skillshare v0.25.2 Release Notes
TL;DR
- Tracked repos installed with
--intoare treated as repos everywhere. - Updating a tracked repo from the dashboard keeps it tracked, and a repo it already broke is repaired on its next update.
update org/teamanduninstall org/teamfind a repo installed with--into org.- Markdown API examples, such as those in anthropics/skills, no longer block install and update.
Tracked repos under --into
install --track --into <dir> places the checkout at <dir>/_repo, but skillshare only recognized a tracked repo at the top level. Its skills were listed as ordinary skills, counted outside the repo in list and status, and grouped wrongly in the dashboard tree.
list,status,check, the dashboard anduninstallnow treat it as a tracked repo.updateanduninstallaccept the short form:devops/skillsresolves todevops/_skills. A skill or folder that exists at the typed path still wins, and a name that matches more than one repo is an error rather than a guess.
skillshare install github.com/team/skills --track --into devops
skillshare update devops/skills
skillshare uninstall devops/skills --dry-runDashboard updates of tracked repos
The Update button reinstalled a tracked repo as a regular skill and dropped its tracked state. Afterwards skillshare update <repo> failed with "matches multiple items".
The dashboard now pulls the repo like the CLI does. A repo whose entry was already rewritten is repaired on its next update, from the CLI or the dashboard:
skillshare update _skillsWhich folders are tracked repos
A tracked repo is a _-prefixed folder that is a git checkout. Some paths treated any git checkout as one, so a skill you cloned by hand was updated with git pull by the dashboard's batch update, update --group and update -p, and reconcile marked it as tracked. It is now handled as a regular skill everywhere. An old entry with tracked: true keeps its source and branch; only the flag is cleared.
Two more fixes protect tracked repos:
uninstallrefuses to remove a skill or folder inside a tracked repo's checkout, even with--force:inside a tracked repo; uninstall the repo instead. Skills under a followed source link can still be removed one at a time.- When a nested
org/_teamhad no metadata entry and a top-level_teamexisted,org/_teamtook_team's entry and its source. Each repo now keeps its own entry.
Audit
API examples in Markdown, such as the system: parameter in anthropics/skills, were reported as CRITICAL prompt injection, so the default policy blocked install and update.
- Recognized SDK parameter shapes are now HIGH: the default policy warns and
--strictstill blocks. Explicit instructions to hide content stay CRITICAL. - Generic disclosure restrictions now use the HIGH rule
prompt-injection-5. Existing overrides or accepted findings forprompt-injection-4do not carry over to it. - A blank line inside raw HTML no longer splits a shell data flow, and a code fence whose info string uses a tab is analyzed.
- Replacing a built-in disclosure rule's regex keeps its whole-line exclusions.
Smaller changes
- owner/repo on the Updates tab. Skills in a subfolder of a tracked repo showed only
trackedon their cards. - A skill at the root of a tracked repo appears inside its repo in the dashboard tree.
- The Pi Extensions tab tells packages from plugins. A Pi package reads
Package · <name>with Pi's black and white mark; a plugin readsPlugin · <name>.