📦 deps(thirdparty): update snapshots
This commit is contained in:
+842
-13
File diff suppressed because it is too large
Load Diff
@@ -21,6 +21,7 @@
|
||||
"@phosphor-icons/react": "^2.1.10",
|
||||
"@supabase/supabase-js": "^2.98.0",
|
||||
"clsx": "^2.1.1",
|
||||
"express-rate-limit": "^8.5.2",
|
||||
"framer-motion": "^12.34.2",
|
||||
"github-markdown-css": "^5.9.0",
|
||||
"highlight.js": "^11.11.1",
|
||||
|
||||
@@ -2,253 +2,253 @@
|
||||
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
|
||||
<url>
|
||||
<loc>http://localhost/</loc>
|
||||
<lastmod>2026-06-21</lastmod>
|
||||
<lastmod>2026-06-23</lastmod>
|
||||
<changefreq>daily</changefreq>
|
||||
<priority>1.0</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>http://localhost/plugins</loc>
|
||||
<lastmod>2026-06-21</lastmod>
|
||||
<lastmod>2026-06-23</lastmod>
|
||||
<changefreq>weekly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>http://localhost/skill/ax-extract-workflow</loc>
|
||||
<lastmod>2026-06-21</lastmod>
|
||||
<lastmod>2026-06-23</lastmod>
|
||||
<changefreq>weekly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>http://localhost/skill/agent-creator</loc>
|
||||
<lastmod>2026-06-21</lastmod>
|
||||
<lastmod>2026-06-23</lastmod>
|
||||
<changefreq>weekly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>http://localhost/skill/remote-gpu-trainer</loc>
|
||||
<lastmod>2026-06-21</lastmod>
|
||||
<lastmod>2026-06-23</lastmod>
|
||||
<changefreq>weekly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>http://localhost/skill/ask-matt</loc>
|
||||
<lastmod>2026-06-21</lastmod>
|
||||
<lastmod>2026-06-23</lastmod>
|
||||
<changefreq>weekly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>http://localhost/skill/bugs-are-annoying</loc>
|
||||
<lastmod>2026-06-21</lastmod>
|
||||
<lastmod>2026-06-23</lastmod>
|
||||
<changefreq>weekly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>http://localhost/skill/codebase-design</loc>
|
||||
<lastmod>2026-06-21</lastmod>
|
||||
<lastmod>2026-06-23</lastmod>
|
||||
<changefreq>weekly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>http://localhost/skill/competitor-analysis</loc>
|
||||
<lastmod>2026-06-21</lastmod>
|
||||
<lastmod>2026-06-23</lastmod>
|
||||
<changefreq>weekly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>http://localhost/skill/diagnosing-bugs</loc>
|
||||
<lastmod>2026-06-21</lastmod>
|
||||
<lastmod>2026-06-23</lastmod>
|
||||
<changefreq>weekly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>http://localhost/skill/domain-modeling</loc>
|
||||
<lastmod>2026-06-21</lastmod>
|
||||
<lastmod>2026-06-23</lastmod>
|
||||
<changefreq>weekly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>http://localhost/skill/grill-me</loc>
|
||||
<lastmod>2026-06-21</lastmod>
|
||||
<lastmod>2026-06-23</lastmod>
|
||||
<changefreq>weekly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>http://localhost/skill/grill-with-docs</loc>
|
||||
<lastmod>2026-06-21</lastmod>
|
||||
<lastmod>2026-06-23</lastmod>
|
||||
<changefreq>weekly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>http://localhost/skill/grilling</loc>
|
||||
<lastmod>2026-06-21</lastmod>
|
||||
<lastmod>2026-06-23</lastmod>
|
||||
<changefreq>weekly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>http://localhost/skill/handoff</loc>
|
||||
<lastmod>2026-06-21</lastmod>
|
||||
<lastmod>2026-06-23</lastmod>
|
||||
<changefreq>weekly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>http://localhost/skill/image-generator</loc>
|
||||
<lastmod>2026-06-21</lastmod>
|
||||
<lastmod>2026-06-23</lastmod>
|
||||
<changefreq>weekly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>http://localhost/skill/improve-codebase-architecture</loc>
|
||||
<lastmod>2026-06-21</lastmod>
|
||||
<lastmod>2026-06-23</lastmod>
|
||||
<changefreq>weekly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>http://localhost/skill/learn</loc>
|
||||
<lastmod>2026-06-21</lastmod>
|
||||
<lastmod>2026-06-23</lastmod>
|
||||
<changefreq>weekly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>http://localhost/skill/lesson-generator</loc>
|
||||
<lastmod>2026-06-21</lastmod>
|
||||
<lastmod>2026-06-23</lastmod>
|
||||
<changefreq>weekly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>http://localhost/skill/llm-council</loc>
|
||||
<lastmod>2026-06-21</lastmod>
|
||||
<lastmod>2026-06-23</lastmod>
|
||||
<changefreq>weekly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>http://localhost/skill/loop-library</loc>
|
||||
<lastmod>2026-06-21</lastmod>
|
||||
<lastmod>2026-06-23</lastmod>
|
||||
<changefreq>weekly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>http://localhost/skill/mailtrap-managing-contacts</loc>
|
||||
<lastmod>2026-06-21</lastmod>
|
||||
<lastmod>2026-06-23</lastmod>
|
||||
<changefreq>weekly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>http://localhost/skill/mailtrap-sending-emails</loc>
|
||||
<lastmod>2026-06-21</lastmod>
|
||||
<lastmod>2026-06-23</lastmod>
|
||||
<changefreq>weekly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>http://localhost/skill/mailtrap-setting-up-sending-domain</loc>
|
||||
<lastmod>2026-06-21</lastmod>
|
||||
<lastmod>2026-06-23</lastmod>
|
||||
<changefreq>weekly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>http://localhost/skill/mailtrap-testing-with-sandbox</loc>
|
||||
<lastmod>2026-06-21</lastmod>
|
||||
<lastmod>2026-06-23</lastmod>
|
||||
<changefreq>weekly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>http://localhost/skill/prototype</loc>
|
||||
<lastmod>2026-06-21</lastmod>
|
||||
<lastmod>2026-06-23</lastmod>
|
||||
<changefreq>weekly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>http://localhost/skill/setup-matt-pocock-skills</loc>
|
||||
<lastmod>2026-06-21</lastmod>
|
||||
<lastmod>2026-06-23</lastmod>
|
||||
<changefreq>weekly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>http://localhost/skill/survey-generator</loc>
|
||||
<lastmod>2026-06-21</lastmod>
|
||||
<lastmod>2026-06-23</lastmod>
|
||||
<changefreq>weekly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>http://localhost/skill/tdd</loc>
|
||||
<lastmod>2026-06-21</lastmod>
|
||||
<lastmod>2026-06-23</lastmod>
|
||||
<changefreq>weekly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>http://localhost/skill/teach</loc>
|
||||
<lastmod>2026-06-21</lastmod>
|
||||
<lastmod>2026-06-23</lastmod>
|
||||
<changefreq>weekly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>http://localhost/skill/to-issues</loc>
|
||||
<lastmod>2026-06-21</lastmod>
|
||||
<lastmod>2026-06-23</lastmod>
|
||||
<changefreq>weekly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>http://localhost/skill/to-prd</loc>
|
||||
<lastmod>2026-06-21</lastmod>
|
||||
<lastmod>2026-06-23</lastmod>
|
||||
<changefreq>weekly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>http://localhost/skill/tools-page-seo-optimizer</loc>
|
||||
<lastmod>2026-06-21</lastmod>
|
||||
<lastmod>2026-06-23</lastmod>
|
||||
<changefreq>weekly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>http://localhost/skill/triage</loc>
|
||||
<lastmod>2026-06-21</lastmod>
|
||||
<lastmod>2026-06-23</lastmod>
|
||||
<changefreq>weekly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>http://localhost/skill/wiki-builder</loc>
|
||||
<lastmod>2026-06-21</lastmod>
|
||||
<lastmod>2026-06-23</lastmod>
|
||||
<changefreq>weekly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>http://localhost/skill/writing-great-skills</loc>
|
||||
<lastmod>2026-06-21</lastmod>
|
||||
<lastmod>2026-06-23</lastmod>
|
||||
<changefreq>weekly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>http://localhost/skill/yao-meta-skill</loc>
|
||||
<lastmod>2026-06-21</lastmod>
|
||||
<lastmod>2026-06-23</lastmod>
|
||||
<changefreq>weekly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>http://localhost/skill/youtube-notetaker</loc>
|
||||
<lastmod>2026-06-21</lastmod>
|
||||
<lastmod>2026-06-23</lastmod>
|
||||
<changefreq>weekly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>http://localhost/skill/android-ui-journey-testing</loc>
|
||||
<lastmod>2026-06-21</lastmod>
|
||||
<lastmod>2026-06-23</lastmod>
|
||||
<changefreq>weekly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>http://localhost/skill/3d-ui</loc>
|
||||
<lastmod>2026-06-21</lastmod>
|
||||
<lastmod>2026-06-23</lastmod>
|
||||
<changefreq>weekly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>http://localhost/skill/ai-native-ui</loc>
|
||||
<lastmod>2026-06-21</lastmod>
|
||||
<lastmod>2026-06-23</lastmod>
|
||||
<changefreq>weekly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>http://localhost/skill/aurora-ui</loc>
|
||||
<lastmod>2026-06-21</lastmod>
|
||||
<lastmod>2026-06-23</lastmod>
|
||||
<changefreq>weekly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
|
||||
@@ -562,15 +562,17 @@
|
||||
"date_added": "2026-06-20",
|
||||
"plugin": {
|
||||
"targets": {
|
||||
"codex": "supported",
|
||||
"claude": "supported"
|
||||
"codex": "blocked",
|
||||
"claude": "blocked"
|
||||
},
|
||||
"setup": {
|
||||
"type": "none",
|
||||
"summary": "",
|
||||
"docs": null
|
||||
},
|
||||
"reasons": []
|
||||
"reasons": [
|
||||
"explicit_target_restriction"
|
||||
]
|
||||
}
|
||||
},
|
||||
{
|
||||
|
||||
@@ -6,6 +6,7 @@ import { execSync } from 'child_process';
|
||||
import { fileURLToPath } from 'url';
|
||||
import { createRequire } from 'module';
|
||||
import crypto from 'crypto';
|
||||
import { ipKeyGenerator, rateLimit } from 'express-rate-limit';
|
||||
|
||||
const __filename = fileURLToPath(import.meta.url);
|
||||
const __dirname = path.dirname(__filename);
|
||||
@@ -20,6 +21,9 @@ const REPO_ZIP_URL = 'https://github.com/sickn33/antigravity-awesome-skills/arch
|
||||
const COMMITS_API_URL = 'https://api.github.com/repos/sickn33/antigravity-awesome-skills/commits/main';
|
||||
const SHA_FILE = path.join(__dirname, '.last-sync-sha');
|
||||
const ARCHIVE_ROOT = 'antigravity-awesome-skills-main/';
|
||||
const SAFE_SKILL_ASSET_RE = /^\/skills\/[A-Za-z0-9._/-]+$/;
|
||||
const REFRESH_RATE_LIMIT_MS = 30_000;
|
||||
const STATIC_RATE_LIMIT_MS = 25;
|
||||
|
||||
// ─── Utility helpers ───
|
||||
|
||||
@@ -114,6 +118,45 @@ function isPathInside(parentPath, childPath) {
|
||||
return relative === '' || (!relative.startsWith('..') && !path.isAbsolute(relative));
|
||||
}
|
||||
|
||||
function getSafeSkillAssetPath(url = '') {
|
||||
let pathname;
|
||||
try {
|
||||
pathname = new URL(url, 'http://localhost').pathname;
|
||||
} catch {
|
||||
return null;
|
||||
}
|
||||
if (!SAFE_SKILL_ASSET_RE.test(pathname)) return null;
|
||||
const parts = pathname.split('/').filter(Boolean);
|
||||
if (parts[0] !== 'skills' || parts.some((part) => part === '.' || part === '..')) return null;
|
||||
return path.join(ROOT_DIR, ...parts);
|
||||
}
|
||||
|
||||
const staticRateLimit = rateLimit({
|
||||
windowMs: STATIC_RATE_LIMIT_MS,
|
||||
limit: 1,
|
||||
standardHeaders: false,
|
||||
legacyHeaders: false,
|
||||
skip: () => process.env.NODE_ENV === 'test',
|
||||
keyGenerator: (req) => `${ipKeyGenerator(getRequestRemoteAddress(req) || '127.0.0.1')}:${req.url || ''}`,
|
||||
handler: (_req, res) => {
|
||||
res.statusCode = 429;
|
||||
res.end('Rate limit exceeded');
|
||||
},
|
||||
});
|
||||
|
||||
const refreshRateLimit = rateLimit({
|
||||
windowMs: REFRESH_RATE_LIMIT_MS,
|
||||
limit: 1,
|
||||
standardHeaders: false,
|
||||
legacyHeaders: false,
|
||||
skip: () => process.env.NODE_ENV === 'test',
|
||||
keyGenerator: (req) => ipKeyGenerator(getRequestRemoteAddress(req) || '127.0.0.1'),
|
||||
handler: (_req, res) => {
|
||||
res.statusCode = 429;
|
||||
res.end(JSON.stringify({ success: false, error: 'Refresh rate limit exceeded' }));
|
||||
},
|
||||
});
|
||||
|
||||
function normalizeArchiveEntryName(entryName) {
|
||||
return String(entryName || '').replace(/\\/g, '/').replace(/^\.\//, '');
|
||||
}
|
||||
@@ -512,6 +555,10 @@ export default function refreshSkillsPlugin() {
|
||||
return {
|
||||
name: 'refresh-skills',
|
||||
configureServer(server) {
|
||||
server.middlewares.use('/skills.json', staticRateLimit);
|
||||
server.middlewares.use('/skills', staticRateLimit);
|
||||
server.middlewares.use('/api/refresh-skills', refreshRateLimit);
|
||||
|
||||
// Serve /skills.json directly from ROOT_DIR
|
||||
server.middlewares.use('/skills.json', (req, res, next) => {
|
||||
const filePath = path.join(ROOT_DIR, 'skills_index.json');
|
||||
@@ -527,8 +574,8 @@ export default function refreshSkillsPlugin() {
|
||||
server.middlewares.use((req, res, next) => {
|
||||
if (!req.url || !req.url.startsWith('/skills/')) return next();
|
||||
|
||||
const relativePath = decodeURIComponent(req.url.replace(/\?.*$/, ''));
|
||||
const filePath = path.join(ROOT_DIR, relativePath);
|
||||
const filePath = getSafeSkillAssetPath(req.url);
|
||||
if (!filePath) return next();
|
||||
const safeRealPath = fs.existsSync(filePath)
|
||||
? resolveSafeRealPath(path.join(ROOT_DIR, 'skills'), filePath)
|
||||
: null;
|
||||
|
||||
+12
-3
@@ -110,11 +110,20 @@ async function loadRefreshHandler() {
|
||||
};
|
||||
|
||||
refreshSkillsPlugin().configureServer(server);
|
||||
const registration = registrations.find((item) => item.path === '/api/refresh-skills');
|
||||
if (!registration) {
|
||||
const apiHandlers = registrations
|
||||
.filter((item) => item.path === '/api/refresh-skills')
|
||||
.map((item) => item.handler);
|
||||
if (!apiHandlers.length) {
|
||||
throw new Error('refresh-skills handler not registered');
|
||||
}
|
||||
return registration.handler;
|
||||
return async (req, res) => {
|
||||
let index = 0;
|
||||
const next = async () => {
|
||||
const handler = apiHandlers[index++];
|
||||
if (handler) await handler(req, res, next);
|
||||
};
|
||||
await next();
|
||||
};
|
||||
}
|
||||
|
||||
describe('refresh-skills plugin security', () => {
|
||||
|
||||
Reference in New Issue
Block a user