Skill import from URLs (generic, not GitHub-only) #948

Closed
opened 2026-06-18 10:57:46 +02:00 by sleepy · 1 comment
Owner

Overview

Allow importing SKILL.md bundles from arbitrary URLs. The upstream implementation targets GitHub raw URLs, but the core feature is generic URL import — works with any URL serving a .md file.

Upstream References

  • PR #2576: Import SKILL.md bundles from public GitHub URLs
  • Upstream commit: b448119 feat(skills): import SKILL.md bundles from public GitHub URLs (#2576)
  • Local paths: ../odysseus_upstream/routes/skills_routes.py
  • Tests: ../odysseus_upstream/tests/test_skill_importer.py

Implementation

  1. Add URL import endpoint to skills routes
  2. Accept arbitrary URL (not GitHub-specific — works with any .md source)
  3. Validate SKILL.md frontmatter (name, description required)
  4. SSRF-guarded fetch (validate URL scheme, no internal hosts)
  5. Store imported skill alongside existing ones
  6. UI: add URL import field in skills management
  7. Port tests/test_skill_importer.py
  8. Adapt URL to work with local Forgejo raw file URLs: https://git.kokoham.com/sleepy/<repo>/raw/branch/path/to/SKILL.md

Priority

Medium — enables sharing skills across instances.

## Overview Allow importing SKILL.md bundles from arbitrary URLs. The upstream implementation targets GitHub raw URLs, but the core feature is generic URL import — works with any URL serving a `.md` file. ## Upstream References - **PR #2576**: Import SKILL.md bundles from public GitHub URLs - **Upstream commit**: `b448119 feat(skills): import SKILL.md bundles from public GitHub URLs (#2576)` - **Local paths**: `../odysseus_upstream/routes/skills_routes.py` - **Tests**: `../odysseus_upstream/tests/test_skill_importer.py` ## Implementation 1. Add URL import endpoint to skills routes 2. Accept arbitrary URL (not GitHub-specific — works with any `.md` source) 3. Validate SKILL.md frontmatter (name, description required) 4. SSRF-guarded fetch (validate URL scheme, no internal hosts) 5. Store imported skill alongside existing ones 6. UI: add URL import field in skills management 7. Port `tests/test_skill_importer.py` 8. Adapt URL to work with local Forgejo raw file URLs: `https://git.kokoham.com/sleepy/<repo>/raw/branch/path/to/SKILL.md` ## Priority Medium — enables sharing skills across instances.
Author
Owner

Merged via squash to dev (7df4ec4). 6 files, +1174 lines. SSRF-guarded URL fetcher with scheme whitelist, public-IP DNS check, redirect validation, Content-Type filtering, 128KB cap. 50 tests passing. PR review: 1 round (scope violation, broken redirect, dead imports, missing Content-Type validation → all fixed).

Merged via squash to dev (7df4ec4). 6 files, +1174 lines. SSRF-guarded URL fetcher with scheme whitelist, public-IP DNS check, redirect validation, Content-Type filtering, 128KB cap. 50 tests passing. PR review: 1 round (scope violation, broken redirect, dead imports, missing Content-Type validation → all fixed).
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
sleepy/odysseus#948
No description provided.