Repository navigation
v1.19.0 — Server-Side Save Skill API
What's New
Server-Side Save Skill API (PR #66)
Moved Chrome extension's webpage-to-skill conversion from client-side content scripts to a server-side API route. This eliminates the Chrome Web Store rejection (content scripts don't inject on pre-existing tabs) and uses the full SkillKit extraction pipeline.
Architecture change:
Before: Extension → Content Script (Turndown) → Download
After: Extension → POST /api/save-skill { url } → Server pipeline → Download
New: POST /api/save-skill API route (docs/fumadocs/src/app/api/save-skill/route.ts)
- Turndown HTML→Markdown conversion with GitHub URL auto-detection
- 5-source weighted tag detection (URL segments, headings, code blocks, keywords, language)
- SSRF protection blocking private IPs, link-local, and multicast addresses
- Rate limiting (10 req/min per IP)
- 5MB response body size limit
Simplified Chrome extension:
- Removed content script,
scriptingpermission, andcontent_scriptsmanifest block - Only 3 minimal permissions:
activeTab,contextMenus,downloads - Selection saves still work offline via Chrome's native
selectionText - Non-JSON error responses handled gracefully
- YAML-escaped URLs in frontmatter
Updated privacy policy and store listing to accurately disclose the URL→server data flow.
Upgrade
npm install -g skillkit@1.19.0Extension
Download skillkit-extension-v1.19.0.zip below, unzip, and load in Chrome via chrome://extensions → "Load unpacked".