Skip to content

feat(skills): built-in skill catalog with install-on-demand - #842

Merged
jackwener merged 2 commits into
mainfrom
feat/builtin-skill-catalog
Jul 12, 2026
Merged

feat(skills): built-in skill catalog with install-on-demand#842
jackwener merged 2 commits into
mainfrom
feat/builtin-skill-catalog

Conversation

@jackwener

Copy link
Copy Markdown
Member

What

Adds a built-in skill catalog that ships with the app and installs on demand.

  • 内置 = shipped, not installed. The 内置 tab now lists a catalog of built-in skills as cards with an install button (未安装 / 已安装). Clicking 安装 copies that skill's SKILL.md into the workspace's skills/<id>.
  • The Office document skills (docx/xlsx/pptx) are part of the same catalog and are no longer auto-copied into every workspace on startup — they install on demand like everything else.
  • 已安装 now lists every skill actually present in the workspace, regardless of source.

Behavior changes

  • No startup auto-install.ensureBundledOfficeSkills (and its bundledSkillsReady gating) is removed; nothing is written into a workspace until the user installs it.
  • Prompt catalog cap removed.buildSkillsPromptFragment no longer truncates to a fixed 12 skills — the 18k-character budget is the only limit, so enabled skills are no longer silently dropped from the system prompt.

How it's built

  • Source of truth: apps/desktop/resources/bundled-skills/<id>/SKILL.md (reviewable, one dir per skill).
  • apps/desktop/scripts/gen-bundled-skill-catalog.mjs embeds the bodies into bundled-skill-catalog.generated.ts (no runtime dependency on the resources dir, mirroring how the Office skills already embed their bodies). A drift test fails if the generated module and the sources diverge.
  • skills.ts: listBundledSkillCatalog(root) + installBundledSkill(root, id), reusing the existing hardened write path (realpath containment, fail-if-exists, atomic temp+rename). The trusted-bundled-lock check is generalized from the three Office ids to the whole catalog (sourceName: maka-bundled).
  • IPC skills:catalog:list / skills:catalog:install → preload skills.catalog.*ChatViewSkillsModuleMain. New shared type BundledSkillCatalogEntry.

Tests

  • New apps/desktop/src/main/__tests__/bundled-skill-catalog.test.ts: catalog lists all entries with valid front-matter/category; install writes the file + a trusted bundled lock and flips the installed flag; install is idempotent (already_exists); unknown/unsafe ids are rejected; generated module stays in sync with the sources.
  • Main process compiles clean and the touched main-process tests pass (38).

Note

Also makes getVisualSmokeState total over its scenario union — a pre-existingTS2366 unrelated to this change, fixed in passing so the main build is green.

Ship a curated set of built-in skills under the 内置 tab that install into a
workspace on demand (内置 ≠ installed): clicking 安装 copies a skill's SKILL.md
into skills/<id>. The Office document skills join the same catalog instead of
being auto-copied into every workspace on startup.
- resources/bundled-skills/<id>/SKILL.md is the reviewable source; a generator
embeds the bodies into bundled-skill-catalog.generated.ts, guarded by a drift
test so the two never diverge
- skills.ts: listBundledSkillCatalog / installBundledSkill; the trusted
bundled-lock check is generalized across the whole catalog
- remove the fixed 12-skill prompt cap in buildSkillsPromptFragment; the
18k-char budget is the only limit, so enabled skills are no longer silently
dropped from the prompt
- wire skills:catalog:list / skills:catalog:install through preload, ChatView
and the Skills panel; 内置 renders install-on-demand cards and 已安装 lists
every workspace skill
Also make getVisualSmokeState total over its scenario union (pre-existing
TS2366).
@MicroGery

Copy link
Copy Markdown
Contributor
  1. Need resolve conflicts
  2. installedIds.has(id) treats any same-id local/managed skill as the trusted bundled version. Compare bundled provenance and content hash, and expose collisions separately.
  3. Existing Office skills use the legacy maka-officecli lock. Switching to maka-bundled while removing migration will turn valid existing installs into metadata errors. Please preserve or migrate trusted legacy locks without overwriting user edits.
  4. Bundled sources should receive explicit security/provenance review. Several skills install dependencies, move files, or deploy externally. Surface these capabilities clearly and verify declared tools.
  5. The generator should reject symlinked, non-regular, or oversized SKILL.md sources.
  6. Invalid categories currently silently fall back to 效率工具, causing tests to pass with incorrect metadata. Bundled metadata validation should fail instead.
  7. Please add negative tests for same-id collisions, forged/legacy locks, modified bundled content, symlinked sources, and failed-install rollback.
    The install-on-demand direction and hardened write path look good, but the trust and migration boundaries need resolution first.

Resolve conflicts around the skills subsystem after main moved skill
scanning / runtime-state / prompt-fragment helpers into @maka/runtime and
extracted the Skills page into module-pages.
- skills.ts: re-apply the built-in catalog (listBundledSkillCatalog /
installBundledSkill) onto the refactored base; the trusted bundled-lock
check now covers both the Office skills and the reverse-engineered catalog
- the 12-skill prompt cap is already gone upstream (budget-based), so drop the
now-redundant local change
- route the 内置 catalog props through module-pages' SkillsPage
- keep upstream's collision-only skill-slug reveal alongside the new 内置 tab
Verified: desktop typecheck clean; 2371 main-process tests and 116 @maka/ui
tests pass.
@jackwener
jackwener merged commit 68e99e2 into mainJul 12, 2026
3 checks passed
@Astro-Han
Astro-Han deleted the feat/builtin-skill-catalog branch July 14, 2026 05:05
Astro-Han pushed a commit that referenced this pull request Aug 12, 2026
* chore(skills): remove unverified bundled skills
Remove the 29 bundled Skills introduced by #842 whose provenance has not been established. Keep computer-use as the only bundled Skill and regenerate the catalog.
Refs #2669
Generated-by: OpenAI Codex
* chore(skills): guard bundled catalog cleanup
Assert the retained bundled catalog end to end and reject legacy hash entries for missing Skill sources.
Generated-by: OpenAI Codex
* docs(skills): define bundled removal upgrade behavior
Document that catalog removal revokes Maka provenance without deleting or disabling user-owned local copies, and lock the boundary with a Runtime Host regression test.
Generated-by: OpenAI Codex
---------
Co-authored-by: hqhq1025 <1506751656@qq.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@jackwener@MicroGery
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
feat(skills): built-in skill catalog with install-on-demand by jackwener · Pull Request #842 · apache/maka · GitHub
Skip to content

feat(skills): built-in skill catalog with install-on-demand - #842

Merged
jackwener merged 2 commits into
mainfrom
feat/builtin-skill-catalog
Jul 12, 2026
Merged

feat(skills): built-in skill catalog with install-on-demand#842
jackwener merged 2 commits into
mainfrom
feat/builtin-skill-catalog

Conversation

@jackwener

Copy link
Copy Markdown
Member

What

Adds a built-in skill catalog that ships with the app and installs on demand.

  • 内置 = shipped, not installed. The 内置 tab now lists a catalog of built-in skills as cards with an install button (未安装 / 已安装). Clicking 安装 copies that skill's SKILL.md into the workspace's skills/<id>.
  • The Office document skills (docx/xlsx/pptx) are part of the same catalog and are no longer auto-copied into every workspace on startup — they install on demand like everything else.
  • 已安装 now lists every skill actually present in the workspace, regardless of source.

Behavior changes

  • No startup auto-install.ensureBundledOfficeSkills (and its bundledSkillsReady gating) is removed; nothing is written into a workspace until the user installs it.
  • Prompt catalog cap removed.buildSkillsPromptFragment no longer truncates to a fixed 12 skills — the 18k-character budget is the only limit, so enabled skills are no longer silently dropped from the system prompt.

How it's built

  • Source of truth: apps/desktop/resources/bundled-skills/<id>/SKILL.md (reviewable, one dir per skill).
  • apps/desktop/scripts/gen-bundled-skill-catalog.mjs embeds the bodies into bundled-skill-catalog.generated.ts (no runtime dependency on the resources dir, mirroring how the Office skills already embed their bodies). A drift test fails if the generated module and the sources diverge.
  • skills.ts: listBundledSkillCatalog(root) + installBundledSkill(root, id), reusing the existing hardened write path (realpath containment, fail-if-exists, atomic temp+rename). The trusted-bundled-lock check is generalized from the three Office ids to the whole catalog (sourceName: maka-bundled).
  • IPC skills:catalog:list / skills:catalog:install → preload skills.catalog.*ChatViewSkillsModuleMain. New shared type BundledSkillCatalogEntry.

Tests

  • New apps/desktop/src/main/__tests__/bundled-skill-catalog.test.ts: catalog lists all entries with valid front-matter/category; install writes the file + a trusted bundled lock and flips the installed flag; install is idempotent (already_exists); unknown/unsafe ids are rejected; generated module stays in sync with the sources.
  • Main process compiles clean and the touched main-process tests pass (38).

Note

Also makes getVisualSmokeState total over its scenario union — a pre-existingTS2366 unrelated to this change, fixed in passing so the main build is green.

Ship a curated set of built-in skills under the 内置 tab that install into a
workspace on demand (内置 ≠ installed): clicking 安装 copies a skill's SKILL.md
into skills/<id>. The Office document skills join the same catalog instead of
being auto-copied into every workspace on startup.
- resources/bundled-skills/<id>/SKILL.md is the reviewable source; a generator
embeds the bodies into bundled-skill-catalog.generated.ts, guarded by a drift
test so the two never diverge
- skills.ts: listBundledSkillCatalog / installBundledSkill; the trusted
bundled-lock check is generalized across the whole catalog
- remove the fixed 12-skill prompt cap in buildSkillsPromptFragment; the
18k-char budget is the only limit, so enabled skills are no longer silently
dropped from the prompt
- wire skills:catalog:list / skills:catalog:install through preload, ChatView
and the Skills panel; 内置 renders install-on-demand cards and 已安装 lists
every workspace skill
Also make getVisualSmokeState total over its scenario union (pre-existing
TS2366).
@MicroGery

Copy link
Copy Markdown
Contributor
  1. Need resolve conflicts
  2. installedIds.has(id) treats any same-id local/managed skill as the trusted bundled version. Compare bundled provenance and content hash, and expose collisions separately.
  3. Existing Office skills use the legacy maka-officecli lock. Switching to maka-bundled while removing migration will turn valid existing installs into metadata errors. Please preserve or migrate trusted legacy locks without overwriting user edits.
  4. Bundled sources should receive explicit security/provenance review. Several skills install dependencies, move files, or deploy externally. Surface these capabilities clearly and verify declared tools.
  5. The generator should reject symlinked, non-regular, or oversized SKILL.md sources.
  6. Invalid categories currently silently fall back to 效率工具, causing tests to pass with incorrect metadata. Bundled metadata validation should fail instead.
  7. Please add negative tests for same-id collisions, forged/legacy locks, modified bundled content, symlinked sources, and failed-install rollback.
    The install-on-demand direction and hardened write path look good, but the trust and migration boundaries need resolution first.

Resolve conflicts around the skills subsystem after main moved skill
scanning / runtime-state / prompt-fragment helpers into @maka/runtime and
extracted the Skills page into module-pages.
- skills.ts: re-apply the built-in catalog (listBundledSkillCatalog /
installBundledSkill) onto the refactored base; the trusted bundled-lock
check now covers both the Office skills and the reverse-engineered catalog
- the 12-skill prompt cap is already gone upstream (budget-based), so drop the
now-redundant local change
- route the 内置 catalog props through module-pages' SkillsPage
- keep upstream's collision-only skill-slug reveal alongside the new 内置 tab
Verified: desktop typecheck clean; 2371 main-process tests and 116 @maka/ui
tests pass.
@jackwener
jackwener merged commit 68e99e2 into mainJul 12, 2026
3 checks passed
@Astro-Han
Astro-Han deleted the feat/builtin-skill-catalog branch July 14, 2026 05:05
Astro-Han pushed a commit that referenced this pull request Aug 12, 2026
* chore(skills): remove unverified bundled skills
Remove the 29 bundled Skills introduced by #842 whose provenance has not been established. Keep computer-use as the only bundled Skill and regenerate the catalog.
Refs #2669
Generated-by: OpenAI Codex
* chore(skills): guard bundled catalog cleanup
Assert the retained bundled catalog end to end and reject legacy hash entries for missing Skill sources.
Generated-by: OpenAI Codex
* docs(skills): define bundled removal upgrade behavior
Document that catalog removal revokes Maka provenance without deleting or disabling user-owned local copies, and lock the boundary with a Runtime Host regression test.
Generated-by: OpenAI Codex
---------
Co-authored-by: hqhq1025 <1506751656@qq.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@jackwener@MicroGery
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat(skills): built-in skill catalog with install-on-demand by jackwener · Pull Request #842 · apache/maka · GitHub
Skip to content

feat(skills): built-in skill catalog with install-on-demand - #842

Merged
jackwener merged 2 commits into
mainfrom
feat/builtin-skill-catalog
Jul 12, 2026
Merged

feat(skills): built-in skill catalog with install-on-demand#842
jackwener merged 2 commits into
mainfrom
feat/builtin-skill-catalog

Conversation

@jackwener

Copy link
Copy Markdown
Member

What

Adds a built-in skill catalog that ships with the app and installs on demand.

  • 内置 = shipped, not installed. The 内置 tab now lists a catalog of built-in skills as cards with an install button (未安装 / 已安装). Clicking 安装 copies that skill's SKILL.md into the workspace's skills/<id>.
  • The Office document skills (docx/xlsx/pptx) are part of the same catalog and are no longer auto-copied into every workspace on startup — they install on demand like everything else.
  • 已安装 now lists every skill actually present in the workspace, regardless of source.

Behavior changes

  • No startup auto-install.ensureBundledOfficeSkills (and its bundledSkillsReady gating) is removed; nothing is written into a workspace until the user installs it.
  • Prompt catalog cap removed.buildSkillsPromptFragment no longer truncates to a fixed 12 skills — the 18k-character budget is the only limit, so enabled skills are no longer silently dropped from the system prompt.

How it's built

  • Source of truth: apps/desktop/resources/bundled-skills/<id>/SKILL.md (reviewable, one dir per skill).
  • apps/desktop/scripts/gen-bundled-skill-catalog.mjs embeds the bodies into bundled-skill-catalog.generated.ts (no runtime dependency on the resources dir, mirroring how the Office skills already embed their bodies). A drift test fails if the generated module and the sources diverge.
  • skills.ts: listBundledSkillCatalog(root) + installBundledSkill(root, id), reusing the existing hardened write path (realpath containment, fail-if-exists, atomic temp+rename). The trusted-bundled-lock check is generalized from the three Office ids to the whole catalog (sourceName: maka-bundled).
  • IPC skills:catalog:list / skills:catalog:install → preload skills.catalog.*ChatViewSkillsModuleMain. New shared type BundledSkillCatalogEntry.

Tests

  • New apps/desktop/src/main/__tests__/bundled-skill-catalog.test.ts: catalog lists all entries with valid front-matter/category; install writes the file + a trusted bundled lock and flips the installed flag; install is idempotent (already_exists); unknown/unsafe ids are rejected; generated module stays in sync with the sources.
  • Main process compiles clean and the touched main-process tests pass (38).

Note

Also makes getVisualSmokeState total over its scenario union — a pre-existingTS2366 unrelated to this change, fixed in passing so the main build is green.

Ship a curated set of built-in skills under the 内置 tab that install into a
workspace on demand (内置 ≠ installed): clicking 安装 copies a skill's SKILL.md
into skills/<id>. The Office document skills join the same catalog instead of
being auto-copied into every workspace on startup.
- resources/bundled-skills/<id>/SKILL.md is the reviewable source; a generator
embeds the bodies into bundled-skill-catalog.generated.ts, guarded by a drift
test so the two never diverge
- skills.ts: listBundledSkillCatalog / installBundledSkill; the trusted
bundled-lock check is generalized across the whole catalog
- remove the fixed 12-skill prompt cap in buildSkillsPromptFragment; the
18k-char budget is the only limit, so enabled skills are no longer silently
dropped from the prompt
- wire skills:catalog:list / skills:catalog:install through preload, ChatView
and the Skills panel; 内置 renders install-on-demand cards and 已安装 lists
every workspace skill
Also make getVisualSmokeState total over its scenario union (pre-existing
TS2366).
@MicroGery

Copy link
Copy Markdown
Contributor
  1. Need resolve conflicts
  2. installedIds.has(id) treats any same-id local/managed skill as the trusted bundled version. Compare bundled provenance and content hash, and expose collisions separately.
  3. Existing Office skills use the legacy maka-officecli lock. Switching to maka-bundled while removing migration will turn valid existing installs into metadata errors. Please preserve or migrate trusted legacy locks without overwriting user edits.
  4. Bundled sources should receive explicit security/provenance review. Several skills install dependencies, move files, or deploy externally. Surface these capabilities clearly and verify declared tools.
  5. The generator should reject symlinked, non-regular, or oversized SKILL.md sources.
  6. Invalid categories currently silently fall back to 效率工具, causing tests to pass with incorrect metadata. Bundled metadata validation should fail instead.
  7. Please add negative tests for same-id collisions, forged/legacy locks, modified bundled content, symlinked sources, and failed-install rollback.
    The install-on-demand direction and hardened write path look good, but the trust and migration boundaries need resolution first.

Resolve conflicts around the skills subsystem after main moved skill
scanning / runtime-state / prompt-fragment helpers into @maka/runtime and
extracted the Skills page into module-pages.
- skills.ts: re-apply the built-in catalog (listBundledSkillCatalog /
installBundledSkill) onto the refactored base; the trusted bundled-lock
check now covers both the Office skills and the reverse-engineered catalog
- the 12-skill prompt cap is already gone upstream (budget-based), so drop the
now-redundant local change
- route the 内置 catalog props through module-pages' SkillsPage
- keep upstream's collision-only skill-slug reveal alongside the new 内置 tab
Verified: desktop typecheck clean; 2371 main-process tests and 116 @maka/ui
tests pass.
@jackwener
jackwener merged commit 68e99e2 into mainJul 12, 2026
3 checks passed
@Astro-Han
Astro-Han deleted the feat/builtin-skill-catalog branch July 14, 2026 05:05
Astro-Han pushed a commit that referenced this pull request Aug 12, 2026
* chore(skills): remove unverified bundled skills
Remove the 29 bundled Skills introduced by #842 whose provenance has not been established. Keep computer-use as the only bundled Skill and regenerate the catalog.
Refs #2669
Generated-by: OpenAI Codex
* chore(skills): guard bundled catalog cleanup
Assert the retained bundled catalog end to end and reject legacy hash entries for missing Skill sources.
Generated-by: OpenAI Codex
* docs(skills): define bundled removal upgrade behavior
Document that catalog removal revokes Maka provenance without deleting or disabling user-owned local copies, and lock the boundary with a Runtime Host regression test.
Generated-by: OpenAI Codex
---------
Co-authored-by: hqhq1025 <1506751656@qq.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@jackwener@MicroGery
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat(skills): built-in skill catalog with install-on-demand by jackwener · Pull Request #842 · apache/maka · GitHub
Skip to content

feat(skills): built-in skill catalog with install-on-demand - #842

Merged
jackwener merged 2 commits into
mainfrom
feat/builtin-skill-catalog
Jul 12, 2026
Merged

feat(skills): built-in skill catalog with install-on-demand#842
jackwener merged 2 commits into
mainfrom
feat/builtin-skill-catalog

Conversation

@jackwener

Copy link
Copy Markdown
Member

What

Adds a built-in skill catalog that ships with the app and installs on demand.

  • 内置 = shipped, not installed. The 内置 tab now lists a catalog of built-in skills as cards with an install button (未安装 / 已安装). Clicking 安装 copies that skill's SKILL.md into the workspace's skills/<id>.
  • The Office document skills (docx/xlsx/pptx) are part of the same catalog and are no longer auto-copied into every workspace on startup — they install on demand like everything else.
  • 已安装 now lists every skill actually present in the workspace, regardless of source.

Behavior changes

  • No startup auto-install.ensureBundledOfficeSkills (and its bundledSkillsReady gating) is removed; nothing is written into a workspace until the user installs it.
  • Prompt catalog cap removed.buildSkillsPromptFragment no longer truncates to a fixed 12 skills — the 18k-character budget is the only limit, so enabled skills are no longer silently dropped from the system prompt.

How it's built

  • Source of truth: apps/desktop/resources/bundled-skills/<id>/SKILL.md (reviewable, one dir per skill).
  • apps/desktop/scripts/gen-bundled-skill-catalog.mjs embeds the bodies into bundled-skill-catalog.generated.ts (no runtime dependency on the resources dir, mirroring how the Office skills already embed their bodies). A drift test fails if the generated module and the sources diverge.
  • skills.ts: listBundledSkillCatalog(root) + installBundledSkill(root, id), reusing the existing hardened write path (realpath containment, fail-if-exists, atomic temp+rename). The trusted-bundled-lock check is generalized from the three Office ids to the whole catalog (sourceName: maka-bundled).
  • IPC skills:catalog:list / skills:catalog:install → preload skills.catalog.*ChatViewSkillsModuleMain. New shared type BundledSkillCatalogEntry.

Tests

  • New apps/desktop/src/main/__tests__/bundled-skill-catalog.test.ts: catalog lists all entries with valid front-matter/category; install writes the file + a trusted bundled lock and flips the installed flag; install is idempotent (already_exists); unknown/unsafe ids are rejected; generated module stays in sync with the sources.
  • Main process compiles clean and the touched main-process tests pass (38).

Note

Also makes getVisualSmokeState total over its scenario union — a pre-existingTS2366 unrelated to this change, fixed in passing so the main build is green.

Ship a curated set of built-in skills under the 内置 tab that install into a
workspace on demand (内置 ≠ installed): clicking 安装 copies a skill's SKILL.md
into skills/<id>. The Office document skills join the same catalog instead of
being auto-copied into every workspace on startup.
- resources/bundled-skills/<id>/SKILL.md is the reviewable source; a generator
embeds the bodies into bundled-skill-catalog.generated.ts, guarded by a drift
test so the two never diverge
- skills.ts: listBundledSkillCatalog / installBundledSkill; the trusted
bundled-lock check is generalized across the whole catalog
- remove the fixed 12-skill prompt cap in buildSkillsPromptFragment; the
18k-char budget is the only limit, so enabled skills are no longer silently
dropped from the prompt
- wire skills:catalog:list / skills:catalog:install through preload, ChatView
and the Skills panel; 内置 renders install-on-demand cards and 已安装 lists
every workspace skill
Also make getVisualSmokeState total over its scenario union (pre-existing
TS2366).
@MicroGery

Copy link
Copy Markdown
Contributor
  1. Need resolve conflicts
  2. installedIds.has(id) treats any same-id local/managed skill as the trusted bundled version. Compare bundled provenance and content hash, and expose collisions separately.
  3. Existing Office skills use the legacy maka-officecli lock. Switching to maka-bundled while removing migration will turn valid existing installs into metadata errors. Please preserve or migrate trusted legacy locks without overwriting user edits.
  4. Bundled sources should receive explicit security/provenance review. Several skills install dependencies, move files, or deploy externally. Surface these capabilities clearly and verify declared tools.
  5. The generator should reject symlinked, non-regular, or oversized SKILL.md sources.
  6. Invalid categories currently silently fall back to 效率工具, causing tests to pass with incorrect metadata. Bundled metadata validation should fail instead.
  7. Please add negative tests for same-id collisions, forged/legacy locks, modified bundled content, symlinked sources, and failed-install rollback.
    The install-on-demand direction and hardened write path look good, but the trust and migration boundaries need resolution first.

Resolve conflicts around the skills subsystem after main moved skill
scanning / runtime-state / prompt-fragment helpers into @maka/runtime and
extracted the Skills page into module-pages.
- skills.ts: re-apply the built-in catalog (listBundledSkillCatalog /
installBundledSkill) onto the refactored base; the trusted bundled-lock
check now covers both the Office skills and the reverse-engineered catalog
- the 12-skill prompt cap is already gone upstream (budget-based), so drop the
now-redundant local change
- route the 内置 catalog props through module-pages' SkillsPage
- keep upstream's collision-only skill-slug reveal alongside the new 内置 tab
Verified: desktop typecheck clean; 2371 main-process tests and 116 @maka/ui
tests pass.
@jackwener
jackwener merged commit 68e99e2 into mainJul 12, 2026
3 checks passed
@Astro-Han
Astro-Han deleted the feat/builtin-skill-catalog branch July 14, 2026 05:05
Astro-Han pushed a commit that referenced this pull request Aug 12, 2026
* chore(skills): remove unverified bundled skills
Remove the 29 bundled Skills introduced by #842 whose provenance has not been established. Keep computer-use as the only bundled Skill and regenerate the catalog.
Refs #2669
Generated-by: OpenAI Codex
* chore(skills): guard bundled catalog cleanup
Assert the retained bundled catalog end to end and reject legacy hash entries for missing Skill sources.
Generated-by: OpenAI Codex
* docs(skills): define bundled removal upgrade behavior
Document that catalog removal revokes Maka provenance without deleting or disabling user-owned local copies, and lock the boundary with a Runtime Host regression test.
Generated-by: OpenAI Codex
---------
Co-authored-by: hqhq1025 <1506751656@qq.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@jackwener@MicroGery
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' feat(skills): built-in skill catalog with install-on-demand by jackwener · Pull Request #842 · apache/maka · GitHub
Skip to content

feat(skills): built-in skill catalog with install-on-demand - #842

Merged
jackwener merged 2 commits into
mainfrom
feat/builtin-skill-catalog
Jul 12, 2026
Merged

feat(skills): built-in skill catalog with install-on-demand#842
jackwener merged 2 commits into
mainfrom
feat/builtin-skill-catalog

Conversation

@jackwener

Copy link
Copy Markdown
Member

What

Adds a built-in skill catalog that ships with the app and installs on demand.

  • 内置 = shipped, not installed. The 内置 tab now lists a catalog of built-in skills as cards with an install button (未安装 / 已安装). Clicking 安装 copies that skill's SKILL.md into the workspace's skills/<id>.
  • The Office document skills (docx/xlsx/pptx) are part of the same catalog and are no longer auto-copied into every workspace on startup — they install on demand like everything else.
  • 已安装 now lists every skill actually present in the workspace, regardless of source.

Behavior changes

  • No startup auto-install.ensureBundledOfficeSkills (and its bundledSkillsReady gating) is removed; nothing is written into a workspace until the user installs it.
  • Prompt catalog cap removed.buildSkillsPromptFragment no longer truncates to a fixed 12 skills — the 18k-character budget is the only limit, so enabled skills are no longer silently dropped from the system prompt.

How it's built

  • Source of truth: apps/desktop/resources/bundled-skills/<id>/SKILL.md (reviewable, one dir per skill).
  • apps/desktop/scripts/gen-bundled-skill-catalog.mjs embeds the bodies into bundled-skill-catalog.generated.ts (no runtime dependency on the resources dir, mirroring how the Office skills already embed their bodies). A drift test fails if the generated module and the sources diverge.
  • skills.ts: listBundledSkillCatalog(root) + installBundledSkill(root, id), reusing the existing hardened write path (realpath containment, fail-if-exists, atomic temp+rename). The trusted-bundled-lock check is generalized from the three Office ids to the whole catalog (sourceName: maka-bundled).
  • IPC skills:catalog:list / skills:catalog:install → preload skills.catalog.*ChatViewSkillsModuleMain. New shared type BundledSkillCatalogEntry.

Tests

  • New apps/desktop/src/main/__tests__/bundled-skill-catalog.test.ts: catalog lists all entries with valid front-matter/category; install writes the file + a trusted bundled lock and flips the installed flag; install is idempotent (already_exists); unknown/unsafe ids are rejected; generated module stays in sync with the sources.
  • Main process compiles clean and the touched main-process tests pass (38).

Note

Also makes getVisualSmokeState total over its scenario union — a pre-existingTS2366 unrelated to this change, fixed in passing so the main build is green.

Ship a curated set of built-in skills under the 内置 tab that install into a
workspace on demand (内置 ≠ installed): clicking 安装 copies a skill's SKILL.md
into skills/<id>. The Office document skills join the same catalog instead of
being auto-copied into every workspace on startup.
- resources/bundled-skills/<id>/SKILL.md is the reviewable source; a generator
embeds the bodies into bundled-skill-catalog.generated.ts, guarded by a drift
test so the two never diverge
- skills.ts: listBundledSkillCatalog / installBundledSkill; the trusted
bundled-lock check is generalized across the whole catalog
- remove the fixed 12-skill prompt cap in buildSkillsPromptFragment; the
18k-char budget is the only limit, so enabled skills are no longer silently
dropped from the prompt
- wire skills:catalog:list / skills:catalog:install through preload, ChatView
and the Skills panel; 内置 renders install-on-demand cards and 已安装 lists
every workspace skill
Also make getVisualSmokeState total over its scenario union (pre-existing
TS2366).
@MicroGery

Copy link
Copy Markdown
Contributor
  1. Need resolve conflicts
  2. installedIds.has(id) treats any same-id local/managed skill as the trusted bundled version. Compare bundled provenance and content hash, and expose collisions separately.
  3. Existing Office skills use the legacy maka-officecli lock. Switching to maka-bundled while removing migration will turn valid existing installs into metadata errors. Please preserve or migrate trusted legacy locks without overwriting user edits.
  4. Bundled sources should receive explicit security/provenance review. Several skills install dependencies, move files, or deploy externally. Surface these capabilities clearly and verify declared tools.
  5. The generator should reject symlinked, non-regular, or oversized SKILL.md sources.
  6. Invalid categories currently silently fall back to 效率工具, causing tests to pass with incorrect metadata. Bundled metadata validation should fail instead.
  7. Please add negative tests for same-id collisions, forged/legacy locks, modified bundled content, symlinked sources, and failed-install rollback.
    The install-on-demand direction and hardened write path look good, but the trust and migration boundaries need resolution first.

Resolve conflicts around the skills subsystem after main moved skill
scanning / runtime-state / prompt-fragment helpers into @maka/runtime and
extracted the Skills page into module-pages.
- skills.ts: re-apply the built-in catalog (listBundledSkillCatalog /
installBundledSkill) onto the refactored base; the trusted bundled-lock
check now covers both the Office skills and the reverse-engineered catalog
- the 12-skill prompt cap is already gone upstream (budget-based), so drop the
now-redundant local change
- route the 内置 catalog props through module-pages' SkillsPage
- keep upstream's collision-only skill-slug reveal alongside the new 内置 tab
Verified: desktop typecheck clean; 2371 main-process tests and 116 @maka/ui
tests pass.
@jackwener
jackwener merged commit 68e99e2 into mainJul 12, 2026
3 checks passed
@Astro-Han
Astro-Han deleted the feat/builtin-skill-catalog branch July 14, 2026 05:05
Astro-Han pushed a commit that referenced this pull request Aug 12, 2026
* chore(skills): remove unverified bundled skills
Remove the 29 bundled Skills introduced by #842 whose provenance has not been established. Keep computer-use as the only bundled Skill and regenerate the catalog.
Refs #2669
Generated-by: OpenAI Codex
* chore(skills): guard bundled catalog cleanup
Assert the retained bundled catalog end to end and reject legacy hash entries for missing Skill sources.
Generated-by: OpenAI Codex
* docs(skills): define bundled removal upgrade behavior
Document that catalog removal revokes Maka provenance without deleting or disabling user-owned local copies, and lock the boundary with a Runtime Host regression test.
Generated-by: OpenAI Codex
---------
Co-authored-by: hqhq1025 <1506751656@qq.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@jackwener@MicroGery
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat(skills): built-in skill catalog with install-on-demand by jackwener · Pull Request #842 · apache/maka · GitHub
Skip to content

feat(skills): built-in skill catalog with install-on-demand - #842

Merged
jackwener merged 2 commits into
mainfrom
feat/builtin-skill-catalog
Jul 12, 2026
Merged

feat(skills): built-in skill catalog with install-on-demand#842
jackwener merged 2 commits into
mainfrom
feat/builtin-skill-catalog

Conversation

@jackwener

Copy link
Copy Markdown
Member

What

Adds a built-in skill catalog that ships with the app and installs on demand.

  • 内置 = shipped, not installed. The 内置 tab now lists a catalog of built-in skills as cards with an install button (未安装 / 已安装). Clicking 安装 copies that skill's SKILL.md into the workspace's skills/<id>.
  • The Office document skills (docx/xlsx/pptx) are part of the same catalog and are no longer auto-copied into every workspace on startup — they install on demand like everything else.
  • 已安装 now lists every skill actually present in the workspace, regardless of source.

Behavior changes

  • No startup auto-install.ensureBundledOfficeSkills (and its bundledSkillsReady gating) is removed; nothing is written into a workspace until the user installs it.
  • Prompt catalog cap removed.buildSkillsPromptFragment no longer truncates to a fixed 12 skills — the 18k-character budget is the only limit, so enabled skills are no longer silently dropped from the system prompt.

How it's built

  • Source of truth: apps/desktop/resources/bundled-skills/<id>/SKILL.md (reviewable, one dir per skill).
  • apps/desktop/scripts/gen-bundled-skill-catalog.mjs embeds the bodies into bundled-skill-catalog.generated.ts (no runtime dependency on the resources dir, mirroring how the Office skills already embed their bodies). A drift test fails if the generated module and the sources diverge.
  • skills.ts: listBundledSkillCatalog(root) + installBundledSkill(root, id), reusing the existing hardened write path (realpath containment, fail-if-exists, atomic temp+rename). The trusted-bundled-lock check is generalized from the three Office ids to the whole catalog (sourceName: maka-bundled).
  • IPC skills:catalog:list / skills:catalog:install → preload skills.catalog.*ChatViewSkillsModuleMain. New shared type BundledSkillCatalogEntry.

Tests

  • New apps/desktop/src/main/__tests__/bundled-skill-catalog.test.ts: catalog lists all entries with valid front-matter/category; install writes the file + a trusted bundled lock and flips the installed flag; install is idempotent (already_exists); unknown/unsafe ids are rejected; generated module stays in sync with the sources.
  • Main process compiles clean and the touched main-process tests pass (38).

Note

Also makes getVisualSmokeState total over its scenario union — a pre-existingTS2366 unrelated to this change, fixed in passing so the main build is green.

Ship a curated set of built-in skills under the 内置 tab that install into a
workspace on demand (内置 ≠ installed): clicking 安装 copies a skill's SKILL.md
into skills/<id>. The Office document skills join the same catalog instead of
being auto-copied into every workspace on startup.
- resources/bundled-skills/<id>/SKILL.md is the reviewable source; a generator
embeds the bodies into bundled-skill-catalog.generated.ts, guarded by a drift
test so the two never diverge
- skills.ts: listBundledSkillCatalog / installBundledSkill; the trusted
bundled-lock check is generalized across the whole catalog
- remove the fixed 12-skill prompt cap in buildSkillsPromptFragment; the
18k-char budget is the only limit, so enabled skills are no longer silently
dropped from the prompt
- wire skills:catalog:list / skills:catalog:install through preload, ChatView
and the Skills panel; 内置 renders install-on-demand cards and 已安装 lists
every workspace skill
Also make getVisualSmokeState total over its scenario union (pre-existing
TS2366).
@MicroGery

Copy link
Copy Markdown
Contributor
  1. Need resolve conflicts
  2. installedIds.has(id) treats any same-id local/managed skill as the trusted bundled version. Compare bundled provenance and content hash, and expose collisions separately.
  3. Existing Office skills use the legacy maka-officecli lock. Switching to maka-bundled while removing migration will turn valid existing installs into metadata errors. Please preserve or migrate trusted legacy locks without overwriting user edits.
  4. Bundled sources should receive explicit security/provenance review. Several skills install dependencies, move files, or deploy externally. Surface these capabilities clearly and verify declared tools.
  5. The generator should reject symlinked, non-regular, or oversized SKILL.md sources.
  6. Invalid categories currently silently fall back to 效率工具, causing tests to pass with incorrect metadata. Bundled metadata validation should fail instead.
  7. Please add negative tests for same-id collisions, forged/legacy locks, modified bundled content, symlinked sources, and failed-install rollback.
    The install-on-demand direction and hardened write path look good, but the trust and migration boundaries need resolution first.

Resolve conflicts around the skills subsystem after main moved skill
scanning / runtime-state / prompt-fragment helpers into @maka/runtime and
extracted the Skills page into module-pages.
- skills.ts: re-apply the built-in catalog (listBundledSkillCatalog /
installBundledSkill) onto the refactored base; the trusted bundled-lock
check now covers both the Office skills and the reverse-engineered catalog
- the 12-skill prompt cap is already gone upstream (budget-based), so drop the
now-redundant local change
- route the 内置 catalog props through module-pages' SkillsPage
- keep upstream's collision-only skill-slug reveal alongside the new 内置 tab
Verified: desktop typecheck clean; 2371 main-process tests and 116 @maka/ui
tests pass.
@jackwener
jackwener merged commit 68e99e2 into mainJul 12, 2026
3 checks passed
@Astro-Han
Astro-Han deleted the feat/builtin-skill-catalog branch July 14, 2026 05:05
Astro-Han pushed a commit that referenced this pull request Aug 12, 2026
* chore(skills): remove unverified bundled skills
Remove the 29 bundled Skills introduced by #842 whose provenance has not been established. Keep computer-use as the only bundled Skill and regenerate the catalog.
Refs #2669
Generated-by: OpenAI Codex
* chore(skills): guard bundled catalog cleanup
Assert the retained bundled catalog end to end and reject legacy hash entries for missing Skill sources.
Generated-by: OpenAI Codex
* docs(skills): define bundled removal upgrade behavior
Document that catalog removal revokes Maka provenance without deleting or disabling user-owned local copies, and lock the boundary with a Runtime Host regression test.
Generated-by: OpenAI Codex
---------
Co-authored-by: hqhq1025 <1506751656@qq.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@jackwener@MicroGery
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); })(); feat(skills): built-in skill catalog with install-on-demand by jackwener · Pull Request #842 · apache/maka · GitHub
Skip to content

feat(skills): built-in skill catalog with install-on-demand - #842

Merged
jackwener merged 2 commits into
mainfrom
feat/builtin-skill-catalog
Jul 12, 2026
Merged

feat(skills): built-in skill catalog with install-on-demand#842
jackwener merged 2 commits into
mainfrom
feat/builtin-skill-catalog

Conversation

@jackwener

Copy link
Copy Markdown
Member

What

Adds a built-in skill catalog that ships with the app and installs on demand.

  • 内置 = shipped, not installed. The 内置 tab now lists a catalog of built-in skills as cards with an install button (未安装 / 已安装). Clicking 安装 copies that skill's SKILL.md into the workspace's skills/<id>.
  • The Office document skills (docx/xlsx/pptx) are part of the same catalog and are no longer auto-copied into every workspace on startup — they install on demand like everything else.
  • 已安装 now lists every skill actually present in the workspace, regardless of source.

Behavior changes

  • No startup auto-install.ensureBundledOfficeSkills (and its bundledSkillsReady gating) is removed; nothing is written into a workspace until the user installs it.
  • Prompt catalog cap removed.buildSkillsPromptFragment no longer truncates to a fixed 12 skills — the 18k-character budget is the only limit, so enabled skills are no longer silently dropped from the system prompt.

How it's built

  • Source of truth: apps/desktop/resources/bundled-skills/<id>/SKILL.md (reviewable, one dir per skill).
  • apps/desktop/scripts/gen-bundled-skill-catalog.mjs embeds the bodies into bundled-skill-catalog.generated.ts (no runtime dependency on the resources dir, mirroring how the Office skills already embed their bodies). A drift test fails if the generated module and the sources diverge.
  • skills.ts: listBundledSkillCatalog(root) + installBundledSkill(root, id), reusing the existing hardened write path (realpath containment, fail-if-exists, atomic temp+rename). The trusted-bundled-lock check is generalized from the three Office ids to the whole catalog (sourceName: maka-bundled).
  • IPC skills:catalog:list / skills:catalog:install → preload skills.catalog.*ChatViewSkillsModuleMain. New shared type BundledSkillCatalogEntry.

Tests

  • New apps/desktop/src/main/__tests__/bundled-skill-catalog.test.ts: catalog lists all entries with valid front-matter/category; install writes the file + a trusted bundled lock and flips the installed flag; install is idempotent (already_exists); unknown/unsafe ids are rejected; generated module stays in sync with the sources.
  • Main process compiles clean and the touched main-process tests pass (38).

Note

Also makes getVisualSmokeState total over its scenario union — a pre-existingTS2366 unrelated to this change, fixed in passing so the main build is green.

Ship a curated set of built-in skills under the 内置 tab that install into a
workspace on demand (内置 ≠ installed): clicking 安装 copies a skill's SKILL.md
into skills/<id>. The Office document skills join the same catalog instead of
being auto-copied into every workspace on startup.
- resources/bundled-skills/<id>/SKILL.md is the reviewable source; a generator
embeds the bodies into bundled-skill-catalog.generated.ts, guarded by a drift
test so the two never diverge
- skills.ts: listBundledSkillCatalog / installBundledSkill; the trusted
bundled-lock check is generalized across the whole catalog
- remove the fixed 12-skill prompt cap in buildSkillsPromptFragment; the
18k-char budget is the only limit, so enabled skills are no longer silently
dropped from the prompt
- wire skills:catalog:list / skills:catalog:install through preload, ChatView
and the Skills panel; 内置 renders install-on-demand cards and 已安装 lists
every workspace skill
Also make getVisualSmokeState total over its scenario union (pre-existing
TS2366).
@MicroGery

Copy link
Copy Markdown
Contributor
  1. Need resolve conflicts
  2. installedIds.has(id) treats any same-id local/managed skill as the trusted bundled version. Compare bundled provenance and content hash, and expose collisions separately.
  3. Existing Office skills use the legacy maka-officecli lock. Switching to maka-bundled while removing migration will turn valid existing installs into metadata errors. Please preserve or migrate trusted legacy locks without overwriting user edits.
  4. Bundled sources should receive explicit security/provenance review. Several skills install dependencies, move files, or deploy externally. Surface these capabilities clearly and verify declared tools.
  5. The generator should reject symlinked, non-regular, or oversized SKILL.md sources.
  6. Invalid categories currently silently fall back to 效率工具, causing tests to pass with incorrect metadata. Bundled metadata validation should fail instead.
  7. Please add negative tests for same-id collisions, forged/legacy locks, modified bundled content, symlinked sources, and failed-install rollback.
    The install-on-demand direction and hardened write path look good, but the trust and migration boundaries need resolution first.

Resolve conflicts around the skills subsystem after main moved skill
scanning / runtime-state / prompt-fragment helpers into @maka/runtime and
extracted the Skills page into module-pages.
- skills.ts: re-apply the built-in catalog (listBundledSkillCatalog /
installBundledSkill) onto the refactored base; the trusted bundled-lock
check now covers both the Office skills and the reverse-engineered catalog
- the 12-skill prompt cap is already gone upstream (budget-based), so drop the
now-redundant local change
- route the 内置 catalog props through module-pages' SkillsPage
- keep upstream's collision-only skill-slug reveal alongside the new 内置 tab
Verified: desktop typecheck clean; 2371 main-process tests and 116 @maka/ui
tests pass.
@jackwener
jackwener merged commit 68e99e2 into mainJul 12, 2026
3 checks passed
@Astro-Han
Astro-Han deleted the feat/builtin-skill-catalog branch July 14, 2026 05:05
Astro-Han pushed a commit that referenced this pull request Aug 12, 2026
* chore(skills): remove unverified bundled skills
Remove the 29 bundled Skills introduced by #842 whose provenance has not been established. Keep computer-use as the only bundled Skill and regenerate the catalog.
Refs #2669
Generated-by: OpenAI Codex
* chore(skills): guard bundled catalog cleanup
Assert the retained bundled catalog end to end and reject legacy hash entries for missing Skill sources.
Generated-by: OpenAI Codex
* docs(skills): define bundled removal upgrade behavior
Document that catalog removal revokes Maka provenance without deleting or disabling user-owned local copies, and lock the boundary with a Runtime Host regression test.
Generated-by: OpenAI Codex
---------
Co-authored-by: hqhq1025 <1506751656@qq.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@jackwener@MicroGery