Repository navigation
Add gabsplat/theme-studio - #165
Conversation
There was a problem hiding this comment.
Needs from you: nothing, changes requested
@Gabsplat, Theme Studio passes every check except one: its listing has no image. The plugin adds a sidebar screen, workspace panels, and a theme, and REVIEW.md requires at least one image for a plugin with visible surfaces.
Change needed: add a media array to paseo-plugin.json and publish a new version, for example:
"media": ["images/studio.png", "images/packs.png", "images/design.png", "images/mobile.png", "images/component.png"]Those files are already in the package, and relative paths resolve against the published version. HTTPS URLs to png, jpg, webp, gif, mp4, or webm files also work; SVG does not. The registry doesn't read paseo-listing.json, so the media listed there doesn't reach the listing. Then comment on #152 once it is published; a maintainer reruns the submission, which updates this pull request to the latest version.
Nothing else needs to change.
Review data
- Artifact: npm
paseo-theme-studio0.6.2,https://registry.npmjs.org/paseo-theme-studio/-/paseo-theme-studio-0.6.2.tgz. npmgitHeadisd834ce7859a61e9c5ee36dbe3243fbf0cb9c1912, which is tagv0.6.2. No npm provenance; the repositoryGabsplat/paseo-theme-studiobelongs to the submitter. - Integrity: SHA-512 of the tarball matches the record and npm's
dist.integrity; version and tarball URL match npm. - Validation:
npm testpasses (143/143).node scripts/validate.ts --online --changedpasses. - Extracted and inspected: all 70 files. Server and shared code read in full; client code read for imports, network, execution, globals, and clipboard.
server/export-assets.tsis generated and embeds four files identical toclient/pack-runtime.tsx,client/pack-transform.ts,shared/theme.ts, andshared/pack.ts. - Install-time commands: none.
paseo-plugin.jsonhas noinstallorbuild.package.jsonhas nopreinstall,install,postinstall, orprepare;prepublishOnly(package.json:46) runs only when the author publishes. - Dependencies: none declared, so nothing is installed with the plugin. It imports
zod,react,react-native,@tanstack/react-query, and@getpaseo/plugin, all provided by Paseo. The repository'spnpm-lock.yamlcarriesintegrityfor every entry and no git or tarball sources; it isn't used at install because there is nothing to install. - Hosts: loopback only.
server/bridge.ts:73listens on127.0.0.1on a random port behind a random bearer token compared in constant time (server/bridge.ts:89-95), and the generated MCP script talks only to that endpoint (server/bridge-source.ts:51). Nofetch, sockets, or external URLs. - Credentials and environment: reads
PASEO_HOME(index.server.ts:28,server/project.ts:26),PASEO_BINandPATHto find thepaseocommand (server/paseo-cli.ts:12-31), andPASEO_AGENT_ID(server/bridge-source.ts:15). Gives connected agents a random per-owner token,PASEO_THEME_STUDIO_OWNER_TOKEN(server/agent-integration.ts:38). No credential files, keychains, or other plugins' storage. - Filesystem: writes under
$PASEO_HOME/theme-studio/. Activating a code component writesclient/generated/*.tsxinto the plugin's own folder (server/components.ts:619-630), only after the user presses "I reviewed this code · Activate" (client/component-library.tsx:671) and only where TypeScript is installed (server/typecheck.ts:161). No user files read. - Execution:
execFileofpaseo plugin ls --jsonto find its own folder (server/project.ts:30);paseo plugin reload theme-studioafter a code activation (index.server.ts:218);tsc --noEmitin a development checkout (server/typecheck.ts:188). Agents run the fixed-templatetheme-mcp.cjsas an MCP server (server/bridge.ts:65). Agent-written components pass an AST filter (server/components.ts:127-223) and user review before they become plugin code, as the overview says. "Connect your agents" is off by default (server/agent-connection.ts:115). Noeval,new Function, or dynamicimport()of remote or computed paths. - Runtime installs: none. Export shows a
paseo plugin installcommand for the user to copy (server/export.ts:143) and runs nothing. - Readability: plain TypeScript and TSX, no minification or obfuscation.
- Source match: all 70 tarball files are byte-identical to the repository at
d834ce7. Files outside the package are tests, dev scripts, docs, and media. - Listing media and visible surfaces: none. The record has no
listing.mediaandpaseo-plugin.jsonhas nomedia. The plugin adds a sidebar screen, workspace panels, a settings screen, Command Center items, a/themecommand, a header button, chat cards, and the "Theme Studio · Live" theme (index.client.tsx:53-240). - Overview:
OVERVIEW.mdis at the package root and follows the shape, with no install steps, badges, or marketing. Its claims match the code: 60 palettes, Codex as the default designer agent, agents can't activate packs or unlock colors (server/store.ts:70-73), agent connection off by default, loopback-only network. - Decision: changes requested, because the listing has no image.
- Reviewed commit:
d955ff9c68de33d2e00618c966529debeb799b0c
The existing package screenshots are now included in listing.media. The requested new package release is unnecessary under the current review policy.
boudra
left a comment
There was a problem hiding this comment.
Approved for 0.6.2. I added the screenshots already shipped in your package to the registry listing. No new release or other action is needed from you.
Review data
- Reviewed head:
09d0f9e5fa25f76657d9ad517fa157f4bc4e7530. - Policy: REVIEW.md blob
7268134d240de9e474c52480f4937af4e369a6e2. - Downloaded
paseo-theme-studio@0.6.2again and verified npm metadata and SHA-512. It is byte-identical to the previously inspected artifact; the outstanding listing-media requirement is resolved. - Confirmed the shipped overview, manifest and package metadata. No runtime dependency installation or install/build commands are required. Rechecked the authenticated loopback bridge and user-controlled code-component activation. No plugin code or dependencies were executed.
- The listing uses the author overview and five images from the exact published version. Viewed the studio image and checked media through online registry validation.
- Current-main registry validation and GitHub Validate passed. Runtime and cross-platform behavior were not exercised.
Closes #152. Submitted by @Gabsplat.
Inline validation passed:
npm testand the checks fromnode scripts/validate.ts --online --changed. The default GITHUB_TOKEN does not trigger the PR validation workflow.Pinned
gabsplat/theme-studio.No npm provenance. The repository link is what the package declares; review the tarball, not the repo.
Review the pinned artifact before merging:
# Artifact: {"kind":"npm","package":"paseo-theme-studio","version":"0.6.2","resolved":"https://registry.npmjs.org/paseo-theme-studio/-/paseo-theme-studio-0.6.2.tgz","integrity":"sha512-zGSZI9wAHvKrMY1gbgQc1OSwMbAK0+22WObxFRJJSX+nLWjiGRMR/gXQvYMefSljN1O610oMVDf86smXlGIB0A=="}{ "id": "gabsplat/theme-studio", "artifact": { "kind": "npm", "package": "paseo-theme-studio", "version": "0.6.2", "resolved": "https://registry.npmjs.org/paseo-theme-studio/-/paseo-theme-studio-0.6.2.tgz", "integrity": "sha512-zGSZI9wAHvKrMY1gbgQc1OSwMbAK0+22WObxFRJJSX+nLWjiGRMR/gXQvYMefSljN1O610oMVDf86smXlGIB0A==" }, "repository": { "url": "https://github.com/Gabsplat/paseo-theme-studio" }, "categories": [ "themes", "extras" ], "submittedAt": "2026-10-07", "submittedBy": "Gabsplat", "reviewedAt": "2026-10-07", "listing": { "name": "Theme Studio" } }