modelstudioai / modelstudioai/cli

[bug]: bl skill init / skill remove ignore --dry-run and perform real changes

Đang mở
#211 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Ngôn ngữ chính
TypeScript
Star
333
Fork
28
Merge trung bình
1 ngày 9 giờ
Pull request đã merge (30 ngày)
33

Mô tả

Environment

  • CLI: bl 1.26.0 (npm install; upgraded from 1.3.2 via bl update today)
  • Skill: 1.26.0 (bailian-cli, installed by bl skill init)
  • Node: v22.22.2
  • OS: darwin 25.6.0 (macOS)
  • Region: cn

Summary

--dry-run is listed under "Global Flags" in bl skill init --help, bl skill remove --help (and add / update), but the whole skill command group ignores it: bl skill init --dry-run performed a full real installation (10 skills fanned out into 56 agent directories), and bl skill remove --name <x> --dry-run really deleted the skill. Exit code 0 in both cases.

Reproduce

# 1. "Preview" what init would do -> actually installs everything
bl skill init --dry-run

# 2. "Preview" a removal -> actually removes it
bl skill remove --name bailian-web-search --dry-run

Expected

With --dry-run, nothing is written or deleted; the command prints the plan (skills, target agent directories, link paths). Alternatively, if dry-run is not supported for these commands, the flag is rejected with a USAGE error and not advertised in their --help.

Actual

bl skill init --dry-run printed:

{
  "status": "success",
  "skills": [
    "bailian-cli", "bailian-finetune", "bailian-gen", "bailian-managed-agent",
    "bailian-protocol", "bailian-sandbox", "bailian-web-search",
    "bailian-docs-llm-wiki", "bailian-model-recommend", "bailian-train-deploy"
  ]
}

and on disk, all within the same second:

  • ~/.bailian/skills/<10 skills>/ were created (~33 MB, mostly bailian-docs-llm-wiki) and ~/.bailian/skills/skill-lock.json was written.
  • Symlinks were fanned out into 56 detected agent skill directories (~/.claude/skills, ~/.agents/skills, ~/.codex/skills, ~/.gemini/skills, ...).
  • The pre-existing real directory ~/.agents/skills/bailian-cli (installed from GitHub via npx skills add modelstudioai/cli and refreshed by bl update a few minutes earlier) was replaced by a symlink to ~/.bailian/skills/bailian-cli. I did not find a backup of the replaced directory.
  • ~/.bailian/telemetry.jsonl recorded a plain {"command":"skill init", ..., "params":{}} entry with no dry-run marker.

bl skill remove --name bailian-web-search --dry-run printed:

{
  "skills": [
    { "name": "bailian-web-search", "status": "removed", "removedLinks": 56 }
  ]
}

and the canonical directory plus all 56 links were really gone; a subsequent real bl skill remove --name bailian-web-search reported "reason": "not installed".

Likely cause

At HEAD, packages/commands/src/commands/skill/{init,add,remove,update,list}.ts never read ctx.settings.dryRun (there is no occurrence of dryRun anywhere under skill/). init.ts calls installSkillWithFanout(...) unconditionally and remove.ts calls unlinkSkillFromAgents(...) / removeSkillDir(...) unconditionally, while the global --dry-run flag is still rendered in every bl skill ... --help.

Why it matters

  • --dry-run is the documented way for agents to preview a mutating command before asking the user for consent (bailian-protocol). Here it silently performs the mutation, so an agent that follows the protocol ends up installing 10 skills into every detected agent app on the machine, which also changes default routing in those agents (e.g. bailian-gen / bailian-web-search claim generation / search requests by default).
  • bl update (npm path) and the automatic update check both run bl skill init afterwards (see also #200), so there is currently no non-mutating way to see what a skill install/update is going to write.

Suggested fix

Either honor dryRun in the skill group (print planned installs/removals with target agent directories and link paths, write nothing), or make these commands reject --dry-run with a USAGE error and drop it from their --help so it cannot be mistaken for a safe preview.

Already tried

  • bl update done today; skill version (1.26.0) aligned with CLI (1.26.0)
  • bl auth status OK (not relevant: skill commands are [No Auth])
  • Different network / region: not applicable, purely local operation

Notes

  • Frequency: Always (reproduced with both skill init and skill remove)
  • Invoked via: Agent (Claude Code)
  • Registry: https://bailian-wiki.oss-cn-hangzhou.aliyuncs.com/skills

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Hướng nghiên cứu

Bắt đầu với packages/commands/src/commands/skill/{init,add,remove,update,list}.ts và kiểm tra cách ctx.settings.dryRun được truyền đến các lệnh skill. Theo dõi init.ts qua installSkillWithFanout và remove.ts qua unlinkSkillFromAgents và removeSkillDir, sau đó chạy các bước tái hiện init và remove đã được ghi trong tài liệu. Hoàn tất khi dry-run in ra kế hoạch mà không ghi, xóa hoặc tạo liên kết, hoặc bị từ chối và không xuất hiện trong phần trợ giúp.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
typescript
Lĩnh vực
cli
Loại issue
Lỗi
Độ khó
3/5
Thời gian dự kiến
1-2 ngày
Mức độ hoạt động
Sôi nổi
Độ rõ ràng
Đặc tả rõ ràng
Mức phù hợp với người mới
72/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.