feat: skill import from URLs (generic, not GitHub-only) (#948) #959

Closed
sleepy wants to merge 2 commits from fix/948-skill-import-urls into dev
Owner

Allow importing SKILL.md bundles from arbitrary URLs.

  • SSRF-guarded URL fetcher with scheme whitelist, public-IP check, redirect validation
  • Frontmatter validation (name + description required)
  • New POST /api/skills/import-from-url endpoint (admin only)
  • UI: import URL input panel in skills toolbar
  • 34 tests covering blocked IPs, URL validation, markdown validation, fetch with redirects, full pipeline

Closes #948

Allow importing SKILL.md bundles from arbitrary URLs. - SSRF-guarded URL fetcher with scheme whitelist, public-IP check, redirect validation - Frontmatter validation (name + description required) - New POST /api/skills/import-from-url endpoint (admin only) - UI: import URL input panel in skills toolbar - 34 tests covering blocked IPs, URL validation, markdown validation, fetch with redirects, full pipeline Closes #948
Ported from upstream commit 5ed9b74 (origin/Sirsyorrz/slash-autocomplete).

- New module: static/js/slashAutocomplete.js
  Reads COMMANDS + LEGACY_ALIASES from slashCommands.js.
  Shows a fixed popup when the composer starts with /.
  Keyboard-navigable (↑↓/Tab/Enter/Esc), click-to-select, scrollable.
  Groups entries by category, promotes short legacy aliases
  (/new, /clear, /web, etc.), excludes easter eggs.
  Lazy-imported on init to avoid blocking page load.

- slashCommands.js: export COMMANDS and LEGACY_ALIASES so the
  autocomplete module can read the command registry.

- chat.js: lazy-import slashAutocomplete on init, wire to #message textarea.

- style.css: popup + row styles using existing CSS variables.

- tests: port static regression tests for MAX_VISIBLE and
  _exactCommandGroupItems behavior.

Closes #946
- Add /v1 auto-insertion for bare api.deepseek.com and api.openai.com hosts
  in build_chat_url and build_models_url (aligns with upstream endpoint_resolver)
- Add 6 tests for DeepSeek and OpenAI bare-host endpoint resolution
- DeepSeek is already registered in the HTML dropdown (https://api.deepseek.com/v1),
  provider detection (_providers.py), logo (providers.js), tool selection,
  and thinking model patterns. This commit ensures the endpoint resolver
  handles bare hosts correctly, closing the gap for manual URL entry.

Closes #947
Issue #948 — Allow importing SKILL.md bundles from any public URL
serving a .md file (not GitHub-specific).

- services/memory/skill_importer.py: SSRF-guarded fetcher, URL
  validation (scheme + public hostname check), frontmatter
  validation (name + description required), redirect safety checks
- routes/skills_routes/router.py: POST /api/skills/import-from-url
  endpoint, requires admin
- routes/skills_routes/models.py: SkillImportUrlRequest model
- static/index.html: Import button + collapsible URL input panel
- static/js/skills.js: _importSkillFromUrl(), panel toggle logic
- tests/test_skill_importer.py: 34 tests covering blocked IPs,
  URL validation, markdown validation, fetch with redirects,
  and full import pipeline
sleepy force-pushed fix/948-skill-import-urls from 116fd65755 to 78e8ee9274 2026-06-18 18:51:49 +02:00 Compare
sleepy closed this pull request 2026-06-18 18:57:23 +02:00

Pull request closed

Sign in to join this conversation.
No description provided.