Skip to content

Pin Keito skill installer package#16

Merged
sionsmith merged 3 commits into
mainfrom
codex/skill-installer-security
May 12, 2026
Merged

Pin Keito skill installer package#16
sionsmith merged 3 commits into
mainfrom
codex/skill-installer-security

Conversation

@sionsmith
Copy link
Copy Markdown
Contributor

@sionsmith sionsmith commented May 12, 2026

Summary

  • pin the keito skill install npm installer hop to skills@1.5.6 instead of a floating installer package
  • set the default skill source to the public GitHub repo osodevops/keito-skill
  • keep the skill source as GitHub; npm is only used to execute the pinned open skills installer package
  • document the install model in the README and add the CI badge
  • update CLI help/errors so they do not advertise a bare npx skills add flow
  • keep the fake npx integration test aligned with the pinned package
  • bump CLI release version to 0.1.6 with changelog entry

Verification

  • cargo fmt --check
  • cargo test
  • cargo clippy --all-targets -- -D warnings
  • stale repo scan: no keito-ai/keito-skill references
  • floating skills installer scan: no floating installer package or bare npx skills add references
  • floating GitHub Actions scan: no workflow action refs using @v*, @main, @master, or @latest

@sionsmith sionsmith merged commit e16f03d into main May 12, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant