Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

feat(workspace): content-based secret detection or a pre-upload file preview for `skill publish`

Open
#1,321 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
35/100
Issue type
Feature
Clarity
Mostly clear
Activity status
Active
Tech stack
typescript
Domain
cli, security

Research direction

Start with packages/opencode/src/altimate/workspace/skill-publish.ts, especially isJunkFile and NEVER_PUBLISH_DIRS, then inspect redactSecrets in src/installation/index.ts for reusable detection patterns. Resolve the scan-versus-confirmation choice and false-positive handling before implementation. Done should prevent unsafe or unreviewed files from being uploaded through both the CLI and TUI paths.

Written by the indexing model from the issue text.

Description

altimate-code skill publish <name> and the TUI "Publish to workspace" action upload every file in the skill directory. The junk filter in packages/opencode/src/altimate/workspace/skill-publish.ts (isJunkFile, NEVER_PUBLISH_DIRS) is a filename blocklist — .env*, .git, private keys and certificates, .npmrc/.netrc, credentials.json, secrets.*, .ssh/.aws/.gnupg/.altimate — so a config.yaml holding a token still ships, and there is no confirmation or file list shown before bytes leave the machine. A published bundle is readable across the workspace and cannot be recalled by deleting the local file.

Options: a content scan for common token shapes (reusing redactSecrets's patterns from src/installation/index.ts) that refuses with the path named; and/or a file-list confirmation in the CLI and a preview in the TUI action picker.

Found during the v0.12.0 release review (CTO and support-engineer personas). Deferred because: needs a design decision on scan-vs-confirm and false-positive handling.

🤖 Generated with Claude Code

https://claude.ai/code/session_012Q51zFUmPg1WwtS5CrGJE6

Dominant language
TypeScript
Stars
815
Forks
135
Avg merge
1d 12h
Merged PRs (30d)
58

Getting set up

Open in Codespaces

Starts the project's dev container in your browser, under your own GitHub account.

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from AltimateAI/altimate-code

All issues in AltimateAI/altimate-code

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.