Skip to content

fix(skills): drop the per-skill permissions keys — the field does not exist in SkillSchema - #511

Merged
os-zhuang merged 1 commit into
mainfrom
claude/agent-metadata-positioning-th5hhm
Jul 28, 2026
Merged

fix(skills): drop the per-skill permissions keys — the field does not exist in SkillSchema#511
os-zhuang merged 1 commit into
mainfrom
claude/agent-metadata-positioning-th5hhm

Conversation

@os-zhuang

Copy link
Copy Markdown
Contributor

All six skills declared permissions: ['crm:…']. SkillSchema has no such field, so Zod strips the key at parse time — it granted and restricted nothing while reading as a security control. That is the ADR-0049 prohibited shape (a security-shaped declaration that lies), flagged in objectstack-ai/objectstack#3820 §4.

Where access is actually gated:

  • agent levelagent.access / agent.permissions, enforced at the chat route;
  • tool level — each tool's own authz when invoked.

The spec now documents this directly on SkillSchema (objectstack-ai/objectstack#3871), so the next author — human or AI — is told before writing the key instead of having it silently vanish.

Diff is deletion-only (12 lines across 6 *.skill.ts). pnpm typecheck, objectstack validate, and the test suite (8 files / 67 tests) all pass.

Refs objectstack-ai/objectstack#3820 · sibling PRs objectstack-ai/objectstack#3871, objectstack-ai/cloud#904

🤖 Generated with Claude Code

https://claude.ai/code/session_01BHjroNkLkajskKbJaidko4


Generated by Claude Code

…ot exist in SkillSchema (objectstack#3820)

All six skills declared `permissions: ['crm:…']`. SkillSchema has no such
field, so Zod strips the key at parse time: it granted and restricted
nothing while reading as a security control — the ADR-0049 prohibited
shape, flagged in objectstack#3820 §4. Access to AI capability is gated at
the agent level (`agent.access`/`agent.permissions`, enforced at the chat
route) and by each tool's own authz; the spec now documents this on
SkillSchema itself (objectstack#3871).

typecheck, `objectstack validate`, and the test suite (67) all pass.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BHjroNkLkajskKbJaidko4
@vercel

vercel Bot commented Jul 28, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
hotcrm-docs Ready Ready Preview, Comment Jul 28, 2026 1:38pm

Request Review

@os-zhuang
os-zhuang marked this pull request as ready for review July 28, 2026 13:46
@os-zhuang
os-zhuang merged commit a257433 into main Jul 28, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants