Repository navigation
feat(skills): load skills from public GitHub repositories - #4525
Merged
Merged
Conversation
Adds a GitHub source type to the skills loader so agents can pull skills straight from a public github.com repo (branch, tag, or commit SHA), with a short-lived ref cache and immutable, safely-extracted snapshots for warm, network-free reloads. Assisted-By: docker-agent
aheritier
approved these changes
Oct 6, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Agents that want ready-made skills today either embed them inline or point at a URL that implements the well-known skills discovery spec. Neither option covers the common case of "there's a public GitHub repo full of skills I want," which today means cloning it by hand and pointing a
localsource at the checkout.This adds a GitHub-aware branch to the skills loader. A
skills:entry that is ahttps://github.com/owner/repoURL (optionally a/tree/<ref>/<dir>form, or?ref=/&path=query parameters) resolves against the GitHub API to a commit SHA, downloads atar.gzsnapshot fromcodeload.github.comwith bounded, path-safe extraction, and caches the result immutably by repository, commit, and directory. Mutable refs (branches, tags, or no ref) are re-resolved every five minutes; a pinned 40-character SHA never re-resolves and a warm cache makes no network calls. An optionalGITHUB_TOKEN, read through the agent's configured environment provider, is sent only toapi.github.comto raise rate limits, never to the archive host, and never enables private repositories.pkg/teamloadernow routes skill-loading failures into load-time warnings instead of a hard failure, so one broken source doesn't take down the others.A full review was done on this branch and requested changes before merge. Per the current request, this PR is opened as a draft to get the diff in front of reviewers rather than patched blind; none of the findings below have been fixed yet.
Known issues from review
pkg/skills/frontmatter.goregresses parsing of existing local skills whose frontmatter has trailing whitespace before the closing---.0600, so executable scripts under a skill's directory lose their executable bit.|,>) fordescription, a gap now more likely to be hit as remote skills become easier to add.GITHUB_TOKENis not forwarded into the sandbox environment provider, so sandboxed sessions silently lose the GitHub authentication the docs describe./tree//skillsURL silently resolves to the default branch instead of being rejected as malformed.There are also open questions flagged but not yet root-caused around cache corruption recovery, whether credentials could leak across concurrent loads sharing a singleflight key, and the exact visibility semantics when a repository's public/private state changes between resolution and reuse. These need follow-up before this is safe to merge.