Skip to content

Add gabsplat/theme-studio - #165

Merged
boudra merged 3 commits into
mainfrom
submit/issue-152
Oct 8, 2026
Merged

boudra merged 3 commits into
mainfrom
submit/issue-152

Conversation

@github-actions

@github-actions github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Closes #152. Submitted by @Gabsplat.
Inline validation passed: npm test and the checks from node scripts/validate.ts --online --changed. The default GITHUB_TOKEN does not trigger the PR validation workflow.

Pinned gabsplat/theme-studio.
No npm provenance. The repository link is what the package declares; review the tarball, not the repo.

Review the pinned artifact before merging:

# Artifact: {"kind":"npm","package":"paseo-theme-studio","version":"0.6.2","resolved":"https://registry.npmjs.org/paseo-theme-studio/-/paseo-theme-studio-0.6.2.tgz","integrity":"sha512-zGSZI9wAHvKrMY1gbgQc1OSwMbAK0+22WObxFRJJSX+nLWjiGRMR/gXQvYMefSljN1O610oMVDf86smXlGIB0A=="}
{
  "id": "gabsplat/theme-studio",
  "artifact": {
    "kind": "npm",
    "package": "paseo-theme-studio",
    "version": "0.6.2",
    "resolved": "https://registry.npmjs.org/paseo-theme-studio/-/paseo-theme-studio-0.6.2.tgz",
    "integrity": "sha512-zGSZI9wAHvKrMY1gbgQc1OSwMbAK0+22WObxFRJJSX+nLWjiGRMR/gXQvYMefSljN1O610oMVDf86smXlGIB0A=="
  },
  "repository": {
    "url": "https://github.com/Gabsplat/paseo-theme-studio"
  },
  "categories": [
    "themes",
    "extras"
  ],
  "submittedAt": "2026-10-07",
  "submittedBy": "Gabsplat",
  "reviewedAt": "2026-10-07",
  "listing": {
    "name": "Theme Studio"
  }
}

@github-actions github-actions Bot added the submission Plugin submission label Oct 7, 2026
@github-actions github-actions Bot mentioned this pull request Oct 7, 2026
2 of 9 tasks
paseo-bot[bot]
paseo-bot Bot previously requested changes Oct 7, 2026

@paseo-bot paseo-bot Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Needs from you: nothing, changes requested

@Gabsplat, Theme Studio passes every check except one: its listing has no image. The plugin adds a sidebar screen, workspace panels, and a theme, and REVIEW.md requires at least one image for a plugin with visible surfaces.

Change needed: add a media array to paseo-plugin.json and publish a new version, for example:

"media": ["images/studio.png", "images/packs.png", "images/design.png", "images/mobile.png", "images/component.png"]

Those files are already in the package, and relative paths resolve against the published version. HTTPS URLs to png, jpg, webp, gif, mp4, or webm files also work; SVG does not. The registry doesn't read paseo-listing.json, so the media listed there doesn't reach the listing. Then comment on #152 once it is published; a maintainer reruns the submission, which updates this pull request to the latest version.

Nothing else needs to change.

Review data

  • Artifact: npm paseo-theme-studio 0.6.2, https://registry.npmjs.org/paseo-theme-studio/-/paseo-theme-studio-0.6.2.tgz. npm gitHead is d834ce7859a61e9c5ee36dbe3243fbf0cb9c1912, which is tag v0.6.2. No npm provenance; the repository Gabsplat/paseo-theme-studio belongs to the submitter.
  • Integrity: SHA-512 of the tarball matches the record and npm's dist.integrity; version and tarball URL match npm.
  • Validation: npm test passes (143/143). node scripts/validate.ts --online --changed passes.
  • Extracted and inspected: all 70 files. Server and shared code read in full; client code read for imports, network, execution, globals, and clipboard. server/export-assets.ts is generated and embeds four files identical to client/pack-runtime.tsx, client/pack-transform.ts, shared/theme.ts, and shared/pack.ts.
  • Install-time commands: none. paseo-plugin.json has no install or build. package.json has no preinstall, install, postinstall, or prepare; prepublishOnly (package.json:46) runs only when the author publishes.
  • Dependencies: none declared, so nothing is installed with the plugin. It imports zod, react, react-native, @tanstack/react-query, and @getpaseo/plugin, all provided by Paseo. The repository's pnpm-lock.yaml carries integrity for every entry and no git or tarball sources; it isn't used at install because there is nothing to install.
  • Hosts: loopback only. server/bridge.ts:73 listens on 127.0.0.1 on a random port behind a random bearer token compared in constant time (server/bridge.ts:89-95), and the generated MCP script talks only to that endpoint (server/bridge-source.ts:51). No fetch, sockets, or external URLs.
  • Credentials and environment: reads PASEO_HOME (index.server.ts:28, server/project.ts:26), PASEO_BIN and PATH to find the paseo command (server/paseo-cli.ts:12-31), and PASEO_AGENT_ID (server/bridge-source.ts:15). Gives connected agents a random per-owner token, PASEO_THEME_STUDIO_OWNER_TOKEN (server/agent-integration.ts:38). No credential files, keychains, or other plugins' storage.
  • Filesystem: writes under $PASEO_HOME/theme-studio/. Activating a code component writes client/generated/*.tsx into the plugin's own folder (server/components.ts:619-630), only after the user presses "I reviewed this code · Activate" (client/component-library.tsx:671) and only where TypeScript is installed (server/typecheck.ts:161). No user files read.
  • Execution: execFile of paseo plugin ls --json to find its own folder (server/project.ts:30); paseo plugin reload theme-studio after a code activation (index.server.ts:218); tsc --noEmit in a development checkout (server/typecheck.ts:188). Agents run the fixed-template theme-mcp.cjs as an MCP server (server/bridge.ts:65). Agent-written components pass an AST filter (server/components.ts:127-223) and user review before they become plugin code, as the overview says. "Connect your agents" is off by default (server/agent-connection.ts:115). No eval, new Function, or dynamic import() of remote or computed paths.
  • Runtime installs: none. Export shows a paseo plugin install command for the user to copy (server/export.ts:143) and runs nothing.
  • Readability: plain TypeScript and TSX, no minification or obfuscation.
  • Source match: all 70 tarball files are byte-identical to the repository at d834ce7. Files outside the package are tests, dev scripts, docs, and media.
  • Listing media and visible surfaces: none. The record has no listing.media and paseo-plugin.json has no media. The plugin adds a sidebar screen, workspace panels, a settings screen, Command Center items, a /theme command, a header button, chat cards, and the "Theme Studio · Live" theme (index.client.tsx:53-240).
  • Overview: OVERVIEW.md is at the package root and follows the shape, with no install steps, badges, or marketing. Its claims match the code: 60 palettes, Codex as the default designer agent, agents can't activate packs or unlock colors (server/store.ts:70-73), agent connection off by default, loopback-only network.
  • Decision: changes requested, because the listing has no image.
  • Reviewed commit: d955ff9c68de33d2e00618c966529debeb799b0c

@boudra
boudra dismissed paseo-bot[bot]’s stale review October 8, 2026 19:36

The existing package screenshots are now included in listing.media. The requested new package release is unnecessary under the current review policy.

@boudra boudra left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved for 0.6.2. I added the screenshots already shipped in your package to the registry listing. No new release or other action is needed from you.

Review data
  • Reviewed head: 09d0f9e5fa25f76657d9ad517fa157f4bc4e7530.
  • Policy: REVIEW.md blob 7268134d240de9e474c52480f4937af4e369a6e2.
  • Downloaded paseo-theme-studio@0.6.2 again and verified npm metadata and SHA-512. It is byte-identical to the previously inspected artifact; the outstanding listing-media requirement is resolved.
  • Confirmed the shipped overview, manifest and package metadata. No runtime dependency installation or install/build commands are required. Rechecked the authenticated loopback bridge and user-controlled code-component activation. No plugin code or dependencies were executed.
  • The listing uses the author overview and five images from the exact published version. Viewed the studio image and checked media through online registry validation.
  • Current-main registry validation and GitHub Validate passed. Runtime and cross-platform behavior were not exercised.

@boudra
boudra merged commit 98ecf8a into main Oct 8, 2026
1 check passed
@boudra
boudra deleted the submit/issue-152 branch October 8, 2026 19:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

submission Plugin submission

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Theme Studio

1 participant