Skill library default ./library + direct execution without explicit opt-in
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 45/100
Hướng nghiên cứu
Start with argument parsing in src/webwright/skill_factory/route.py and direct execution in src/webwright/skill_factory/execute.py; compare the default-library behavior with the warning in src/webwright/tools/skill_use.py. Trace how a resolved skill.py is launched, then define the confirmation and library-location behavior against the suggested fix. Done means cwd is no longer the implicit default and first use of an unconfirmed library requires an explicit opt-in.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
The skill-library commands resolve their library to ./library relative to the current working directory when SKILL_LIBRARY_ROOT is unset, and route executes what it finds there directly — no model in the loop, no confirmation step. Library entries are executable programs by design (skill.py files the project's own docs describe as shareable, committable artifacts), so the cwd default means "run the programs sitting next to wherever I happen to be standing".
Current code (main)
-
src/webwright/skill_factory/route.py:166-167:p.add_argument("--library", default=os.environ.get("SKILL_LIBRARY_ROOT", "library"), help="Path to the skill library (default: $SKILL_LIBRARY_ROOT or ./library).")libraryhere is a bare relative path, so it resolves against the process cwd. -
src/webwright/skill_factory/execute.py:1,23-56— the module's own docstring: "Direct execution: run an executable skill on filled params, no agent, no model."run_skillruns the resolvedskill.pyviasubprocess.run([sys.executable, str(skill.resolve()), "taskspec.json"], ...)with no approval or trust prompt anywhere. -
src/webwright/tools/skill_use.py:60-67warns when a relative library path resolves to nothing — the missing-library case is handled loudly, but a./librarythat does exist in the cwd loads silently.
The footgun
Running python -m webwright.skill_factory.route "<task>" from a directory that merely contains a library/ folder — a cloned repo, an unpacked archive, a shared drive mount — loads and executes whatever skill.py files are in it, at the user's privilege, with no signal beyond the decision line the command prints. The intent is surely "my library, learned in earlier runs" (the examples ship --library "$WORKSPACE_DIR/../library" for exactly that). But an absolute or user-level default plus an explicit --library for "run a library from this directory" would keep the convenience while making "execute third-party programs" an affirmative act rather than a side effect of cwd.
This is a hardening request, not a bug report: sharing libraries is a designed feature, and a user who passes --library <someone else's dir> has asked for it. The gap is only the default — discovery by cwd plus zero-confirmation execution of whatever is discovered.
Suggested fix
- Default the library root to a user-level location (
$SKILL_LIBRARY_ROOT, else something like~/.webwright/library), never cwd; the shipped example invocations that pass--libraryexplicitly are unaffected. - On first execution against a library not seen before, print the resolved absolute path and require an explicit flag (
--yesor an interactive confirm) — a one-time opt-in per library. - Optionally record known libraries (path + a hash of their contents) so re-running a previously confirmed library stays frictionless while a changed or new one re-prompts.
- Ngôn ngữ chính
- Python
- Star
- 6k
- Fork
- 383
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Chuẩn bị môi trường
Dự án này không cung cấp dev container, Dockerfile hay hướng dẫn đóng góp, nên bạn cần tự thiết lập môi trường: hãy bắt đầu từ README và xem hướng dẫn đóng góp lần đầu của chúng tôi để biết các bước chung.
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của microsoft/Webwright
-
task_showcase: default bind 0.0.0.0 contradicts the documented 127.0.0.1:5005Có thể đã có người làm Có pull request liên kết đang mở hoặc đã được merge. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
-
Memory leak: page.on() event listeners never removed on closeCó thể đã có người làm @rahulrao85 đã nhận 88 ngày trước. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
-
SKILL.md says Firefox is a prerequisite, but README.md doesn't.Có thể đã có người làm @nuthalapativarun đã nhận 134 ngày trước. Đang mở
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 78/100
-
playwright_patterns.md 'Browser launch skeleton' crashes with UnicodeEncodeError on Windows when aria_snapshot output contains non-cp1252 charactersCó thể đã có người làm @raykuo998 đã nhận 136 ngày trước. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
-
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 25/100
Tất cả issue của microsoft/Webwright
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
-
EvaluationSuite.run fails with default args_for_task and mutates supplied kwargsCó thể đã có người làm @ktz03 đã nhận hôm nay. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
huggingface/evaluate#825 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Add `django-upgrade` to the CIĐang mởdependencies feature github_actions good first issue
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 62/100
wemake-services/wemake-django-template#3149 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
[request] vsg/1.1.16Đang mởupstream update
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 65/100
conan-io/conan-center-index#31142 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
area:core bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
Maintainer thường phản hồi trong vòng 1 ngày