import assert from "node:assert/strict"; import { test } from "node:test"; import { build } from "esbuild"; import { Miniflare, convertV4MiniflareOptions } from "miniflare"; const origin = { kind: "upload", filename: "fixture.skill.json" }; const instructions = ( body = "Read references/guide.md before writing.", fields = "", ) => `---\nname: fixture-skill\ndescription: Useful fixture instructions\nmetadata:\n version: "1.2.3-beta.1+build.7"\n${fields}---\n${body}`; const entry = (content = instructions()) => ({ path: "SKILL.md", content }); const file = (path, content = "Resource", encoding = "text") => ({ path, content, encoding, }); const packageOf = (...files) => ({ formatVersion: 1, files }); test( "Skill packages validate a bounded portable contract and load through native Agents Skills without execution", { timeout: 60_000 }, async (t) => { const bundle = await build({ entryPoints: ["tests/fixtures/skill-package-worker.ts"], alias: { path: "node:path" }, target: "es2022", bundle: true, write: false, format: "esm", platform: "neutral", conditions: ["workerd", "worker", "browser"], mainFields: ["module", "main"], external: ["cloudflare:*", "node:*"], }); const worker = new Miniflare( convertV4MiniflareOptions({ modules: true, script: bundle.outputFiles[0].text, compatibilityDate: "2026-09-04", compatibilityFlags: ["nodejs_compat"], }), ); const validate = async (envelope, options = {}) => ( await worker.dispatchFetch("https://fixture.example", { method: "POST", body: JSON.stringify({ envelope, origin, ...options }), }) ).json(); const valid = async (envelope, options) => { const result = await validate(envelope, options); assert.equal(result.ok, true, JSON.stringify(result)); return result; }; const invalid = async (envelope, code, options, label = code) => { const result = await validate(envelope, options); assert.equal(result.ok, false, label); if (code) assert.equal(result.code, code, `${label}: ${JSON.stringify(result)}`); assert.equal(typeof result.path, "string"); return result; }; try { await t.test( "native Skills preserve sibling and nested Markdown references", async () => { const paths = [ "SKILL-MECHANICS.md", "agents/reviewer.md", "scripts/NOTES.MD", ]; const result = await valid( packageOf( entry(), ...paths.map((path) => file(path, `Read ${path}`)), ), { native: true }, ); assert.deepEqual(result.metadata.scripts, []); assert.deepEqual( result.resources.map((resource) => resource.content), paths.map((path) => `Read ${path}`), ); assert.ok(result.read.includes("Read SKILL-MECHANICS.md")); assert.equal(result.executed, false); }, ); for (const [label, metadataLines] of [ ["object", " __proto__: { hidden: unvalidated }"], ["cycle", " __proto__: &a [*a]"], ["oversized string", ` __proto__: "${"x".repeat(1025)}"`], [ "entry count", `${Array.from({ length: 31 }, (_, index) => ` extra-${index}: value`).join("\n")}\n __proto__: value`, ], ]) await t.test( `rejects own __proto__ metadata ${label} through native validation`, async () => { await invalid( packageOf(entry(instructions(undefined, `${metadataLines}\n`))), "invalid_metadata", { native: true }, ); }, ); await t.test( "preserves valid leading BOM resource bytes through native reading", async () => { const content = "\uFEFF# Guide"; const bom = await valid( packageOf(entry(), file("references/guide.md", content)), { native: true }, ); assert.equal(bom.resources[0].content, content); assert.equal(bom.resources[0].size, Buffer.byteLength(content)); assert.equal( bom.metadata.totalBytes, Buffer.byteLength(instructions()) + Buffer.byteLength(content), ); assert.ok(bom.read.includes(content)); }, ); await t.test( "reports the original index of unsorted invalid input", async () => { const failure = await invalid( packageOf(file("resources/guide.exe"), entry()), "unsupported_file", ); assert.equal(failure.path, "files.0.path"); }, ); await t.test("reports corrective metadata bounds", async () => { const failure = await invalid( packageOf( entry(instructions(undefined, `license: "${"L".repeat(201)}"\n`)), ), "invalid_metadata", ); assert.equal(failure.path, "SKILL.md.license"); assert.match(failure.message, /200/); assert.ok(!failure.message.includes("L".repeat(201))); }); await t.test( "identifies unrecognized frontmatter and envelope keys", async () => { const frontmatter = await invalid( packageOf( entry(instructions(undefined, "unsupported-field: value\n")), ), "invalid_metadata", ); assert.equal(frontmatter.path, "SKILL.md.unsupported-field"); const envelope = await invalid( { ...packageOf(entry()), claimedOrigin: "trusted" }, "invalid_package", ); assert.equal(envelope.path, "claimedOrigin"); }, ); await t.test("preserves semantic version correction", async () => { const failure = await invalid( packageOf( entry(instructions().replace('"1.2.3-beta.1+build.7"', '"01.0.0"')), ), "invalid_metadata", ); assert.match(failure.path, /metadata/); assert.match(failure.message, /semantic version|semver|1\.0\.0/i); }); const png = "iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8/x8AAwMCAO+jL1sAAAAASUVORK5CYII="; const script = 'globalThis.__skillPackageExecuted = true; throw new Error("Skill scripts must remain inert");'; const files = [ entry( instructions( undefined, 'license: MIT\ncompatibility: Cloudflare Workers\nallowed-tools: "shell network"\n', ), ), file("references/guide.md", "# A trusted local fixture reference"), file("resources/data.json", '{"value":1}'), file("scripts/process.js", script), file("assets/pixel.png", png, "base64"), ]; const result = await valid(packageOf(...files), { native: true }); assert.equal(result.metadata.name, "fixture-skill"); assert.equal(result.metadata.version, "1.2.3-beta.1+build.7"); assert.equal(result.metadata.fileCount, 5); assert.deepEqual(result.metadata.scripts, ["scripts/process.js"]); assert.match(result.metadata.fingerprint, /^[a-f0-9]{64}$/); assert.equal( result.metadata.totalBytes, files.reduce( (total, item) => total + Buffer.byteLength( item.content, item.encoding === "base64" ? "base64" : "utf8", ), 0, ), ); assert.equal(result.listed[0].sourceId, "fixture-source"); assert.equal( result.loaded.body, "Read references/guide.md before writing.", ); assert.equal(result.loaded.version, result.metadata.version); assert.equal( result.resources.find((item) => item.path === "scripts/process.js") .content, script, ); assert.equal( result.resources.find((item) => item.path === "assets/pixel.png") .mimeType, "image/png", ); assert.match(result.catalog, /fixture-skill/); assert.match(result.activated, /Read references\/guide\.md/); assert.match(result.read, /skill_resource/); assert.deepEqual(result.tools.sort(), [ "activate_skill", "read_skill_resource", ]); assert.deepEqual(result.warnings, []); assert.equal(result.executed, false); const reversed = await valid(packageOf(...files.toReversed()), { origin: { kind: "bundled", release: "0.2.0" }, }); assert.equal( reversed.metadata.fingerprint, result.metadata.fingerprint, "file order and provenance do not change content identity", ); const changed = await valid( packageOf( ...files.map((item) => item.path === "resources/data.json" ? { ...item, content: '{"value":2}' } : item, ), ), ); assert.notEqual( changed.metadata.fingerprint, result.metadata.fingerprint, ); await invalid(packageOf(entry()), "duplicate_skill", { reservedNames: ["fixture-skill"], }); await valid(packageOf(entry()), { reservedNames: ["another-skill"] }); for (const envelope of [ { formatVersion: 2, files: [entry()] }, { files: [entry()] }, { ...packageOf(entry()), origin: { kind: "bundled", release: "claimed" }, }, packageOf({ ...entry(), executable: true }), packageOf(), ]) await invalid(envelope, "invalid_package"); await invalid( packageOf(file("references/guide.md")), "missing_instructions", ); await invalid( packageOf(entry("No YAML frontmatter")), "invalid_metadata", ); for (const version of [ "1", "1.2", "v1.2.3", "01.2.3", "1.2.3-01", "1.2.3-a.01", "1.2.3-", "1.2.3+", "", ]) await invalid( packageOf( entry( instructions().replace( '"1.2.3-beta.1+build.7"', JSON.stringify(version), ), ), ), "invalid_metadata", undefined, `invalid version ${version}`, ); for (const version of [ "0.0.0", "1.0.0", "1.2.3-0", "1.2.3-alpha-beta.0+001", ]) await valid( packageOf( entry( instructions().replace( '"1.2.3-beta.1+build.7"', JSON.stringify(version), ), ), ), ); for (const name of [ "Uppercase", "has_underscore", "two words", "-prefix", "suffix-", "two--dashes", "a".repeat(65), ]) await invalid( packageOf( entry( instructions().replace( "name: fixture-skill", `name: ${JSON.stringify(name)}`, ), ), ), "invalid_metadata", ); await invalid( packageOf( entry( instructions().replace(' version: "1.2.3-beta.1+build.7"\n', ""), ), ), "invalid_metadata", ); await invalid( packageOf( entry( instructions().replace( "description: Useful fixture instructions", 'description: " "', ), ), ), "invalid_metadata", ); await invalid( packageOf(entry(instructions(undefined, "unknown: forbidden\n"))), "invalid_metadata", ); await invalid( packageOf(entry(instructions(undefined, "name: duplicate-name\n"))), "invalid_metadata", ); await invalid( packageOf( entry( instructions().replace( " version:", " version: 1.0.0\n version:", ), ), ), "invalid_metadata", ); await invalid( packageOf( entry( instructions().replace( "description: Useful fixture instructions", "description: *missing", ), ), ), "invalid_metadata", ); const aliasBomb = `description: &a [a,a,a,a,a,a,a,a,a,a]\nmetadata:\n version: &b [*a,*a,*a,*a,*a,*a,*a,*a,*a,*a]\n expansion: [*b,*b,*b,*b,*b,*b,*b,*b,*b,*b]`; await invalid( packageOf( entry(`---\nname: fixture-skill\n${aliasBomb}\n---\nInstructions`), ), "invalid_metadata", ); await invalid( packageOf(entry(instructions(" \n\t"))), "invalid_instructions", ); for (const path of [ "../bad.md", "resources/../bad.md", "resources/./bad.md", "/resources/file.md", "resources\\file.md", "resources/%2e%2e/file.md", "resources//file.md", "resources/.hidden.md", "resources/file.md/", "resources/file..", "resources/CON.txt", "assets/NUL.png", "scripts/COM1.js", "resources/lpt9/readme.md", "C:/resources/file.md", "resources/a\u0000.md", "other/file.txt", ]) await invalid( packageOf(entry(), file(path)), "invalid_path", undefined, path, ); for (const paths of [ ["SKILL.md", "skill.md"], ["resources/Readme.md", "resources/readme.md"], ["resources/data.json", "resources/data.json/file.md"], ["resources/DATA.json", "resources/data.json/file.md"], ["SKILL.md", "SKILL.md"], ]) await invalid( packageOf(entry(), ...paths.map((path) => file(path))), "duplicate_path", undefined, paths.join(" + "), ); for (const resource of [ file("scripts/tool.ts"), file("scripts/tool.tsx"), file("scripts/tool.js", "eA==", "base64"), file("resources/code.js"), file("assets/image.png", "image", "text"), file("references/guide.md", "eA==", "base64"), file("assets/data.exe", "eA==", "base64"), ]) await invalid( packageOf(entry(), resource), "unsupported_file", undefined, resource.path, ); await invalid( packageOf( file( "SKILL.md", Buffer.from(instructions()).toString("base64"), "base64", ), ), "invalid_encoding", ); for (const content of [ "Zg", "Zh==", "Zg===", "Zg==\n", "Z g==", "_w==", "!!!!", ]) await invalid( packageOf(entry(), file("assets/pixel.png", content, "base64")), "invalid_encoding", undefined, `base64 ${content}`, ); await invalid( packageOf(entry(), file("resources/text.txt", "\ud800")), "invalid_encoding", ); await valid( packageOf( entry( "---\nname: fixture-skill\ndescription: Boundaries\nmetadata:\n version: 1.0.0\n---\n" + "x".repeat(32 * 1024), ), ), ); await invalid( packageOf(entry(instructions("x".repeat(32 * 1024 + 1)))), "invalid_instructions", ); await invalid( packageOf(entry(instructions("🦊".repeat(8193)))), "invalid_instructions", ); await valid( packageOf(entry(), file("resources/max.txt", "x".repeat(256 * 1024))), ); await invalid( packageOf( entry(), file("resources/over.txt", "x".repeat(256 * 1024 + 1)), ), "file_too_large", ); await invalid( packageOf(entry(), file("resources/unicode.txt", "🦊".repeat(65537))), "file_too_large", ); await valid( packageOf( entry(), ...Array.from({ length: 127 }, (_, i) => file(`resources/file-${i}.txt`, ""), ), ), ); await invalid( packageOf( entry(), ...Array.from({ length: 128 }, (_, i) => file(`resources/file-${i}.txt`, ""), ), ), "invalid_package", ); const entryBytes = Buffer.byteLength(instructions()); const totalFiles = [ entry(), ...Array.from({ length: 7 }, (_, i) => file(`resources/max-${i}.txt`, "x".repeat(256 * 1024)), ), file("resources/last.txt", "x".repeat(256 * 1024 - entryBytes)), ]; assert.equal( (await valid(packageOf(...totalFiles))).metadata.totalBytes, 2 * 1024 * 1024, ); await invalid( packageOf( ...totalFiles.map((item, i) => i === totalFiles.length - 1 ? { ...item, content: item.content + "x" } : item, ), ), "package_too_large", ); await valid(packageOf(entry(instructions("🦊".repeat(8192))))); await valid( packageOf( entry(), file( "assets/max.png", Buffer.alloc(256 * 1024).toString("base64"), "base64", ), ), ); await invalid( packageOf( entry(), file( "assets/over.png", Buffer.alloc(256 * 1024 + 1).toString("base64"), "base64", ), ), "file_too_large", ); const largeMetadata = Array.from( { length: 31 }, (_, index) => ` extra-${index}: "${"m".repeat(1024)}"`, ).join("\n"); const oversizedEntry = `---\nname: fixture-skill\ndescription: "${"d".repeat(1024)}"\nmetadata:\n version: 1.0.0\n${largeMetadata}\n---\n${"x".repeat(32 * 1024)}`; assert.ok(Buffer.byteLength(oversizedEntry) > 64 * 1024); await invalid(packageOf(entry(oversizedEntry)), "file_too_large"); const manyMetadata = instructions().replace( ' version: "1.2.3-beta.1+build.7"', ` version: "1.2.3"\n${Array.from({ length: 32 }, (_, index) => ` extra-${index}: value`).join("\n")}`, ); await invalid(packageOf(entry(manyMetadata)), "invalid_metadata"); const urlOrigin = await valid(packageOf(entry()), { origin: { kind: "url", url: "https://example.com/skills/fixture.json?token=private#fragment", }, }); assert.deepEqual(urlOrigin.metadata.origin, { kind: "url", url: "https://example.com/skills/fixture.json", }); for (const invalidOrigin of [ { kind: "url", url: "bad" }, { kind: "url", url: "http://example.com/file" }, { kind: "url", url: "https://user:password@example.com/file" }, { kind: "upload", filename: "../package.json" }, { kind: "url", url: "https://example.com/file", trusted: true }, ]) await invalid(packageOf(entry()), "invalid_origin", { origin: invalidOrigin, }); } finally { await worker.dispose(); } }, );