Problem
The skill trust and settings readers treat an unsupported schema or invalid shape as an empty v1 store. Subsequent writes replace the original file with a new v1 file. In settings, an absent record means enabled: true, so an older CLI can also re-enable a skill that a newer store had disabled.
Reproduction (built from current main, b037891)
- Write
skill-settings.json with {"schema_version":2,"settings":[{"projectRoot":"*","skillId":"example","enabled":false,"automatic":false}]}.
loadSkillSettings() returns an empty v1 store. skill_discovery.ts therefore computes enabled = true for example.
- Call
saveSkillSetting() for another skill. The file becomes schema v1 with only the new record; the prior setting is gone.
- The same schema-2-to-v1 replacement happens to
skill-trust.json after recordTrust() adds a record. I reproduced both with separate temporary config directories.
Relevant code: src/core/skills/skill_settings.ts, skill_trust.ts, and skill_discovery.ts.
Expected
Keep missing, corrupt, and unsupported-version stores distinct. An incompatible settings store should not be interpreted as permission to enable skills, and no mutator should overwrite unknown/corrupt source bytes. Surface an actionable diagnostic or explicit repair path. Add tests for both readers and writes against a future schema and malformed JSON.
Problem
The skill trust and settings readers treat an unsupported schema or invalid shape as an empty v1 store. Subsequent writes replace the original file with a new v1 file. In settings, an absent record means
enabled: true, so an older CLI can also re-enable a skill that a newer store had disabled.Reproduction (built from current
main,b037891)skill-settings.jsonwith{"schema_version":2,"settings":[{"projectRoot":"*","skillId":"example","enabled":false,"automatic":false}]}.loadSkillSettings()returns an empty v1 store.skill_discovery.tstherefore computesenabled = trueforexample.saveSkillSetting()for another skill. The file becomes schema v1 with only the new record; the prior setting is gone.skill-trust.jsonafterrecordTrust()adds a record. I reproduced both with separate temporary config directories.Relevant code:
src/core/skills/skill_settings.ts,skill_trust.ts, andskill_discovery.ts.Expected
Keep missing, corrupt, and unsupported-version stores distinct. An incompatible settings store should not be interpreted as permission to enable skills, and no mutator should overwrite unknown/corrupt source bytes. Surface an actionable diagnostic or explicit repair path. Add tests for both readers and writes against a future schema and malformed JSON.