Commit graph

79 commits

Author SHA1 Message Date
who96
fb02862d44 Refresh local registry for local skill search 2026-03-31 15:20:23 +08:00
who96
f4451aa0ac mcp: keep local skill search lightweight 2026-03-31 15:20:23 +08:00
Dennis-yxchen
ccda314d34 Merge pull request #30 from voidborne-d/fix/fix-skill-already-registered
fix: register_skill_dir returns existing SkillMeta for already-registered skills
2026-03-31 15:01:26 +08:00
Dennis-yxchen
aa16419e46 docs: update register_skill_dir docstring to reflect idempotent return 2026-03-31 14:58:01 +08:00
Dennis-yxchen
90b2ffab6a
Merge pull request #32 from mvonrenteln/fix/pin-litellm-safe-version
fix: pin litellm to <1.82.7 to mitigate PYSEC-2026-2 supply-chain attack
2026-03-30 21:04:23 +08:00
Marc von Renteln
4f61cb2fa1 fix: pin litellm to <1.82.7 to avoid PYSEC-2026-2 supply-chain attack
Versions 1.82.7 and 1.82.8 of litellm were published on March 24, 2026
and contained malicious code that exfiltrated credentials (SSH keys,
cloud credentials, .env files, API keys) to an attacker-controlled domain.

Pin the dependency to >=1.70.0,<1.82.7 in both pyproject.toml and
requirements.txt as a stopgap until litellm can be replaced with direct
provider SDK calls.

See: https://github.com/HKUDS/OpenSpace/issues/31
Ref: PYSEC-2026-2, BerriAI/litellm#24521
2026-03-29 11:16:10 +02:00
chaohuang-ai
11bdf128d9
Update README.md 2026-03-29 10:44:38 +08:00
d 🔹
c8fb895feb fix: register_skill_dir returns existing SkillMeta for already-registered skills
Fixes #29. When a skill is already registered, register_skill_dir()
returned None, which caused fix_skill() to incorrectly report a failure.

Now returns the existing SkillMeta instead of None when the skill_id
is already present in the registry, making register_skill_dir() truly
idempotent as its callers (fix_skill, _auto_register_skill_dirs) expect.
2026-03-28 19:06:42 +00:00
xlrrrr
67125c378d docs: update openclaw setup instructions in host_skills README 2026-03-28 10:53:53 +08:00
xlrrrr
978e8fbc92 docs: update openclaw setup instructions in host_skills README 2026-03-28 10:35:03 +08:00
Dennis-yxchen
800aa6b074
Merge pull request #10 from warren618/fix/evolver-confirmation-parsing
fix(evolver): use word-boundary matching in _parse_confirmation to prevent false positives
2026-03-27 21:37:08 +08:00
warren618
1257f4cfee fix(evolver): use stem-style matching for confirm/reject/skip keywords
Per reviewer feedback: keep strict \byes\b / \bno\b word boundaries to
prevent false positives, but widen confirm/reject/skip to stem-style
\bconfirm\w*\b etc. so common LLM variants like "confirmed", "rejected",
"skipping" still parse correctly instead of falling through to the
default False path.
2026-03-27 13:34:20 +08:00
xlr
e0ce168904 fix: prevent stdio deadlock on Windows 2026-03-27 13:08:32 +08:00
who96
efd020317c docs: apply PR1 dashboard install review fixes 2026-03-27 10:25:52 +08:00
who96
b009cd3027 docs: clarify dashboard install and fallback startup 2026-03-27 10:25:52 +08:00
xlrrrr
687fb05e89 docs: add lightweight clone instructions 2026-03-26 22:43:18 +08:00
warren618
9333eaed42 fix(evolver): use word-boundary matching in _parse_confirmation to prevent false positives 2026-03-26 12:06:11 +08:00
xlrrrr
38b51c8605 feat: re-scan skill dirs on each call 2026-03-26 11:21:48 +08:00
xlrrrr
dd8740e37a feat: re-scan skill dirs on each call 2026-03-26 11:14:54 +08:00
chaohuang-ai
f7007be82c
Update README.md 2026-03-26 01:04:48 +08:00
chaohuang-ai
2193069e97
Update README.md 2026-03-26 01:04:17 +08:00
xlrrrr
4aade50316 fix: rename platform package to platforms 2026-03-26 00:09:50 +08:00
Xu Lingrui
a0b1222403
add Chinese README 2026-03-25 18:23:59 +08:00
xlrrrr
dd34f3041f add Chinese README 2026-03-25 18:22:24 +08:00
xlrrrr
c8bf3f359f initial commit 2026-03-24 20:38:41 +08:00
Xu Lingrui
feda9edcb7
initial commit 2026-03-24 16:28:47 +08:00
Dennis-yxchen
9c6ff02811
initial commit 2026-03-24 16:16:32 +08:00
Xu Lingrui
050c631948
add MIT License 2026-03-24 16:04:55 +08:00
spidercatfly
6ff4861f88 initial commit 2026-03-24 16:03:22 +08:00