feat(skills): make security constraints optional for approval skills - #90
Merged
Merged
Conversation
Skills that require approval often enforce their own limits, so asking for a separate security constraint on every request only produced filler text. Requests and approvals may now leave it blank; a blank field adds nothing to the system prompt. Clearing the pre-filled template submits no constraint instead of falling back to it, and reviewers can clear the requested text the same way. A database scope is still required when the skill offers one. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Skills that require approval often enforce their own limits, so forcing a separate security constraint on every install request only produced filler text. The field is now optional.
批准时必须选择数据库范围). An empty or cleared constraint is stored asNULL, and nothing is appended to the AI employee's system prompt.skillEditor.policyRequiredstrings.docs/skills-management.md) and CHANGELOG updated. No database migration.Test plan
pytest tests/api/test_bot_skills.py tests/api/test_skill_catalog.py tests/api/test_skill_delete.py(27 passed), including a new end-to-end case: blank request → approval without policy → install succeeds → no constraint section in the promptruff check/ruff format --checkvue-tsc --noEmit,eslint,vitest run(294 passed)🤖 Generated with Claude Code