skills add --skill <name> bypasses the metadata.internal gate (--all honors it)
I maintainer di solito rispondono entro 1 giorno
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 3/5
- Tempo stimato
- 1-2 giorni
- Idoneità per principianti
- 68/100
- Tipo di issue
- Bug
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Attiva
- Stack tecnologico
- node.js, typescript
- Ambito
- cli, documentation, tooling
Direzione di ricerca
Start by tracing the npx skills add explicit --skill path and compare its metadata handling with the --all path described in the reproduction. Verify the behavior with the listed commands and ensure an internal skill is refused unless INSTALL_INTERNAL_SKILLS=1 is set. Also update CLAUDE.md:12 so its installation guidance matches the documented behavior in .claude/skills/README.md and the other catalog surfaces.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Summary
#3856 marked the six repo-native skills metadata.internal: true so they stay out of public installs. The gate works on --all. It does not work when a skill is named explicitly with --skill, so all six are still publicly installable today with no flag and no env var.
Reproduction
Run each in an empty directory. Observed today on main at 14b9e2039, installer npx skills add.
| Command | INSTALL_INTERNAL_SKILLS |
Internal six | Total installed |
|---|---|---|---|
npx skills add heygen-com/hyperframes --all |
unset | excluded ✅ | 20 |
npx skills add heygen-com/hyperframes --all |
=1 |
pulled ✅ | 26 |
npx skills add heygen-com/hyperframes --skill changelog-video |
unset | pulled ❌ | 1 |
$ mkdir /tmp/t && cd /tmp/t
$ npx skills add heygen-com/hyperframes --skill changelog-video
● Selected 1 skill: changelog-video
◇ Installed 1 skill
✓ ./.agents/skills/changelog-video
universal: Antigravity, Codex, Cursor, Droid, Gemini CLI +15 more
symlinked: Claude Code
The installed SKILL.md is byte-identical to .claude/skills/changelog-video/SKILL.md on current main, marker included:
metadata:
internal: true
So the registry is serving current content and the flag is present in the payload. The explicit-install path just never checks it.
Expected
.claude/skills/README.md, added in #3856, states the contract:
Each repo-native skill declares
metadata.internal: true, sonpx skills addskips it during normal installs (including--all). This does not change local agent discovery. To explicitly install these skills elsewhere, setINSTALL_INTERNAL_SKILLS=1when running the installer.
An explicit --skill <internal-name> without INSTALL_INTERNAL_SKILLS=1 should refuse, the way --all does. Right now the env var is the documented escape hatch for a door that has no lock.
Why it matters
The explicit path ships the full skill directory, 712K, not just the prompt:
assets/fonts/TT_Norms_Pro_{Medium,Bold,Normal}.woff2
assets/fonts/tt_norms_pro_mono_regular-webfont.woff2
assets/fonts/ABCSolarDisplay-Bold.woff2
assets/bgm.mp3
assets/bg-pattern.mp4
references/{build-spec,script-voice,visualization-registry}.md
references/lexicon.json
examples/master-skeleton.html
scripts/align-captions.mjs
Those are commercial foundry webfonts and house brand assets going out through a public install command. That is the exposure #3856 was closing, and it is still open on this path. Worth a licensing check independent of the fix.
Second, smaller finding
CLAUDE.md:12 still documents the pre-#3856 behavior:
npx skills add heygen-com/hyperframes # interactive picker (terminal only; --all also pulls the 6 repo-internal skills under .claude/skills)
The --all run above disproves that, 20 skills and none of the six. #3856 updated AGENTS.md, README.md, and docs/guides/skills.mdx but not CLAUDE.md. The repo's own "Skill catalog maintenance" section requires these surfaces move in lockstep.
Environment
macOS 15.6, Node via npx, repo at 14b9e2039.
- Lingua principale
- TypeScript
- Stelle
- 54.1k
- Fork
- 4.9k
- Merge medio
- 7h 29m
- PR unite (30g)
- 778
Preparare l'ambiente
Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di heygen-com/hyperframes
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
heygen-com/hyperframes#5027 ·
I maintainer di solito rispondono entro 1 giorno
-
fix(producer): propagate useGpu to HDR layered streaming encoderForse già presa @Monster-GM l’ha presa 1 giorno fa. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 87/100
heygen-com/hyperframes#5002 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
heygen-com/hyperframes#4702 · 1 commento · 1 reazione ·
I maintainer di solito rispondono entro 1 giorno
-
Studio catalog prompt editor has no accessible nameForse già presa @lorenzozanee l’ha presa 12 giorni fa. Apertabug difficulty/easy triage/ready
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
heygen-com/hyperframes#4384 ·
I maintainer di solito rispondono entro 1 giorno
-
lint: validate composition variables declared on supported root elementsForse di nuovo libera Una pull request per questa issue è stata chiusa senza essere unita. Apertabug difficulty/easy triage/ready
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
heygen-com/hyperframes#4383 ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di heygen-com/hyperframes
Issue simili
-
fix(data-lake): wizard source step still previews the local slug, not the server-disambiguated oneApertadata-lake
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
I maintainer di solito rispondono entro 1 giorno
-
enhancement good first issue priority: low size: XS
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
I maintainer di solito rispondono entro 1 giorno
-
Empty label or headline exports the editor hint ("LABEL" / "Headline goes here") into the PNGAperta
Difficoltà 1/5 1-3 ore Idoneità per principianti 88/100
-
Spray wall wizard: Done button on the hold review step sits under the navigation header (iOS)Apertabug ios mobile priority:P1
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 90/100
streamplace/streamplace#1351 ·
I maintainer di solito rispondono entro 2 giorni