scripts/plan-canvas.js and scripts/control-pane.js both define their own
openBrowser helpers for launching the user's default browser. The two
implementations have diverged:
- plan-canvas.js dispatches across darwin/win32/linux but its
try/spawn try/catch does not catch async child errors (ENOENT/EACCES
on hosts without the launcher command). Returns a bare true/false.
- control-pane.js is darwin-only and silently returns early on
Windows/Linux, so the two scripts behave inconsistently across
platforms.
When the launcher command is missing (e.g. headless CI without xdg-open)
the JSON output still says 'browser: opened', lying to the agent.
Changes:
- scripts/lib/platform-launch.js: shared openBrowser helper that
dispatches per platform, wires child 'error' so ENOENT/EACCES
propagate, and returns {opened, reason} instead of a bare boolean.
- scripts/plan-canvas.js: drops its local helper, imports the shared
one, and adds browserReason to its JSON output.
- scripts/control-pane.js: replaces its darwin-only branch with the
shared helper and logs the structured reason on failure.
- tests/lib/platform-launch.test.js: 7 node:test cases covering
opener-command selection, invalid-URL guard, structured-result
shape, and a smoke run for the actual spawn.
Verification: node --test tests/lib/platform-launch.test.js → 7/7 pass.
Co-authored-by: auyua9 <auyua9@users.noreply.github.com>
The Claude Code docs page at code.claude.com/docs/en/mcp-overview no
longer exists (404). The current MCP page is
https://code.claude.com/docs/en/mcp ("Connect Claude Code to tools via
MCP"). Update the link in the English, zh-CN, and tr versions of the
shortform guide.
Co-authored-by: kuishou68 <kuishou68@users.noreply.github.com>
Add focused security regression for sdk-cli allowlisting and document
IOC scan + allowlist probe output under .pr/security-evidence-3171.md.
Signed-off-by: Frank_zhu <58329837+Frank-zhu0404@users.noreply.github.com>
Windows: compare repo identity via normalizeRepoPath/sameRepoIdentity (8.3 short names, case, separators; inode fallback). All nine windows-latest jobs green on 52587005.
skillforge validate reports SF1009 (no license declared) on every skill
in .agents/skills. This adds license: MIT to all 39, matching the
repository LICENSE.
license only. The Codex mirror's frontmatter is governed by an allowlist
in tests/ci/codex-skill-surface.test.js - allowed-tools, description,
license, metadata, name - and license is the one field on it that
skillforge asks for. compatibility is deliberately absent here; widening
that contract is a separate decision about what the Codex surface
supports.
node tests/ci/codex-skill-surface.test.js: 4 passed, 0 failed.
Split out of #2993 so both PRs land under the review-bot file limits.
Co-authored-by: Çağrı Solakoğlu <cagri.solakoglu@vtcenerji.com>
The real-PTY test piped answers on fixed sleeps, typing them ahead of
readline. Under CI load the first answer could land before the interface
listened, shifting every later answer onto the wrong question: the
ubuntu-latest Node 18.x npm job installed Claude only, exited 0, and never
printed the Kimi profile prompt while the sibling yarn, pnpm, and bun jobs
on the same Node version passed. Answer each prompt once it appears on
screen instead; spawned stdio goes through cat because the macOS script(1)
refuses a socket stdin.