refactor: standardize on zcube Penpot MCP

This commit is contained in:
2026-08-27 12:28:48 +00:00
parent 46070cbe78
commit 82659d10ec
+12 -15
View File
@@ -1,7 +1,7 @@
--- ---
name: corp-v1-channel-ui-ux name: corp-v1-channel-ui-ux
description: "Use when operating or synchronizing a Corp v1 project's UI/UX channel. Maintains project frontend design work, Penpot artifacts, design-system decisions, accessibility evidence, and implementation handoffs while correlating verified activity across the project's seven channels." description: "Use when operating or synchronizing a Corp v1 project's UI/UX channel. Maintains project frontend design work, Penpot artifacts, design-system decisions, accessibility evidence, and implementation handoffs while correlating verified activity across the project's seven channels."
version: 1.1.0 version: 1.2.0
author: Hermes Agent author: Hermes Agent
license: MIT license: MIT
metadata: metadata:
@@ -85,9 +85,9 @@ Proposed work may be explored before all inputs are final, but it must remain vi
Penpot is the editable source of truth for interface design at this time. Penpot is the editable source of truth for interface design at this time.
### Dual MCP design plane ### Hermes Penpot MCP
Hermes uses two complementary Penpot MCP servers. Treat their configured `enabled` state and per-tool include list as an operational safety boundary, not as proof that a target file is ready: Hermes uses **only** `penpot-zcube-v1` for Penpot automation. The official plugin-based `penpot` MCP is not part of the operating model and must not be configured, requested, or treated as a fallback. Treat the server's configured `enabled` state and per-tool include list as an operational safety boundary:
```yaml ```yaml
mcp_servers: mcp_servers:
@@ -96,15 +96,12 @@ mcp_servers:
# Local stdio, browserless Penpot RPC operations. # Local stdio, browserless Penpot RPC operations.
tools: tools:
include: [explicitly approved tools only] include: [explicitly approved tools only]
penpot:
enabled: true
# Penpot Plugin API; requires the intended file to be open and attached.
``` ```
- **`penpot-zcube-v1`** is the preferred browserless path for authenticated team/project/file discovery and approved page, frame, shape, text, component, alignment, media, snapshot, and library-read operations. It runs as a local stdio child of Hermes and uses the Bitwarden-managed Penpot API credential. It must remain pinned, production-audited, restricted to the approved Penpot instance, and fail-closed through `tools.include`. The pinned build does not expose `export_shape`; use the Plugin API export path for review images. - **`penpot-zcube-v1`** provides authenticated team/project/file discovery and approved page, frame, shape, text, component, alignment, media, snapshot, and library-read operations. It runs as a local stdio child of Hermes and uses the Bitwarden-managed Penpot API credential. It must remain pinned, production-audited, restricted to the approved Penpot instance, and fail-closed through `tools.include`.
- **`penpot`** is the Plugin API path for richer live-file operations such as native token, variant, library-asset, flex/grid-layout, interaction, selection, and visual inspection workflows. It is usable only when its MCP token is valid and the exact intended file is actively attached in Penpot. - The pinned build does not expose native rendered PNG/SVG export, plugin-runtime tokens, variants, interactions, live selection, or Penpot frontend visual inspection. Report those exact capability limits honestly; do not reintroduce the official MCP to obtain them. Review aids may use a separately approved non-MCP rendering path, while Penpot remains the editable source.
Set `mcp_servers.<name>.enabled` to `true` or `false` through the supported Hermes configuration command or UI, then start a fresh agent session or restart the gateway for the change to take effect. Use `hermes mcp configure <name>` to toggle individual tools. Never interpret disabling one server as permission to broaden the other server's tool set. Keep sampling disabled for the community server. Set `mcp_servers.penpot-zcube-v1.enabled` to `true` or `false` through supported Hermes configuration, then start a fresh agent session or restart the gateway for the change to take effect. Use `hermes mcp configure penpot-zcube-v1` to toggle individual tools. Disabling the server never authorizes an alternate Penpot MCP. Keep sampling disabled.
Before browserless mutation through `penpot-zcube-v1`: Before browserless mutation through `penpot-zcube-v1`:
@@ -116,7 +113,7 @@ Before browserless mutation through `penpot-zcube-v1`:
6. stop on revision conflict or ambiguous duplicate names rather than retrying blindly; 6. stop on revision conflict or ambiguous duplicate names rather than retrying blindly;
7. use the backend API or a separately approved cleanup path for destructive file/project/team operations, which remain disabled in the community MCP allowlist. 7. use the backend API or a separately approved cleanup path for destructive file/project/team operations, which remain disabled in the community MCP allowlist.
If the Plugin API is disconnected, use `penpot-zcube-v1` for supported browserless work instead of reporting a blanket Penpot blocker. If work requires native tokens, variants, flex/grid layout, live selection, or another capability absent from the browserless server, report that narrower plugin-attachment requirement honestly. If work requires a capability absent from `penpot-zcube-v1`, report the specific limitation and continue with supported editable work. Do not ask for plugin attachment or configure the official Penpot MCP.
For every governed design package: For every governed design package:
@@ -210,14 +207,14 @@ Link each design package from its authoritative Feature record and relevant Arch
1. Resolve the exact project code and seven same-project channel IDs. 1. Resolve the exact project code and seven same-project channel IDs.
2. Read enough channel and repository evidence to establish current Scope, Architecture, design, Delivery, and release state without duplicating prior work. 2. Read enough channel and repository evidence to establish current Scope, Architecture, design, Delivery, and release state without duplicating prior work.
3. Verify the Penpot file belongs to the intended project and the referenced pages/boards exist; select `penpot-zcube-v1` for supported browserless work or `penpot` for native live-file capabilities. 3. Verify the Penpot file belongs to the intended project and the referenced pages/boards exist; use only `penpot-zcube-v1` for Penpot MCP work.
4. Review the complete user flow, responsive states, component variants, content rules, and accessibility expectations. 4. Review the complete user flow, responsive states, component variants, content rules, and accessibility expectations.
5. Confirm proposed versus approved status and immutable approval evidence. 5. Confirm proposed versus approved status and immutable approval evidence.
6. Update durable project documentation using the adopted Docusaurus skill. 6. Update durable project documentation using the adopted Docusaurus skill.
7. Validate documentation structure, links, typecheck, production build, and deployed readback when documentation changes. 7. Validate documentation structure, links, typecheck, production build, and deployed readback when documentation changes.
8. Read back the exact remote artifact and any posted Discord guidance. 8. Read back the exact remote artifact and any posted Discord guidance.
9. Verify that no Corp project cronjob or scheduler job exists. 9. Verify that no Corp project cronjob or scheduler job exists.
10. Verify each configured Penpot MCP server's `enabled` state, selected tools, credential presence without disclosure, and the exact readback appropriate to the chosen server. 10. Verify `penpot-zcube-v1` is the only configured Penpot MCP, its `enabled` state and selected tools are correct, the API credential is present without disclosure, and exact readback passed.
11. Report exact Penpot links, documentation paths, commit/PR/CI evidence, approval status, remaining gates, and any inaccessible Penpot surface. 11. Report exact Penpot links, documentation paths, commit/PR/CI evidence, approval status, remaining gates, and any inaccessible Penpot surface.
## Common Pitfalls ## Common Pitfalls
@@ -233,7 +230,7 @@ Link each design package from its authoritative Feature record and relevant Arch
9. Inspecting another project's channels. 9. Inspecting another project's channels.
10. Creating or retaining a cronjob or scheduler job for this channel. 10. Creating or retaining a cronjob or scheduler job for this channel.
11. Exposing Penpot credentials, session data, private tokens, or authorization headers. 11. Exposing Penpot credentials, session data, private tokens, or authorization headers.
12. Treating a disconnected Plugin API as proof that browserless `penpot-zcube-v1` design work is impossible. 12. Reintroducing or requesting the official plugin-based `penpot` MCP instead of operating solely through `penpot-zcube-v1`.
13. Enabling all community-server tools, especially destructive team/project/file administration, instead of maintaining a fail-closed include list. 13. Enabling all community-server tools, especially destructive team/project/file administration, instead of maintaining a fail-closed include list.
14. Retrying a low-level `update-file` mutation after an uncertain response without revision and object readback. 14. Retrying a low-level `update-file` mutation after an uncertain response without revision and object readback.
@@ -249,5 +246,5 @@ Link each design package from its authoritative Feature record and relevant Arch
- [ ] Implementation handoff links exact tasks, dependencies, and acceptance evidence. - [ ] Implementation handoff links exact tasks, dependencies, and acceptance evidence.
- [ ] Project documentation and remote/deployed artifacts were verified when changed. - [ ] Project documentation and remote/deployed artifacts were verified when changed.
- [ ] No Corp project cronjob or scheduler job exists. - [ ] No Corp project cronjob or scheduler job exists.
- [ ] The selected Penpot MCP server was enabled, capability-appropriate, and restricted to its approved tools. - [ ] `penpot-zcube-v1` was the only configured Penpot MCP and was restricted to approved tools.
- [ ] Browserless mutations include exact file/page/object/revision readback; Plugin API mutations include exact active-file verification. - [ ] Mutations include exact file/page/object/revision readback; unsupported capabilities are reported without adding another Penpot MCP.