fix(manifest): also block Agent Plugins $schema while skill frontmatter is non-conformant - #1427
Conversation
…er is non-conformant oh-my-pi >= 17.3 routes on the same $schema prefix to a strict provider that rejects any SKILL.md with keys outside the Agent Skills closed set or a non-string allowed-tools; 30 of 33 skills vanished (#1411). #1426 already removed the $schema; this makes the guard require conformant frontmatter too, so the schema cannot return once only the size condition clears. Refs #1411 Claude-Session: https://claude.ai/code/session_0139gs5yWrMWY9Crx17Ci2Zv
PR SummaryCursor Bugbot is generating a summary for commit 5c759ab. Configure here. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5c759ab3fc
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
A regex only caught the block-list spelling; flow lists and null slipped through as conformant. Use the repo's frontmatter parser and check the parsed type. Claude-Session: https://claude.ai/code/session_0139gs5yWrMWY9Crx17Ci2Zv
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: ec2beb9811
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Mirror the strict validator fully (name, description, license, compatibility, metadata, allowed-tools) so the $schema gate cannot pass a skill a strict client would still reject. Claude-Session: https://claude.ai/code/session_0139gs5yWrMWY9Crx17Ci2Zv
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 8f496b0. Configure here.
…mitted package Claude-Session: https://claude.ai/code/session_0139gs5yWrMWY9Crx17Ci2Zv
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 8451ee5545
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
The posture is now that the root plugin.json never carries the Agent Plugins $schema, so the conditional gate and its frontmatter predicate are replaced by a plain assertion. The size ratchet stays. Claude-Session: https://claude.ai/code/session_0139gs5yWrMWY9Crx17Ci2Zv
* fix(ce-commit-push-pr): root PR stacks on the parent PR the user named (EveryInc#1365) * fix(ce-babysit-pr): decode gh output as UTF-8 on Windows (EveryInc#1368) * fix(ce-prototype): cover decisions settled by seeing, not just driving (EveryInc#1369) * perf(tests): cut suite wall time by splitting the largest test file (EveryInc#1370) * fix(tests): stop the cross-model routes test reading the working tree (EveryInc#1371) * fix(ce-doc-review): ask only where a real choice exists, batch the rest (EveryInc#1373) * feat(ce-prototype): add a seeing-mode craft floor and durable storage (EveryInc#1374) * fix(ce-pov): stop the panel guessing the cross-model host argument (EveryInc#1375) * chore(cross-model): pin the Grok peer to 4.6 (EveryInc#1376) * docs(skills): rewrite user skill pages for accuracy and clearer use (EveryInc#1377) * fix(commit): append known plan unit ids to commit subjects (EveryInc#1379) * fix(ce-work): stop sandboxed workers committing in linked worktrees (EveryInc#1382) * fix(ce-doc-review): edit HTML plans in native format (EveryInc#1381) * fix(ce-code-review): cover adversarial after quota or auth no-review (EveryInc#1380) * fix(skills): correct a rejected dispatch instead of spending the fallback (EveryInc#1383) * fix(ce-compound): find Claude sessions started outside the repo root (EveryInc#1378) * ci(windows-native): retry peer-job-runner smoke on ctypes flake (EveryInc#1384) * fix(ce-debug): stop asking at the handoff, stop shipping unoffered work (EveryInc#1385) * docs(solutions): record why skill gates state conditions, not git commands (EveryInc#1386) * fix(skills): drop the residual-findings record file for real sinks (EveryInc#1387) * fix(ce-doc-review): run the cross-model pass when CROSS_MODEL_PEERS is unset (EveryInc#1389) * fix(ce-proof): sync with current Proof v3 contract (EveryInc#1390) * fix(skill-authoring): make goal-first the default when authoring and reviewing skills (EveryInc#1391) * fix(cross-model): let reviews run on Fable and pin model/effort from CE config (EveryInc#1392) * docs(cross-model): point superseded peer benchmarks at the luna/xhigh decision (EveryInc#1393) * fix(cross-model): discover the Codex.app-bundled codex CLI and name the peer-CLI requirement (EveryInc#1395) * feat(cross-model): add cross_model_review_mode checkout egress gate (EveryInc#1396) * fix(ce-compound-refresh): compare knowledge-track learnings against guidance they name (EveryInc#1399) * docs(solutions): capture the named-guidance contradiction-check learning (EveryInc#1400) * fix(ce-compound): prefer the repo's own frontmatter vocabulary over the Rails-era enums (EveryInc#1394) * fix(ce-work): stop asking about branches before starting work (EveryInc#1397) * fix(review): answer covered cases on skill prose with the condition, not a patch (EveryInc#1401) * fix(scratch): fall back to $TMPDIR when /tmp cannot host the scratch root (EveryInc#1398) * feat(ce-skill-work): repo-local skill for authoring, editing, reviewing, and responding to review on skills (EveryInc#1402) * fix(ce-pov): reject non-final peer positions instead of folding them in (EveryInc#1403) * feat(manifest): add Agent Plugins v1.0.0 manifest support (EveryInc#1345) * chore: release main (EveryInc#1354) * fix(ce-work): run cross-model verification on warm checkouts (EveryInc#1404) * fix(ce-skill-work): author for Sol/Fable, not Opus-era procedure (EveryInc#1408) * docs(skill-design): retarget stale learning citations (EveryInc#1409) * fix(ce-setup): support read-only sandboxes (EveryInc#1407) * fix(ce-skill-work): require pointer descriptions (EveryInc#1410) * chore: release main (EveryInc#1405) * fix(ce-work): let a project-defined shipping process override ce-commit-push-pr (EveryInc#1416) * fix(ce-doc-review): state the CROSS_MODEL_PEERS gate as a condition at the gate (EveryInc#1421) * fix(ce-strategy): ground the interview in the repo and share the file safely (EveryInc#1419) * fix(ce-babysit-pr): fall back for private ref 404 (EveryInc#1418) Co-authored-by: Trevin Chow <trevin@trevinchow.com> * fix(ce-commit-push-pr): make medium and large PR descriptions scannable (EveryInc#1422) * chore: release main (EveryInc#1420) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> * fix(ce-plan): make Goal Capsule Objective outcome-shaped with a Means slot (EveryInc#1424) * fix(manifest): drop Agent Plugins $schema so Codex stops truncating skills at 8KB (EveryInc#1426) * fix(manifest): also block Agent Plugins $schema while skill frontmatter is non-conformant (EveryInc#1427) * chore: release main (EveryInc#1425) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> * docs(solutions): capture why the Agent Plugins $schema is a host routing switch (EveryInc#1428) * fix(skills): Make CE portable on no-checkout / shared-workspace hosts (EveryInc#1429) Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: Trevin Chow <tmchow@users.noreply.github.com> * chore: release main (EveryInc#1430) * fix(orca): reconcile fork identity and guards with upstream 3.22.4 Re-pin the fork release identity to 3.22.4-orca.5 (release-as, version literals in the Orca suites), resolve the upstream-currency check against the latest compound-engineering-v* release tag instead of the upstream/main tip (main carries unreleased commits), regenerate the skill-local Orca role-registry bundles, re-anchor the lfg step-8 ordering test to upstream's rewritten Ship step, and compact the ce-simplify-code Orca hook to a conditional pointer so the skill fits Codex's 8000-byte prompt bound (mechanism stays in references/orca-review-dispatch.md, which already owns it). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019PxdaWqiHDDsPPBHdDevQC * ci(orca): fetch upstream release tags for the provenance currency check The check now resolves the latest compound-engineering-v* tag; without tags the CI fallback compared the pin to the upstream/main tip, which fails whenever upstream carries unreleased commits. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019PxdaWqiHDDsPPBHdDevQC * ci: pin bun to 1.3.14 bun 1.4.0 (picked up by bun-version: latest on 2026-08-21) hangs the subprocess-heavy suites on Linux runners: ce-pov and cross-model tests hit their 5s/20s caps and the profile-lock contention test times out, inflating the test job from ~2m to 13m. The same suites pass on 1.3.14 locally and in the last green run (2026-08-19). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019PxdaWqiHDDsPPBHdDevQC --------- Co-authored-by: Trevin Chow <trevin@trevinchow.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Ruslan Kurkebayev <kurkebayev.ruslan@gmail.com> Co-authored-by: cmbish <carter.m.bish@gmail.com> Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: Trevin Chow <tmchow@users.noreply.github.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

Summary
Closes the guard gap behind #1411. The user-visible fix — removing the Agent Plugins
$schemafrom rootplugin.json— already landed in #1426 for the Codex truncation case, and it also restores oh-my-pi: omp 17.3.5 routes on the same$schemaprefix to a strict provider whose frontmatter validator rejects 30 of 33 skills (argument-hint,disable-model-invocation, list-valuedallowed-tools). But #1426's guard only forbade the$schemawhile a skill exceeds Codex's 8 KB bound, so once the size refactor finishes the schema could return and silently re-break omp.Refs #1411 (fixed by #1426 on release; this PR keeps it fixed).
What changed
tests/codex-skill-prompt-budget.test.ts: the$schemainvariant now requires both every skill under 8 KB and everySKILL.mdfrontmatter within the Agent Skills closed field set with a stringallowed-tools(mirrors omp'svalidateAgentSkillFrontmatter/skills-ref). The failure message names each blocking skill and why. A second test pins the predicate against known-rejected (ce-plan,ce-setup,ce-proof) and known-loading (ce-commit,ce-worktree) skills.docs/specs/agent-plugins.md: records the omp finding, flips the "runtime impact unverified" note to proven, and adds the frontmatter condition to the restore criteria.Validation
Re-adding the
$schemalocally fails the test withce-proof: allowed-tools is not a string,ce-plan: unknown key(s): argument-hint, etc. Fullbun run test(3175 pass) andrelease:validateclean.Security Disclosure
No security-relevant changes.
Agent Disclosure
Claude Code · claude-fable-5