Skip to content

feat(ci): check skill packages and content before publishing (2/4) - #127

Draft
miscreantmoogly wants to merge 3 commits into
validate-skills/1-frontmatterfrom
validate-skills/2-package
Draft

miscreantmoogly wants to merge 3 commits into
validate-skills/1-frontmatterfrom
validate-skills/2-package

Conversation

@miscreantmoogly

@miscreantmoogly miscreantmoogly commented Oct 8, 2026 •

Copy link
Copy Markdown

Stacked PR 2 of 4. Based on #126; review and merge in order. This diff shows only this PR's changes.

Description

Adds the rules for what gets published and installed.

Published set. The skill folder minus evals/, .skilleval.yaml, .skilleval.yml, CHANGELOG.md, README.md and images/ (skill-rules/published-files.json).

  • README.md and images/ are documentation for GitHub and the Pages site, and the repo's own upload zip command already leaves README out.
  • Leaving them out means a docs fix isn't a new version that shows customers an update.

For the published files:

  • Limits: at most 100 files, and a zip under 1 MiB less a 64 KiB margin. Warns past 90%.
  • Extensions: must be on the skills/.gitignore allowlist.
    • The check parses that file rather than copying the list, so there's one list.
    • It reads the list from the merge base, so a new extension applies once its .gitignore change merges.
    • .gitignore alone can be bypassed with git add -f.
  • Paths:
    • only letters, digits, ., _ and -;
    • at most 512 characters;
    • no hidden parts;
    • no Windows-reserved names;
    • no part ending in a period;
    • no two paths that differ only in case.
  • No #! files.

Anywhere in the folder, evals/ included:

  • regular files only: no executable bits, symbolic links or submodules;
  • no scripts/ folders;
  • no AWS access key IDs or private keys. The documented example key is allowed.

Content safety:

  • Invisible characters in published text are errors. That covers zero-width characters, bidi controls, a BOM and Unicode tag characters, which can hide instructions from reviewers while the model still reads them.
  • Raw <script>/<iframe>-style HTML, javascript: links and http:// links in published Markdown are warnings.

All 34 skills pass, and these rules add no new warnings.

Type of change

  • Documentation or infrastructure change

Testing

  • 102 unit and integration tests pass, including:
    • real executable bits and symlinks committed to throwaway repos;
    • a PR that adds !*.sh to skills/.gitignore and still fails.
  • There's a new conformance case for each rule. Key-shaped and invisible-character data is stored as base64, so no file contains a literal key.
  • --base-ref origin/main: 34 skills, 0 errors.

@ams-thakkar

Copy link
Copy Markdown
Contributor

Holding this one, and #125 likewise: @aadimch and @miscreantmoogly have each built the same check independently, and the two are not compatible as they stand — most pointedly, metadata.deprecated is specified oppositely (quoted "true" here, unquoted true in #125), and each documents its own form in CONTRIBUTING.md.

I have asked the two of you to agree on which set to keep.

Adds the rules for the published file set, the skill folder minus evals/,
.skilleval.yaml, .skilleval.yml and CHANGELOG.md: at most 100 files and a
zip under 1 MiB less a margin, extensions from the skills/.gitignore
allowlist (read from the merge base), safe and case-distinct paths, no hidden
files and no #! files. Anywhere in the folder: regular files only, no
scripts/ folders, no AWS access key IDs or private keys. Invisible characters
in published text are errors; raw HTML, javascript: and http:// links in
published Markdown are warnings.
…rately

A folder name ending in a newline matched the path pattern, because $ also
matches before a trailing newline. The docs no longer claim that reading the
extension allowlist from the base branch stops a pull request from widening
it: the pull request runs its own copy of the check either way.
README.md is documentation for GitHub and the Pages site, and the repo's own
upload zip command already leaves it out; images/ is only used by READMEs.
Publishing them would make every docs fix a new version that shows
customers an update. Both join evals/, .skilleval.yaml, .skilleval.yml and
CHANGELOG.md in published-files.json.
@miscreantmoogly
miscreantmoogly force-pushed the validate-skills/2-package branch from eecfb34 to da0b80f Compare October 9, 2026 17:35
@miscreantmoogly
miscreantmoogly added this pull request to stack #134 October 9, 2026 20:09

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants