Commit Graph
22 Commits
Author SHA1 Message Date
can1357 2ad61c7b92 feat(discovery): added Agent Plugins 1.0.0 standard support
- New agent-plugins provider discovers packages with a root plugin.json
  targeting the canonical schema (agent-plugins.org) from marketplace
  installs, --plugin-dir, and configured extension roots; skills/ and
  mcp.json load per spec with closed-schema validation,
  ${PLUGIN_ROOT}/${PLUGIN_DATA} expansion, reserved subprocess
  environment, instance-keyed data dirs, and per-component isolation.
- Package-boundary containment (spec §4.1) is enforced before every
  read via the new contained-path helpers, including skill:// resource
  access from the read tool and bash; plugin skill files must
  realpath-resolve inside the plugin root (skills carry containRoot).
- Legacy claude-plugins/omp-plugins providers yield skills and MCP
  surfaces of standard-targeting roots to the new provider and skip
  fatally invalid packages.
2026-08-07 05:59:52 +02:00
can1357 418076e44a fix: treat escaped quotes inside double-quoted backticks as inner quoting
Bash treats \" inside a backtick substitution nested in double quotes as
a quote delimiter for the inner command; the generic backslash-skip made
isInsideShellQuote report such quoted literals as unquoted, wrongly
expanding internal URLs inside them (Codex P2 review finding).
2026-07-23 22:15:23 +02:00
roboomp 70e92d32a6 fix(tool): expand internal urls inside backtick substitutions
isInsideShellQuote opened an expansion context for $() command
substitution but never tracked legacy backtick substitution, so an
unquoted skill:// (or other supported scheme) nested directly inside a
backtick pair within double quotes kept the outer quote active and was
left literal. Treat an unescaped backtick as an expansion-context
boundary on the same substitution stack, restoring the outer quote when
the pair closes, matching $() behavior including nesting in either
order. Single-quoted and escaped-backtick text stay literal.

Fixes #5645
2026-07-23 19:20:08 +00:00
roboomp ea320d745b fix(bash): resolved nested internal URLs
- Tracked quote context independently inside command substitutions.
- Covered unquoted skill URLs nested under outer double quotes.

Fixes #5535
2026-07-14 22:21:53 +00:00
can1357 a9998ae07b Merge PR #5086: fix(agent): isolate memory root resolution (@roboomp)
# Conflicts:
#	packages/coding-agent/src/internal-urls/memory-protocol.ts
2026-07-14 18:41:54 +02:00
roboomp cf4e510acd fix(tool): resolved bare skill urls to directories
Bare skill:// URLs now resolve to the skill directory for path-only tool operations while read still returns SKILL.md instructions.

Fixes #5087
2026-07-10 15:14:06 +00:00
roboomp f26fffb8e0 fix(agent): isolated memory root resolution
Resolved file-backed memory://root URLs from the calling session cwd before falling back to the global registry.

Passed the caller cwd through bash internal-URL expansion so redirected memory paths cannot pick another live agent root.

Fixes #5079
2026-07-10 14:48:24 +00:00
roboomp 1adc202bf5 fix(coding-agent): preserved literal bash internal URLs
Left unresolved internal URLs unchanged during bash command expansion so quoted literal mentions can execute verbatim.

Skipped expansion for URL tokens embedded inside larger quoted shell text while preserving resolvable path-argument expansion.

Fixes #4737
2026-07-06 18:00:14 +00:00
roboomp ff397cf27a fix(read): kept large artifacts reachable from path-only resolvers
Bash URL expansion and search/grep only need sourcePath; they now request pathOnly resolution so large artifacts stay usable for search/copy workflows while unbounded content materialization stays blocked.

Fixes #4482
2026-07-03 23:17:46 +00:00
djdembeckandcan1357 5e45bee73f refactor: improve path handling with normalization refactor
- Refactor path normalization to combine expandPath and normalizeLocalScheme
- Add validation in utils.ts to reject local:// paths as filesystem paths
- Fix bash-skill-urls regex to handle hyphen-prefixed local:/ patterns
- Add tests for hyphen-prefixed and @local: patterns
2026-04-18 22:41:09 +02:00
djdembeckandcan1357 c7c3d4a82d fix: avoid matching local:/ in filesystem paths
- Add negative lookbehind to regex in bash-skill-urls to prevent matching local:/
  inside paths like /repo/local:/PLAN.md
- Normalize local scheme before expanding paths in path-utils
- Add test cases for both changes
2026-04-18 22:41:09 +02:00
djdembeckandcan1357 91998d326d fix: handle local:/ single-slash URL pattern
Expands the regex pattern to match local:/ (single-slash) URLs in addition to local:// (triple-slash), preventing potential Linux path leaks.

- Add regex patterns for single-quoted, double-quoted, and unquoted local:/ URLs
- Add test coverage for all three quote styles
2026-04-18 22:41:08 +02:00
djdembeckandcan1357 f353873b75 refactor: extract local:// URL normalization to shared utility
Extract duplicate normalizeLocalScheme regex pattern into a shared function in path-utils.ts. Updated interactive-mode.ts, approved-plan.ts, agent-session.ts, bash-skill-urls.ts, and plan-mode-guard.ts to use the shared utility. Also fixed error message formatting (removed extra backslashes).
2026-04-18 22:40:07 +02:00
djdembeckandcan1357 5da806671e fix: prevent local:// URI from creating local: directory on Linux
On Linux, Node's path.normalize() collapses the double slash in
local://PLAN.md to local:/PLAN.md, creating a directory called local:
in the project root instead of routing through the local:// protocol handler.

Defense-in-depth fixes across 5 layers:

1. resolveToCwd() now throws if a path starts with any internal URL
   scheme prefix (local:, agent:, skill:, etc.), preventing all 59
   call sites from treating URIs as relative filesystem paths.

2. resolvePlanPath() now matches on local: prefix (not just local://)
   and normalizes local:/ to local:// before resolution, catching
   all slash variants.

3. Bash URL expansion regex and early-exit checks now also match
   local:/ (single slash), and normalize before resolution.

4. Edit preview/diff functions now gracefully skip internal URL paths
   instead of crashing via the resolveToCwd guard.

5. All startsWith('local://') checks updated to startsWith('local:')
   with normalization in agent-session, interactive-mode, and
   approved-plan modules.

Also adds local: to .gitignore to prevent accidental commits of the
leaked directory.
2026-04-18 22:40:07 +02:00
Miroslav Drbalandcan1357 4e199f93f7 feat: add marketplace plugin system
Add Claude Code-compatible marketplace plugin infrastructure:

- Registry: types, ID helpers, atomic read/write for marketplaces.json
  and installed_plugins.json (Claude Code format with version: 2)
- Fetcher: classifySource (6 ordered rules), parseMarketplaceCatalog,
  fetchMarketplace (local sources; git/http stubs for Phase 2)
- Resolver + Cache: resolvePluginSource with pathIsWithin containment,
  cachePlugin, removeCachedPlugin, cleanOrphanedCache
- MarketplaceManager: orchestrates add/remove/update marketplaces,
  install/uninstall/enable plugins, clearPluginRootsCache on mutation
- CLI: omp plugin marketplace add|remove|update|list,
  omp plugin discover, classifyInstallTarget for name@marketplace
- Discovery: listClaudePluginRoots reads OMP registry alongside
  Claude's, OMP authoritative for duplicate plugin IDs
- Args: --plugin-dir repeatable flag (parsing only, runtime wiring TBD)
- Slash command: /reload-plugins clears fs + roots cache
- Test fixtures and 130 tests across 8 test files
2026-03-30 13:44:53 +02:00
can1357 e31f2ef6f0 refactor: simplified null checks using optional chaining across TypeScript and Rust modules
- Simplified null/empty checks across TypeScript codebase using optional chaining operator (?.) for improved readability.
- Replaced explicit null checks in validation logic with optional chaining in oauth-discovery, gemini-cli, claude, zai, and lsp modules.
- Updated error handling in Rust command invocation to use double question mark operator (??) for cmd_result.
- Consolidated null validation patterns across tools (bash-skill-urls, browser, gemini-image, resolve) and keybindings using optional chaining.
2026-03-26 14:09:14 +01:00
can1357 90f68431bf Fix local URL resolution for bash destinations 2026-02-23 01:51:54 +01:00
can1357 95ecf8ad1a refactor(coding-agent): simplified URL resolution and template formatting
- Removed try-catch wrapper around URL resolution in expandInternalUrls, allowing errors to propagate to caller.
- Simplified template formatting in subagent-user-prompt.md by collapsing context block to single line.
2026-02-22 18:44:50 +01:00
can1357 cd5c9655aa refactor: renamed notes protocol to local
- Renamed the `notes://` protocol to `local://` for better clarity.
- Updated all internal references, prompts, and tool documentation.
- Migrated plan storage paths to use the new `local://` scheme.
2026-02-22 18:05:22 +01:00
can1357 563d6a0ab9 feat(coding-agent): introduced notes:// protocol for session-scoped artifact storage
- Replaced plan:// protocol with notes:// for session-scoped artifact storage and plan finalization.
- Added title parameter to exit_plan_mode tool to enable plan file renaming during approval workflow.
- Implemented NotesProtocolHandler for notes:// URL scheme with path traversal protection and session fallback.
- Added renameApprovedPlanFile function to handle plan artifact finalization with validation and error handling.
- Updated system prompt documentation to reference notes:// protocol and internal URL schemes for artifact access.
2026-02-22 17:41:01 +01:00
can1357 8276390877 refactor(coding-agent): standardized XML tags and RFC 2119 keywords across prompts
- Standardized XML tag naming from snake_case to kebab-case across 50+ prompt files for consistency.
- Replaced imperative language with RFC 2119 keywords (MUST/SHOULD/MAY/MUST NOT) throughout system and tool prompts for clarity.
- Removed artifactsDir parameter from Python executor and simplified environment variable handling to use PI_SESSION_FILE only.
- Renamed read_path.md to read-path.md and updated memory guidance with hierarchy rules and conflict resolution workflow.
- Added noEscape option to bash URL expansion and extracted cwd parameter from leading cd commands for improved path handling.
- Exported NO_PAGER_ENV constant from bash-interactive module for centralized environment variable management.
2026-02-22 17:12:27 +01:00
can1357 ba1e3f8a07 fix(coding-agent): expanded internal url resolution and hardened memory protocol
Fixes #54
Fixes #74
2026-02-18 15:14:21 +01:00