feat: initial commit - Jhonny Editor
- Adicionado estrutura completa do projeto - Configurado MCP server para Premiere Pro - Adicionado documentação e skills - Configurado Gitignore para o projeto
This commit is contained in:
@@ -0,0 +1,21 @@
|
||||
# Recommendation 41: filtered MCP subscription stream
|
||||
|
||||
## Evidence
|
||||
|
||||
MCP 2026-07-28 replaces unsolicited change notifications and `resources/subscribe` with one client-opened `subscriptions/listen` stream. Servers must only send notification types and resource URIs accepted by the stream filter.
|
||||
|
||||
- [MCP subscriptions](https://modelcontextprotocol.io/specification/2026-07-28/basic/patterns/subscriptions)
|
||||
- [TypeScript SDK 2026-07-28 migration](https://ts.sdk.modelcontextprotocol.io/v2/migration/support-2026-07-28.html)
|
||||
|
||||
## Proposed improvement
|
||||
|
||||
Publish tool-catalog, workflow-resource, and privacy-safe project-context changes through a bounded subscription bus. Authorize every requested notification category and URI before acknowledging it, with an in-process default and an explicit multi-replica adapter.
|
||||
|
||||
## Acceptance criteria
|
||||
|
||||
- Unrequested notification types and URIs are never delivered.
|
||||
- Slow consumers have bounded queues, coalescing, and explicit overflow semantics.
|
||||
- Legacy notification behavior remains protocol-version gated.
|
||||
- Disconnect, cancellation, reconnect, and multi-tenant isolation have contract tests.
|
||||
|
||||
The stream reports server-side change events; it does not prove Premiere applied an edit.
|
||||
@@ -0,0 +1,21 @@
|
||||
# Recommendation 42: contextual prompt and resource completions
|
||||
|
||||
## Evidence
|
||||
|
||||
MCP completion lets servers suggest up to 100 values for prompt arguments and resource-template variables, optionally using already resolved arguments as context.
|
||||
|
||||
- [MCP completion](https://modelcontextprotocol.io/specification/draft/server/utilities/completion)
|
||||
- [MCP TypeScript SDK completion](https://ts.sdk.modelcontextprotocol.io/v2/servers/completion.html)
|
||||
|
||||
## Proposed improvement
|
||||
|
||||
Add completions for workflow prompt names, safe operation profiles, project-context handles, and resource-template identifiers. Generate suggestions only from the caller's authorized, current capability view and never expose raw paths or transcript text.
|
||||
|
||||
## Acceptance criteria
|
||||
|
||||
- Results are prefix-bounded, deterministic, deduplicated, and capped at 100.
|
||||
- Missing context returns an empty result rather than widening scope.
|
||||
- Stale or unauthorized handles are omitted.
|
||||
- Latency, cardinality, and cross-principal isolation are tested.
|
||||
|
||||
Completion values are usability hints and must still pass normal tool validation.
|
||||
@@ -0,0 +1,21 @@
|
||||
# Recommendation 43: MRTR roots as an explicit workspace boundary
|
||||
|
||||
## Evidence
|
||||
|
||||
MCP roots let clients expose selected file or directory URIs. In MCP 2026-07-28, a server obtains roots during a request through an MRTR `ListRootsRequest` and the client must advertise the roots capability.
|
||||
|
||||
- [MCP roots](https://modelcontextprotocol.io/specification/2026-07-28/client/roots)
|
||||
- [MCP multi-round-trip requests](https://py.sdk.modelcontextprotocol.io/handlers/multi-round-trip)
|
||||
|
||||
## Proposed improvement
|
||||
|
||||
For workspace import, preset, interchange, and export operations, intersect configured server policy with client-provided roots. Bind the canonical root set to the operation digest and revalidate it immediately before filesystem access.
|
||||
|
||||
## Acceptance criteria
|
||||
|
||||
- Unsupported clients retain the existing explicit-path policy without silent widening.
|
||||
- Symlink, junction, case, encoding, and parent-traversal tests fail closed.
|
||||
- Changed roots invalidate pending confirmation and application handles.
|
||||
- Root names and paths are redacted from default telemetry.
|
||||
|
||||
Client-provided roots describe intended scope; operating-system permissions remain authoritative.
|
||||
+21
@@ -0,0 +1,21 @@
|
||||
# Recommendation 44: resource annotations and context budgets
|
||||
|
||||
## Evidence
|
||||
|
||||
MCP resources and content blocks may declare `audience`, `priority`, and `lastModified` annotations so clients can filter, rank, and reason about freshness.
|
||||
|
||||
- [MCP resources](https://modelcontextprotocol.io/specification/2026-07-28/server/resources)
|
||||
- [MCP tools and embedded resources](https://modelcontextprotocol.io/specification/2026-07-28/server/tools)
|
||||
|
||||
## Proposed improvement
|
||||
|
||||
Annotate supported-actions, workflow, diagnostics, and project-context resources from a centralized policy. Pair annotations with explicit byte/token budgets, deterministic truncation, and freshness derived from revisioned source data.
|
||||
|
||||
## Acceptance criteria
|
||||
|
||||
- Priority is policy-defined and cannot be raised by project content.
|
||||
- `lastModified` reflects the source revision rather than response generation time.
|
||||
- Audience filtering never substitutes for authorization.
|
||||
- Budget and truncation behavior is stable across pagination and cache hits.
|
||||
|
||||
Annotations are client hints, not mandatory context inclusion or a security boundary.
|
||||
+20
@@ -0,0 +1,20 @@
|
||||
# Recommendation 45: prompt and resource injection boundary
|
||||
|
||||
## Evidence
|
||||
|
||||
The MCP prompt specification requires implementations to validate prompt inputs and outputs to prevent injection and unauthorized resource access. Premiere metadata and transcripts are untrusted project content.
|
||||
|
||||
- [MCP prompts security](https://modelcontextprotocol.io/specification/2026-07-28/server/prompts)
|
||||
|
||||
## Proposed improvement
|
||||
|
||||
Represent project-derived text as labeled data blocks with provenance, size limits, and escaping rather than concatenating it into trusted workflow instructions. Separate server-authored instructions, user arguments, and Premiere-derived content in every prompt renderer.
|
||||
|
||||
## Acceptance criteria
|
||||
|
||||
- Adversarial clip names, markers, metadata, and transcripts cannot add server instructions.
|
||||
- Resource links are independently authorized before rendering.
|
||||
- Truncation preserves provenance and cannot splice delimiters ambiguously.
|
||||
- A corpus tests injection, Unicode controls, nested markup, and oversized content.
|
||||
|
||||
Containment reduces instruction confusion but cannot guarantee model behavior.
|
||||
@@ -0,0 +1,20 @@
|
||||
# Recommendation 46: layered MCP end-to-end ping
|
||||
|
||||
## Evidence
|
||||
|
||||
MCP clients and servers can use `ping()` to verify that the protocol peer still answers independently of application operations.
|
||||
|
||||
- [MCP TypeScript client calls](https://ts.sdk.modelcontextprotocol.io/v2/clients/calling.html)
|
||||
|
||||
## Proposed improvement
|
||||
|
||||
Expose separate transport, authenticated-server, UXP-panel, and Premiere-readiness liveness levels. Use MCP ping only for the first two levels and keep bounded Adobe read probes behind explicit diagnostics.
|
||||
|
||||
## Acceptance criteria
|
||||
|
||||
- Ping performs no project mutation and returns no project content.
|
||||
- Timeouts distinguish network, server event-loop, bridge, modal-host, and no-project states.
|
||||
- Rate limits prevent ping amplification or telemetry-cardinality abuse.
|
||||
- Tests prove a successful MCP ping cannot mark the Premiere host ready.
|
||||
|
||||
This complements the UXP heartbeat; the two signals measure different hops.
|
||||
@@ -0,0 +1,21 @@
|
||||
# Recommendation 47: canonical MCP resource URI policy
|
||||
|
||||
## Evidence
|
||||
|
||||
MCP resources require valid unique URIs and may use standard or custom schemes. Resource templates and subscriptions make URI identity part of authorization, caching, and notification routing.
|
||||
|
||||
- [MCP resources](https://modelcontextprotocol.io/specification/2026-07-28/server/resources)
|
||||
- [MCP subscriptions](https://modelcontextprotocol.io/specification/2026-07-28/basic/patterns/subscriptions)
|
||||
|
||||
## Proposed improvement
|
||||
|
||||
Define canonical custom URIs for project contexts, operation receipts, compatibility reports, and artifacts. Normalize and validate scheme, authority, encoding, path segments, identifiers, and query fields before lookup or authorization.
|
||||
|
||||
## Acceptance criteria
|
||||
|
||||
- Equivalent encodings cannot create cache or authorization aliases.
|
||||
- File URIs never bypass the existing path containment policy.
|
||||
- Unknown schemes and duplicate canonical identities fail deterministically.
|
||||
- Subscription and read authorization use the same canonicalizer.
|
||||
|
||||
A canonical URI identifies a server resource; it does not establish filesystem safety by itself.
|
||||
@@ -0,0 +1,21 @@
|
||||
# Recommendation 48: experimental C2PA inspection lab
|
||||
|
||||
## Evidence
|
||||
|
||||
Adobe documents C2PA soft-binding resolution for recovering a manifest after credentials are stripped, while Premiere Content Credentials automation remains beta or lacks a stable documented Premiere API.
|
||||
|
||||
- [Adobe CAI soft-binding API](https://developer.adobe.com/cai-soft-binding-api)
|
||||
- [Adobe Premiere UXP changelog](https://developer.adobe.com/premiere-pro/uxp/changelog)
|
||||
|
||||
## Proposed improvement
|
||||
|
||||
Build an opt-in, read-only lab that accepts an explicitly selected artifact, extracts only bounded provenance identifiers, and optionally resolves a soft binding through an allowlisted Adobe endpoint. Keep it outside the stable action catalog until a stable Premiere API and host evidence exist.
|
||||
|
||||
## Acceptance criteria
|
||||
|
||||
- Disabled by default with separate network consent and quotas.
|
||||
- No signing, credential creation, or authenticity verdict is claimed.
|
||||
- Manifest output is size-bounded, schema-validated, and privacy-redacted.
|
||||
- Fixtures cover absent, malformed, stripped, conflicting, and offline credentials.
|
||||
|
||||
C2PA provenance data supplies history claims; it does not prove media is truthful.
|
||||
@@ -0,0 +1,21 @@
|
||||
# Recommendation 49: UXP external-launch policy
|
||||
|
||||
## Evidence
|
||||
|
||||
Adobe UXP requires explicit `launchProcess` manifest permissions for external schemes and file extensions, distinguishes `openPath()` from `openExternal()`, and reports user denial through return values.
|
||||
|
||||
- [Adobe UXP external-process recipe](https://developer.adobe.com/premiere-pro/uxp/resources/recipes/external-process)
|
||||
- [Adobe Premiere UXP manifest](https://developer.adobe.com/premiere-pro/uxp/plugins/concepts/manifest/)
|
||||
|
||||
## Proposed improvement
|
||||
|
||||
If the panel adds “open export,” “reveal artifact,” or documentation links, route them through one allowlisted launch broker. Require a user gesture, canonical destination, scheme/extension policy, and explicit denial handling.
|
||||
|
||||
## Acceptance criteria
|
||||
|
||||
- Production permissions contain only reviewed schemes and extensions.
|
||||
- Arguments, custom commands, UNC paths, and untrusted URLs are rejected.
|
||||
- Launch failures never become export failures or success claims.
|
||||
- Windows and macOS packaging tests verify the exact manifest.
|
||||
|
||||
This recommendation does not add process execution to the current production panel.
|
||||
+21
@@ -0,0 +1,21 @@
|
||||
# Recommendation 50: keyframe semantic verification
|
||||
|
||||
## Evidence
|
||||
|
||||
Adobe’s stable `ComponentParam` API exposes keyframe lists, values at time, and interpolation actions; `Keyframe` exposes position, value, and temporal interpolation mode.
|
||||
|
||||
- [Adobe ComponentParam reference](https://developer.adobe.com/premiere-pro/uxp/ppro-reference/classes/componentparam)
|
||||
- [Adobe Keyframe reference](https://developer.adobe.com/premiere-pro/uxp/ppro-reference/classes/keyframe)
|
||||
|
||||
## Proposed improvement
|
||||
|
||||
Extend typed effect automation with a dry-run keyframe plan that canonicalizes tick positions, parameter value types, interpolation modes, and expected pre-state. After one transaction, read back the complete affected range and report semantic differences.
|
||||
|
||||
## Acceptance criteria
|
||||
|
||||
- Duplicate ticks, unsupported value shapes, invalid interpolation, and out-of-range times fail before mutation.
|
||||
- Confirmation binds component identity, parameter identity, sequence revision, and plan digest.
|
||||
- Unknown commit state is never automatically retried.
|
||||
- Licensed-host fixtures cover scalar, boolean, color, and point parameters where supported.
|
||||
|
||||
Keyframe readback proves parameter state, not rendered visual correctness.
|
||||
Reference in New Issue
Block a user