Repository navigation
fix: reject malformed agent identity YAML - #534
Conversation
Validation and consumer evaluation at current head
The remaining ordering gate is the active v2.0.0 publication run https://github.com/devantler-tech/agent-plugins/actions/runs/37398681434. Its release commit must remain current main until publication and independent tag/release readback finish. After that, I will rebind this head, base, ownership and readiness before promotion and normal protected merge. |
devantler
left a comment
There was a problem hiding this comment.
🤖 Generated by the Agentic Engineer
Self-review (fallback — CodeRabbit, Codex and Cursor Bugbot unavailable)
Reviewed commit: 4d65e56
- CodeRabbit: the authenticated included-plan summary at 2026-10-06 00:38:12 UTC says one included review per hour and zero remain. The same organization's capacity refusal at 00:39:15 UTC states a 54-minute recovery window ending 01:33:15 UTC. Sources: devantler-tech/agent-skills#263 (comment) and devantler-tech/agent-skills#264 (comment); organization-capacity scope is also shown at devantler-tech/agent-skills#264 (comment). Freshly re-read during this round; no quota retry or paid overage.
- Codex: account code-review usage exhausted at 2026-10-06 00:30:33 UTC, with no stated reset. Source: #533 (comment). Freshly re-read; recovery requires restored account capacity.
- Cursor Bugbot: authenticated user/team usage or spend limit at 2026-10-05 23:26:22 UTC, with no stated reset. Source: devantler-tech/monorepo#3854 (comment). Freshly re-read; recovery requires an administrator to restore account capacity.
I reviewed the complete current diff against 72f0f4c and the shared frontmatter observer's production callers. Plain identity parsing now refuses reserved leading YAML indicators and mapping separators while preserving permitted interior punctuation, quoted scalars and Unicode scalar content. ASCII YAML separation remains distinct from the nonblank-text observer, so a non-ASCII space cannot silently turn a supported scalar into syntax.
Block headers allow one nonzero indentation indicator and one chomping indicator in either order. The body observer enforces explicit or inferred indentation, tracks oversized leading blanks, permits tabs only after usable indentation, and cannot resume a scalar after a dedented comment. Duplicate keys, closed-header observation and direct provenance-key checks remain enforced. This is a minimum identity/provenance observer, not a general YAML decoder or a substitute for the specification validator.
The actual complete package gate at this current head passes the expanded name/description matrix and healthy current package. Negative cases require the identity field's own diagnostic; healthy controls include plain, quoted, literal, folded, Unicode, blank and valid tab layouts. The complete 433-case manifest suite and 49 bundled-edit cases passed, and an independent YAML parser agreed with the actual gate across 38 boundary cases. The signed native base refresh has exactly the same tree as this session's signed integration candidate; it introduces no extra code.
Direct current-PR review objects, conversation and complete threads were read; no findings or competing human work were observed. Native checks expose no Bugbot verdict. This review records source review only: required CI and marketplace publication must finish before promotion/merge.
Verdict: no P0/P1 findings
No other actionable findings.
Ready for normal protected merge at The actual package gate was exercised at this head: malformed plain/block identities are refused with the tested field's diagnostic, while supported plain, quoted, literal, folded and Unicode controls and the healthy package pass. The complete package-boundary regression suite, 433 manifest cases, 49 bundled-edit controls and independent 38-case YAML/parser comparison pass. Fresh native exact-head CI is settled: 44 successes and two expected automation skips, including the required aggregate and configured quality/scanning checks. Current-head substantive fallback review passes the exact-head checker. Complete direct comment, review and thread reads show no findings or maintainer blocker. The completed signed native base refresh was independently inspected and matches the session's signed integration candidate; no competing human work was observed. GitHub reports The ordering gate is now clear: marketplace v2.0.0 has been published at the required main commit, with independent tag/release/canonical-note readback and a fresh tag-pinned actual native installation verifying all 26 skills and 115 supporting files. The PR body contract passes. I will rebind head/base and discussion immediately before promotion and merge. |
Merged through the normal protected path at The complete package-boundary suite was rerun from the actual merge commit and reports zero failures. Malformed plain/block identities, inconsistent indentation and invalid blank/tab/comment layouts are refused; supported identity forms and the healthy package remain usable. This preserves the specification validator's role rather than treating the minimum frontmatter observer as a complete YAML decoder. The merge used successful exact-head required CI and substantive current-head review. Postmerge main CI is separately running; no settled postmerge CI result is claimed. Marketplace v2.0.0 publication and independent tag-pinned consumer verification completed before this merge. |
Why
Package validation can accept malformed agent identities even though a YAML reader refuses them, allowing an unusable agent to ship with a green result.
What
Reject malformed identity declarations before a package passes while retaining supported plain, quoted and multiline identities.
Fixes #531