Skip to content

Do not treat incompatible skill stores as empty and overwrite them #192

Description

@AetherAI3

Problem

The skill trust and settings readers treat an unsupported schema or invalid shape as an empty v1 store. Subsequent writes replace the original file with a new v1 file. In settings, an absent record means enabled: true, so an older CLI can also re-enable a skill that a newer store had disabled.

Reproduction (built from current main, b037891)

  1. Write skill-settings.json with {"schema_version":2,"settings":[{"projectRoot":"*","skillId":"example","enabled":false,"automatic":false}]}.
  2. loadSkillSettings() returns an empty v1 store. skill_discovery.ts therefore computes enabled = true for example.
  3. Call saveSkillSetting() for another skill. The file becomes schema v1 with only the new record; the prior setting is gone.
  4. The same schema-2-to-v1 replacement happens to skill-trust.json after recordTrust() adds a record. I reproduced both with separate temporary config directories.

Relevant code: src/core/skills/skill_settings.ts, skill_trust.ts, and skill_discovery.ts.

Expected

Keep missing, corrupt, and unsupported-version stores distinct. An incompatible settings store should not be interpreted as permission to enable skills, and no mutator should overwrite unknown/corrupt source bytes. Surface an actionable diagnostic or explicit repair path. Add tests for both readers and writes against a future schema and malformed JSON.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions