Skip to content

chore(skills): absorb the public skill library in-repo; retire the amico-plugin fetch pipeline - #255

Merged
aarontrowbridge merged 1 commit into
mainfrom
chore/skills-into-amicode
Aug 4, 2026
Merged

chore(skills): absorb the public skill library in-repo; retire the amico-plugin fetch pipeline#255
aarontrowbridge merged 1 commit into
mainfrom
chore/skills-into-amicode

Conversation

@aarontrowbridge

Copy link
Copy Markdown
Member

What

Moves the 37 surface: public skills from harmoniqs/amico-plugin into packages/extension/skills/ and deletes the extract → release-tarball → fetch_skills.mjs vendoring chain. Public skills are product content: they change in lockstep with the scores and the prompt, and now land in the same PR, versioned with the extension.

Source: amico-plugin working tree @ e01d514 (branch aaron/demo-hardware-grounding-prova). amico-slack was a symlink into ~/.amico/skills/ and is resolved to real content here (the raw symlink broke vsce's secretlint with EISDIR).

Why

  • Kills the two-repo skill loop: edit skill → tag plugin → CI tarball → bump skills.lock.json → repackage vsix. Now: edit skill, done.
  • Kills the version drift: plugin.json 1.6.0 / marketplace.json 1.4.1 / CHANGELOG 1.7.3 / skills.lock v1.7.0 all said different things.
  • The OSS boundary becomes the repo boundary. The extract pipeline's leak-guard was a regex gate; amico-plugin#52 showed an internal-tagged skill could ride the public bundle under that regime. DEFAULT_LIBRARY_ROOTS now reads: in-repo skills/ admits {public} only (the only root a Marketplace user has), ~/.amico/vaults/armonissima/skills admits {internal} (mount presence = eligibility proof — the internal library's new home after the plugin dissolution).

Changes

  • packages/extension/skills/ — the 37 public skills (new).
  • src/opencode_config.tsDEFAULT_LIBRARY_ROOTS re-homed (see above).
  • Deleted: scripts/fetch_skills.mjs, skills.lock.json, vendor/skills-public/, the fetch:skills script + step in ci.yml/release.yml (and the amico-plugin token-scope note — OPENCODE_FETCH_TOKEN now only needs the opencode fork).
  • Tests: vsix gate asserts extension/skills/ ships and internal names never appear; the leak guard lints the in-repo dir at source; package_skills real-root assertions run unconditionally for the public tier and skip-gate on the vault mount for internal.
  • Comment refresh in package_skills.ts / agent_defs.ts; dropped the dead amico-plugin: namespace prefix in two copied skills (tdd, test are invoked by bare name).

Verification

  • tsc --noEmit clean.
  • Fresh amicode.vsix packages with skills/ (79 files); the vsix-gate test file passes against it.
  • Extension suite: 861 passed, 1 skipped. amico-run suite: 940 passed, 12 skipped.
  • (Note: running vitest from inside an Amicode session leaks AMICO_PYTHON into the child env and reds 3 server_auth tests — pre-existing environmental flakiness, green under a scrubbed env.)

Follow-ups (not this PR)

  • Phase 2: internal skills + fleet profiles//gates/ land in the armonissima vault; Claude hooks retire; profile_verb.ts default root re-points.
  • Phase 3: harmoniqs/amico-plugin gets a tombstone README and archives after a soak.

…ico-plugin fetch pipeline

Public skills are product content — version-locked with the scores and the
prompt, changed in the same PRs. This moves the 37 surface:public skills from
harmoniqs/amico-plugin (working tree @ e01d514, branch
aaron/demo-hardware-grounding-prova; amico-slack resolved from its
~/.amico/skills symlink target — a raw symlink broke vsce's secretlint with
EISDIR) into packages/extension/skills/, and deletes the extract -> release
tarball -> fetch_skills vendoring chain (fetch_skills.mjs, skills.lock.json,
vendor/skills-public, the fetch:skills step + token notes in ci/release).

DEFAULT_LIBRARY_ROOTS re-homes both tiers (ADR-0003):
  1. packages/extension/skills/ — admits {public} only; the ONLY root a
     Marketplace user has. The public/private boundary is now the REPO
     boundary, not a regex gate (see amico-plugin#52 — the internal-tag leak
     happened under the regex regime).
  2. ~/.amico/vaults/armonissima/skills — admits {internal}; mount presence
     IS the eligibility proof, same pattern as the retired dev checkout.

Tests: the vsix packaging gate asserts extension/skills/ ships and internal
names never appear; the two-tier leak guard now lints the in-repo dir at
source; package_skills real-root assertions run unconditionally (in-repo) and
skip-gate on the vault mount (internal). Verified: typecheck clean; fresh
amicode.vsix packages skills/ (79 files); extension suite 861 passed,
amico-run suite 940 passed.
@aarontrowbridge
aarontrowbridge merged commit 1b49d47 into main Aug 4, 2026
6 checks passed
@aarontrowbridge
aarontrowbridge deleted the chore/skills-into-amicode branch August 4, 2026 18:24
jeonghun-jj-lee added a commit that referenced this pull request Aug 5, 2026
Aaron moved all skills into the extension (public) and armonissima
(internal) on main (PRs #258, #255). Our branch still carries the old
default roots, but this copy makes the skill available when the PR
merges — the extension's bundled ./skills dir is the first public root
on main.
jeonghun-jj-lee added a commit that referenced this pull request Aug 7, 2026
* feat(bug-report): orchestrator create/arm/open + bridge allowlist & lifecycle kinds (amicode#250)

* test(bug-report): lifecycle — archive-on-filed, abort+delete on abandon (amicode#250)

* test(bug-report): single-open invariant — sequential reveal + concurrent join (amicode#250)

* test(bug-report): failure cleanup, unknown-id drops, terminal latches (amicode#250)

* feat(bug-report): boot-param gate, relay lanes, postToApp down-lane, sink wiring (amicode#250)

* test(bug-report): origin session is read-only provenance across every path (amicode#250)

* feat(bug-report): register amicode.reportBug, wire the manager + boot-param gate at every session prep (amicode#250)

* refactor(bug-report): one scoped collection URL, typed down-message, bounded lifecycle logging (amicode#250)

* fix(extension): bug-report-poke up-kind — re-post open-bug-report on app boot (amicode#249 QA)

The app pokes once per frame boot with the flag on; the manager answers
with a fresh open-bug-report when a bug session is live (joining an
in-flight create, never double-creating), silence otherwise. Also: [bug]
lifecycle log lines for the open/poke paths — the preview debugging had
to spelunk the db for what one log line would have said.

* fix(extension): zombie guard — reap orphaned bug sessions on close (amicode#249 QA)

The sync watch can surface a bug session orphaned by a dead extension
host. Closing that dock posted bug-report-closed for an id the new manager
never knew; dropping it left an immortal session the watch resurrected
forever. Unknown-id closes now read the session: bug_report metadata + not
archived → abort + hard delete; archived (filed) sessions and genuinely
foreign ids are never touched.

* feat(extension): pin the bug session's model from the button's live selection (amicode#249 QA)

The report-a-bug bridge command may now carry the composer's current
{providerID, modelID, variant}; the manager pins it on the arming command
(model: '<provider>/<model>') so the bug session runs the model the user
was actually using — subscription provider included (Zen never silently
becomes Go). Shape-validated at the bridge, bounded, stripped when
malformed; absent falls back to the server default.

* fix(extension): defensive postToApp + ghost-session guard (amicode#249 QA)

Two robustness gaps hit in the live preview dogfood:
- postToApp's retry timer threw 'Webview is disposed' when the chat
  panel closed between the two posts (window closing mid-flow). The
  down-lane now wraps both posts in try/catch — a lost open heals via
  the app's boot poke + sync watch.
- A session closed while the bridge was down (disposed webview, dead
  window) left manager.current pinned to a ghost: every later button
  click would reveal nothing and never create. The reveal path now
  probes session liveness (GET, 404-tolerant) before posting —
  a dead memory clears itself and falls through to a fresh create.

* feat(extension): hardcode the bug session to opencode/deepseek-v4-pro (amicode#249)

Cheap, fast, no OpenAI/Claude — the report-a-bug command now always
pins the arm to deepseek-v4-pro, bypassing the server default.

* chore: bundle report-a-bug skill with the extension (amicode#249)

Aaron moved all skills into the extension (public) and armonissima
(internal) on main (PRs #258, #255). Our branch still carries the old
default roots, but this copy makes the skill available when the PR
merges — the extension's bundled ./skills dir is the first public root
on main.

* docs(skills): clarify the confirm gate's text-field interaction (amicode#249)

The 'Edit with notes' option requires the user to select it AND type
modifications in the 'Type your own answer' free-text field — the
question tool always appends this field as the last radio option.
Previous wording implied a separate textbox that doesn't exist.

* docs(skills): free-form confirm — textbox always visible, no radio gate (amicode#249)

The confirm step now asks via a plain free-form text question with no
pre-defined options, so the 'Type your own answer' field IS the only
input — always visible. Reply with 'file it', 'edit: <changes>', or
'veto' — the skill parses the answer.

* docs(skills): make the confirm gate match the intake question format exactly (amicode#249)

The confirm step now uses the same 'Ask **one** question, via the `question`
tool' pattern as step 5, which the model follows reliably. Explicit 'Never
ask follow-ups' header prevents the model from inventing repo/comment
questions before the gate.

* feat(app+skill): debug borders for the answer area + comment-on-existing pathway (amicode#249)

- Red/blue debug borders around the answer wrapper + question content —
  proves the area renders; textarea is inside.
- The confirm gate gains a fourth option: 'comment: <repo>#<issue> <text>'
  posts a clarifying comment to an existing issue via gh issue comment,
  prints the sentinel, ends the session.

* fix: remove stray skills/SKILL.md

* bug reporter: deny question tool, free-form dialogue only

- createSession passes permission: [{question, deny, *}] — the question
  tool is invisible to the model (hard guardrail, same as CLI non-interactive).
- Skill step 2 (capture) and step 6 (confirm gate): 'via the question tool'
  replaced with 'output as plain text, wait for the user's reply.'
- Explicit 'Do not use the question tool' directive in both steps.
- Option A: at least one content question, accepts user follow-ups.

* skill: sentinel prints after ANY GitHub action, explicit format for comment path

- Sentinel is a lifecycle signal, not a semantic bug-classification
  judgment. Prints after issue created, comment posted, OR chore filed.
- Comment path: explicit AMICODE_BUG_FILED format with full issue URL
  (construct from repo + number).
- Removed 'actual filing' language that made the model skip the sentinel
  for comments.
- Invariants updated: 'any successful GitHub action' replaces 'actual
  filing'.

* feat: bug report uses the server's default model (no hardcoded model)

- armSession omits the model field entirely — the server uses whatever
  model the user has configured globally (their defaultModel or the
  server's built-in default).
- Removed findOriginModel (session.model isn't set by the model picker,
  only at session create — so it's always empty for picker-users).
- No amicode.bugReportModel setting (unnecessary complexity).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant