Skills Agentes

Pr Publication Safety

Nota interna de seguridad del proyecto no-mistakes. Se usa al cambiar el render del cuerpo del PR, la redacción de rutas de home, la publicación de rutas de artefacto o los marcadores de attestation de pipeline.

Estrellas
8.2k

en todo el repo

Actividad
62

0–100, la ruta de este skill

Actualizado
anteayer

último commit aquí

Commits
2

últimos 90 días

Contexto
1.1k tok

29 tok en reposo

Paquete
1 archivo

4 KB

Instalar

Funciona con cualquier agente que lea SKILL.md

npx -y skills add kunchenguid/no-mistakes --skill pr-publication-safety --agent claude-code

Se instala solo en este repositorio.

Qué hace

  • Nota interna de seguridad sobre la redacción de rutas de home en el contenido publicado del PR: `internal/safepath` es el dueño único, el análogo de rutas de `internal/safeurl`.
  • `RedactText` reescribe el home del proceso más `/home/<user>`, `/Users/<user>` y `C:\Users\<user>` a `~`, incondicionalmente y en cada ocurrencia; las formas nuevas se añaden ahí, no en un call site.
  • `PRStep.buildPRContent` es el único límite de render: dibuja con `draftPRContent` y devuelve `redactPRContent(content)`, cubriendo prosa de agente, intención, findings, resúmenes de fix, errores de paso y rutas de artefacto.
  • El cuerpo del PR debe contener exactamente UN marcador de attestation de pipeline vivo, el del propio run; los agentes de paso incrustan marcadores ajenos de forma rutinaria al capturar cuerpos de PR generados.
  • La neutralización se hace en el punto de ensamblaje (`appendGeneratedSectionsToCleanBodyWithinLimit` más las dos rutas de intención), nunca por ruta de render.

Úsalo cuando

  • Se cambia el render del cuerpo del PR, la redacción de rutas de home, la publicación de rutas de artefacto o los marcadores de attestation de pipeline.

No lo uses cuando

    Qué lo activa

    Di cualquiera de estas frases y el agente debería cargar este skill.

    • Voy a tocar el render del cuerpo del PR en no-mistakes
    • Añade una forma nueva de ruta de home a la redacción
    • Revisa que solo haya un marcador de attestation vivo en el PR

    SKILL.md

    En inglés

    Home-Path Redaction in Published PR Content (security)

    • internal/safepath is the one owner of home-directory redaction, the path analogue of internal/safeurl. RedactText rewrites the process's own home plus /home/<user>, /Users/<user>, and C:\Users\<user> to ~, unconditionally and for every occurrence. Add new shapes there rather than scrubbing paths at a call site. Candidate resolution must stay free of filepath.IsAbs/VolumeName and of any reliance on filepath.Clean's separator normalisation: those answer for the build platform, and on Windows IsAbs discards the POSIX-rooted HOME that Git Bash, MSYS2, and Cygwin set - silently disabling redaction instead of failing. Regression: TestUsableHomeCandidate_AcceptsBothPlatformSpellings, TestHomeCandidates_AreSeparatorSpellingIndependent.
    • PRStep.buildPRContent is the single render boundary: it drafts through draftPRContent and returns redactPRContent(content), and Execute publishes exactly that. Every source that can reach a PR body - agent prose, extracted intent, findings, fix summaries, step errors, artifact path, artifact captions, and captured output embedded from evidence files - is covered there, so a new rendering path cannot reintroduce the leak. Redaction runs after every length cap, which is only safe because the placeholder is never longer than the path it replaces.
    • The artifacts[].path description in testFindingsSchema (common.go) must not solicit absolute paths, and must not forbid them either. The renderer's allowlist is the worktree or the run's evidence directory and a path under neither is dropped, while the evidence directory defaults under the operator's home - so soliciting more just re-supplies what the boundary has to strip, and a blanket "never report a home directory path" clause makes an obedient agent drop its own evidence. Publication safety is the pr.go boundary's job; the schema only stops soliciting paths from elsewhere on the machine. Regressions: TestTestFindingsSchema_DoesNotSolicitAbsolutePaths, TestTestFindingsSchema_KeepsEvidenceDirectoryPathsReportable.
    • Two other public surfaces deliberately do NOT share this rendering and are not covered: agent-authored commit subjects (commitAgentFixes -> Commit.RenderFixMessage), which reach the remote through Push, and the opt-in evidence branch (test.evidence.store_in_repo), which copies artifact files verbatim. Keep the internal/safepath package doc honest about that scope.
    • The PR body must contain exactly ONE live pipeline-attestation marker, the run's own. require-no-mistakes (.github/actions/require-no-mistakes/verify.py) binds the FIRST marker in the RAW body to the PR head, so a foreign copy placed earlier fails a PR the pipeline did produce - and a code fence is no defense, because that scan is raw text. Step agents embed foreign markers routinely, by capturing a generated PR body as evidence.
    • A CI repair that publishes a new head rewrites only that live marker's head_sha in the current PR body (restampPublishedAttestation) and does not send a title. It never inserts a marker that was not already there. Hosts without a PR content reader skip the restamp instead of failing the push. Regressions: TestCIStep_PublishRepairRebindsAttestationAcrossRepairPushes, TestCIStep_PublishRepairDoesNotMintAttestation, TestCIStep_PublishRepairSkipsRestampWithoutReader, TestRestampPRAttestation_PreservesContentEditedWhilePreparingRewrite, TestUpdatePROmitsTitleWhenEmpty.
    • Neutralize at the assembly choke point (appendGeneratedSectionsToCleanBodyWithinLimit plus the two intent paths), never per render path. pipelineMD alone carries the real marker and is left intact; BuildPipelineSummaryFor neutralizes its own step-detail blocks, which quote agent text. A first attempt put this in escapePipelineFoldMarkers - per-render-path - and shipped three live foreign markers to #831 anyway. Regressions: TestPRStep_ForeignAttestationsInEveryComponentDoNotShadowTheRealOne (all components at once), plus the per-component guards in pr_test.go.
    • Regressions: internal/safepath/redact_test.go, internal/pipeline/steps/pr_homepath_test.go.

    Reproducido de kunchenguid/no-mistakes bajo licencia MIT. Leer esta página en markdown.

    Archivos

    1 archivo en el paquete. Solo se lee SKILL.md al activarse — las referencias se cargan si el skill decide que las necesita.

    Detalles

    Categoría
    Seguridad
    Licencia
    MIT
    Recursos incluidos
    Solo SKILL.md
    Código fuente
    Ver SKILL.md

    Más de kunchenguid/no-mistakes

    Este repo incluye 16 skills. Si instalas uno, normalmente ya tienes los demás.

    Valida tus cambios de código por el pipeline de no-mistakes (review de código automatizado, tests, lint, docs, push, PR y CI) antes de que lleguen al destino de push configurado. Se activa con `/no-mistakes`.

    Costo de contexto al activarse
    5.9k tok
    Tamaño del paquete
    1 archivo
    Última actualización
    hace 3 días
    devops infraestructura

    Nota interna del proyecto no-mistakes. Se usa al cambiar la readiness de CI, la recogida de checks del forge, los reruns, los timeouts de CI o la monitorización del ciclo de vida del PR.

    Costo de contexto al activarse
    2.6k tok
    Tamaño del paquete
    1 archivo
    Última actualización
    anteayer
    devops infraestructura

    Nota interna del proyecto no-mistakes. Se usa al cambiar las sesiones de review, las decisiones sobre findings, los timeouts de agente, el comportamiento del Test local o la conformidad con la intención.

    Costo de contexto al activarse
    4.1k tok
    Tamaño del paquete
    1 archivo
    Última actualización
    hace 3 días
    herramientas desarrollo

    Nota interna del proyecto no-mistakes. Se usa al añadir o cambiar tests, el harness e2e, el aislamiento de procesos de test o el sharding de tests en CI.

    Costo de contexto al activarse
    1.1k tok
    Tamaño del paquete
    1 archivo
    Última actualización
    anteayer
    testing qa

    Nota interna del proyecto no-mistakes. Se usa al cambiar la configuración de modelo o esfuerzo de un agente, los mapeos de adaptador o los perfiles de candidato de eval, todo bajo el dueño único `internal/agentcfg`.

    Costo de contexto al activarse
    519 tok
    Tamaño del paquete
    1 archivo
    Última actualización
    hace 3 días
    herramientas desarrollo

    Nota interna del proyecto no-mistakes. Se usa al cambiar la sincronización de la rama local, la recuperación de custodia, el binding del head tras el review, el rebase o la seguridad del force-push, cuyo objetivo es no perder código.

    Costo de contexto al activarse
    2.5k tok
    Tamaño del paquete
    1 archivo
    Última actualización
    hace 3 días
    herramientas desarrollo

    Skills relacionados

    Barreras de seguridad para comandos destructivos (gstack).

    Costo de contexto al activarse
    879 tok
    Tamaño del paquete
    4 archivos
    Última actualización
    hace 15 días
    Permisos
    seguridad

    Cso

    131k

    Modo Chief Security Officer: auditoría de seguridad centrada en infraestructura, con OWASP Top 10, modelado de amenazas STRIDE y verificación activa.

    Costo de contexto al activarse
    19.2k tok
    Tamaño del paquete
    6 archivos
    Última actualización
    hace 12 días
    Permisos
    seguridad

    Guard

    131k

    Modo de máxima seguridad: avisos ante comandos destructivos más restricción de ediciones a un directorio concreto (gstack).

    Costo de contexto al activarse
    850 tok
    Tamaño del paquete
    2 archivos
    Última actualización
    hace 15 días
    Permisos
    seguridad