\tawait ctx.reload();\n\t\t\t\treturn;\n\t\t\t}\n\n\t\t\t// ── publish <name> [--to <marketplace-dir>] ─────────────────────────\n\t\t\tif (trimmed.startsWith(\"publish\")) {\n\t\t\t\tconst rest = trimmed.slice(\"publish\".length).trim();\n\t\t\t\tconst toMatch = /(?:^|\\s)--to\\s+(\\S+)/.exec(rest);\n\t\t\t\tconst name = rest.replace(/(?:^|\\s)--to\\s+\\S+/, \"\").trim();\n\t\t\t\tif (!name) {\n\t\t\t\t\tctx.ui.notify(\"Usage: /plugin publish <name> [--to <marketplace-dir>]\", \"warning\");\n\t\t\t\t\treturn;\n\t\t\t\t}\n\t\t\t\tconst plugin = getPlugin(cwd, name);\n\t\t\t\tif (!plugin) {\n\t\t\t\t\tctx.ui.notify(`No plugin named \"${name}\" is installed or authored here.`, \"error\");\n\t\t\t\t\treturn;\n\t\t\t\t}\n\n\t\t\t\tctx.ui.notify(`Packaging \"${name}\" — running publish checks…`, \"info\");\n\t\t\t\tconst result = await packagePlugin(plugin);\n\t\t\t\tif (!result.ok) {\n\t\t\t\t\t// A red gate blocks staging too: the point of the strict run is that a\n\t\t\t\t\t// plugin other people install has passed it, and staging is the step\n\t\t\t\t\t// that puts it on the path to them.\n\t\t\t\t\tctx.ui.notify(`Not publishable yet.\\n${result.instructions}`, \"error\");\n\t\t\t\t\treturn;\n\t\t\t\t}\n\n\t\t\t\tif (!toMatch) {\n\t\t\t\t\tconst hint = entryNeedsSource(result.entry)\n\t\t\t\t\t\t? \"\\nRe-run with --to <marketplace-dir> to vendor it into a local marketplace checkout (which fills `source` in).\"\n\t\t\t\t\t\t: \"\";\n\t\t\t\t\tctx.ui.notify(`${result.instructions}${hint}`, \"info\");\n\t\t\t\t\treturn;\n\t\t\t\t}\n\n\t\t\t\tconst staged = stageIntoMarketplace(plugin, result.platform, toMatch[1]);\n\t\t\t\tif (!staged.ok) {\n\t\t\t\t\tctx.ui.notify(staged.message, \"error\");\n\t\t\t\t\treturn;\n\t\t\t\t}\n\t\t\t\tctx.ui.notify(\n\t\t\t\t\t`${staged.message}\\n\\nReview the diff, then commit and open the pull request yourself — ` +\n\t\t\t\t\t\t\"hoocode deliberately stops short of pushing a plugin into a marketplace.\",\n\t\t\t\t\t\"info\",\n\t\t\t\t);\n\t\t\t\treturn;\n\t\t\t}\n\n\t\t\t// ── remove <name> ───────────────────────────────────────────────────\n\t\t\tif (trimmed.startsWith(\"remove\")) {\n\t\t\t\tconst name = trimmed.slice(\"remove\".length).trim();\n\t\t\t\tif (!name) {\n\t\t\t\t\tctx.ui.notify(\"Usage: /plugin remove <name>\", \"warning\");\n\t\t\t\t\treturn;\n\t\t\t\t}\n\t\t\t\tconst outcome = uninstallPlugin(cwd, name);\n\t\t\t\tif (!outcome.removed) {\n\t\t\t\t\tctx.ui.notify(outcome.message, \"info\");\n\t\t\t\t\treturn;\n\t\t\t\t}\n\t\t\t\tctx.ui.notify(`${outcome.message} Reloading…`, \"info\");\n\t\t\t\tawait ctx.reload();\n\t\t\t\treturn;\n\t\t\t}\n\n\t\t\tctx.ui.notify(\n\t\t\t\t\"Usage: /plugin marketplace add|list|refresh | /plugin list | /plugin install <name> [--scope user|project] | \" +\n\t\t\t\t\t\"/plugin trust [list] | /plugin untrust | \" +\n\t\t\t\t\t\"/plugin remove <name> | /plugin publish <name> [--to <marketplace-dir>]\",\n\t\t\t\t\"warning\",\n\t\t\t);\n\t\t},\n\t});\n}\n"]}