Skip to content

Update Excel plugin listings - #4481

Merged
aaronpowell merged 2 commits into
github:mainfrom
sbroenne:excel-plugin-updates-90af73608cf2
Oct 6, 2026
Merged

aaronpowell merged 2 commits into
github:mainfrom
sbroenne:excel-plugin-updates-90af73608cf2

Conversation

@sbroenne

@sbroenne sbroenne commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Pull Request Checklist

  • I have read and followed the CONTRIBUTING.md guidelines.
  • I have read and followed the Guidance for submissions involving paid services.
  • My contribution adds a new instruction, prompt, agent, skill, workflow, or canvas extension file in the correct directory.
  • The file follows the required naming convention.
  • The content is clearly structured and follows the example format.
  • I have tested my instructions, prompt, agent, skill, workflow, or canvas extension with GitHub Copilot.
  • I have run npm start and verified that README.md is up to date.
  • I am targeting the main branch for this pull request.

Description

Updates the existing excel-cli and excel-mcp listings from 2.0.1 to 2.2.1, pinned to release v2.2.1 and commit 8941e5d59a068e421ddbddf40107c6f505f5acac in sbroenne/mcp-server-excel-plugins. This supersedes the earlier 2.2.0 proposal on the same PR. Only the two plugins' entries in plugins/external.json and the generated .github/plugin/marketplace.json change here; the referenced plugin release has broader changes described below.

From custom download scripts to npm/npx: the old plugin scripts queried GitHub Releases, downloaded and verified executable archives, and maintained their own runtime cache. The new launch paths use published npm packages, with npm handling package resolution and caching.

Plugin Previous launch Current launch
excel-cli Plugin-managed GitHub Release download/cache and executable launch npx -y @sbroenne/excelcli@latest, through bin/start-cli.ps1
excel-mcp PowerShell bin/start-mcp.ps1 and the custom downloader Direct npx -y @sbroenne/mcp-server-excel@latest in mcp.json

The retained CLI wrapper preserves quoted JSON arguments under Windows PowerShell; it is a small npm launcher, not the retired downloader. Plugin installation does not put the bare excelcli command on PATH. Neither plugin requires the old global-install helper or a separate standalone executable installation.

The CLI discovery finding is addressed in 2.2.1. The published plugin now includes a small general skills/excel-cli/SKILL.md for ordinary workbook requests. It tells the agent where to find the bundled launcher, to use that same launcher for subsequent commands, and to discover exact syntax through native --help. It also distinguishes plugin-bundled paths from standalone skill installations, which must locate the actual installed plugin. This fixes the missing launcher instructions without restoring the former command/reference catalog. The source fix was merged in sbroenne/mcp-server-excel#1049; the existing 2.2.0 tag was not rewritten.

Removed or narrowed guidance:

  • The old broad CLI skill/reference collection is replaced by the small discovery skill; its former bundled command and workflow reference catalog stays removed.
  • The general plugins/excel-mcp/skills/excel-mcp/ tree is removed, including its SKILL.md and bundled references. MCP tool schemas remain the runtime command contract.
  • plugins/excel-mcp/skills/excel-mcp/references/calculation.md is removed, not added. This corrects the original generated description.
  • Both bin/download.ps1 scripts and both global-install helpers are removed. MCP's bin/start-mcp.ps1 is also removed; the CLI npm wrapper remains.
  • Both plugins include an optional report-formatting skill. These skills do not replace ordinary-work CLI discovery or MCP tool schemas.

The guidance changes do not themselves remove Excel operations from the runtime. Requirements: Windows, installed desktop Microsoft Excel 2016 or later, and Node.js 18 or later with npm/npx on PATH. Users need their own Excel installation/license; the plugins are MIT-licensed. This is not a cross-platform or Excel-free implementation.

The plugin source is pinned to the reviewed release/commit. The runtime launchers intentionally use npm's @latest tag, so the marketplace source SHA does not pin the runtime version.

Reviewable sources:


Type of Contribution

  • New instruction file.
  • New prompt file.
  • New agent file.
  • New plugin.
  • New skill file.
  • New agentic workflow.
  • New canvas extension.
  • Update to existing instruction, prompt, agent, plugin, skill, workflow, or canvas extension.
  • Other (please specify):

Additional Notes

I maintain both plugins. The description was checked against the immutable published sources, including the new CLI discovery skill, rather than inferred from a changed-path list.

Validation for the corrected source/release:

  • Source fix: 18 skill-generation tests, seven plugin build/publication-output tests, and all six publication-script test groups passed. They cover both CLI skill version stamps, legacy layouts, rejected mixed layouts, standalone path guidance, and the real publisher's no-write preview.
  • Release build completed with zero warnings/errors. Public @microsoft/vally 0.12.0 structural validation passed for the three prepared skills, with no discovery errors.
  • The 2.2.1 release workflow built and verified all packages, verified native Windows ARM64 packages, validated every prepared skill with the pinned official Agent Skills validator, and published the corrected immutable plugin release.
  • The refreshed submission passed npm ci --ignore-scripts --no-audit --no-fund, npm run plugin:validate, and npm run build in a disposable, credential-free upstream checkout. The guarded writer updated this existing PR, and its final checks restrict the diff to the two listing files.

Successful release/publication/update run. GitHub initially created the release draft but the immediate follow-up lookup failed; retrying only the failed job and its dependents succeeded without republishing the successful npm/NuGet/VS Code jobs.

Earlier installation and real-Excel E2E/smoke checks were performed against 2.2.0, not rerun against 2.2.1. No live natural-language Copilot evaluation of automatic skill selection was run. Structural tests establish that the launcher instructions are present and correctly packaged; they do not prove which skill a model will select.

Unchecked checklist items: this updates existing external-plugin listings rather than adding a new content file; no live Copilot selection session was run; and npm start was not invoked by that exact name. Upstream defines it as npm run build, which the workflow passed, but the checkbox remains unchecked to record the actual command used.


By submitting this pull request, I confirm that my contribution abides by the Code of Conduct and will be licensed under the MIT License.

@sbroenne
sbroenne requested review from a team as code owners October 4, 2026 15:58
Copilot AI balanced review requested due to automatic review settings October 4, 2026 15:58
@github-actions github-actions Bot added external-plugin Public external plugin submission plugin PR touches plugins labels Oct 4, 2026
@github-actions

github-actions Bot commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

🔒 PR Risk Scan Results

Scanned 2 changed file(s).

Severity Count
🔴 High 0
🟠 Medium 4
ℹ️ Info 0
Severity Rule File Line Match
🟠 package-exec-command .github/plugin/marketplace.json 957 "description": "Windows-only Excel automation plugin that runs the latest excelcli package through npx.",
🟠 package-exec-command .github/plugin/marketplace.json 988 "description": "Windows-only Excel automation plugin that runs the latest ExcelMcp MCP server through npx.",
🟠 package-exec-command plugins/external.json 755 "description": "Windows-only Excel automation plugin that runs the latest excelcli package through npx.",
🟠 package-exec-command plugins/external.json 786 "description": "Windows-only Excel automation plugin that runs the latest ExcelMcp MCP server through npx.",

This is an automated soft-gate report. Findings indicate review targets and do not block merge by themselves.

@github-actions

github-actions Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

🚦 Submission status: 👀 Ready for review

Risk tier: merge-risk:high — Privileged execution, automation, or review-policy change
Required to merge: passing submission-gate checks plus 2 approvals from reviewers with write access, including a maintainer with admin or maintain permission.

Why this tier
  • plugins/external.json is a high-risk path (automation, scripts, MCP config, hooks, or review policy)

Automated checks

Check Status Details
Line endings ✅ Passed Passed · logs
Spelling ✅ Passed Passed · logs
Generated README consistency ✅ Passed Passed · logs
Plugin and extension validation ✅ Passed Passed · logs
Plugin structure ✅ Passed Passed · logs
Risk scan ✅ Passed Passed · logs
Contributor reputation ✅ Passed Passed · logs
Duplicate resource scan ✅ Passed Passed · logs
PR quality signal ⏭️ Skipped Skipped by its workflow · logs
Canvas/plugin smoke test ⏭️ Skipped Not reported for this commit

Review

  • Approvals: 0/2
  • Assigned reviewer: not assigned yet — comment /request-review to ask for one
  • Review target date: not set
  • Still needed: 2 more approval(s); an approval from a maintainer with admin or maintain permission
  • The core-maintainers pool is not staffed yet; an approver with admin or maintain permission is required instead.

Commands

Command Who What it does
/rerun-checks PR author, maintainers Re-runs failed or incomplete checks and re-evaluates this gate
/request-review PR author, maintainers Asks the review rotation to assign a reviewer (adds needs-reviewer)

Updated for 40b8be0 · gate run · This comment is maintained automatically — see submission gate docs.

@github-actions github-actions Bot added the ready-for-review Submission passed intake validation and is ready for maintainer review label Oct 4, 2026
@github-actions

github-actions Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

✅ External plugin PR checks passed

  • Changed entries detected: 2
  • Workflow state label: ready-for-review
  • Full logs: Download quality gate artifact
  • Status legend: ✅ pass · ⚠️ warning · 🛑 fail

Per-plugin quality summary

Plugin spec compliance (non-blocking) vally lint install smoke test version match ref/sha consistency canvas structure overall source tree
excel-cli ✅ pass ✅ pass ✅ pass ✅ pass ✅ pass ⚪ not_run ✅ pass 8941e5d59a068e421ddbddf40107c6f505f5acac
excel-mcp ✅ pass ✅ pass ✅ pass ✅ pass ✅ pass ⚪ not_run ✅ pass 8941e5d59a068e421ddbddf40107c6f505f5acac

Gate output details

excel-cli - spec compliance (✅ pass)

Agent Plugins v1.0.0 manifest checks passed for plugin.json.
excel-cli - vally lint (✅ pass)

✅ excel-cli-report-formatting (2/2 checks passed)
    ✓ [spec-compliance] All 1 skill(s) are spec-compliant.
        ✓ spec-compliance: All spec checks passed.
    ✓ [valid-refs] All file references across 1 skill(s) are valid.
        ✓ valid-refs: All file references resolve to existing files within the skill directory.
✅ excel-cli (2/2 checks passed)
    ✓ [spec-compliance] All 1 skill(s) are spec-compliant.
        ✓ spec-compliance: All spec checks passed.
    ✓ [valid-refs] All file references across 1 skill(s) are valid.
        ✓ valid-refs: All file references resolve to existing files within the skill directory.

2 skill(s) linted, 2 passed
excel-cli - install smoke test (✅ pass)

Install smoke test succeeded. Verified /tmp/external-plugin-quality-kv61wd/copilot-home/.copilot/installed-plugins/external-plugin-intake/excel-cli/plugin.json.
excel-cli - version match (pass)

- v2.2.1: matched version "2.2.1" at "plugins/excel-cli/plugin.json".
- 8941e5d59a068e421ddbddf40107c6f505f5acac: matched version "2.2.1" at "plugins/excel-cli/plugin.json".
excel-cli - ref/sha consistency (pass)

source.ref "v2.2.1" resolves to the same commit as source.sha "8941e5d59a068e421ddbddf40107c6f505f5acac".
excel-cli - canvas structure (not_run)

Canvas structure gate skipped because plugin is not tagged with "canvas".
excel-mcp - spec compliance (✅ pass)

Agent Plugins v1.0.0 manifest checks passed for plugin.json.
excel-mcp - vally lint (✅ pass)

✅ excel-mcp-report-formatting (2/2 checks passed)
    ✓ [spec-compliance] All 1 skill(s) are spec-compliant.
        ✓ spec-compliance: All spec checks passed.
    ✓ [valid-refs] All file references across 1 skill(s) are valid.
        ✓ valid-refs: All file references resolve to existing files within the skill directory.

1 skill(s) linted, 1 passed
excel-mcp - install smoke test (✅ pass)

Install smoke test succeeded. Verified /tmp/external-plugin-quality-t5mwOB/copilot-home/.copilot/installed-plugins/external-plugin-intake/excel-mcp/plugin.json.
excel-mcp - version match (pass)

- v2.2.1: matched version "2.2.1" at "plugins/excel-mcp/plugin.json".
- 8941e5d59a068e421ddbddf40107c6f505f5acac: matched version "2.2.1" at "plugins/excel-mcp/plugin.json".
excel-mcp - ref/sha consistency (pass)

source.ref "v2.2.1" resolves to the same commit as source.sha "8941e5d59a068e421ddbddf40107c6f505f5acac".
excel-mcp - canvas structure (not_run)

Canvas structure gate skipped because plugin is not tagged with "canvas".
- excel-cli: spec=pass, vally-lint=pass, install-smoke=pass, version-match=pass, ref-sha-consistency=pass, canvas-structure=not_run, overall=pass
- excel-mcp: spec=pass, vally-lint=pass, install-smoke=pass, version-match=pass, ref-sha-consistency=pass, canvas-structure=not_run, overall=pass

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The CLI update removes its general automation skill, and the PR description understates the upstream removals.

Review effort: Balanced
Findings: 1 High severity · 1 Low severity

Open (2)
What changed in this PR

Updates the external Excel plugins from v2.0.1 to v2.2.0.

Changes:

  • Updates descriptions, versions, refs, and immutable SHAs.
  • Regenerates matching marketplace entries.
File Description
plugins/​external.json Updates Excel plugin listings.
.github/​plugin/​marketplace.json Mirrors regenerated listings.

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread plugins/external.json Outdated
Comment thread plugins/external.json Outdated
Copilot AI balanced review requested due to automatic review settings October 4, 2026 18:49

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The external plugins execute latest-tag npm packages, and v2.2.1 lacks live installation and discovery validation.

Review effort: Balanced
Findings: 1 High severity

Open (1)
Resolved since last review (1)

@sbroenne

sbroenne commented Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

/request-review

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

🙋 Added needs-reviewer. Reviewer routing is assigning a reviewer now.

@sbroenne

sbroenne commented Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

/rerun-checks

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

🔁 /rerun-checks for 40b8be0

Re-running: Submission Gate.

The status comment updates when the checks finish.

@aaronpowell
aaronpowell merged commit aa91c04 into github:main Oct 6, 2026
52 of 58 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

external-plugin Public external plugin submission merge-risk:high needs-reviewer plugin PR touches plugins ready-for-review Submission passed intake validation and is ready for maintainer review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants