Skip to content

fix: repair authored skill installation and verification safety - #8

Merged
scrimshawlife-ctrl merged 4 commits into
mainfrom
fix/authored-skills-audit
Sep 5, 2026
Merged

scrimshawlife-ctrl merged 4 commits into
mainfrom
fix/authored-skills-audit

Conversation

@scrimshawlife-ctrl

Copy link
Copy Markdown
Contributor

Summary

Repair authored skill installation and upgrade safety: active-profile routing, validated staged activation, output/session preservation, explicit failure status and recoverable interrupted renames. Correct affected recipes, packaging and current-distribution metadata; preserve existing license grants and divergent variants.

Verification

  • Independent review and bounded interruption-recovery re-review passed on this commit.
  • Parent reran PYTHONPATH=src:scripts python -m pytest -q -ra --tb=short -o addopts= tests tests_audit in an isolated Python 3.12 environment.
  • 212 passed, 5 skipped, 20 subtests passed in 32.86s
  • Symlink redirects, private-file exclusions, failed checks, output preservation and real-rename fault injections covered by regression tests.
  • Changed-file syntax/frontmatter, whitespace, added-line security and unchanged license-file checks passed.

Limits

No real profile installation, live provider usage, merge or release. Upgrade transactions are not power-loss/crash-atomic; stop runtime writers while upgrading. Existing customizations outside preserved output are retained in backup rather than automatically merged.

@scrimshawlife-ctrl
scrimshawlife-ctrl requested a review from a team as a code owner September 5, 2026 01:46
@github-actions

github-actions Bot commented Sep 5, 2026

Copy link
Copy Markdown

CC @Zero-State-LLC/partner-agents. Flagged for shared triage.

@prabu-openclaw prabu-openclaw left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment-only (not approving) — same concerns as the sibling Sigil-Forge/NeonGenie PRs:

  1. Relicensing MIT → LicenseRef-Zero-State-Proprietary-1.0 (README, SKILL.md, hyperlex.manifest.yaml, pyproject classifiers) bundled into a PR titled as a safety/audit fix. That's a legal/business decision and should be called out and approved separately from the technical installer changes.
  2. New scripts/install_transaction.py plus a new --rollback path in install.sh that replaces the old cp -a-based rollback with staged install/backup/activate logic, including re-running the hyperlex check+smoke suite on a rollback candidate before restoring it. This touches destructive filesystem paths (replacing a live skill install) and adds a documented non-atomic window during rename recovery. Adversarial tests (test_transaction.py's interrupted-rename matrix, symlink rejection, secrets-not-packaged) look solid and cover the failure modes I'd probe for.

CI is green. Flagging for a human owner of the Hermes install/profile model to sign off on the destructive-path semantics and the relicensing decision before merge — not blocking on a defect I found.

@scrimshawlife-ctrl

Copy link
Copy Markdown
Contributor Author

Licensing-scope clarification for owner review

The pre-PR source already contained the supplied proprietary root license. This PR changes contradictory metadata to match that existing file; it does not edit LICENSE or LICENSE_POLICY, and does not claim to revoke any historical grants. I rechecked the original base and current tracked license bytes:

Owner/legal sign-off on the metadata and distribution intent is still appropriate; this comment is evidence, not human approval. The PR will remain unmerged. Installer follow-up findings are being handled separately where applicable.

@scrimshawlife-ctrl
scrimshawlife-ctrl merged commit aef8064 into main Sep 5, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants