Skip to content

[WIP] Add hardcoded trusted publisher seed list for discovery layer - #15

Draft
indhra with Claude wants to merge 2 commits into
mainfrom
claude/add-trusted-publisher-seed-list
Draft

indhra with Claude wants to merge 2 commits into
mainfrom
claude/add-trusted-publisher-seed-list

Conversation

@Claude

@Claude Claude AI commented May 14, 2026

Copy link
Copy Markdown

Thanks for asking me to work on this. I will get started on it and keep this PR's description up to date as I form a plan and make progress.


This section details on the original issue you should resolve

<issue_title>[P1] feat: hardcoded trusted-publisher seed list (the actual value prop)</issue_title>
<issue_description>## Problem

agent-hunter's discovery layer does not currently surface the high-trust community publishers who are the actual long-tail value justifying the tool's existence (since Claude Code's official /plugin only indexes the ~80–100 plugins in claude-plugins-official and does not auto-discover community skill repos).

When I ran bin/hunt . on this repo, top 3 were:

  1. pandanpc/mcp-server — 0⭐, unknown author
  2. bssm-oss/CodeAgora — 0⭐, unknown author
  3. mmexia/mybotvault — 0⭐, unknown author

None of the well-known community skill repos (verified existence + size via gh api on 2026-05-14) appeared:

Publisher Repo Stars Last push Owner followers
mattpocock mattpocock/skills 80,911 2026-05-13 16,229
garrytan garrytan/gstack 96,242 2026-05-13 9,081
VoltAgent VoltAgent/awesome-agent-skills 21,672 2026-05-10 2,898
anthropics anthropics/claude-plugins-official 19,348 2026-05-14 (org)
alirezarezvani alirezarezvani/claude-skills 14,756 2026-05-14 1,547
simonw simonw/claude-skills 922 2025-12-12 14,832

Note: this very repo's own .claude/CLAUDE.md lists gstack skills as "Recommended Skills Sources" — the user found them via word-of-mouth, not via agent-hunter. That manual word-of-mouth path is exactly what this tool should replace.

Proposed fix

Create references/TRUSTED_PUBLISHERS.yaml:

- handle: mattpocock
  primary_repo: mattpocock/skills
  domains: [typescript, javascript, testing, engineering]
  trust_boost: 0.25
  note: "TypeScript educator; 80k+ stars; ~16k followers; active 2026"

- handle: garrytan
  primary_repo: garrytan/gstack
  domains: [product, design, qa, engineering, release]
  trust_boost: 0.25
  note: "YC president; 96k+ stars; gstack = 23 opinionated skills"

- handle: simonw
  primary_repo: simonw/claude-skills
  domains: [python, ai-tooling, data]
  trust_boost: 0.20
  note: "Mirror of /mnt/skills from Claude code interpreter"

- handle: alirezarezvani
  primary_repo: alirezarezvani/claude-skills
  domains: [general, productivity, marketing, product, compliance]
  trust_boost: 0.15
  note: "263+ skills across multiple coding agents"

- handle: VoltAgent
  primary_repo: VoltAgent/awesome-agent-skills
  domains: [meta, registry, multi-agent]
  trust_boost: 0.15
  note: "Curated registry of 1000+ skills across Claude/Codex/Gemini/Cursor"

- handle: anthropics
  primary_repo: anthropics/claude-plugins-official
  domains: [official, foundational]
  trust_boost: 0.30
  note: "Official Anthropic marketplace; auto-registered in Claude Code"

Scorer changes in scripts/scorer.py:

  • Load TRUSTED_PUBLISHERS.yaml once per hunt.
  • For any candidate whose owner matches a handle, add trust_boost to trust_score.
  • Reporter labels these [TRUSTED] instead of [RAW] or [COMMUNITY].
  • "Why" line includes the publisher note: Why: Trusted publisher (Matt Pocock, 80k+⭐); domain match: typescript.

Files

  • references/TRUSTED_PUBLISHERS.yaml (new)
  • scripts/scorer.py (loader + boost application)
  • scripts/reporter.py (TRUSTED label + Why line)
  • tests/test_scorer.py (boost application)
  • tests/fixtures/trusted_publishers_minimal.yaml (test fixture)

Acceptance criteria

  • Hunt on a TypeScript-flavored project surfaces mattpocock/skills in top 3 with [TRUSTED] label.
  • Hunt on a Python project surfaces simonw/claude-skills.
  • Hunt on agent-hunter itself (Python + Claude tooling) surfaces a relevant TRUSTED publisher in top 3 rather than three 0⭐ unknowns.
  • YAML loader handles missing/malformed entries gracefully (unit-tested).
  • Numbers in YAML notes match real gh api data (this issue documents the source values).

Effort

M (3–5h)

Related

Pairs with #(GitHub signal scoring) and #(install command switch) to deliver the full v0.2.0 discovery upgrade.</issue_description>

Comments on the Issue (you are @claude[agent] in this section)

- Created references/TRUSTED_PUBLISHERS.yaml with 6 community publishers
- Updated scorer.py to load publishers and apply trust boost (0.15-0.30)
- Updated reporter.py to show [TRUSTED] label and publisher notes
- Added comprehensive tests for boost logic, error handling
- All 23 scorer tests pass (4 new tests for trusted publishers)

Agent-Logs-Url: https://github.com/indhra/agent-hunter/sessions/1e0b5fcb-f788-42f0-83ce-3cd9dca6ddcf

Co-authored-by: indhra <55424779+indhra@users.noreply.github.com>
@Claude
Claude AI requested a review from indhra May 14, 2026 13:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[P1] feat: hardcoded trusted-publisher seed list (the actual value prop)

2 participants