Skip to content
This repository was archived by the owner on Aug 6, 2026. It is now read-only.

feat(tasks): bundle local skills into sha256-verified zip artifacts - #2923

Merged
tatoalo merged 2 commits into
graphite-base/2923from
local-skill-02-bundler
Jun 29, 2026
Merged

feat(tasks): bundle local skills into sha256-verified zip artifacts#2923
tatoalo merged 2 commits into
graphite-base/2923from
local-skill-02-bundler

Conversation

@tatoalo

@tatoalo tatoalo commented Jun 25, 2026

Copy link
Copy Markdown
Contributor

Problem

for cloud tasks, local skill invocations only sent the slash command text. User-local and repo-local skills were available in the local editor but not in the cloud sandbox

Changes

  • let's bundle uploadable local skills into zip artifacts with SHA-256 metadata and send them through the existing cloud artifact upload flow.

  • install skill_bundle artifacts in the agent server before prompt delivery, inject the bundled skill instructions for the invoked turn, and suppress the raw slash command from the model-facing prompt so local skills behave like actual skills rather than unsupported commands

  • refresh slash command metadata when a follow-up command is submitted, so newly created local skills can be selected and invoked without starting a brand-new task.

closes https://github.com/PostHog/code/issues/2260

@github-actions

github-actions Bot commented Jun 25, 2026

Copy link
Copy Markdown

React Doctor found no issues in the changed files. 🎉

Reviewed by React Doctor for commit e8dec75.

@greptile-apps

greptile-apps Bot commented Jun 25, 2026

Copy link
Copy Markdown
Contributor

Reviews (1): Last reviewed commit: "feat(tasks): bundle local skills into sh..." | Re-trigger Greptile

Comment thread packages/workspace-server/src/services/skills/skill-bundler.ts Outdated
Comment thread packages/workspace-server/src/services/skills/skill-bundler.ts Outdated
Comment thread packages/workspace-server/src/services/skills/skill-bundler.ts
@tatoalo
tatoalo force-pushed the local-skill-02-bundler branch from 259d373 to e8dec75 Compare June 25, 2026 09:48
@tatoalo
tatoalo force-pushed the local-skill-01-contracts branch from bf42454 to b44c3b4 Compare June 25, 2026 09:48
@tatoalo tatoalo self-assigned this Jun 25, 2026
@tatoalo
tatoalo requested a review from a team June 25, 2026 10:41
@tatoalo
tatoalo marked this pull request as ready for review June 25, 2026 10:41
@greptile-apps

greptile-apps Bot commented Jun 25, 2026

Copy link
Copy Markdown
Contributor

Security Review

  • Arbitrary filesystem read via unguarded skillPath (packages/workspace-server/src/services/skills/skills.ts): The new bundleLocalSkill method omits the resolveKnownSkillDir check that every other skill-path consumer in the file applies. This check is the documented defense against turning the endpoint into an arbitrary filesystem read. Any caller who can reach the tRPC port can provide any path that contains a SKILL.md and receive the full directory contents as a base64-encoded zip.

Reviews (2): Last reviewed commit: "feat(tasks): bundle local skills into sh..." | Re-trigger Greptile

Comment thread packages/workspace-server/src/services/skills/skills.ts
@tatoalo
tatoalo changed the base branch from local-skill-01-contracts to graphite-base/2923 June 29, 2026 14:34
@tatoalo
tatoalo force-pushed the graphite-base/2923 branch from b44c3b4 to 7f3aa86 Compare June 29, 2026 14:35
@graphite-app

graphite-app Bot commented Jun 29, 2026

Copy link
Copy Markdown

Merge activity

  • Jun 29, 2:37 PM UTC: Graphite disabled "merge when ready" on this PR due to: unsigned commits detected.

@tatoalo
tatoalo merged commit 016d9f5 into graphite-base/2923 Jun 29, 2026
28 of 38 checks passed
@tatoalo
tatoalo deleted the local-skill-02-bundler branch June 29, 2026 14:50
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants