* feat(registry): move community registry source of truth into the public repo The site's registry page says "Lägg till en egen" and links here, but the MDX entries lived in the private website repo, so an external contributor had no path to open the PR we were inviting (found by the first person who tried). This makes the invitation real: - registry/entries/ + registry/authors/ hold the 20 existing entries and 2 author profiles, migrated verbatim from the website repo, which now syncs FROM this directory instead of owning the content - registry/README.md documents the frontmatter convention and the flow - scripts/validate-registry.ts (npm run validate:registry, wired into core-build) checks structure and rejects JSX/import/export in bodies: the site renders entries through MDX, which would execute those inside the website build - CONTRIBUTING.md points at the registry for listing community work Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Signed-off-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com> * fix(registry): close MDX-safety gaps and correct six compliance claims from PR review Review bot findings on #1458, both verified and addressed: - The body safety gate only rejected capitalized JSX tags, but MDX also evaluates lowercase HTML tags (<div>, <img onerror=...>) and bare {...} expressions. The validator now rejects any raw tag and any brace outside fenced code and backtick inline code; literal tags in prose go in backticks. Verified: a crafted entry with all three bypasses fails, all existing content still passes. - Six factual errors in migrated entries, each checked against the skill sources in .claude/skills/ before editing (these were live on the site already): traktamente 2026 is 300 kr not 260; employer contributions for 66+ at year start (67+ from 2026) are 10.21% not "65+: 16.36%", and the under-18 0% claim is replaced with the documented 18-22 youth reduction; electronics reverse-charge threshold is 100 000 kr excl VAT per invoice not 250 000; half prisbasbelopp 2026 is 29 600 not 24 750; kostnadsställe is SIE dimension 1 not 7; SRU period suffixes encode the fiscal-year end range (P1 jan-apr, P2 maj-aug, P4 sep-dec) not fixed months. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Signed-off-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com> --------- Signed-off-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com> Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
3.6 KiB
Community Registry
This directory is the source of truth for the registry shown at gnubok.se/community/registry: skills, MCP servers, workflows and apps built on Accounted. The website syncs its registry pages from here, so adding an entry is a normal pull request against this repo.
Structure
registry/
entries/ one .mdx file per registry entry
authors/ one .mdx file per author profile
Files starting with _ are templates and are ignored by validation and sync.
Adding an entry
- Copy
entries/_template.mdxtoentries/<your-slug>.mdx. The filename is the slug and the public URL:gnubok.se/community/registry/<your-slug>. - If this is your first contribution, copy
authors/_template.mdxtoauthors/<your-handle>.mdx. Theauthorfield in your entry must match an author file, so first-time contributors add both files in the same PR. - Validate locally:
npm run validate:registry(ornpx tsx scripts/validate-registry.tswithout installing everything). - Open a PR. Commits need a DCO sign-off (
git commit -s), same as the rest of the repo; see CONTRIBUTING.md.
A maintainer reviews the entry (does it work, does it describe itself honestly, is the content safe) and merges. After merge the website pulls the entry in with its registry sync; expect it live on the site within a few days of merging.
Entry frontmatter
Required:
| Field | Type | Notes |
|---|---|---|
title |
string | Shown as the card and page title |
description |
string | Card subtitle, max 500 chars; put detail in the body |
slug |
string | Must equal the filename |
kind |
skill | mcp | workflow | app |
Which shelf it goes on |
author |
string | Handle of a file in authors/ |
status |
live | beta | archived |
Be honest; beta is fine |
lang |
sv | en |
Language of the entry body |
personas |
list | Any of founder, finance, byra, developer |
publishedAt |
date | YYYY-MM-DD |
updatedAt |
date | YYYY-MM-DD, bump when you edit |
At least one of installCommand, downloadUrl, repoUrl, externalUrl is
required so readers can actually get the thing. Optional extras:
featured (maintainer-set), oauthScopes, gnubokTools (which MCP tools it
touches), requiresWriteScope, sieCompatible, version, faq (list of
{q, a}), related (list of slugs), ogImageEyebrow.
Body rules
The body after the frontmatter is plain Markdown (headings, lists, tables,
links, fenced code blocks). The website renders bodies through MDX, which
evaluates raw tags (lowercase HTML included), {...} expressions and
import/export statements at build time, so the validator rejects all of
them. Fenced code blocks and backtick inline code are fine; they are
displayed, never executed. Need a literal <tag> or {value} in prose? Put
it in backticks.
Write the body like documentation, not a landing page: what it does, what it needs (scopes, API keys), what it will not do, and one honest limitation beats three superlatives.
What gets accepted
- It must exist and work against Accounted today (the live app or the MCP server).
- It must describe its write behavior truthfully. Anything that writes to the ledger goes through staged operations that a human approves; entries that work around that will not be listed.
- No fees are charged for listing, and your IP stays yours. Entries are documentation and are contributed under this repo's license; the thing the entry points to keeps whatever license you gave it.