Skip to content

fix(yara): match skill install paths case-insensitively in the Bash hook - #1344

Draft
gewenyu99 wants to merge 1 commit into
mainfrom
posthog/fix-yara-glob
Draft

gewenyu99 wants to merge 1 commit into
mainfrom
posthog/fix-yara-glob

Conversation

@gewenyu99

@gewenyu99 gewenyu99 commented Sep 24, 2026 •

Copy link
Copy Markdown
Collaborator

Scope: Bug fix: one-line behavior change. Review.

Problem

The skill scanner finds files to scan with a glob that matches extensions case-sensitively. A file like PAYLOAD.TXT inside an installed skill never matches *.txt, so YARA never reads it. The Bash skill-install hook and scanInstalledSkill both go through this scanner, so both miss it.

Changes

scanSkillFiles passes caseSensitiveMatch: false to fast-glob. Extensions now match in any case, on every filesystem.

Test plan

  • New src/agent/__tests__/skill-case-scan.test.ts builds a real skill directory with SKILL.md and a poisoned PAYLOAD.TXT, then runs the Bash skill-install hook on it. The hook now terminates. Without the fix, the test fails because the file is never scanned.
  • pnpm typecheck, pnpm lint (0 errors), pnpm vitest run (202 files, 3356 tests) and pnpm test:arch pass.

Created with PostHog Desktop

The skill scanner's glob matched extensions case-sensitively, so a file
like PAYLOAD.TXT inside an installed skill was never read or scanned.
The glob now ignores case, and a real-filesystem test covers the Bash
skill-install hook.

Generated-By: PostHog Desktop
Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
@github-actions

Copy link
Copy Markdown

🧙 Wizard CI

Run the Wizard CI and test your changes against wizard-workbench example apps by replying with a GitHub comment using one of the following commands:

Test all apps:

  • /wizard-ci all

Test all apps in a directory:

  • /wizard-ci ai-observability
  • /wizard-ci basic-integration
  • /wizard-ci feature-flags
  • /wizard-ci mcp-analytics
  • /wizard-ci replay-vision
  • /wizard-ci revenue
  • /wizard-ci self-driving
  • /wizard-ci warehouse
  • /wizard-ci warehouse-seeded

Test an individual app:

  • /wizard-ci ai-observability/anthropic
  • /wizard-ci ai-observability/google-adk
  • /wizard-ci ai-observability/groq
Show more apps
  • /wizard-ci ai-observability/manual-capture
  • /wizard-ci ai-observability/openai
  • /wizard-ci ai-observability/openai-agents
  • /wizard-ci ai-observability/opentelemetry
  • /wizard-ci ai-observability/vercel-ai
  • /wizard-ci basic-integration/android
  • /wizard-ci basic-integration/angular
  • /wizard-ci basic-integration/astro
  • /wizard-ci basic-integration/django
  • /wizard-ci basic-integration/fastapi
  • /wizard-ci basic-integration/flask
  • /wizard-ci basic-integration/flutter
  • /wizard-ci basic-integration/javascript-node
  • /wizard-ci basic-integration/javascript-web
  • /wizard-ci basic-integration/laravel
  • /wizard-ci basic-integration/next-js
  • /wizard-ci basic-integration/nuxt
  • /wizard-ci basic-integration/python
  • /wizard-ci basic-integration/rails
  • /wizard-ci basic-integration/react-native
  • /wizard-ci basic-integration/react-router
  • /wizard-ci basic-integration/sveltekit
  • /wizard-ci basic-integration/swift
  • /wizard-ci basic-integration/tanstack-router
  • /wizard-ci basic-integration/tanstack-start
  • /wizard-ci basic-integration/vue
  • /wizard-ci feature-flags/django
  • /wizard-ci feature-flags/next-js
  • /wizard-ci mcp-analytics/custom-dispatcher
  • /wizard-ci mcp-analytics/typescript-sdk
  • /wizard-ci replay-vision/javascript-node
  • /wizard-ci replay-vision/next-js
  • /wizard-ci replay-vision/react-vite
  • /wizard-ci revenue/stripe
  • /wizard-ci self-driving/astro
  • /wizard-ci self-driving/fastapi
  • /wizard-ci self-driving/nuxt
  • /wizard-ci self-driving/react-router
  • /wizard-ci self-driving/sveltekit
  • /wizard-ci warehouse/monorepo-env
  • /wizard-ci warehouse/multi-source-next
  • /wizard-ci warehouse/stripe-node
  • /wizard-ci warehouse/zero-source
  • /wizard-ci warehouse-seeded/next-stripe
  • /wizard-ci warehouse-seeded/next-stripe-declined

Test against a Context Mill branch:

  • /wizard-ci all context-mill:my-branch

Add context-mill:<branch> to any command above to pin the Context Mill branch. It defaults to main.

Results will be posted here when complete.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant