claude plugin validate --strict in CI: what it checks in a Sume entry
Run claude plugin validate with --strict so warnings fail the build. The MCP checks that hit a Sume entry: undeclared keys, bad URLs, literal credentials.

Add claude plugin validate ./your-plugin --strict to CI and a Sume hosted MCP entry gets checked on every change. The plugin manifest reference says validate reports passed, passed with warnings, or failed, and that --strict turns warnings into failures. Its MCP checks need Claude Code v2.1.281 or later.
For a Sume plugin, the useful catches are a header that holds a literal key, a ${user_config.KEY} that points at an option you never declared, and a URL that is not an absolute one.
What it flags in an MCP entry
From the reference, applied to a Sume entry for https://mcp.sume.com/mcp.
| Finding | Level | Sume example |
|---|---|---|
| Entry Claude Code would drop on load | Error | A malformed server block |
| ${user_config.KEY} not declared in the manifest | Error | Typo: sume_api_ky |
| Remote url that is not a valid absolute URL | Error | mcp.sume.com/mcp without https:// |
| http:// or ws:// to a non-loopback host | Warning | http://mcp.sume.com/mcp |
| Header value that looks like a literal credential | Warning | Authorization: Bearer followed by a pasted key |
| Missing version, description or author | Warning | Fails the build under --strict |
A CI step
The command runs in a shell, so any CI system can call it. Use the plugin directory as the argument and let the exit code decide the job.
claude plugin validate ./sume-media --strictSteps
Fix the warnings once on your machine first. Add version, description and author. Move the key into a sensitive userConfig option and reference it from headers. Keep the URL exactly https://mcp.sume.com/mcp. Then add the CI line. When a teammate pastes a real key into a header by mistake, the build fails before the plugin ships.
- Install Claude Code 2.1.281 or later in the CI image so the MCP checks run.
- Do not rely on validate to find every secret; run your own secret scanner too.
- Re-run after changing the server name, because hook matchers depend on it.
Warnings worth treating as failures
Under --strict, every warning breaks the build, which sounds harsh until you read the list. A plain http:// URL to a non-loopback host is a warning, and for a paid service it is simply a mistake: always use the https URL. A header that looks like a literal credential is a warning, and in a shared repository it is a leak. Treat both as errors in your head even when the tool calls them warnings.
The check cannot see secrets stored somewhere else in the repository, so keep a secret scanner in the same pipeline.
What Sume does not do
The validator checks the file, not the connection. It cannot tell you the key works. After install, call mcp_health to see whether Sume accepted the credential, and use tools_list to see which tools the session can call.
Sources
Related posts
More in Developers
- Claude tool search limits: 200-char regex, 500-char BM25, 5 results
Claude's tool search tool has fixed limits on pattern length, results and deferred tools. What they mean for a Sume hosted MCP tool list.
- Cloudflare Queue consumer 15 min wall time: poll a Sume job
A Queue consumer on Cloudflare can run 15 minutes of wall time, but a Sume job can wait longer. Re-enqueue with a delay and honor next_poll_after_seconds.
- Sume webhooks in a Cloudflare Worker: verify, queue, 204
A Worker that verifies a Sume delivery with verifyWebhook, hands the event to a queue with ctx.waitUntil, and replies 204 inside Sume's 10-second limit.
- Cloudflare Workers CPU time vs wall clock for a Sume webhook
A Sume webhook verifier on Workers spends CPU only on the HMAC and body read, not on waiting. See the limits and a WebCrypto verifier.
Written by Sume