feat: initial commit - Jhonny Editor

- Adicionado estrutura completa do projeto
- Configurado MCP server para Premiere Pro
- Adicionado documentação e skills
- Configurado Gitignore para o projeto
This commit is contained in:
João Henrique
2026-09-08 09:59:31 -04:00
commit b541f502ba
1507 changed files with 387650 additions and 0 deletions
@@ -0,0 +1,21 @@
# Recommendation 41: filtered MCP subscription stream
## Evidence
MCP 2026-07-28 replaces unsolicited change notifications and `resources/subscribe` with one client-opened `subscriptions/listen` stream. Servers must only send notification types and resource URIs accepted by the stream filter.
- [MCP subscriptions](https://modelcontextprotocol.io/specification/2026-07-28/basic/patterns/subscriptions)
- [TypeScript SDK 2026-07-28 migration](https://ts.sdk.modelcontextprotocol.io/v2/migration/support-2026-07-28.html)
## Proposed improvement
Publish tool-catalog, workflow-resource, and privacy-safe project-context changes through a bounded subscription bus. Authorize every requested notification category and URI before acknowledging it, with an in-process default and an explicit multi-replica adapter.
## Acceptance criteria
- Unrequested notification types and URIs are never delivered.
- Slow consumers have bounded queues, coalescing, and explicit overflow semantics.
- Legacy notification behavior remains protocol-version gated.
- Disconnect, cancellation, reconnect, and multi-tenant isolation have contract tests.
The stream reports server-side change events; it does not prove Premiere applied an edit.
@@ -0,0 +1,21 @@
# Recommendation 42: contextual prompt and resource completions
## Evidence
MCP completion lets servers suggest up to 100 values for prompt arguments and resource-template variables, optionally using already resolved arguments as context.
- [MCP completion](https://modelcontextprotocol.io/specification/draft/server/utilities/completion)
- [MCP TypeScript SDK completion](https://ts.sdk.modelcontextprotocol.io/v2/servers/completion.html)
## Proposed improvement
Add completions for workflow prompt names, safe operation profiles, project-context handles, and resource-template identifiers. Generate suggestions only from the caller's authorized, current capability view and never expose raw paths or transcript text.
## Acceptance criteria
- Results are prefix-bounded, deterministic, deduplicated, and capped at 100.
- Missing context returns an empty result rather than widening scope.
- Stale or unauthorized handles are omitted.
- Latency, cardinality, and cross-principal isolation are tested.
Completion values are usability hints and must still pass normal tool validation.
@@ -0,0 +1,21 @@
# Recommendation 43: MRTR roots as an explicit workspace boundary
## Evidence
MCP roots let clients expose selected file or directory URIs. In MCP 2026-07-28, a server obtains roots during a request through an MRTR `ListRootsRequest` and the client must advertise the roots capability.
- [MCP roots](https://modelcontextprotocol.io/specification/2026-07-28/client/roots)
- [MCP multi-round-trip requests](https://py.sdk.modelcontextprotocol.io/handlers/multi-round-trip)
## Proposed improvement
For workspace import, preset, interchange, and export operations, intersect configured server policy with client-provided roots. Bind the canonical root set to the operation digest and revalidate it immediately before filesystem access.
## Acceptance criteria
- Unsupported clients retain the existing explicit-path policy without silent widening.
- Symlink, junction, case, encoding, and parent-traversal tests fail closed.
- Changed roots invalidate pending confirmation and application handles.
- Root names and paths are redacted from default telemetry.
Client-provided roots describe intended scope; operating-system permissions remain authoritative.
@@ -0,0 +1,21 @@
# Recommendation 44: resource annotations and context budgets
## Evidence
MCP resources and content blocks may declare `audience`, `priority`, and `lastModified` annotations so clients can filter, rank, and reason about freshness.
- [MCP resources](https://modelcontextprotocol.io/specification/2026-07-28/server/resources)
- [MCP tools and embedded resources](https://modelcontextprotocol.io/specification/2026-07-28/server/tools)
## Proposed improvement
Annotate supported-actions, workflow, diagnostics, and project-context resources from a centralized policy. Pair annotations with explicit byte/token budgets, deterministic truncation, and freshness derived from revisioned source data.
## Acceptance criteria
- Priority is policy-defined and cannot be raised by project content.
- `lastModified` reflects the source revision rather than response generation time.
- Audience filtering never substitutes for authorization.
- Budget and truncation behavior is stable across pagination and cache hits.
Annotations are client hints, not mandatory context inclusion or a security boundary.
@@ -0,0 +1,20 @@
# Recommendation 45: prompt and resource injection boundary
## Evidence
The MCP prompt specification requires implementations to validate prompt inputs and outputs to prevent injection and unauthorized resource access. Premiere metadata and transcripts are untrusted project content.
- [MCP prompts security](https://modelcontextprotocol.io/specification/2026-07-28/server/prompts)
## Proposed improvement
Represent project-derived text as labeled data blocks with provenance, size limits, and escaping rather than concatenating it into trusted workflow instructions. Separate server-authored instructions, user arguments, and Premiere-derived content in every prompt renderer.
## Acceptance criteria
- Adversarial clip names, markers, metadata, and transcripts cannot add server instructions.
- Resource links are independently authorized before rendering.
- Truncation preserves provenance and cannot splice delimiters ambiguously.
- A corpus tests injection, Unicode controls, nested markup, and oversized content.
Containment reduces instruction confusion but cannot guarantee model behavior.
@@ -0,0 +1,20 @@
# Recommendation 46: layered MCP end-to-end ping
## Evidence
MCP clients and servers can use `ping()` to verify that the protocol peer still answers independently of application operations.
- [MCP TypeScript client calls](https://ts.sdk.modelcontextprotocol.io/v2/clients/calling.html)
## Proposed improvement
Expose separate transport, authenticated-server, UXP-panel, and Premiere-readiness liveness levels. Use MCP ping only for the first two levels and keep bounded Adobe read probes behind explicit diagnostics.
## Acceptance criteria
- Ping performs no project mutation and returns no project content.
- Timeouts distinguish network, server event-loop, bridge, modal-host, and no-project states.
- Rate limits prevent ping amplification or telemetry-cardinality abuse.
- Tests prove a successful MCP ping cannot mark the Premiere host ready.
This complements the UXP heartbeat; the two signals measure different hops.
@@ -0,0 +1,21 @@
# Recommendation 47: canonical MCP resource URI policy
## Evidence
MCP resources require valid unique URIs and may use standard or custom schemes. Resource templates and subscriptions make URI identity part of authorization, caching, and notification routing.
- [MCP resources](https://modelcontextprotocol.io/specification/2026-07-28/server/resources)
- [MCP subscriptions](https://modelcontextprotocol.io/specification/2026-07-28/basic/patterns/subscriptions)
## Proposed improvement
Define canonical custom URIs for project contexts, operation receipts, compatibility reports, and artifacts. Normalize and validate scheme, authority, encoding, path segments, identifiers, and query fields before lookup or authorization.
## Acceptance criteria
- Equivalent encodings cannot create cache or authorization aliases.
- File URIs never bypass the existing path containment policy.
- Unknown schemes and duplicate canonical identities fail deterministically.
- Subscription and read authorization use the same canonicalizer.
A canonical URI identifies a server resource; it does not establish filesystem safety by itself.
@@ -0,0 +1,21 @@
# Recommendation 48: experimental C2PA inspection lab
## Evidence
Adobe documents C2PA soft-binding resolution for recovering a manifest after credentials are stripped, while Premiere Content Credentials automation remains beta or lacks a stable documented Premiere API.
- [Adobe CAI soft-binding API](https://developer.adobe.com/cai-soft-binding-api)
- [Adobe Premiere UXP changelog](https://developer.adobe.com/premiere-pro/uxp/changelog)
## Proposed improvement
Build an opt-in, read-only lab that accepts an explicitly selected artifact, extracts only bounded provenance identifiers, and optionally resolves a soft binding through an allowlisted Adobe endpoint. Keep it outside the stable action catalog until a stable Premiere API and host evidence exist.
## Acceptance criteria
- Disabled by default with separate network consent and quotas.
- No signing, credential creation, or authenticity verdict is claimed.
- Manifest output is size-bounded, schema-validated, and privacy-redacted.
- Fixtures cover absent, malformed, stripped, conflicting, and offline credentials.
C2PA provenance data supplies history claims; it does not prove media is truthful.
@@ -0,0 +1,21 @@
# Recommendation 49: UXP external-launch policy
## Evidence
Adobe UXP requires explicit `launchProcess` manifest permissions for external schemes and file extensions, distinguishes `openPath()` from `openExternal()`, and reports user denial through return values.
- [Adobe UXP external-process recipe](https://developer.adobe.com/premiere-pro/uxp/resources/recipes/external-process)
- [Adobe Premiere UXP manifest](https://developer.adobe.com/premiere-pro/uxp/plugins/concepts/manifest/)
## Proposed improvement
If the panel adds “open export,” “reveal artifact,” or documentation links, route them through one allowlisted launch broker. Require a user gesture, canonical destination, scheme/extension policy, and explicit denial handling.
## Acceptance criteria
- Production permissions contain only reviewed schemes and extensions.
- Arguments, custom commands, UNC paths, and untrusted URLs are rejected.
- Launch failures never become export failures or success claims.
- Windows and macOS packaging tests verify the exact manifest.
This recommendation does not add process execution to the current production panel.
@@ -0,0 +1,21 @@
# Recommendation 50: keyframe semantic verification
## Evidence
Adobe’s stable `ComponentParam` API exposes keyframe lists, values at time, and interpolation actions; `Keyframe` exposes position, value, and temporal interpolation mode.
- [Adobe ComponentParam reference](https://developer.adobe.com/premiere-pro/uxp/ppro-reference/classes/componentparam)
- [Adobe Keyframe reference](https://developer.adobe.com/premiere-pro/uxp/ppro-reference/classes/keyframe)
## Proposed improvement
Extend typed effect automation with a dry-run keyframe plan that canonicalizes tick positions, parameter value types, interpolation modes, and expected pre-state. After one transaction, read back the complete affected range and report semantic differences.
## Acceptance criteria
- Duplicate ticks, unsupported value shapes, invalid interpolation, and out-of-range times fail before mutation.
- Confirmation binds component identity, parameter identity, sequence revision, and plan digest.
- Unknown commit state is never automatically retried.
- Licensed-host fixtures cover scalar, boolean, color, and point parameters where supported.
Keyframe readback proves parameter state, not rendered visual correctness.