Skip to content

fix: serialize skill scaffold YAML safely 🤖🤖🤖 - #4339

Open
Mnilax wants to merge 1 commit into
github:mainfrom
Mnilax:fix/skill-scaffold-yaml
Open

Mnilax wants to merge 1 commit into
github:mainfrom
Mnilax:fix/skill-scaffold-yaml

Conversation

@Mnilax

@Mnilax Mnilax commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Pull Request Checklist

  • I have read and followed CONTRIBUTING.md.
  • I am targeting main.
  • I ran npm run build; generated files remain unchanged.
  • Resource-content, paid-service and in-Copilot testing checklist items are not applicable: this changes the existing scaffolding CLI, not a submitted skill or paid-service integration.

Description

The skill creator interpolates the description into an unquoted YAML scalar. For example, Review API: protobuf and gRPC contracts produces invalid frontmatter, while a description containing # silently loses the rest of the text.

Serialize name and description with the existing js-yaml dependency, forcing single-quoted strings. No dependency, generated content or CLI argument behavior changes.

Type of Contribution

  • Other: fix the existing skill scaffolding CLI and add regression tests.

Verification

  • node --test eng/create-skill.test.mjs: both tests fail against the original CLI and pass with this fix. The tests invoke the real CLI in isolated temporary fixtures and cover colons, hashes, apostrophes, backslashes and multiline values.
  • npm run build, npm run plugin:validate, npm run skill:validate: passed; all 426 skills validate.
  • bash eng/fix-line-endings.sh and git diff --check: passed.
  • Separately, the existing YAML-parser tests have three Windows EPERM failures when creating symlinks; their four non-symlink tests pass. These files are unchanged.

AI-assisted implementation and independent review. Open, closed and merged PRs were screened again by affected path, symbol and bug terms before submission; no matching fix was identified. This eng/** change remains subject to the repository's high-risk review gate.

@Mnilax
Mnilax requested a review from a team as a code owner October 1, 2026 19:03
@github-actions github-actions Bot added merge-risk:high ready-for-review Submission passed intake validation and is ready for maintainer review labels Oct 1, 2026
@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

🚦 Submission status: ⏳ Awaiting automation

Risk tier: merge-risk:high — Privileged execution, automation, or review-policy change
Required to merge: passing submission-gate checks plus 2 approvals from reviewers with write access, including a maintainer with admin or maintain permission.

Why this tier
  • eng/create-skill.mjs is a high-risk path (automation, scripts, MCP config, hooks, or review policy)
  • eng/create-skill.test.mjs is a high-risk path (automation, scripts, MCP config, hooks, or review policy)

Automated checks

Check Status Details
Line endings ✅ Passed Passed · logs
Spelling ✅ Passed Passed · logs
Contributor reputation ✅ Passed Passed · logs
Duplicate resource scan ✅ Passed Passed · logs
PR quality signal ⏭️ Skipped Skipped by its workflow · logs
Contributor risk signal 🔧 Infrastructure failure The contributor check succeeded but its result artifact was missing, unreadable, or for another commit · logs

Action needed

  • 🔧 Contributor risk signal hit an automation problem that is not caused by your contribution. Comment /rerun-checks to retry; maintainers are notified if it keeps failing.

Review

  • Approvals: 0/2
  • Assigned reviewer: not assigned yet — comment /request-review to ask for one
  • Review target date: not set
  • Still needed: 2 more approval(s); an approval from a maintainer with admin or maintain permission
  • The core-maintainers pool is not staffed yet; an approver with admin or maintain permission is required instead.

Commands

Command Who What it does
/rerun-checks PR author, maintainers Re-runs failed or incomplete checks and re-evaluates this gate
/request-review PR author, maintainers Asks the review rotation to assign a reviewer (adds needs-reviewer)

Updated for a1fa369 · gate run · This comment is maintained automatically — see submission gate docs.

@github-actions github-actions Bot added awaiting-automation and removed ready-for-review Submission passed intake validation and is ready for maintainer review labels Oct 4, 2026
@Mnilax

Mnilax commented Oct 4, 2026

Copy link
Copy Markdown
Contributor Author

/rerun-checks

@Mnilax

Mnilax commented Oct 4, 2026

Copy link
Copy Markdown
Contributor Author

/request-review

@github-actions

github-actions Bot commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

🔁 /rerun-checks for a1fa369

Re-running: Submission Gate.

The status comment updates when the checks finish.

@github-actions

github-actions Bot commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

🙋 Added needs-reviewer. Reviewer routing is assigning a reviewer now.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant