Skip to content

feat(skills): discover installed pi CLI skills before import - #814

Merged
vastsa merged 10 commits into
vastsa:mainfrom
yuxino:codex/feat-pi-skill-discovery
Sep 24, 2026
Merged

vastsa merged 10 commits into
vastsa:mainfrom
yuxino:codex/feat-pi-skill-discovery

Conversation

@yuxino

@yuxino yuxino commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Skills installed by pi CLI under ~/.pi/agent/npm/node_modules are currently invisible unless users locate and import the package directory manually. This follows the explicit discovery and trust flow requested in #236.

Settings → Skills now lists installed pi npm packages read-only. Users can inspect the source and declared skills, then explicitly Import and enable through a native confirmation. Cancellation leaves the package untouched; successful imports use the existing trusted-plugin path and are marked Already imported. Discovery never executes package code or silently imports it.

pi-skill-discovery-demo.mp4

The recording shows the original happy path at c31b63b; the follow-up regression checks below cover the current revision. It uses the published planning-with-files@3.17.1 package in an isolated desktop profile and pi CLI home. A local model fixture requests the real Skill tool; its arguments and returned document are shown in the application. No live model service is used.

Regression checks cover discovery, cancellation, changed packages during confirmation, duplicate imports, and loading the imported skill in the real runtime. The Skills interaction test also covers retry after failure and refreshing persisted registration after a runtime startup failure. Discovery is verified with 300 hoisted dependencies and an unreadable scope, so unrelated packages cannot hide healthy skills. Build, desktop typecheck, lint, docs checks, and desktop/shared/i18n suites pass.

Scope: globally installed pi npm packages, including scoped package names. This does not scan arbitrary CLI configuration paths, follow symlinked packages, or automatically update imported copies. Imported packages remain manageable in Plugins.

Validation candidate
  • Task commit: e7118c9c648c84b696d1d1f902925aa779b94192
  • Base main: 0111e306c120ad5820688d7608cb37bad8fbcc1f
  • PR integration commit: 7a1309110677661e0aff602619b06ab85dedf5b6; its tree matches the tested task head.
  • Environment: macOS arm64, isolated Electron app/profile; Host compiled from the same worktree.
  • Candidate checks: pnpm check:pr-base; 33 importer/runtime regression tests including the published package; six React/Chromium interaction scenarios with controlled API results. An isolated real Host and plugin child process additionally verified import, disable, re-enable, process restart, uninstall, and re-import.
  • Desktop recording: native consent/import/tool inspection at c31b63b; not a recording of the later failure-path changes.
  • Follow-up checks: desktop build/typecheck, pnpm lint, pnpm docs:check, and the candidate checks above. The initial revision also passed pnpm build:js and desktop/shared/i18n suites.
  • No Rust source or persistence schema changes; no live provider or installed-user-profile test.

Fixes #236

Users can find skills installed by pi CLI without locating hidden npm
package folders. Keep discovery read-only and require native consent
before using the existing trusted import and registration flow.

Cover cancellation, stale consent, duplicate imports, runtime skill
loading, and the reported published package with isolated tests.

fixes vastsa#236
Hoisted npm dependencies and unreadable scope directories must not hide
otherwise valid skill packages. Keep per-package validation while letting
healthy candidates remain discoverable.

An import may be registered before its runtime fails to start. Refresh
host-owned state after errors so the panel does not offer a duplicate
import, and preserve the error and existing Plugins recovery guidance.

Refs vastsa#236
Keep both skill discovery and temporary attachment fork scenarios when
merging the current upstream main. Preserve the original feature commits
and all upstream behavior without rewriting the shared PR history.
Include the current upstream queue admission fix in the skill discovery
candidate so reviewers can validate both changes together. Preserve the
original feature implementation and published branch history.
Keep the shared PR current with upstream main while preserving its
skill discovery contracts and the contributor's commit history.
Validate the combined candidate before updating the existing PR.
Preserve both skill discovery and hosted-search release notes while
bringing the shared PR up to current main without rewriting history.
Include the new WebDAV compatibility work before candidate validation.
Preserve the original PR behavior and both upstream and author history.
Integrate upstream main at 41367a2
without rewriting the shared PR history.

Resolve the ADR index and unreleased notes by preserving entries from
both branches. Keep the original pi CLI skill discovery implementation,
translations, regression coverage, and trust flow unchanged.

Use GitHub's isolated merge preview for non-conflicting files; the
scratch preview commit is not part of this branch's history.
Full build and runtime test suites were not run in this environment.
Merge upstream main b6c10c6
without rewriting the existing PR history. Preserve both the upstream
header-value export and the pi-skill-discovery export.

The remaining files merge automatically. The resolved file passed syntax,
input-blob, duplicate-export and conflict-marker checks. Full build and
runtime tests were not run in this environment.
Preserve both unreleased entries while integrating the current upstream
without rewriting the shared PR history. Supply the skill discovery
strings for the newly added Brazilian Portuguese locale.
@vastsa
vastsa merged commit 88cf631 into vastsa:main Sep 24, 2026
4 checks passed
@vastsa

vastsa commented Sep 25, 2026

Copy link
Copy Markdown
Owner

Please route the import flow through the existing “Import Plugin” path rather than adding a separate skill-package import path. Discovery can remain read-only, but importing/enabling should use the existing plugin import lifecycle.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug] SKILL不显示

2 participants