Plugin v1 Final — completes the Wave 2 set (2.3 MCP servers + 2.2r Integrations with env vars) and passes the Wave 2.5 security scan.
Added
Wave 2.3 — MCP server declaration
filesystem-pm— injects@modelcontextprotocol/server-filesysteminto~/.claude.jsonunder keyplugin-pm-essentials-filesystem-pm, pointing to${WORKSPACE}/workspace/project. Requiresnpxin PATH.- After install/update, a banner prompts you to restart Claude Code CLI to activate the MCP server.
Wave 2.2r — Integration: Todoist
- Declares
TODOIST_PLUGIN_API_KEYenv var underintegrations[].env_vars. - Appears in
/integrations→ Custom tab as "PM Essentials — Todoist" card with a "via plugin" badge and schema-driven Configure modal (password input, masked display, audit logs keys only). - On uninstall,
# plugin-pm-essentialssection is automatically removed from.env(no leaked credentials). - Note:
health_checkis intentionally omitted in v0.4.0. The Todoist REST API requires a Bearer Authorization header, which is not yet supported by the v1HealthCheckSpecschema (headers support is a v2 follow-up).
Wave 2.5 — Security scan compliance
- All agent/skill markdown reviewed; no prompt injection, dangerous SQL, or shell exec patterns.
- Scan verdict:
APPROVE.
Requires
EvoNexus core with Waves 2.3 + 2.2r + 2.5 schema support (branch feature/plugins-v1, merge pending). Installs cleanly on older cores — both mcp_servers and integrations are optional fields; the core will pick them up on upgrade.
Upgrading from v0.3.1
No breaking changes. Update in place via the Plugin Detail page. MCP server entry is appended to ~/.claude.json (backed up to ~/.claude.json.evonexus-backup-<ts>). Todoist integration appears disconnected until you paste your API key in Configure.