Commit graph

17 commits

Author SHA1 Message Date
Dennis-yxchen
64a3076058 fix: pass max_iterations to grounding agent in no-skill execution path
Without this, the no-skill path ignores the resolved max_iterations
and uses whatever default the agent has, instead of the configured
grounding_max_iterations value.

Co-authored-by: wul48527-code <wul48527-code@users.noreply.github.com>
2026-03-31 17:03:00 +08:00
Dennis-yxchen
f845c5f7fb fix(security): harden zip extraction and import_skill against path traversal
- Add resolve() + is_relative_to() check in _extract_zip() to block
  nested traversal entries like nested/../../escape.txt
- Sanitize server-provided skill name in import_skill() to prevent
  directory escape via malicious record metadata
- Add 6 regression tests covering both attack vectors

Closes #17

Co-authored-by: LeftX <xzq-xu@users.noreply.github.com>
2026-03-31 16:23:56 +08:00
xlrrrr
63b01cfcef fix: CLI entry point now respects OPENSPACE_MODEL and OPENSPACE_LLM_* env vars 2026-03-31 15:36:13 +08:00
who96
fb02862d44 Refresh local registry for local skill search 2026-03-31 15:20:23 +08:00
who96
f4451aa0ac mcp: keep local skill search lightweight 2026-03-31 15:20:23 +08:00
Dennis-yxchen
aa16419e46 docs: update register_skill_dir docstring to reflect idempotent return 2026-03-31 14:58:01 +08:00
d 🔹
c8fb895feb fix: register_skill_dir returns existing SkillMeta for already-registered skills
Fixes #29. When a skill is already registered, register_skill_dir()
returned None, which caused fix_skill() to incorrectly report a failure.

Now returns the existing SkillMeta instead of None when the skill_id
is already present in the registry, making register_skill_dir() truly
idempotent as its callers (fix_skill, _auto_register_skill_dirs) expect.
2026-03-28 19:06:42 +00:00
xlrrrr
67125c378d docs: update openclaw setup instructions in host_skills README 2026-03-28 10:53:53 +08:00
xlrrrr
978e8fbc92 docs: update openclaw setup instructions in host_skills README 2026-03-28 10:35:03 +08:00
Dennis-yxchen
800aa6b074
Merge pull request #10 from warren618/fix/evolver-confirmation-parsing
fix(evolver): use word-boundary matching in _parse_confirmation to prevent false positives
2026-03-27 21:37:08 +08:00
warren618
1257f4cfee fix(evolver): use stem-style matching for confirm/reject/skip keywords
Per reviewer feedback: keep strict \byes\b / \bno\b word boundaries to
prevent false positives, but widen confirm/reject/skip to stem-style
\bconfirm\w*\b etc. so common LLM variants like "confirmed", "rejected",
"skipping" still parse correctly instead of falling through to the
default False path.
2026-03-27 13:34:20 +08:00
xlr
e0ce168904 fix: prevent stdio deadlock on Windows 2026-03-27 13:08:32 +08:00
warren618
9333eaed42 fix(evolver): use word-boundary matching in _parse_confirmation to prevent false positives 2026-03-26 12:06:11 +08:00
xlrrrr
38b51c8605 feat: re-scan skill dirs on each call 2026-03-26 11:21:48 +08:00
xlrrrr
dd8740e37a feat: re-scan skill dirs on each call 2026-03-26 11:14:54 +08:00
xlrrrr
4aade50316 fix: rename platform package to platforms 2026-03-26 00:09:50 +08:00
spidercatfly
6ff4861f88 initial commit 2026-03-24 16:03:22 +08:00