fix(knowledge): frame the video title and URL in the video-digest resume prompt as untrusted data
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 2/5
- 見積もり時間
- 1〜3時間
- 初心者へのやさしさ
- 62/100
- issue の種類
- バグ
- 明瞭さ
- 明確に書かれている
- 活発さ
- 活発
- 技術スタック
- javascript
調査の方向性
plugins/knowledge/skills/video-digest/extraction/watch/watch-state.js の buildContinuationPrompt から始めてください。title と sourceUrl は 326 行目と 330 行目付近で埋め込まれています。46〜47 行目の状態フィールドも確認してください。再利用するフレーミングの骨組みとして docs/conventions/untrusted-content/README.md を読んでください。完了条件は、title と URL が区切られたデータブロック内にあり、改行が統合され、バッククォートが無害化されていること、見出しに生のタイトルが含まれなくなっていること、そして命令文の行とコードフェンスを含むタイトルがそのブロック内にのみ現れることを新しいテストで示すことです。
索引モデルが issue の本文から書いたものです。
説明
Summary
buildContinuationPrompt in watch-state.js interpolates the video title and source URL straight into the resume prompt. Both come from the video's own metadata, which the video's publisher controls. The prompt is the text a fresh session reads as its instructions, and it is written into the slice, so a title carrying imperative text lands in the instruction channel with no data framing.
Failure scenario
Expected: ingested metadata is presented as data, never instructions, per the framing contract in docs/conventions/untrusted-content/README.md (classification, finding, authority floor).
Actual: the first line is # Continue /knowledge:video-digest watch — ${state.title} and a later line is Source: ${state.sourceUrl}, unquoted and unframed. A title such as one containing a sentence addressed to the agent reads, to the resuming session, as part of its own prompt. #6820 framed the ingested transcripts, comments and pages; this prompt is a separate ingest path that the fix did not cover.
Evidence
- Title in the prompt heading: https://github.com/melodic-software/claude-code-plugins/blob/7787be41e98e30cd6e3b82e99494886d77e30895/plugins/knowledge/skills/video-digest/extraction/watch/watch-state.js#L326
- Source URL in the prompt: https://github.com/melodic-software/claude-code-plugins/blob/7787be41e98e30cd6e3b82e99494886d77e30895/plugins/knowledge/skills/video-digest/extraction/watch/watch-state.js#L330
- The state fields the prompt reads (
sourceUrl,title): https://github.com/melodic-software/claude-code-plugins/blob/7787be41e98e30cd6e3b82e99494886d77e30895/plugins/knowledge/skills/video-digest/extraction/watch/watch-state.js#L46-L47 - Framing contract: https://github.com/melodic-software/claude-code-plugins/blob/7787be41e98e30cd6e3b82e99494886d77e30895/docs/conventions/untrusted-content/README.md
watch-state.jshas no untrusted-content wording on main (searched for "untrusted").
Suggested fix
Carry the inline framing spine from the untrusted-content convention in the prompt, move the title and URL into a clearly delimited data block (for example a fenced block, with newlines in the title collapsed and backticks neutralized), and keep the heading free of the raw title. Add a test that a title containing an imperative line and a code fence does not appear outside the data block.
Related
- #6820 (framed ingested transcripts, comments and pages)
- docs/conventions/untrusted-content/README.md
🤖 Generated with Claude Code
- 主要言語
- Shell
- スター
- 22
- フォーク
- 2
- 平均マージ
- 6時間 10分
- マージ済み PR(30日)
- 937
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートなし
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
melodic-software/claude-code-plugins のほかの issue
-
docs(evals): note CLAUDE_CODE_PRINT_BG_WAIT_CEILING_MS for headless eval runs that use workflowsオープンgood first issue needs-triage priority: low
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
melodic-software/claude-code-plugins#7022 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
good first issue needs-triage priority: low
難易度 1/5 1時間未満 初心者へのやさしさ 88/100
melodic-software/claude-code-plugins#7019 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
good first issue needs-triage priority: medium
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
melodic-software/claude-code-plugins#7014 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
good first issue needs-triage priority: low
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
melodic-software/claude-code-plugins#6982 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
needs-human needs-triage
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
melodic-software/claude-code-plugins#6897 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
melodic-software/claude-code-plugins の issue をすべて見る
似ている issue
-
難易度 1/5 1時間未満 初心者へのやさしさ 71/100
t4t5/omdrop-owl#14 ·
メンテナーはふだん 1 日以内に返信
-
enhancement
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
メンテナーはふだん 1 日以内に返信
-
ready
難易度 2/5 1〜3時間 初心者へのやさしさ 92/100
kubeflow/pipelines#14784 · コメント 1 件 ·
メンテナーはふだん 2 日以内に返信
-
implement-spec: step 9 cleanup collides with branch -D guards and with rewritten integration historyオープンneeds-triage
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
mattpocock/skills#1251 ·
メンテナーはふだん 1 日以内に返信