postinstall installs Ark skills into shared agent directories without separate confirmation
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 48/100
- Tipo di issue
- Bug
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Attiva
- Stack tecnologico
- javascript, node.js
- Ambito
- cli, developer-experience
Direzione di ricerca
Start in scripts/postinstall.js at lines 60, 216, and 344, then review the related consent concern in issue #24. Reproduce an install or update and verify that connecting does not modify every detected agent directory without explicit confirmation or a selected target; document the opt-out and affected paths when applicable.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Summary
Installing or updating @volcengine/ark-cli runs an npm postinstall hook that automatically executes +connect --refresh without a separate user confirmation. The connect flow detects agent environments and installs the full Ark CLI skill bundle into their skill locations. In the observed setup, 25 skills were installed under the shared ~/.agents/skills directory.
Codex subsequently discovered those skills and included their names and descriptions in the <skills_instructions> developer message of later sessions. Package installation therefore changed persistent configuration consumed by another agent harness, with a recurring downstream context payload.
Verified on 1.0.33; the relevant postinstall implementation is byte-identical through 1.0.36, the latest stable release.
Related: #24 reported the same postinstall +connect --refresh behavior on v1.0.23 and raised the opt-in/consent concern.
This issue adds two pieces of follow-up evidence rather than intending to duplicate that report:
- the relevant postinstall implementation was verified on 1.0.33 and is byte-identical through 1.0.36 (latest stable);
- the downstream Codex impact was measured directly from rollout files: 30 affected sessions, 33
<skills_instructions>injections, and 439,579 B attributable to the 25 Ark skill entries.
Happy for maintainers to track the underlying fix under #24 if preferred; the measurements here are intended as additional impact evidence.
Trigger mechanism
At scripts/postinstall.js:344, the hook calls:
execFileSync(binPath, ["+connect", "--refresh"])
The hook skips CI environments (scripts/postinstall.js:216), and ARKCLI_SKIP_POSTINSTALL=1 is available (scripts/postinstall.js:60). The CLI also has a --path capability for a targeted installation, but the automatic connect path does not use it to limit the target agent.
Measured downstream impact
In the September 21–29, 2026 observation window, 30 sessions were affected across 161 rollouts in the relevant statistics scope. There were 33 <skills_instructions> injections: 27 sessions had one and three sessions had two, consistent with a resumed session receiving the metadata again. All 33 injections contained the 25 Ark skill entries.
| Measurement | Observed value |
|---|---|
Complete <skills_instructions> developer message |
22,646–51,365 B per injection |
| Complete message median | 46,970 B |
| Complete messages across 33 injections | 1,511,925 B |
| Ark skill entries attributable median | 13,387 B per injection |
| Ark skill entries attributable total | 439,579 B |
The 25 Ark skill descriptions contain 7,406 characters in one copy. Depending on tokenizer, the attributable payload corresponds roughly to 3.5K–5.5K tokens per injection, or 115K–180K tokens across the 33 observed injections. These token figures are estimates; the byte measurements above are the primary evidence.
No Ark CLI skill invocation was observed in the audited logs (1,929 Antigravity command log entries and 255 Codex rollouts).
Why this behavior is surprising
The user action was to install or update one CLI package. The lifecycle hook also modified persistent skill configuration automatically consumed by other agent harnesses. The scope of that side effect is broader than the package installation makes visible to the user.
In agent harnesses, skill descriptions can become recurring prompt context rather than passive files on disk. This makes the default installation behavior relevant to future sessions even when no Ark CLI skill is invoked.
Reproduction / evidence anchors
Two local Codex rollout anchors from the frozen evidence set illustrate the developer-message payload:
rollout-2026-09-21T23-12-33-*.jsonl:3: complete<skills_instructions>message, 51,109 B.rollout-2026-09-22T03-28-51-*.jsonl:277: complete<skills_instructions>message, 22,646 B.
To inspect this in a Codex rollout, find <skills_instructions>, confirm the record is a response_item with role=developer, identify the Ark skill entries, and measure both the complete message bytes and the bytes attributable to those entries. The private rollout and conversation contents are not included here.
Suggested fixes
- Explicit opt-in or scoped installation. Avoid modifying every detected agent environment by default during
postinstall. For example, prompt the user to runarkcli +connect, request confirmation before the first connect, require selection of a target agent, or use the existing--pathcapability for a scoped installation. - Slim metadata and progressive disclosure. Provide shorter auto-discovery descriptions or a slim skill index, with full descriptions loaded only after a skill is selected.
- Clearer installation disclosure. If automatic connect remains, show the detected agents, modified paths, skill count, opt-out method, and uninstall method in the installation output.
- Lingua principale
- Go
- Stelle
- 139
- Fork
- 15
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Preparare l'ambiente
Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di volcengine/ark-cli
-
[BUG] Responses API:tools 含 web_search 声明时,deepseek 将 function_call_output 误读为用户消息,多轮工具对话可形成死循环Aperta
Difficoltà 4/5 3-5 giorni Idoneità per principianti 45/100
volcengine/ark-cli#26 · 6 commenti ·
-
[UX] postinstall silently injects 25 arkcli skills into every detected AI agent — should be opt-inAperta
Difficoltà 4/5 3-5 giorni Idoneità per principianti 52/100
volcengine/ark-cli#24 · 1 reazione ·
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 45/100
volcengine/ark-cli#16 · 2 commenti ·
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 52/100
volcengine/ark-cli#15 · 1 commento ·
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 64/100
volcengine/ark-cli#10 · 1 commento ·
Tutte le issue di volcengine/ark-cli
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
I maintainer di solito rispondono entro 1 giorno
-
duplication
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
openvibely/openvibely#1443 ·
I maintainer di solito rispondono entro 2 giorni
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 80/100
keyxmakerx/Chronicle#1179 ·
I maintainer di solito rispondono entro 1 giorno
-
raised-by:worker
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
medici-finance/assay#2486 ·
I maintainer di solito rispondono entro 1 giorno
-
area/testing kind/bug triage/needs-triage
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
cozystack/cozystack#4841 · 1 reazione ·
I maintainer di solito rispondono entro 2 giorni