Repository navigation
feat(ci): check skill packages and content before publishing (2/4) - #127
Draft
miscreantmoogly wants to merge 3 commits into
Draft
miscreantmoogly wants to merge 3 commits into
miscreantmoogly wants to merge 3 commits into
Conversation
1 task done
Contributor
|
Holding this one, and #125 likewise: @aadimch and @miscreantmoogly have each built the same check independently, and the two are not compatible as they stand — most pointedly, I have asked the two of you to agree on which set to keep. |
Adds the rules for the published file set, the skill folder minus evals/, .skilleval.yaml, .skilleval.yml and CHANGELOG.md: at most 100 files and a zip under 1 MiB less a margin, extensions from the skills/.gitignore allowlist (read from the merge base), safe and case-distinct paths, no hidden files and no #! files. Anywhere in the folder: regular files only, no scripts/ folders, no AWS access key IDs or private keys. Invisible characters in published text are errors; raw HTML, javascript: and http:// links in published Markdown are warnings.
…rately A folder name ending in a newline matched the path pattern, because $ also matches before a trailing newline. The docs no longer claim that reading the extension allowlist from the base branch stops a pull request from widening it: the pull request runs its own copy of the check either way.
README.md is documentation for GitHub and the Pages site, and the repo's own upload zip command already leaves it out; images/ is only used by READMEs. Publishing them would make every docs fix a new version that shows customers an update. Both join evals/, .skilleval.yaml, .skilleval.yml and CHANGELOG.md in published-files.json.
miscreantmoogly
force-pushed
the
validate-skills/2-package
branch
from
October 9, 2026 17:35
eecfb34 to
da0b80f
Compare
miscreantmoogly
added this pull request to stack #134
October 9, 2026 20:09
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Adds the rules for what gets published and installed.
Published set. The skill folder minus
evals/,.skilleval.yaml,.skilleval.yml,CHANGELOG.md,README.mdandimages/(skill-rules/published-files.json).README.mdandimages/are documentation for GitHub and the Pages site, and the repo's own upload zip command already leaves README out.For the published files:
skills/.gitignoreallowlist..gitignorechange merges..gitignorealone can be bypassed withgit add -f..,_and-;#!files.Anywhere in the folder,
evals/included:scripts/folders;Content safety:
<script>/<iframe>-style HTML,javascript:links andhttp://links in published Markdown are warnings.All 34 skills pass, and these rules add no new warnings.
Type of change
Testing
!*.shtoskills/.gitignoreand still fails.--base-ref origin/main: 34 skills, 0 errors.