Fix packaged lookup for managed agent skills - #90
Merged
Conversation
Resolve named sync requests from both skills/ and agent-skills/, ship the managed agent-skill tree in 0.1.61, and fail the release guard if any repository-managed agent-skill file is omitted. Agent: cossus
Contributor
Author
|
[REVIEW] NO_GO — #90 @ 063229c — lens: correctness+security+gates, reviewer Hostus (1 of 1) Scope read:
Commands and measured results:
Blocking P0/P1 findings:
Security findings:
Non-blocking follow-ups:
|
Agent: Hostus
Contributor
Author
|
[REVIEW] GO — #90 @ 34b3fed — lens: correctness+security+gates, reviewer Hostus (1 of 1) Focused re-review of the one named P1 and its direct regressions:
Commands and measured results after the fix:
Blocking P0/P1 findings: none remain. The prior P1 was fixed and the affected shared-writer lanes are green. Non-blocking follow-ups: none from the focused remediation scope. |
This was referenced Aug 9, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
ca7fb4e7-466a-441d-89e8-39928370f116) after fix(agent-skill): use executable fleet rollout route #89.skills syncrequests from both the publicskills/catalog and repository-managedagent-skills/, while preserving executable-pointer behavior and traversal rejection.agent-skills/tree in@hasna/skills@0.1.61and make the release guard reject any omitted repository-managed agent-skill file.agent-skills/entered the tarball.Exact candidate
5244c8e8013f78b4d2755a01c3aa307f56f11fda063229cb54bfab180ed2d3b5fde5f08402c2222bValidation
30 pass / 3 failacross lookup, packlist, and release-guard omission.33 pass / 0 fail.rc=0.rc=0.rc=0; memory and SQLite ran, while PostgreSQL explicitly skipped becauseHASNA_SKILLS_TEST_DATABASE_URLwas unset.22 pass / 0 fail.rc=0;565 package-visible files (281 code)scanned and certified.fleet-package-rolloutreturnedrc=0with five create/update actions.missing-managed-agent-skillreturnedrc=1with fivenot found in this machine's corpusskips.0.1.61assertion: literaltrue; extracted packed positive returnedrc=0, and the missing-name negative returnedrc=1.no leaks found.1 commits scannedandno leaks found.Release boundary
The npm registry still reports latest
0.1.60;@hasna/skills@0.1.61returnsE404. A patch release of0.1.61is required after review and merge before managed distribution can use this fix.No live agent home was written, and this PR does not merge, publish, install, or perform a live sync.
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.