Skip to content

feat(skills): make security constraints optional for approval skills - #90

Merged
wxkingstar merged 1 commit into
mainfrom
claude/optional-skill-policy
Oct 1, 2026
Merged

wxkingstar merged 1 commit into
mainfrom
claude/optional-skill-policy

Conversation

@wxkingstar

Copy link
Copy Markdown
Owner

Summary

Skills that require approval often enforce their own limits, so forcing a separate security constraint on every install request only produced filler text. The field is now optional.

  • Install request: no longer rejects an empty security constraint. An omitted field still falls back to the catalog template; an explicitly cleared field (the UI pre-fills the template) now really submits none instead of silently falling back.
  • Review: only the database scope is required when the skill offers one (批准时必须选择数据库范围). An empty or cleared constraint is stored as NULL, and nothing is appended to the AI employee's system prompt.
  • UI: the install and review textareas show an "optional" hint; the approval page shows "未填写" when the requester left it blank. Removes the unused skillEditor.policyRequired strings.
  • Docs (docs/skills-management.md) and CHANGELOG updated. No database migration.

Test plan

  • pytest tests/api/test_bot_skills.py tests/api/test_skill_catalog.py tests/api/test_skill_delete.py (27 passed), including a new end-to-end case: blank request → approval without policy → install succeeds → no constraint section in the prompt
  • ruff check / ruff format --check
  • vue-tsc --noEmit, eslint, vitest run (294 passed)

🤖 Generated with Claude Code

Skills that require approval often enforce their own limits, so asking
for a separate security constraint on every request only produced filler
text. Requests and approvals may now leave it blank; a blank field adds
nothing to the system prompt. Clearing the pre-filled template submits
no constraint instead of falling back to it, and reviewers can clear the
requested text the same way. A database scope is still required when the
skill offers one.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@wxkingstar
wxkingstar merged commit 92aae22 into main Oct 1, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant