Repository navigation
feat: expand portable skills into mstack - #1
Merged
Merged
Conversation
3metaJun
commented
Sep 10, 2026
3metaJun
commented
Sep 10, 2026
3metaJun
commented
Sep 10, 2026
3metaJun
commented
Sep 10, 2026
3metaJun
commented
Sep 10, 2026
3metaJun
commented
Sep 10, 2026
3metaJun
commented
Sep 10, 2026
3metaJun
commented
Sep 10, 2026
3metaJun
commented
Sep 10, 2026
3metaJun
commented
Sep 10, 2026
3metaJun
commented
Sep 10, 2026
Owner
Author
Adversarial review — 4 parallel reviewers (security · correctness/test-gaps · provenance & license · docs/consistency)Verdict: fix-before-merge. No security hole found — no command injection or path traversal in the installer/remote path, the secrets scan is clean, and most of the PR description's claims verified under attack. But this review found one watcher hang, two classes of broken shipped instructions, a license-text gap, and several installer data-safety gaps. Detailed findings are in the inline comments; summary below. What checked out clean (verified, not assumed)
Top findings (details inline)
Notable (no good inline anchor)
PR-description claim audit
The design underneath is sound — findings 1–12 are mostly mechanical (renames, path repointing, guarded rollback, a CI job, two license paragraphs). Happy to re-review the fixes. |
This was referenced Sep 11, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The repository previously exposed a smaller portable skill set with a local-only installer. This expands it into mstack: one 50-skill bundle for Codex, Claude Code, OpenCode, and pi, with optional agents, the adapted workflow guide, meta-mode tools, and the source-only Benny automation pack.
The installer now supports named local and SSH environments, per-Harness adapters, atomic staging, locking, backup and rollback. This also adds model-role execution, Harness smoke checks, context auditing and reconciliation, and pinned upstream synchronization with checkout provenance, path containment, stale-file handling, and transformed-baseline manifests.
Verification
npm teston Windows: 50 skills validated, 47/47 tests passed.npm teston WSL Debian: 50 skills validated, 47/47 tests passed;bash -n tools/meta-mode/worktree-audit.shpassed.npm run check-upstream -- --source G:\agents_temp\pstack-read\pstack --strict: 47 pstack skills and all configured artifacts matched pinned commit7366ac1.npm pack --dry-run --json: 199 files, no audit, key, or PEM files.--replace: skill and artifact installation, backup, local environment isolation, lock/stage cleanup, and remote cleanup verified.--replace: installation and same-volume backup verified, then cleaned.claude-haiku-4-5-20251001: nativeSkillinvocation ofmeta-modesucceeded.Agent: GPT-6 via Codex