Skip to content

[dotnet-port-fixes] Harden file skill discovery #822

Description

@github-actions

Summary

Port the .NET file-skill discovery hardening from microsoft/agent-framework#7540 into the Go agent/skills/fsskills loader. The Go change now skips symlinked SKILL.md files, resources, and scripts during discovery while still allowing a caller-configured root path that is itself a symlink.

Ported .NET PRs

Breaking Changes

No. Exported Go APIs are unchanged; the loader only rejects unsafe file-skill paths that previously could be followed through symlinks.

Tests and Examples

  • Added parity tests for symlinked SKILL.md, resource, and script paths, plus configured-root symlink support
  • Ran go test ./agent/skills/fsskills

Notes

  • This PR keeps the scope to the file-skill symlink hardening that maps cleanly to the existing Go API surface.
  • The existing Go discovery logic already continues past unreadable directories without aborting sibling skill discovery, so no additional API-safe change was needed there.
  • Upstream commit: microsoft/agent-framework@94bbfb2

Generated by .NET to Go Fixes and Test Porting Agent · gpt54 · 215.2 AIC · ⌖ 13.2 AIC · ⊞ 24.2K · ◷


Note

This was originally intended as a pull request, but GitHub Actions is not permitted to create or approve pull requests in this repository.
The changes have been pushed to branch copilot/dotnet-port-fsskills-hardening-20260811-2d23946e974262e7.

Click here to create the pull request

To fix the permissions issue, go to Settings → Actions → General and enable Allow GitHub Actions to create and approve pull requests. See also: gh-aw FAQ

Show patch preview (269 of 269 lines)
From 70d89c3536ec2fbae4bcdd97671555a76a10d84f Mon Sep 17 00:00:00 2001
From: "github-actions[bot]" <github-actions[bot]@users.noreply.github.com>
Date: Tue, 11 Aug 2026 03:13:32 +0000
Subject: [PATCH] agent/skills/fsskills: harden file skill discovery

Port .NET file-skill discovery hardening so symlinked skill files, resources, and scripts are skipped while a symlinked configured root remains supported.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
---
 agent/skills/fsskills/source.go             | 63 ++++++++++++++----
 agent/skills/fsskills/source_script_test.go | 26 ++++++++
 agent/skills/fsskills/source_test.go        | 74 +++++++++++++++++++++
 3 files changed, 151 insertions(+), 12 deletions(-)

diff --git a/agent/skills/fsskills/source.go b/agent/skills/fsskills/source.go
index 95e01f585..d714965c8 100644
--- a/agent/skills/fsskills/source.go
+++ b/agent/skills/fsskills/source.go
@@ -170,7 +170,7 @@ func NewSourceOptions(opts SourceOptions, filesystems ...fs.FS) *Source {
 
 // Skills discovers and loads valid skills from the configured filesystems.
 func (s *Source) Skills(ctx context.Context) ([]*skills.Skill, error) {
-	directories := discoverSkillDirectories(s.filesystems)
+	directories := discoverSkillDirectories(s.filesystems, s.logger)
 	s.logger.Info("Discovered potential skills", "count", len(directories))
 
 	skills := make([]*skills.Skill, 0, len(directories))
@@ -190,10 +190,10 @@ func (s *Source) Skills(ctx context.Context) ([]*skills.Skill, error) {
 	return skills, nil
 }
 
-func discoverSkillDirectories(filesystems []fs.FS) []discoveredSkillDir {
+func discoverSkillDirectories(filesystems []fs.FS, logger *slog.Logger) []discoveredSkillDir {
 	var results []discoveredSkillDir
 	for _, filesystem := range filesystems {
-		searchForSkills(filesystem, ".", &results, 0)
+		searchForSkills(filesystem, ".", logger, &results, 0)
 	}
 	return results
 }
@@ -203,9 +203,23 @@ func discoverSkillDirectories(filesystems []fs.FS) []d
... (truncated)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions