Skip to content

Commit 570def4

Browse files
Add C# and shell execution playbooks with icons, aliases, and integration tests:
- Introduced `code-run-csharp` and `code-run-shell` skills with detailed playbooks for computation and shell command execution. - Added new icons to `AppIcon.razor` and updated associated skill metadata. - Enhanced skill alias validation and tests to support `#` suffix usage. - Updated UI and CSS for better hover and edit interactions in endpoint rows. - Integrated unit tests for skill catalog exposure and alias matching.
1 parent 0d35ff6 commit 570def4

10 files changed

Lines changed: 279 additions & 6 deletions

File tree

‎src/AI.Contracts/Skills/SkillIcons.cs‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -39,6 +39,7 @@ public static bool IsPath(string icon) =>
3939
"git-rebase", "git-rebase-auto", "git-merge-auto",
4040
"code-plan", "code-explain", "code-refactor", "code-tests-add", "code-build-fix",
4141
"code-review", "code-performance-optimize", "code-dependencies-update", "code-security-review", "code-docs-update",
42+
"code-run-csharp", "code-run-shell",
4243
"devops-ci-create", "devops-ci-fix", "devops-container-create", "devops-compose-configure",
4344
"devops-config-review", "devops-release-prepare", "devops-deploy", "devops-rollback",
4445
"devops-incident-diagnose", "devops-observability-configure", "devops-infrastructure-change", "devops-backup-verify",

‎src/AI.Server/Application/Skills/SkillMarkdown.cs‎

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -23,9 +23,9 @@ public static SkillDefinition Parse(string content, string source, Guid? project
2323
throw new ArgumentException("Skill id must be lowercase letters, digits and hyphens, starting with a letter.");
2424
var aliases = Field("aliases") is { } aliasesText
2525
? JsonSerializer.Deserialize<string[]>(aliasesText) ?? [] : [];
26-
if (aliases.Length > 8 || aliases.Any(alias => !IsCommand(alias) || alias == id)
26+
if (aliases.Length > 8 || aliases.Any(alias => !IsAlias(alias) || alias == id)
2727
|| aliases.Distinct(StringComparer.Ordinal).Count() != aliases.Length)
28-
throw new ArgumentException("Skill aliases are up to 8 distinct commands spelled like an id and different from it.");
28+
throw new ArgumentException("Skill aliases are up to 8 distinct commands spelled like an id, optionally ending in #, and different from it.");
2929
var icon = Field("icon");
3030
if (icon is not null && !SkillIcons.IsValid(icon))
3131
throw new ArgumentException($"Skill icon must be one of: {string.Join(", ", SkillIcons.Names)}; "
@@ -77,6 +77,9 @@ public static string Body(string content)
7777
return string.Join('\n', lines.Skip(end + 1)).Trim();
7878
}
7979

80+
private static bool IsAlias(string text) =>
81+
IsCommand(text) || text.Length is >= 2 and <= 64 && text[^1] == '#' && IsCommand(text[..^1]);
82+
8083
private static bool IsCommand(string text) =>
8184
text.Length is >= 1 and <= 64 && text[0] is >= 'a' and <= 'z' && text[^1] != '-'
8285
&& text.All(character => character is >= 'a' and <= 'z' or >= '0' and <= '9' or '-');
Lines changed: 78 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,78 @@
1+
---
2+
id: code-run-csharp
3+
name: Code run csharp
4+
aliases: ["c#","cs","csharp","cs-run"]
5+
icon: code-run-csharp
6+
kind: playbook
7+
description: Solve algorithmic, computational and complex automation tasks with C# through cs_run when available; may change files or external data only within the user's authorized scope, with risk, duration and encoding checks.
8+
parameters: {"type":"object","properties":{"task":{"type":"string","description":"The calculation or automation goal"},"paths":{"type":"array","items":{"type":"string"},"maxItems":200,"description":"Input or output paths provided by the user"}},"additionalProperties":false}
9+
tools: ["tool_search","cs_run","process_run","read_text_file","get_file_info","list_directory","write_file","create_directory","ask_user"]
10+
---
11+
12+
The user's instructions take precedence. Follow repository instructions and use ordinary
13+
permission-checked tools; this playbook grants no access. Report in the user's language.
14+
Use C# for algorithms, graph search, optimization, exact arithmetic, simulations, hypothesis
15+
checks and complex data transformations when a script improves reliability. Prefer a dedicated
16+
tool for simple operations. A normal C# development request does not require executing a script.
17+
18+
1. Establish the goal, input, output and authorized changes from the message and parameters.
19+
Check available tools; discover `cs_run` through `tool_search` when necessary. It is an optional
20+
external tool and may not be installed or connected. Source files or a .NET runtime do not prove
21+
availability. Read the actual tool description and schema, including its host OS and limits.
22+
If unavailable, explain briefly and continue with a suitable available tool or runtime through
23+
`process_run`; do not install or connect a server automatically. Report a concrete blocker if
24+
no available mechanism can complete the task.
25+
2. Select an algorithm and estimate time, memory and output size. Pass data through `arguments`
26+
(`Args`) or `globals` (`Globals`, a read-only dictionary of `JsonElement`), rather than injecting
27+
user text into source code. Use top-level C# statements and optional `using` directives; no
28+
`Program` or `Main` is needed. A final expression without a semicolon is the return value.
29+
Each call is independent. Use `BigInteger` for exact large integers, `decimal` when exact decimal
30+
arithmetic is needed, explicit tolerances for numerical methods and a seed for reproducible
31+
simulations. Additional `imports` are namespaces; `references` are resolvable assembly names or
32+
DLL paths, not NuGet package names. Never assume automatic package installation.
33+
3. Assess real risks before execution: deletion, overwrite, moves, database/network mutations,
34+
resource exhaustion and side effects of invoked programs. `cs_run` runs in the server process,
35+
not a sandbox; its working directory does not restrict access. Client files may not exist on
36+
the server. Resolve and verify full source/destination paths, empty inputs, existing outputs,
37+
symlinks/junctions and source/destination overlap. Before recursive deletion or moves verify
38+
the final target is inside the intended authorized area, not an accidental root, home or whole
39+
working tree. Preview targets or use a dry run where supported. Preserve important originals
40+
or write and verify a separate output before replacement. For read-only calculations, check
41+
resource bounds without introducing a blanket approval step. Existing authorization stands;
42+
prepare concrete targets and ask only for missing authorization for irreversible actions
43+
outside the request. Declined stops that action; unresolved approval never authorizes it.
44+
4. Plan duration before starting. Work can take hours and exceed both tool and client timeouts.
45+
The known cs_run contract accepts `timeoutMs` from 1 to 120000, default 120000; the current
46+
schema wins. Never pass a value above its maximum. For long work, use bounded batches with
47+
persisted checkpoints and resumable progress, or a genuinely available managed long-running
48+
job/session with status, logs, cancellation and a final result. Moving to `process_run` alone
49+
does not remove its timeout. If no suitable mechanism exists, explain the limit and prepare a
50+
reproducible script without claiming it ran. Do not leave background Tasks in the server or
51+
bypass timeouts. Bound loops with a local deadline (for example `Stopwatch`) and pass local
52+
cancellation tokens to cooperative I/O. Arbitrary C# is not guaranteed to stop on timeout;
53+
use a controlled separate process if hard termination or isolation is required. Check actual
54+
state before retrying timed-out work, especially mutations.
55+
5. Preserve encoding. JSON code, Args and Globals are Unicode strings; ordinary Console output
56+
is captured as text. Changing the server's global Console encoding is unnecessary and does not
57+
repair incorrectly decoded input. For byte streams and files choose an explicit encoding;
58+
default new text artifacts to UTF-8 without BOM unless the consumer requires another format.
59+
Respect existing BOM, encoding and line endings; missing BOM does not establish UTF-8. Use
60+
strict decoding when corruption matters rather than silently persisting replacement characters.
61+
For child programs separately agree stdin/stdout/stderr encodings before launch. Distinguish
62+
encoding from culture; use explicit numeric/date formats or InvariantCulture for machine data.
63+
Check a short non-ASCII round trip when its preservation is important. Avoid logging secrets.
64+
6. Run the self-contained script with a verified server-side absolute `workingDirectory` when
65+
needed. In the known implementation, a missing directory can leave the previous directory
66+
unchanged, so verify existence. Return compact structured data with `JsonSerializer.Serialize`:
67+
`returnValue` and `variables` are textual renderings, not automatically JSON objects. Known
68+
limits are 262144 code characters, 32768 characters per output stream, 4096 per value and 64
69+
returned variables. Save large authorized results to a file, verify it and ensure the user can
70+
access it if the server is remote. Avoid modifying server global state, Environment.Exit and
71+
unjoined background work. Run operations sharing process state sequentially.
72+
7. Inspect `success`, `diagnostics`, `error`, `timedOut`, `truncated`, stdout and stderr. Fix
73+
compilation problems from diagnostics. Before retrying runtime failures inspect partial side
74+
effects: restoration of working directory/environment/console does not roll back files or
75+
remote data. Validate a known small case, invariant, independent calculation or error bound;
76+
for batches verify the full expected range was completed. Do not accept a truncated answer as
77+
complete. The final answer contains the computed result, verification and material accuracy or
78+
completion limits; for large artifacts include their accessible location and a useful summary.
Lines changed: 105 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,105 @@
1+
---
2+
id: code-run-shell
3+
name: Code run shell
4+
aliases: ["shell","cli","powershell","pwsh","process-run"]
5+
icon: code-run-shell
6+
kind: playbook
7+
description: Run programs and shell commands through process_run on Windows, Linux or macOS, including PowerShell; may change files or external data only within the user's authorized scope, with risk, duration and encoding checks.
8+
parameters: {"type":"object","properties":{"task":{"type":"string","description":"The command or automation goal"},"shell":{"type":"string","description":"Shell explicitly chosen by the user"},"workingDirectory":{"type":"string","description":"Working directory provided by the user"}},"additionalProperties":false}
9+
tools: ["tool_search","process_run","read_text_file","get_file_info","list_directory","write_file","create_directory","ask_user"]
10+
---
11+
12+
The user's instructions take precedence. Follow repository instructions and use ordinary
13+
permission-checked tools; this playbook grants no access. Report in the user's language.
14+
Prefer a direct executable and argv array. Use a shell for its built-ins, pipelines, redirection
15+
or scripts, and a dedicated tool when it better serves the task.
16+
17+
1. Establish the goal, inputs and authorized side effects. Check `process_run` availability,
18+
discovering it through `tool_search` if needed, and read its current description/schema.
19+
If unavailable, briefly explain and use another available executor; do not install/connect
20+
tools automatically. Identify the server OS, not the client's OS, and verify executable paths,
21+
shell availability/version and working directory with permitted read-only checks.
22+
2. Use `executable`, string-array `arguments`, verified `workingDirectory` and supported
23+
`timeoutMs`. In the known contract, a bare executable name is resolved through PATH even with
24+
a working directory; use an absolute path or `./name` for a file in that directory. Each array
25+
element is one argv entry: do not wrap a path in extra quotes just because it contains spaces.
26+
There is no implicit shell, glob or variable expansion; `*`, `~`, `$VAR`, `%VAR%`, pipes and
27+
redirects are literal arguments unless a shell explicitly parses them. Stdin is closed at
28+
launch: use noninteractive modes and supported input files, not interactive prompts. Known
29+
parameters do not include stdin, environment, encoding, background mode or session polling;
30+
do not invent them. The actual schema wins.
31+
3. Choose the shell explicitly when required:
32+
- Windows PowerShell 7: `pwsh` with `-NoLogo`, `-NoProfile`, `-NonInteractive`, `-Command`,
33+
then one string of PowerShell code; or use `-File` for a verified .ps1 file.
34+
- Windows PowerShell 5.1: `powershell.exe` with the same switches, but use syntax and encoding
35+
supported by that version. PowerShell 7 is not guaranteed to be installed.
36+
- Windows cmd: `cmd.exe` with `/d`, `/s`, `/c`, then cmd code for cmd built-ins or .cmd/.bat
37+
files. Respect cmd-specific quoting and percent expansion.
38+
- Linux/macOS POSIX shell: verified `/bin/sh` with `-c`, then POSIX code; avoid Bash extensions.
39+
For Bash-specific code use verified `bash` with `--noprofile`, `--norc`, `-c`, then Bash code.
40+
Do not assume a particular Bash version, especially on macOS. Use zsh only when appropriate
41+
and verified. `pwsh` also works on Linux/macOS when actually installed.
42+
Respect host path syntax, case sensitivity, executable extensions and line endings. Avoid
43+
interactive profiles unless required. On Windows keep recursive filesystem operations in one
44+
shell, using PowerShell -LiteralPath where applicable; do not enumerate there and delete via cmd.
45+
4. For complex PowerShell use a .ps1 with `param(...)`, `-File` and values as separate arguments.
46+
Example argv: `["-NoLogo","-NoProfile","-NonInteractive","-File","C:\\work\\job.ps1",
47+
"-InputPath","C:\\work\\данные.json"]`; first verify those actual paths or use the host's paths.
48+
`-Command` receives code to be parsed: an argv array does not protect interpolated data inside
49+
that code. For POSIX shell pass data as positional arguments: `sh -c '<code using "$1">'
50+
task '<value>'`. Use `--` for values beginning with '-' only when the program supports it.
51+
JSON escaping is not shell escaping. PowerShell -EncodedCommand is Base64 of UTF-16LE code,
52+
not protection against injection or an output-encoding setting. Do not automatically bypass
53+
ExecutionPolicy. For scripts requiring stop-on-error set `$ErrorActionPreference = 'Stop'`;
54+
check `$LASTEXITCODE` immediately after important native programs and propagate an appropriate
55+
`exit` code. Nonterminating PowerShell errors and native program failures need separate checks.
56+
5. Assess deletion, overwrite, moves, database/network changes and disk exhaustion before launch.
57+
The working directory is not a sandbox. Verify full targets, empty inputs, source/destination
58+
overlap, existing outputs and symlinks/junctions. Before recursive deletion/moves confirm the
59+
final path is within the intended authorized area, not an accidental root, home or entire
60+
working tree. Preview targets or use dry-run/-WhatIf where supported; preserve important
61+
originals or write and verify a new output before replacement. Inspect the entire command:
62+
redirection can truncate a file before the program succeeds. Do not add blanket approval for
63+
ordinary reads or already authorized changes. Prepare concrete targets and ask only for missing
64+
authorization for irreversible actions outside the request. Declined stops that action;
65+
unresolved approval does not authorize it. Process termination does not undo partial changes.
66+
6. Estimate duration: builds, data processing and automation may take hours. Check tool/client
67+
limits and whether a genuine managed long-running execution mechanism exists. The known
68+
`timeoutMs` range is 1–120000, default 120000; timeout/cancellation terminates the process tree.
69+
Do not exceed the schema. If insufficient, use safely separable batches/stages with checkpoints,
70+
or an available managed job/session/queue with identifier, status, logs, cancellation and final
71+
result. Do not split atomic operations in ways that damage integrity. Change a timeout setting
72+
only when actually supported and authorized. If no suitable mechanism exists, explain the
73+
limit and prepare a reproducible script without claiming completion. Do not bypass limits with
74+
nohup, &, detached processes or Start-Process: children may be terminated and launch does not
75+
prove completion. When a supported workflow needs Start-Process on Windows, use -WindowStyle
76+
Hidden unless a visible interactive window is explicitly needed. After timeout inspect actual
77+
status, partial artifacts and logs before retrying safely resumable work.
78+
7. Agree encodings for input files, stdout/stderr and artifacts. JSON argv is Unicode, but child
79+
byte streams and files may use UTF-8, OEM/ANSI or UTF-16. Prefer explicit UTF-8 modes when the
80+
program supports them; agree with the tool's decoder rather than assuming UTF-8. If the decoder
81+
cannot be configured, capture raw output to a file using byte-preserving means and read it
82+
with a known encoding through an available file tool or controlled decoder. Do not repair text
83+
after replacement characters have lost information. Check a short Cyrillic/non-ASCII example
84+
when important. Preserve existing encoding, BOM and line endings; default new text to UTF-8
85+
without BOM unless the consumer needs another format. Do not expose secrets in argv or logs.
86+
- PowerShell 7 usually writes UTF-8 without BOM; Windows PowerShell 5.1 defaults vary by cmdlet,
87+
and Out-File/> commonly write UTF-16LE. Specify -Encoding with a value supported by the version.
88+
For .ps1 with non-ASCII under 5.1 use UTF-8 with BOM or another correctly readable encoding.
89+
Use .NET file APIs when an exact byte format is needed.
90+
- `[Console]::OutputEncoding` governs console output; `$OutputEncoding` governs text sent to
91+
native programs through pipelines. Set them locally only as needed and agree with decoding.
92+
Neither `chcp 65001` nor a PowerShell encoding assignment forces every native program to
93+
emit UTF-8. Avoid `cmd /u` unless UTF-16 output from cmd built-ins matches the decoder.
94+
- On Linux/macOS verify an available UTF-8 locale rather than assuming C.UTF-8 exists. The known
95+
runner restricts inherited environment variables; do not assume LANG or arbitrary credentials
96+
survive. Use a supported program/wrapper mechanism for required environment, without changing
97+
the server globally. Locale also affects dates, decimal separators and sorting; use explicit
98+
machine formats when needed.
99+
8. Inspect `exitCode`, `error`, `timedOut`, `truncated`, stdout and stderr. A nonzero code depends on
100+
the program's contract (for example a search with no matches); absence of stderr is not proof of
101+
success. Known capture is limited to 32768 characters per stream; save complete authorized logs
102+
through program options or an explicit shell redirect with a correct encoding. Verify the final
103+
artifacts and intended postconditions. Before retrying failures inspect partial side effects.
104+
The final answer contains the requested command result or accessible artifacts, actual checks
105+
and any unresolved duration, encoding or completeness limits. A running job is not a passed run.

‎src/AI.Server/Skills/BuiltIn/skill-create/SKILL.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,7 @@ Skill conventions:
2626
activity, timer, alarm, calendar-check, repeat, history, palette, brush, pen-tool, crop, camera,
2727
video, microphone, headphones, music, map, git-rebase, git-rebase-auto, git-merge-auto, code-plan,
2828
code-explain, code-refactor, code-tests-add, code-build-fix, code-review, code-performance-optimize,
29-
code-dependencies-update, code-security-review, code-docs-update, devops-ci-create, devops-ci-fix,
29+
code-dependencies-update, code-security-review, code-docs-update, code-run-csharp, code-run-shell, devops-ci-create, devops-ci-fix,
3030
devops-container-create, devops-compose-configure, devops-config-review, devops-release-prepare,
3131
devops-deploy, devops-rollback, devops-incident-diagnose, devops-observability-configure,
3232
devops-infrastructure-change, devops-backup-verify, qa-plan, qa-acceptance-define, qa-cases-create,

0 commit comments

Comments
 (0)