fix(skills): preserve package identity through install and review - #6753
Merged
Merged
Conversation
Scope: shared skill frontmatter boundaries, remote skill metadata and digest coverage, unavailable-home discovery, and archive executable modes in the seven declared paths. Skill slug migration is deferred to preserve exact-name disabled state. No implementation edits or gates run at this checkpoint.
Seven declared paths are preserved for review. Formatting and diff whitespace checks passed; production, Rust, npm and web gates have not run. Review identified pending digest fail-closed/read-cap corrections, no-home cache sync guard, and the integration harness include boundary. This is an unqualified intermediate checkpoint, not a ready-to-land change. Unicode slug migration remains deferred.
Reuse one frontmatter reader for discovery, profiles and install. Preserve owner executable intent in archives, keep local receipts out of package input, include all payload files and relative paths in bounded digests, and refuse global cache work when a home directory is unavailable. Validation: production cargo check passed; 330 focused Rust tests and 16 CLI install integration tests passed, 0 failed/ignored; npm test 636 passed, 0 failed; npm run check:web passed. Linux exercises the non-UTF8 filename fixture because APFS refuses creating it. Hosted CI pending. Signed-off-by: Hunter B <hmbown@gmail.com>
This was referenced Sep 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No-Issue: verified package input and review consistency findings.
Skill discovery, agent profiles and package installation now use one frontmatter reader. It handles Unicode indentation, leading BOMs, standalone fences and wrapped descriptions consistently. Archive extraction preserves executable intent for the owner and keeps installer-owned root receipts separate from package input. Plugin trust continues to use its existing state store.
Package review hashes all payload files with their relative paths, including hidden/backup files. Relative roots and filesystem aliases now produce the same digest, while moving a file within the package changes it. Ambiguous metadata names, unreadable entries and unsupported file types are refused; actual reads are bounded even if a file grows. Changed coverage can make an existing trust receipt stale, requiring review again. Missing-home discovery omits global roots, and registry sync refuses before configuration or network work when it has no cache destination.
Validation on final source:
cargo check -p codewhale-tui --lib --locked: passed.npm test: 636 passed, 0 failed;npm run check:web: passed.Non-ASCII skill-name collision handling requires a separate activation-state migration and is tracked separately. Hosted CI remains required before merge.