[3.10.0] - 2026-09-30
Theme: Seeker HUD (beta) — a local web UI for the whole toolchain — plus a path-traversal security fix, three machine-readable CLI commands, an opt-in SQLite skill search index, MiniMax video input, and PDF vector-figure extraction.
The Seeker HUD web UI is in beta. It ships in this release for early feedback: screens,
/api/*routes, and the UI state stored under~/.skill-seekers/ui/may change between minor releases without a deprecation period. The CLI, the MCP server, and every existing platform adaptor are unaffected. Please report HUD issues on GitHub.
Security
- Path traversal in the
fetch_configMCP tool (CWE-22) (#462 reported by @Harmenszoon, fixed in PR #464 by @emecii) — the git-URL mode passed the rawconfig_nameargument intocache_dir / f"temp_{name}", andclone_or_pullboth deletes that path (onrefreshor a failed pull) and clones attacker-chosen content into it, so a crafted name could delete or overwrite directories outside the cache. The shared clone boundary now validates the cache name, andfetch_configvalidatesconfig_nameonce for all three modes in both MCP servers (the named-source and API modes wrote<destination>/<name>.jsonfrom the raw name too). All name checks now go through one allowlist (services/path_safety.validate_path_segment: leading letter or digit, then letters, digits,.,_,-), which also rejects NUL bytes, whitespace and dot-files such as.git; the workflow, config-publisher and marketplace validators delegate to it. A failed pull on a cached clone now falls through to a fresh clone instead of deleting the cache and reporting an error.
Added
- Seeker HUD (beta) — a local web app for the whole toolchain.
pip install "skill-seekers[ui]"thenskill-seekers uiopens a React + FastAPI interface onhttp://127.0.0.1:8770(loopback only) with Overview, Create, Skills, Configs, Workflows, Analyze, Environment, and job-history screens; every long-running action runs as a streamed job. The built frontend is bundled into the wheel, so no Node toolchain is needed to use it. The beta status is shown in the sidebar and the launcher banner and documented indocs/guides/WEB_UI.md; the HUD-specific entries below describe the screens in detail. - MiniMax-M3 video input and thinking modes (#468 by @octo-patch) —
AgentClient.call_with_video()sends a local MP4/AVI/MOV/MKV clip as an OpenAI-compatiblevideo_urlpart (MiniMax-M3 only, 50 MB inline cap enforced before the request), andMINIMAX_THINKING=adaptive|disabled(or athinking=call argument) is carried in the request body. Both are registry-driven —supports_video,video_models,video_max_bytes,thinking_modes,thinking_envon the provider entry — so_call_apistill never branches on a provider name. The thinking mode is validated once at client construction; under the Anthropic protocol it is ignored with a warning instead of silently dropped. No built-in pipeline calls the video path yet. - Opt-in SQLite search index for generated skills (#393, PR #463 by @emecii) —
skill-seekers create <source> --index(or"index": truein a config file) writesscripts/index.db(FTS5 with BM25, LIKE-style fallback where FTS5 is unavailable) and a stdlib-onlyscripts/search.pythat returns rankedfile#anchorpointers, and appends a search-first block to SKILL.md. Off by default, Markdown untouched, zero new dependencies; the Claude packager already shipsscripts/. Sections are split at headings outside fenced code blocks,index.mdtable-of-contents pages are skipped, anchors follow GitHub's rules, query tokens are quoted soNOT/ORare plain words, and nothing is installed when a skill has no indexable references. Enhancement and indexing now resolve the skill directory the same way the scrapers do, including a config-fileoutput_dir. skill-seekers doctor --json(#459 by @Whxuan0701) — machine-readable diagnostics for CI and agents:version, per-check results, pass/warn/failsummary,healthyandexit_code, as exactly one JSON document on stdout. Import-time noise from dependencies is forwarded to stderr, a crashing check is reported as{"error": ...}, andverbose_detail(which carries masked API-key fragments) is only populated with--verbose, matching the human report. Thedoctorcommand now has a section in the CLI reference.skill-seekers quality <dir> --json(#458 by @Whxuan0701) — the quality report on stdout as exactly one JSON document, for pipelines. No defaultquality_report.jsonis written in this mode (--outputstill saves a copy), diagnostics and the threshold-gate reason go to stderr, errors are emitted as{"error": ...}, and--report/--jsonare mutually exclusive. The report file is now written before anything is printed, so a failed--outputwrite cannot leave a complete report on stdout with a non-zero exit.skill-seekers detect <source> [--json](#457 by @Whxuan0701) — read-only preview of howcreatewould classify and parse a source, for scripts, CI and agent workflows. Runs the same detect-and-validate stage ascreate(now shared asSourceDetector.resolve), reportsvalid/validation_error, always emits JSON on stdout under--json(errors included), and exits2for undetectable or unusable sources. Documented in the CLI reference,AGENTS.mdand the docs index.- Fluxion AI joins as a Bronze sponsor — small logo in the README sponsor section across all 12 languages, captioned "Sponsor — Bronze" per rule 2, listed in
SPONSORS.mdwithsince: September 2026. Sponsorship active on GitHub Sponsors since 2026-09-16; link carries standardutm_*parameters only (rule 4) and the transparent PNG passed asset review (rule 6). - Vector figures are extracted from PDF pages (#434, PR #451 by @bferanmi806-sketch) — PDF image extraction relied on
page.get_images()+doc.extract_image(xref), which only see embedded raster objects, so vector-only diagrams reached neither the extracted assets nor the generated skill. Meaningful vector drawing clusters are now rendered as PNG assets alongside the raster path, with nearby labels kept in the clip. Entries inextracted_imagescarrysource(raster/vector) andbbox, and pages gainvector_figures_count(images_countstays raster-only, sototal_imageskeeps its meaning for the generated statistics).- Detection is deliberately conservative and rejects page frames, separator rules, line-ruled tables and small decorative marks. A cluster made entirely of wide fill-only bands is page furniture — that is what a shaded code block, callout or admonition looks like — and is rejected, so ordinary docs PDFs do not emit PNGs of their own code samples.
- Figures are emitted in reading order rather than by area, so the
vectorNsuffix and the order in the generated reference markdown follow the page. --min-image-sizenow applies to vector figures on the same pixel basis as rasters; previously the flag silently did nothing for them.- Raster/vector de-duplication compares IoU, not intersection-over-smaller-area. Under the latter, any fully contained raster scored 1.0, so a 30x30pt embedded logo deleted the entire architecture diagram enclosing it.
- Cost guardrails: clustering is skipped above
VECTOR_MAX_DRAWINGS(2000) orVECTOR_MAX_CLUSTERS(400), and cluster membership is resolved through a coarse grid index instead of comparing every cluster against every drawing. A 3000-path page (scatter plot, map, CAD export) went from 56.3s and zero figures to 0.17s — this path is on by default, so that cost was previously paid per page.
- Sponsor entries in
sponsors.jsongain an optionalsincefield and alogo_svgvector companion. - Readability metrics in the quality checker (#228, PR #441 by @bferanmi806-sketch) —
skill-seekers qualitynow reports Flesch Reading Ease, Flesch-Kincaid Grade Level, average sentence length, and average paragraph length for SKILL.md prose, plus aggregated notes for over-long sentences and paragraphs. YAML frontmatter, fenced code, and inline code are excluded, and no new dependency is added. Scores use English-language formulas and may be inaccurate for other languages.- Readability is reported as info, never as warnings:
quality_scorededucts 5 points per warning andquality --thresholdexits non-zero in CI, so emitting warnings would have dropped scores by up to 10 points and failed existing quality gates on skills that had not changed. A regression test pins this contract.
- Readability is reported as info, never as warnings:
- Seeker HUD: skills are tagged by origin (
seeker/plugin · <name>/manual) with a filter; external skills are read-only except port/package (API returns 403 on mutation). - Seeker HUD:
GET /api/mcp/statusprobes the stdio/HTTP transports; the Seeker MCP tab shows real status and copyable client config. - Seeker HUD: live skill search shared between the top bar and the grid; configs search; 25/50/100 paging on the skills, configs and workflows lists.
- Seeker HUD: routed skill page at
/skills/<id>with Overview, SKILL.md, Files, Installs, Enhance, Analysis, Export, and History tabs, replacing the skill drawer. - Seeker HUD: routed config page at
/configs/<id>with Overview, JSON, Validate, Estimate, Sync, Push/Submit, and Generate tabs. - Seeker HUD: Workflows screen at
/workflows(rows select/workflows/<name>) lists, views, copies, edits, validates, and deletes enhancement-workflow YAML. - Seeker HUD: Analyze screen at
/analyzeruns the C3.x codebase-analysis tools against a directory, skill, or owner/repo target and records manifests underoutput/_analysis/. - Seeker HUD: Environment screen at
/environmentadds Doctor, Servers (start/stop the MCP HTTP and embedding servers), and Agents (install/reinstall a skill) panels alongside the MCP tools catalogue. - Seeker HUD: twelve new job types —
upload,translate,update,quality,analyze,split,push,submit,sync-check,generate-config,install-agent,server— back the new page actions; servers started from Environment run as jobs, and stopping the server cancels the job. - Seeker HUD: new
routes/package (one module per screen,register(app, ctx)) and a sharedHudContextcarrying workspace/job-manager state into every route.
Changed
- Sponsors: the RapidProxy (Silver) and Atlas Cloud placements were removed after those sponsorships lapsed (#470); Fluxion AI (Bronze) is the active sponsor.
- Docs: zh-CN README translation polish (#450).
- Seeker HUD: "Library" tab is now "Configs", "MCP Tools" is now "Seeker MCP".
- Seeker HUD: externally-installed skills now report a checker-derived quality score (was a fixed 70), their real install path as source (was "external install"), and no default "external" tag.
- Seeker HUD: opening a skill or config from any table, card, or job output now navigates to its routed page instead of opening a drawer;
/mcpredirects to/environment, where the MCP tools catalogue is a collapsible panel rather than its own screen.
Fixed
-
skill-seekers-doctorconsole script restored (#456) — the entry point had shipped broken from v3.7.0 through v3.9.1; a test now checks that every declaredskill-seekers-*console script resolves to a real function. -
Scheduled vector-database export workflow runs again — the inline Python in
.github/workflows/vector-db-export.ymlwas indented inside itspython3 -c "..."string, so every scheduled export failed withIndentationErrorbefore touching an adaptor. The blocks now start at column 0. -
Benchmark: the compare test is deterministic (#471).
-
The default enhancement level set with
skill-seekers configis honoured again —createresolves the level as CLI--enhance-level→ config-fileenhancement.level→ the user'sai_enhancement.default_enhance_level→ the shipped default (2). It had been consumed by the old dispatcher until the unifiedcreatecommand (Feb 2026) and silently ignored since, whileskill-seekers configkept displaying it. The fresh default is now 2 everywhere (it was 1 in the config manager and 2 on the CLI). The read is side-effect free: a plaincreatestill never creates a config directory. -
Docs —
HOW_TO_GUIDES.mdno longer tells you to runskill-seekers-enhanceon a single.mdfile (it takes the skill directory), andTROUBLESHOOTING.mdexplains theunrecognized arguments: --enhance-levelerror seen on 3.4.0 and earlier (raised in #465; the call path was removed in 3.5.0 — upgrade). Thearguments/enhance.pydocstring no longer claimsenhance_skill_local.pybuilds from the shared table; that worker has its own narrower parser. -
Seeker HUD: installed-plugin scan no longer reads
~/.claude/plugins/{marketplaces,repos,data}/(catalogue clones), which over-reported skills from plugins that were never installed. -
Seeker HUD: MCP HTTP transport is reported live only when /health identifies Skill Seekers' own server (was any listener on the port); packaging an external skill no longer writes the archive into the plugin cache.
-
Seeker HUD: a
SKILL.mdnested inside a skill directory (e.g. vercel'sai-sdk/upstream/) no longer shows up as a separate skill; pressing Enter in the top-bar search no longer triggers the opened drawer's first action; the Seeker MCP status cards no longer overflow; the web API test fixture now owns its ownJobManager, so test jobs stop leaking into~/.skill-seekers/ui/. -
Seeker HUD: config sync-state paths are read and written through one sanitised
sync_state_path()helper, closing a path-traversal read of arbitrary*_sync.jsonfiles via an unsanitised configname. -
Seeker HUD: sync checks now detect and report unreachable pages (non-zero exit,
status: "error", unreachable-page count) instead of silently recording a down docs site as zero changes. -
Seeker HUD: analysis runs are isolated per target by a hashed run directory, so concurrent runs no longer share state, and a stale previous run's leftover test output no longer falsely triggers the guides step. Running one tool now merges into the target's manifest instead of replacing it (a re-run clears only that tool's own output), and the manifest is written even when a tool exits non-zero, recording the failure alongside the results that survived.
-
Seeker HUD: uploads to the vector/RAG targets work again — the packager's
<name>-<target>.jsonoutput was filtered out by an archive-only extension check, so every Chroma/Weaviate/Pinecone upload failed with "produced no archive". -
Seeker HUD:
POST /api/environment/agents/{agent}/installno longer accepts a caller-suppliedskill_dir; the install source is always the workspace's own bootstrap output. Upload targets are derived from the adaptor registry, sofaiss/qdrantare rejected up front instead of queueing a job that dies in argparse. -
Seeker HUD: leaving a skill or config page with unsaved SKILL.md / JSON edits now asks for confirmation — the sidebar, header search and breadcrumbs used to discard the draft silently, since
BrowserRouterhas nouseBlocker. -
Seeker HUD: unmatched
/api/*paths now 404 for every HTTP method, without widening the SPA catch-all route's accepted methods. -
Seeker HUD: Doctor check levels are normalised (
pass/warn/fail→ok/warning/error) so the status pill reflects real failures, and agent install paths resolve under the HUD's workspace root instead of the server process's working directory. -
Unified multi-source builds preserve readable source references (#453) — converter-backed sources such as PDF and EPUB no longer leave their generated Markdown stranded in the scrape cache while the final skill contains only an index or raw JSON. Each source's
references/tree and adjacent assets are copied into an indexed namespace, preventing same-name collisions and preserving relative asset links; visual video frames andskip_scrapereference locations are preserved too.- Namespaces are
<scrape index>_<sanitized id>(raw data JSON included), so URL/path ids are filesystem-safe and same-named inputs stay apart. Links in the synthesized SKILL.md are rewritten to the unified locations instead of pointing at the sub-skill'sreferences/*.md. - The builder now recreates the
references/entries it owns on every build (source-type directories,api/,codebase_analysis/,conflicts.md); user files kept elsewhere underreferences/are left alone. A copy failure inside a cached sub-skill is logged and the build continues. - The unified API-mode enhancement prompt reads references through the same bounded reader the platform adaptors use (200k chars total, 30k per file, keyed by relative path). Previously it inlined every reference file unbounded, which the full PDF/EPUB trees would have pushed past any model's context window.
- Namespaces are