chore(skills): absorb the public skill library in-repo; retire the amico-plugin fetch pipeline - #255
Merged
Merged
Conversation
…ico-plugin fetch pipeline
Public skills are product content — version-locked with the scores and the
prompt, changed in the same PRs. This moves the 37 surface:public skills from
harmoniqs/amico-plugin (working tree @ e01d514, branch
aaron/demo-hardware-grounding-prova; amico-slack resolved from its
~/.amico/skills symlink target — a raw symlink broke vsce's secretlint with
EISDIR) into packages/extension/skills/, and deletes the extract -> release
tarball -> fetch_skills vendoring chain (fetch_skills.mjs, skills.lock.json,
vendor/skills-public, the fetch:skills step + token notes in ci/release).
DEFAULT_LIBRARY_ROOTS re-homes both tiers (ADR-0003):
1. packages/extension/skills/ — admits {public} only; the ONLY root a
Marketplace user has. The public/private boundary is now the REPO
boundary, not a regex gate (see amico-plugin#52 — the internal-tag leak
happened under the regex regime).
2. ~/.amico/vaults/armonissima/skills — admits {internal}; mount presence
IS the eligibility proof, same pattern as the retired dev checkout.
Tests: the vsix packaging gate asserts extension/skills/ ships and internal
names never appear; the two-tier leak guard now lints the in-repo dir at
source; package_skills real-root assertions run unconditionally (in-repo) and
skip-gate on the vault mount (internal). Verified: typecheck clean; fresh
amicode.vsix packages skills/ (79 files); extension suite 861 passed,
amico-run suite 940 passed.
This was referenced Aug 4, 2026
jeonghun-jj-lee
added a commit
that referenced
this pull request
Aug 7, 2026
* feat(bug-report): orchestrator create/arm/open + bridge allowlist & lifecycle kinds (amicode#250)
* test(bug-report): lifecycle — archive-on-filed, abort+delete on abandon (amicode#250)
* test(bug-report): single-open invariant — sequential reveal + concurrent join (amicode#250)
* test(bug-report): failure cleanup, unknown-id drops, terminal latches (amicode#250)
* feat(bug-report): boot-param gate, relay lanes, postToApp down-lane, sink wiring (amicode#250)
* test(bug-report): origin session is read-only provenance across every path (amicode#250)
* feat(bug-report): register amicode.reportBug, wire the manager + boot-param gate at every session prep (amicode#250)
* refactor(bug-report): one scoped collection URL, typed down-message, bounded lifecycle logging (amicode#250)
* fix(extension): bug-report-poke up-kind — re-post open-bug-report on app boot (amicode#249 QA)
The app pokes once per frame boot with the flag on; the manager answers
with a fresh open-bug-report when a bug session is live (joining an
in-flight create, never double-creating), silence otherwise. Also: [bug]
lifecycle log lines for the open/poke paths — the preview debugging had
to spelunk the db for what one log line would have said.
* fix(extension): zombie guard — reap orphaned bug sessions on close (amicode#249 QA)
The sync watch can surface a bug session orphaned by a dead extension
host. Closing that dock posted bug-report-closed for an id the new manager
never knew; dropping it left an immortal session the watch resurrected
forever. Unknown-id closes now read the session: bug_report metadata + not
archived → abort + hard delete; archived (filed) sessions and genuinely
foreign ids are never touched.
* feat(extension): pin the bug session's model from the button's live selection (amicode#249 QA)
The report-a-bug bridge command may now carry the composer's current
{providerID, modelID, variant}; the manager pins it on the arming command
(model: '<provider>/<model>') so the bug session runs the model the user
was actually using — subscription provider included (Zen never silently
becomes Go). Shape-validated at the bridge, bounded, stripped when
malformed; absent falls back to the server default.
* fix(extension): defensive postToApp + ghost-session guard (amicode#249 QA)
Two robustness gaps hit in the live preview dogfood:
- postToApp's retry timer threw 'Webview is disposed' when the chat
panel closed between the two posts (window closing mid-flow). The
down-lane now wraps both posts in try/catch — a lost open heals via
the app's boot poke + sync watch.
- A session closed while the bridge was down (disposed webview, dead
window) left manager.current pinned to a ghost: every later button
click would reveal nothing and never create. The reveal path now
probes session liveness (GET, 404-tolerant) before posting —
a dead memory clears itself and falls through to a fresh create.
* feat(extension): hardcode the bug session to opencode/deepseek-v4-pro (amicode#249)
Cheap, fast, no OpenAI/Claude — the report-a-bug command now always
pins the arm to deepseek-v4-pro, bypassing the server default.
* chore: bundle report-a-bug skill with the extension (amicode#249)
Aaron moved all skills into the extension (public) and armonissima
(internal) on main (PRs #258, #255). Our branch still carries the old
default roots, but this copy makes the skill available when the PR
merges — the extension's bundled ./skills dir is the first public root
on main.
* docs(skills): clarify the confirm gate's text-field interaction (amicode#249)
The 'Edit with notes' option requires the user to select it AND type
modifications in the 'Type your own answer' free-text field — the
question tool always appends this field as the last radio option.
Previous wording implied a separate textbox that doesn't exist.
* docs(skills): free-form confirm — textbox always visible, no radio gate (amicode#249)
The confirm step now asks via a plain free-form text question with no
pre-defined options, so the 'Type your own answer' field IS the only
input — always visible. Reply with 'file it', 'edit: <changes>', or
'veto' — the skill parses the answer.
* docs(skills): make the confirm gate match the intake question format exactly (amicode#249)
The confirm step now uses the same 'Ask **one** question, via the `question`
tool' pattern as step 5, which the model follows reliably. Explicit 'Never
ask follow-ups' header prevents the model from inventing repo/comment
questions before the gate.
* feat(app+skill): debug borders for the answer area + comment-on-existing pathway (amicode#249)
- Red/blue debug borders around the answer wrapper + question content —
proves the area renders; textarea is inside.
- The confirm gate gains a fourth option: 'comment: <repo>#<issue> <text>'
posts a clarifying comment to an existing issue via gh issue comment,
prints the sentinel, ends the session.
* fix: remove stray skills/SKILL.md
* bug reporter: deny question tool, free-form dialogue only
- createSession passes permission: [{question, deny, *}] — the question
tool is invisible to the model (hard guardrail, same as CLI non-interactive).
- Skill step 2 (capture) and step 6 (confirm gate): 'via the question tool'
replaced with 'output as plain text, wait for the user's reply.'
- Explicit 'Do not use the question tool' directive in both steps.
- Option A: at least one content question, accepts user follow-ups.
* skill: sentinel prints after ANY GitHub action, explicit format for comment path
- Sentinel is a lifecycle signal, not a semantic bug-classification
judgment. Prints after issue created, comment posted, OR chore filed.
- Comment path: explicit AMICODE_BUG_FILED format with full issue URL
(construct from repo + number).
- Removed 'actual filing' language that made the model skip the sentinel
for comments.
- Invariants updated: 'any successful GitHub action' replaces 'actual
filing'.
* feat: bug report uses the server's default model (no hardcoded model)
- armSession omits the model field entirely — the server uses whatever
model the user has configured globally (their defaultModel or the
server's built-in default).
- Removed findOriginModel (session.model isn't set by the model picker,
only at session create — so it's always empty for picker-users).
- No amicode.bugReportModel setting (unnecessary complexity).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Moves the 37
surface: publicskills fromharmoniqs/amico-pluginintopackages/extension/skills/and deletes the extract → release-tarball →fetch_skills.mjsvendoring chain. Public skills are product content: they change in lockstep with the scores and the prompt, and now land in the same PR, versioned with the extension.Source: amico-plugin working tree @
e01d514(branchaaron/demo-hardware-grounding-prova).amico-slackwas a symlink into~/.amico/skills/and is resolved to real content here (the raw symlink broke vsce's secretlint withEISDIR).Why
DEFAULT_LIBRARY_ROOTSnow reads: in-reposkills/admits{public}only (the only root a Marketplace user has),~/.amico/vaults/armonissima/skillsadmits{internal}(mount presence = eligibility proof — the internal library's new home after the plugin dissolution).Changes
packages/extension/skills/— the 37 public skills (new).src/opencode_config.ts—DEFAULT_LIBRARY_ROOTSre-homed (see above).scripts/fetch_skills.mjs,skills.lock.json,vendor/skills-public/, thefetch:skillsscript + step inci.yml/release.yml(and the amico-plugin token-scope note —OPENCODE_FETCH_TOKENnow only needs the opencode fork).extension/skills/ships and internal names never appear; the leak guard lints the in-repo dir at source;package_skillsreal-root assertions run unconditionally for the public tier and skip-gate on the vault mount for internal.package_skills.ts/agent_defs.ts; dropped the deadamico-plugin:namespace prefix in two copied skills (tdd,testare invoked by bare name).Verification
tsc --noEmitclean.amicode.vsixpackages withskills/ (79 files); the vsix-gate test file passes against it.AMICO_PYTHONinto the child env and reds 3server_authtests — pre-existing environmental flakiness, green under a scrubbed env.)Follow-ups (not this PR)
profiles//gates/land in the armonissima vault; Claude hooks retire;profile_verb.tsdefault root re-points.harmoniqs/amico-plugingets a tombstone README and archives after a soak.