Skip to content

feat(cli): add skill packs (design, process, behavior) with pinned, verified installs - #3

Merged
weisser-dev merged 5 commits into
mainfrom
feat/design-pack
Oct 3, 2026
Merged

weisser-dev merged 5 commits into
mainfrom
feat/design-pack

Conversation

@weisser-dev

Copy link
Copy Markdown
Owner

Summary

New feature: skill packs for OpenCode (minor release 1.5.0).

  • awesome-opencode packs [--pack design|process|behavior|all] [--global] [--only ...] [--all] [--list] [--dry-run] [--force]
  • awesome-opencode design-pack (alias for packs --pack design), configure packs, a menu entry "Install skill packs", and an optional question at the end of the full setup (default: no).
  • Installs skills to .opencode/skills/<name>/SKILL.md (or ~/.config/opencode/skills/ with --global, honoring XDG_CONFIG_HOME / OPENCODE_CONFIG_DIR) and commands to .opencode/commands/<name>.md (or ~/.config/opencode/commands/). Paths and the "folder name = skill name" rule were checked against the OpenCode source (packages/opencode/src/skill/index.ts, config/command.ts) and docs.
  • Packs: design (frontend design skills incl. vendored Web Interface Guidelines and local Playwright checks), process (23 lifecycle skills + /spec /plan /build /test /constraints /review /webperf /code-simplify /ship), behavior (ponytail, opt-in, never part of all).
  • templates/packs/ is imported from weisser-dev/agentic-skills (source of truth, review notes; see feat(packs): add design, process and behavior skill packs with pinned installer agentic-skills#1) via cli-tool/scripts/import-packs.js.

Security model

  • Bundled items (own skills, vendored and adapted copies) are copied from the package, no network (e.g. web-design-guidelines installs offline).
  • Items installed unmodified from upstream are downloaded only from raw.githubusercontent.com for the repo + 40-char commit in templates/packs/sources.lock.json; every file must match its sha256 pin; everything is built and verified before the first write.
  • Nothing executed; no hooks/plugins/MCP servers. Locally modified or foreign items are refused unless --force (backup kept in .agentic-pack-backups/, renamed so OpenCode does not load it).

Other changes

  • ci(release): npm version --allow-same-version, because the version is now bumped in the PR.
  • README section with license/commit table, AGENTS.md, CHANGELOG 1.5.0.

Test plan

  • npm test: 108 pass, 0 fail (21 new: lock integrity, provenance/license files, forbidden run-time patterns, selection, URL safety, install/idempotency/refusal/backup/sha256-mismatch with a synthetic lock, offline install of bundled items)
  • CI checks run locally: syntax, agent count 108, skill count 15, templates synced, npm pack --dry-run
  • Live install into a temp project: packs --pack all,behavior (38 skills, 9 commands), re-run up-to-date; DESIGN.md output byte-identical to the agentic-skills bash installer
  • Release via workflow_dispatch with version 1.5.0 after merge

templates/packs holds sources.lock.json and the bundled design, process and behavior pack items imported from weisser-dev/agentic-skills (scripts/import-packs.js). Third-party folders keep their LICENSE and an UPSTREAM.md with the pinned commit and changes.
awesome-opencode packs / design-pack / configure packs install skills into .opencode/skills (or ~/.config/opencode/skills with --global) and commands into .opencode/commands. Pinned upstream files are downloaded only from raw.githubusercontent.com at the locked commit and verified by sha256; nothing is executed; locally modified items are refused without --force; --dry-run makes no network calls.
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

@weisser-dev
weisser-dev merged commit b0ead7e into main Oct 3, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant