feat(workspace): content-based secret detection or a pre-upload file preview for `skill publish`
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 35/100
- Issue type
- Feature
- Clarity
- Mostly clear
- Activity status
- Active
- Tech stack
- typescript
Research direction
Start with packages/opencode/src/altimate/workspace/skill-publish.ts, especially isJunkFile and NEVER_PUBLISH_DIRS, then inspect redactSecrets in src/installation/index.ts for reusable detection patterns. Resolve the scan-versus-confirmation choice and false-positive handling before implementation. Done should prevent unsafe or unreviewed files from being uploaded through both the CLI and TUI paths.
Written by the indexing model from the issue text.
Description
altimate-code skill publish <name> and the TUI "Publish to workspace" action upload every file in the skill directory. The junk filter in packages/opencode/src/altimate/workspace/skill-publish.ts (isJunkFile, NEVER_PUBLISH_DIRS) is a filename blocklist — .env*, .git, private keys and certificates, .npmrc/.netrc, credentials.json, secrets.*, .ssh/.aws/.gnupg/.altimate — so a config.yaml holding a token still ships, and there is no confirmation or file list shown before bytes leave the machine. A published bundle is readable across the workspace and cannot be recalled by deleting the local file.
Options: a content scan for common token shapes (reusing redactSecrets's patterns from src/installation/index.ts) that refuses with the path named; and/or a file-list confirmation in the CLI and a preview in the TUI action picker.
Found during the v0.12.0 release review (CTO and support-engineer personas). Deferred because: needs a design decision on scan-vs-confirm and false-positive handling.
🤖 Generated with Claude Code
- Dominant language
- TypeScript
- Stars
- 815
- Forks
- 135
- Avg merge
- 1d 12h
- Merged PRs (30d)
- 58
Getting set up
Starts the project's dev container in your browser, under your own GitHub account.
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from AltimateAI/altimate-code
-
test: MCP tests fail when the developer's ~/.claude.json has MCP servers (HOME is not sandboxed)Open
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
AltimateAI/altimate-code#1386 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
AltimateAI/altimate-code#1384 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
AltimateAI/altimate-code#1323 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
AltimateAI/altimate-code#1288 ·
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 92/100
AltimateAI/altimate-code#1285 ·
Maintainers usually reply within 1 day
All issues in AltimateAI/altimate-code
Similar issues
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
aiko-chan-ai/DiscordBotClient#380 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
vercel/ai-elements#507 ·
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
Maintainers usually reply within 2 days
-
Difficulty 2/5 Half a day Newbie friendliness 84/100
anaclumos/qa-interns#148 · 1 comment ·
Maintainers usually reply within 1 day