Skip to content

Tool description enhancement and security features#12

Merged
Minitour merged 3 commits into
mainfrom
develop
Feb 20, 2026
Merged

Tool description enhancement and security features#12
Minitour merged 3 commits into
mainfrom
develop

Conversation

@Minitour
Copy link
Copy Markdown
Contributor

  • Updated setup_tool description to be clearer
  • Small UI adjustments
  • Added security features allowing the user to configure blocked phrases and allowed characters to prevent installation of malicious skills

@Minitour Minitour self-assigned this Feb 20, 2026
@Minitour Minitour merged commit 8296ca4 into main Feb 20, 2026
8 checks passed
Minitour added a commit that referenced this pull request May 14, 2026
- Sanitize rendered markdown with DOMPurify before injecting via
  dangerouslySetInnerHTML to prevent XSS from upstream registry content
- Probe all adapter capabilities via view() instead of hard-coding
  capabilities[0], so multi-capability adapters resolve items correctly
- Expand reserved-prefix list (bitbucket:, npm:, file:) and add comment
  to keep it in sync with parseSkillSource schemes
- Add 30s TTL-based memoization to ensureLoaded() so list() doesn't
  re-stat the registries directory on every web UI navigation
- Fix yamlDump to emit booleans/numbers as bare YAML values instead of
  JSON-quoted strings, making copied snippets round-trippable
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant