Skip to content
This repository was archived by the owner on Oct 9, 2026. It is now read-only.

fix: the agent can read the global and built-in skills it lists - #47

Closed
mekjr1 wants to merge 1 commit into
mainfrom
fix/skills-readable
Closed

mekjr1 wants to merge 1 commit into
mainfrom
fix/skills-readable

Conversation

@mekjr1

@mekjr1 mekjr1 commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Fixes #37.

The skill catalog in the system prompt tells the model to read each skill's SKILL.md with read_file and gives its absolute path. With Restrict to Workspace on, the default, read_file reads only the workspace, the media folder and tools.allow_read_paths. It answered "path escapes workspace" for a skill in $COMPA_HOME/skills or in the built-in folder ($COMPA_BUILTIN_SKILLS, or skills beside the executable).

buildAllowReadPatterns now adds the global and built-in skill folders, as it adds the media folder. It uses the same ^<folder>(?:<separator>|$) pattern, which the file tools also check against the link-resolved path. The context builder and the patterns get the global folder from one helper, globalSkillsDir, and the built-in one from skills.BuiltinDir. So they name the folders the loader lists.

Every tool that takes the read paths uses these patterns: read_file, list_dir, exec, send_file, load_image and the message tool's local media. So a skill's other files, and the scripts its instructions run, can be reached too. The writing tools use tools.allow_write_paths and are unchanged. Embedders no longer need COMPA_TOOLS_ALLOW_READ_PATHS for their built-in skills.

docs/use.md now names the skill folders among the paths file tools may read and commands may name. It also names the attachment folder for commands, which was already allowed. CHANGELOG line.

Test: TestNewAgentInstance_ReadsTheSkillsTheCatalogLists puts one skill in each folder and reads every skill the loader lists with the agent's read_file. On main it fails with "path escapes workspace".

@mekjr1

mekjr1 commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #63, which includes this change or replaces it.

@mekjr1 mekjr1 closed this Oct 9, 2026
@mekjr1
mekjr1 deleted the fix/skills-readable branch October 9, 2026 03:27
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

The prompt tells the model to read global and built-in skills with read_file, which refuses them

1 participant