github yusufkaraaslan/Skill_Seekers v3.10.0

3 hours ago

[3.10.0] - 2026-09-30

Theme: Seeker HUD (beta) — a local web UI for the whole toolchain — plus a path-traversal security fix, three machine-readable CLI commands, an opt-in SQLite skill search index, MiniMax video input, and PDF vector-figure extraction.

The Seeker HUD web UI is in beta. It ships in this release for early feedback: screens, /api/* routes, and the UI state stored under ~/.skill-seekers/ui/ may change between minor releases without a deprecation period. The CLI, the MCP server, and every existing platform adaptor are unaffected. Please report HUD issues on GitHub.

Security

  • Path traversal in the fetch_config MCP tool (CWE-22) (#462 reported by @Harmenszoon, fixed in PR #464 by @emecii) — the git-URL mode passed the raw config_name argument into cache_dir / f"temp_{name}", and clone_or_pull both deletes that path (on refresh or a failed pull) and clones attacker-chosen content into it, so a crafted name could delete or overwrite directories outside the cache. The shared clone boundary now validates the cache name, and fetch_config validates config_name once for all three modes in both MCP servers (the named-source and API modes wrote <destination>/<name>.json from the raw name too). All name checks now go through one allowlist (services/path_safety.validate_path_segment: leading letter or digit, then letters, digits, ., _, -), which also rejects NUL bytes, whitespace and dot-files such as .git; the workflow, config-publisher and marketplace validators delegate to it. A failed pull on a cached clone now falls through to a fresh clone instead of deleting the cache and reporting an error.

Added

  • Seeker HUD (beta) — a local web app for the whole toolchain. pip install "skill-seekers[ui]" then skill-seekers ui opens a React + FastAPI interface on http://127.0.0.1:8770 (loopback only) with Overview, Create, Skills, Configs, Workflows, Analyze, Environment, and job-history screens; every long-running action runs as a streamed job. The built frontend is bundled into the wheel, so no Node toolchain is needed to use it. The beta status is shown in the sidebar and the launcher banner and documented in docs/guides/WEB_UI.md; the HUD-specific entries below describe the screens in detail.
  • MiniMax-M3 video input and thinking modes (#468 by @octo-patch) — AgentClient.call_with_video() sends a local MP4/AVI/MOV/MKV clip as an OpenAI-compatible video_url part (MiniMax-M3 only, 50 MB inline cap enforced before the request), and MINIMAX_THINKING=adaptive|disabled (or a thinking= call argument) is carried in the request body. Both are registry-driven — supports_video, video_models, video_max_bytes, thinking_modes, thinking_env on the provider entry — so _call_api still never branches on a provider name. The thinking mode is validated once at client construction; under the Anthropic protocol it is ignored with a warning instead of silently dropped. No built-in pipeline calls the video path yet.
  • Opt-in SQLite search index for generated skills (#393, PR #463 by @emecii) — skill-seekers create <source> --index (or "index": true in a config file) writes scripts/index.db (FTS5 with BM25, LIKE-style fallback where FTS5 is unavailable) and a stdlib-only scripts/search.py that returns ranked file#anchor pointers, and appends a search-first block to SKILL.md. Off by default, Markdown untouched, zero new dependencies; the Claude packager already ships scripts/. Sections are split at headings outside fenced code blocks, index.md table-of-contents pages are skipped, anchors follow GitHub's rules, query tokens are quoted so NOT/OR are plain words, and nothing is installed when a skill has no indexable references. Enhancement and indexing now resolve the skill directory the same way the scrapers do, including a config-file output_dir.
  • skill-seekers doctor --json (#459 by @Whxuan0701) — machine-readable diagnostics for CI and agents: version, per-check results, pass/warn/fail summary, healthy and exit_code, as exactly one JSON document on stdout. Import-time noise from dependencies is forwarded to stderr, a crashing check is reported as {"error": ...}, and verbose_detail (which carries masked API-key fragments) is only populated with --verbose, matching the human report. The doctor command now has a section in the CLI reference.
  • skill-seekers quality <dir> --json (#458 by @Whxuan0701) — the quality report on stdout as exactly one JSON document, for pipelines. No default quality_report.json is written in this mode (--output still saves a copy), diagnostics and the threshold-gate reason go to stderr, errors are emitted as {"error": ...}, and --report/--json are mutually exclusive. The report file is now written before anything is printed, so a failed --output write cannot leave a complete report on stdout with a non-zero exit.
  • skill-seekers detect <source> [--json] (#457 by @Whxuan0701) — read-only preview of how create would classify and parse a source, for scripts, CI and agent workflows. Runs the same detect-and-validate stage as create (now shared as SourceDetector.resolve), reports valid / validation_error, always emits JSON on stdout under --json (errors included), and exits 2 for undetectable or unusable sources. Documented in the CLI reference, AGENTS.md and the docs index.
  • Fluxion AI joins as a Bronze sponsor — small logo in the README sponsor section across all 12 languages, captioned "Sponsor — Bronze" per rule 2, listed in SPONSORS.md with since: September 2026. Sponsorship active on GitHub Sponsors since 2026-09-16; link carries standard utm_* parameters only (rule 4) and the transparent PNG passed asset review (rule 6).
  • Vector figures are extracted from PDF pages (#434, PR #451 by @bferanmi806-sketch) — PDF image extraction relied on page.get_images() + doc.extract_image(xref), which only see embedded raster objects, so vector-only diagrams reached neither the extracted assets nor the generated skill. Meaningful vector drawing clusters are now rendered as PNG assets alongside the raster path, with nearby labels kept in the clip. Entries in extracted_images carry source (raster/vector) and bbox, and pages gain vector_figures_count (images_count stays raster-only, so total_images keeps its meaning for the generated statistics).
    • Detection is deliberately conservative and rejects page frames, separator rules, line-ruled tables and small decorative marks. A cluster made entirely of wide fill-only bands is page furniture — that is what a shaded code block, callout or admonition looks like — and is rejected, so ordinary docs PDFs do not emit PNGs of their own code samples.
    • Figures are emitted in reading order rather than by area, so the vectorN suffix and the order in the generated reference markdown follow the page.
    • --min-image-size now applies to vector figures on the same pixel basis as rasters; previously the flag silently did nothing for them.
    • Raster/vector de-duplication compares IoU, not intersection-over-smaller-area. Under the latter, any fully contained raster scored 1.0, so a 30x30pt embedded logo deleted the entire architecture diagram enclosing it.
    • Cost guardrails: clustering is skipped above VECTOR_MAX_DRAWINGS (2000) or VECTOR_MAX_CLUSTERS (400), and cluster membership is resolved through a coarse grid index instead of comparing every cluster against every drawing. A 3000-path page (scatter plot, map, CAD export) went from 56.3s and zero figures to 0.17s — this path is on by default, so that cost was previously paid per page.
  • Sponsor entries in sponsors.json gain an optional since field and a logo_svg vector companion.
  • Readability metrics in the quality checker (#228, PR #441 by @bferanmi806-sketch) — skill-seekers quality now reports Flesch Reading Ease, Flesch-Kincaid Grade Level, average sentence length, and average paragraph length for SKILL.md prose, plus aggregated notes for over-long sentences and paragraphs. YAML frontmatter, fenced code, and inline code are excluded, and no new dependency is added. Scores use English-language formulas and may be inaccurate for other languages.
    • Readability is reported as info, never as warnings: quality_score deducts 5 points per warning and quality --threshold exits non-zero in CI, so emitting warnings would have dropped scores by up to 10 points and failed existing quality gates on skills that had not changed. A regression test pins this contract.
  • Seeker HUD: skills are tagged by origin (seeker / plugin · <name> / manual) with a filter; external skills are read-only except port/package (API returns 403 on mutation).
  • Seeker HUD: GET /api/mcp/status probes the stdio/HTTP transports; the Seeker MCP tab shows real status and copyable client config.
  • Seeker HUD: live skill search shared between the top bar and the grid; configs search; 25/50/100 paging on the skills, configs and workflows lists.
  • Seeker HUD: routed skill page at /skills/<id> with Overview, SKILL.md, Files, Installs, Enhance, Analysis, Export, and History tabs, replacing the skill drawer.
  • Seeker HUD: routed config page at /configs/<id> with Overview, JSON, Validate, Estimate, Sync, Push/Submit, and Generate tabs.
  • Seeker HUD: Workflows screen at /workflows (rows select /workflows/<name>) lists, views, copies, edits, validates, and deletes enhancement-workflow YAML.
  • Seeker HUD: Analyze screen at /analyze runs the C3.x codebase-analysis tools against a directory, skill, or owner/repo target and records manifests under output/_analysis/.
  • Seeker HUD: Environment screen at /environment adds Doctor, Servers (start/stop the MCP HTTP and embedding servers), and Agents (install/reinstall a skill) panels alongside the MCP tools catalogue.
  • Seeker HUD: twelve new job types — upload, translate, update, quality, analyze, split, push, submit, sync-check, generate-config, install-agent, server — back the new page actions; servers started from Environment run as jobs, and stopping the server cancels the job.
  • Seeker HUD: new routes/ package (one module per screen, register(app, ctx)) and a shared HudContext carrying workspace/job-manager state into every route.

Changed

  • Sponsors: the RapidProxy (Silver) and Atlas Cloud placements were removed after those sponsorships lapsed (#470); Fluxion AI (Bronze) is the active sponsor.
  • Docs: zh-CN README translation polish (#450).
  • Seeker HUD: "Library" tab is now "Configs", "MCP Tools" is now "Seeker MCP".
  • Seeker HUD: externally-installed skills now report a checker-derived quality score (was a fixed 70), their real install path as source (was "external install"), and no default "external" tag.
  • Seeker HUD: opening a skill or config from any table, card, or job output now navigates to its routed page instead of opening a drawer; /mcp redirects to /environment, where the MCP tools catalogue is a collapsible panel rather than its own screen.

Fixed

  • skill-seekers-doctor console script restored (#456) — the entry point had shipped broken from v3.7.0 through v3.9.1; a test now checks that every declared skill-seekers-* console script resolves to a real function.

  • Scheduled vector-database export workflow runs again — the inline Python in .github/workflows/vector-db-export.yml was indented inside its python3 -c "..." string, so every scheduled export failed with IndentationError before touching an adaptor. The blocks now start at column 0.

  • Benchmark: the compare test is deterministic (#471).

  • The default enhancement level set with skill-seekers config is honoured again — create resolves the level as CLI --enhance-level → config-file enhancement.level → the user's ai_enhancement.default_enhance_level → the shipped default (2). It had been consumed by the old dispatcher until the unified create command (Feb 2026) and silently ignored since, while skill-seekers config kept displaying it. The fresh default is now 2 everywhere (it was 1 in the config manager and 2 on the CLI). The read is side-effect free: a plain create still never creates a config directory.

  • Docs — HOW_TO_GUIDES.md no longer tells you to run skill-seekers-enhance on a single .md file (it takes the skill directory), and TROUBLESHOOTING.md explains the unrecognized arguments: --enhance-level error seen on 3.4.0 and earlier (raised in #465; the call path was removed in 3.5.0 — upgrade). The arguments/enhance.py docstring no longer claims enhance_skill_local.py builds from the shared table; that worker has its own narrower parser.

  • Seeker HUD: installed-plugin scan no longer reads ~/.claude/plugins/{marketplaces,repos,data}/ (catalogue clones), which over-reported skills from plugins that were never installed.

  • Seeker HUD: MCP HTTP transport is reported live only when /health identifies Skill Seekers' own server (was any listener on the port); packaging an external skill no longer writes the archive into the plugin cache.

  • Seeker HUD: a SKILL.md nested inside a skill directory (e.g. vercel's ai-sdk/upstream/) no longer shows up as a separate skill; pressing Enter in the top-bar search no longer triggers the opened drawer's first action; the Seeker MCP status cards no longer overflow; the web API test fixture now owns its own JobManager, so test jobs stop leaking into ~/.skill-seekers/ui/.

  • Seeker HUD: config sync-state paths are read and written through one sanitised sync_state_path() helper, closing a path-traversal read of arbitrary *_sync.json files via an unsanitised config name.

  • Seeker HUD: sync checks now detect and report unreachable pages (non-zero exit, status: "error", unreachable-page count) instead of silently recording a down docs site as zero changes.

  • Seeker HUD: analysis runs are isolated per target by a hashed run directory, so concurrent runs no longer share state, and a stale previous run's leftover test output no longer falsely triggers the guides step. Running one tool now merges into the target's manifest instead of replacing it (a re-run clears only that tool's own output), and the manifest is written even when a tool exits non-zero, recording the failure alongside the results that survived.

  • Seeker HUD: uploads to the vector/RAG targets work again — the packager's <name>-<target>.json output was filtered out by an archive-only extension check, so every Chroma/Weaviate/Pinecone upload failed with "produced no archive".

  • Seeker HUD: POST /api/environment/agents/{agent}/install no longer accepts a caller-supplied skill_dir; the install source is always the workspace's own bootstrap output. Upload targets are derived from the adaptor registry, so faiss/qdrant are rejected up front instead of queueing a job that dies in argparse.

  • Seeker HUD: leaving a skill or config page with unsaved SKILL.md / JSON edits now asks for confirmation — the sidebar, header search and breadcrumbs used to discard the draft silently, since BrowserRouter has no useBlocker.

  • Seeker HUD: unmatched /api/* paths now 404 for every HTTP method, without widening the SPA catch-all route's accepted methods.

  • Seeker HUD: Doctor check levels are normalised (pass/warn/fail → ok/warning/error) so the status pill reflects real failures, and agent install paths resolve under the HUD's workspace root instead of the server process's working directory.

  • Unified multi-source builds preserve readable source references (#453) — converter-backed sources such as PDF and EPUB no longer leave their generated Markdown stranded in the scrape cache while the final skill contains only an index or raw JSON. Each source's references/ tree and adjacent assets are copied into an indexed namespace, preventing same-name collisions and preserving relative asset links; visual video frames and skip_scrape reference locations are preserved too.

    • Namespaces are <scrape index>_<sanitized id> (raw data JSON included), so URL/path ids are filesystem-safe and same-named inputs stay apart. Links in the synthesized SKILL.md are rewritten to the unified locations instead of pointing at the sub-skill's references/*.md.
    • The builder now recreates the references/ entries it owns on every build (source-type directories, api/, codebase_analysis/, conflicts.md); user files kept elsewhere under references/ are left alone. A copy failure inside a cached sub-skill is logged and the build continues.
    • The unified API-mode enhancement prompt reads references through the same bounded reader the platform adaptors use (200k chars total, 30k per file, keyed by relative path). Previously it inlined every reference file unbounded, which the full PDF/EPUB trees would have pushed past any model's context window.

Don't miss a new Skill_Seekers release

NewReleases is sending notifications on new releases.