Skip to content

Remove leftover legacy skills feature code - #832

Merged
kody-bot merged 4 commits into
mainfrom
cursor/remove-legacy-skills-c476
Jul 21, 2026
Merged

kody-bot merged 4 commits into
mainfrom
cursor/remove-legacy-skills-c476

Conversation

@kentcdodds

@kentcdodds kentcdodds commented Jul 21, 2026 •

Copy link
Copy Markdown
Owner

Summary

Strip the last product-code remnants of the old Kody skills feature so the tree reads as if that feature never existed (historical D1 migrations kept as-is).

Removed

  • packages/worker/src/mcp/skills/ (skill-parameters + tests) and the dead runKodyWithRegistry expression/snippet path that was its only caller
  • skill-runner-token: reserved secret-name reservation
  • Publish-note schema/type compat for legacy entityKind: 'skill' | 'app'
  • Unused acorn dependency (only used by skill-parameters)
  • stripCodeFences / hasTopLevelModuleSyntax helpers that only served that dead path

Renamed / cleaned

  • docs/contributing/skill-patterns/ → execute-patterns/
  • Docs/test fixtures that still said “skills” for package-storage examples

Live execute continues to use runModuleWithRegistry / runBundledModuleWithRegistry with params passed to the default export.

npm run validate passes.

System recap — extends existing primitives (medium risk)

Mode: recap · Base: main @ 51c8e8d5 · Head: e17be872

Classification: extends — removes dead skill-era execute surface, secret-name reservation, and publish-note parse compat; no new primitives.

Primitives touched

Primitive Group Impact
capabilities-execute runtime extends — delete unused runKodyWithRegistry / skill-params wrapping
mcp-server surfaces extends — drop mcp/skills module and skill-runner secret guard
repo-sessions runtime extends — parse publish notes with current entity kinds only
capability-registry assistant composes — repo_show_publish_note output schema follows
package-runtime runtime composes — fixture rename only
jobs assistant composes — test cast cleanup only
secrets assistant composes — maintenance 404 fixture cleanup only

System map

Dead skill-era execute helpers and secret/publish compat are removed; live module execute is unchanged.

Legend: green = composes (wiring only) · amber = extended by this PR · red = new primitive · gray = context (unchanged, included only when an edge crosses it).

flowchart LR
	capabilitiesExecute["capabilities-execute<br/>Capabilities execute runtime"]:::extended
	mcpServer["mcp-server<br/>MCP endpoint"]:::extended
	repoSessions["repo-sessions<br/>Repo sessions"]:::extended
	capabilityRegistry["capability-registry<br/>Capability registry"]:::touched
	mcpServer -->|"delete mcp/skills + skill-runner reserve"| capabilitiesExecute
	capabilityRegistry -->|"repo_show_publish_note schema"| repoSessions
	classDef touched fill:#1a7f37,color:#fff
	classDef extended fill:#9a6700,color:#fff
	classDef added fill:#cf222e,color:#fff
	classDef untouched fill:#57606a,color:#fff
Loading

Before / after

Area Before After
Execute snippet path runKodyWithRegistry + buildParameterizedSkillCode removed (module path only)
Secret names skill-runner-token:* reserved/hidden no reserved skill-runner names
Publish notes parse skill/app entity kinds current job/package only (raw_note still returned)
Open in Web Open in Cursor 

Summary by CodeRabbit

  • Documentation
    • Added Cloudflare API v4 execute-pattern guidance, including secret-aware requests, approved host requirements, and expected request/response formats.
    • Updated the Cloudflare Developer Docs example to tighten path validation.
    • Refreshed package storage documentation examples to use items terminology.
  • Bug Fixes / Security
    • Switched publish-note validation to the current schema and removed legacy Git note parsing, rejecting outdated note structures.
    • Strengthened reserved secret name checks with clearer validation errors.
  • Breaking Changes
    • Removed MCP skill parameter handling (parameterized skill execution support may no longer be available).

Delete the unused skill-parameters module and dead runKodyWithRegistry
expression path, drop skill-runner secret reservations and skill/app
publish-note compat, and rename contributor execute-pattern docs away
from the old skills naming.
@coderabbitai

coderabbitai Bot commented Jul 21, 2026 •

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@cursor[bot], you've reached your PR review limit, so we couldn't start this review.

Next review available in: 46 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 470aa6bd-7fee-422c-a875-b0d18bfc18b3

📥 Commits

Reviewing files that changed from the base of the PR and between 5778b17 and 6c9c96d.

📒 Files selected for processing (1)
  • docs/contributing/execute-patterns/cloudflare-developer-docs.md
📝 Walkthrough

Walkthrough

Adds Cloudflare execute-pattern documentation, removes legacy inline execution and parameterization paths, tightens publish-note and secret-name contracts, updates package runtime fixtures, and simplifies related tests.

Changes

Cloudflare execute patterns

Layer / File(s) Summary
Cloudflare execute-pattern documentation
docs/contributing/execute-patterns/*, packages/worker/src/mcp/cloudflare/cloudflare-rest-client.ts
Adds Cloudflare API v4 and Developer Docs retrieval patterns with host/path validation, secret-aware requests, response handling, examples, and updated documentation references.

Module runtime cleanup

Layer / File(s) Summary
Module execution path removal
packages/worker/src/mcp/run-kody-registry.ts, packages/worker/src/mcp/run-kody-registry.node.test.ts
Removes runKodyWithRegistry, its normalization and parameterization dependencies, and shifts relevant coverage to runModuleWithRegistry.
Package runtime fixture updates
docs/use/packages.md, packages/worker/package.json, packages/worker/src/package-runtime/*, packages/worker/src/mcp/run-kody-registry.node.test.ts
Updates package examples and fixtures from skills to notes/items and replaces the worker dependency entry.

Publish note schema tightening

Layer / File(s) Summary
Current publish-note contract
packages/worker/src/repo/publish-git-notes.ts, packages/worker/src/mcp/capabilities/repo/repo-show-publish-note.ts, packages/worker/src/jobs/service.node.test.ts
Removes legacy publish-note types and schema handling, narrows parsed note types, and validates capability output with the current schema.

Secret-name guard updates

Layer / File(s) Summary
Reserved secret validation
packages/worker/src/mcp/secrets/name-guards.ts, packages/worker/src/mcp/secrets/service.node.test.ts
Uses explicit reserved secret names, adds assertSecretNameAllowed, and removes reserved-secret test seeding helpers.

Maintenance route test update

Layer / File(s) Summary
Unknown maintenance endpoint assertion
packages/worker/src/security/public-route-hardening.workers.test.ts
Replaces looped maintenance requests with one unknown-endpoint request and direct 404 JSON assertions.

Estimated code review effort: 4 (Complex) | ~45 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly matches the main change: removing leftover legacy skills feature code.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch cursor/remove-legacy-skills-c476

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@kody-bot
kody-bot marked this pull request as ready for review July 21, 2026 22:07
@github-actions

github-actions Bot commented Jul 21, 2026 •

Copy link
Copy Markdown
Contributor

🔎 Preview deployed: https://kody-pr-832.kody-a99.workers.dev

Worker: kody-pr-832
D1: kody-pr-832-db
KV: kody-pr-832-oauth-kv

Mocks:

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@docs/contributing/execute-patterns/cloudflare-developer-docs.md`:
- Around line 55-70: Update assertAllowedPath to construct and return the
canonical URL, then validate url.pathname against the allowed prefixes and
traversal rules before returning it for fetch use. Reject leading or trailing
whitespace instead of normalizing it with trim(), and update the caller to use
the validator’s returned URL rather than constructing a separate URL afterward.

In `@packages/worker/src/package-runtime/package-storage.workers.test.ts`:
- Around line 250-251: Update the comment near the package-storage test setup to
state that package invocations leave ambient storage unbound and that the runner
seeds the package’s bucket for packageStorage(). Remove the outdated claim that
invocations bind ambient storage to the same ID.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 301f6318-f4e2-44c1-8e77-ad1826e6268f

📥 Commits

Reviewing files that changed from the base of the PR and between 51c8e8d and e17be87.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (17)
  • docs/contributing/execute-patterns/cloudflare-api-v4.md
  • docs/contributing/execute-patterns/cloudflare-developer-docs.md
  • docs/use/packages.md
  • packages/worker/package.json
  • packages/worker/src/jobs/service.node.test.ts
  • packages/worker/src/mcp/capabilities/repo/repo-show-publish-note.ts
  • packages/worker/src/mcp/cloudflare/cloudflare-rest-client.ts
  • packages/worker/src/mcp/run-kody-registry.node.test.ts
  • packages/worker/src/mcp/run-kody-registry.ts
  • packages/worker/src/mcp/secrets/name-guards.ts
  • packages/worker/src/mcp/secrets/service.node.test.ts
  • packages/worker/src/mcp/skills/skill-parameters.node.test.ts
  • packages/worker/src/mcp/skills/skill-parameters.ts
  • packages/worker/src/module-source.ts
  • packages/worker/src/package-runtime/package-storage.workers.test.ts
  • packages/worker/src/repo/publish-git-notes.ts
  • packages/worker/src/security/public-route-hardening.workers.test.ts
💤 Files with no reviewable changes (5)
  • packages/worker/src/mcp/skills/skill-parameters.node.test.ts
  • packages/worker/src/module-source.ts
  • packages/worker/package.json
  • packages/worker/src/mcp/skills/skill-parameters.ts
  • packages/worker/src/mcp/run-kody-registry.ts

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Inline review comments failed to post. This is likely due to GitHub's internal server error or limits when posting large numbers of comments. If you are seeing this consistently it is likely a permissions issue. Please check "Moderation" -> "Code review limits" under your organization settings.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@docs/contributing/execute-patterns/cloudflare-developer-docs.md`:
- Around line 55-70: Update assertAllowedPath to construct and return the
canonical URL, then validate url.pathname against the allowed prefixes and
traversal rules before returning it for fetch use. Reject leading or trailing
whitespace instead of normalizing it with trim(), and update the caller to use
the validator’s returned URL rather than constructing a separate URL afterward.

In `@packages/worker/src/package-runtime/package-storage.workers.test.ts`:
- Around line 250-251: Update the comment near the package-storage test setup to
state that package invocations leave ambient storage unbound and that the runner
seeds the package’s bucket for packageStorage(). Remove the outdated claim that
invocations bind ambient storage to the same ID.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 301f6318-f4e2-44c1-8e77-ad1826e6268f

📥 Commits

Reviewing files that changed from the base of the PR and between 51c8e8d and e17be87.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (17)
  • docs/contributing/execute-patterns/cloudflare-api-v4.md
  • docs/contributing/execute-patterns/cloudflare-developer-docs.md
  • docs/use/packages.md
  • packages/worker/package.json
  • packages/worker/src/jobs/service.node.test.ts
  • packages/worker/src/mcp/capabilities/repo/repo-show-publish-note.ts
  • packages/worker/src/mcp/cloudflare/cloudflare-rest-client.ts
  • packages/worker/src/mcp/run-kody-registry.node.test.ts
  • packages/worker/src/mcp/run-kody-registry.ts
  • packages/worker/src/mcp/secrets/name-guards.ts
  • packages/worker/src/mcp/secrets/service.node.test.ts
  • packages/worker/src/mcp/skills/skill-parameters.node.test.ts
  • packages/worker/src/mcp/skills/skill-parameters.ts
  • packages/worker/src/module-source.ts
  • packages/worker/src/package-runtime/package-storage.workers.test.ts
  • packages/worker/src/repo/publish-git-notes.ts
  • packages/worker/src/security/public-route-hardening.workers.test.ts
💤 Files with no reviewable changes (5)
  • packages/worker/src/mcp/skills/skill-parameters.node.test.ts
  • packages/worker/src/module-source.ts
  • packages/worker/package.json
  • packages/worker/src/mcp/skills/skill-parameters.ts
  • packages/worker/src/mcp/run-kody-registry.ts
🛑 Comments failed to post (2)
docs/contributing/execute-patterns/cloudflare-developer-docs.md (1)

55-70: 🔒 Security & Privacy | 🟡 Minor | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

node -e "for (const p of ['/api/%2e%2e/secret', ' /api/resources/']) console.log(p, '=>', new URL(p, 'https://developers.cloudflare.com').pathname)"

Repository: kentcdodds/kody

Length of output: 219


🏁 Script executed:

sed -n '1,140p' docs/contributing/execute-patterns/cloudflare-developer-docs.md

python3 - <<'PY'
from urllib.parse import urljoin
tests = ['/api/%2e%2e/secret', ' /api/resources/', '/api/resources/%2e%2e/secret', '/api/resources/%2e%2e%2fsecret', '/api/resources/..%2fsecret']
base='https://developers.cloudflare.com'
for t in tests:
    print(t, '=>', __import__('subprocess').run(
        ['node','-e',f"console.log(new URL({t!r}, {base!r}).pathname)"],
        capture_output=True,text=True
    ).stdout.strip())
PY

Repository: kentcdodds/kody

Length of output: 3031


🏁 Script executed:

sed -n '1,140p' docs/contributing/execute-patterns/cloudflare-developer-docs.md

python3 - <<'PY'
tests = ['/api/%2e%2e/secret', ' /api/resources/', '/api/resources/%2e%2e/secret', '/api/resources/%2e%2e%2fsecret', '/api/resources/..%2fsecret']
base='https://developers.cloudflare.com'
import subprocess
for t in tests:
    out = subprocess.run(
        ['node','-e',f"console.log(new URL({t!r}, {base!r}).pathname)"],
        capture_output=True,text=True,check=True
    ).stdout.strip()
    print(f"{t} => {out}")
PY

Repository: kentcdodds/kody

Length of output: 3031


Validate the canonical pathname before allowlisting it. /api/%2e%2e/secret passes the string checks here but new URL(...).pathname normalizes it to /secret, so the fetch can escape the intended prefix. Return the URL from the validator and check url.pathname; the current trim() also accepts leading/trailing whitespace.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@docs/contributing/execute-patterns/cloudflare-developer-docs.md` around lines
55 - 70, Update assertAllowedPath to construct and return the canonical URL,
then validate url.pathname against the allowed prefixes and traversal rules
before returning it for fetch use. Reject leading or trailing whitespace instead
of normalizing it with trim(), and update the caller to use the validator’s
returned URL rather than constructing a separate URL afterward.
packages/worker/src/package-runtime/package-storage.workers.test.ts (1)

250-251: 📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Update the comment to the current package-storage contract.

Lines 250-251 state that package invocations bind ambient storage, but package invocations now leave it unbound; this runner seeds the bucket for packageStorage() instead.

Proposed fix
-		// Seed the package's own bucket the way the package would in its own
-		// runtime (package invocations bind ambient storage to the same id).
+		// Seed the package's own bucket for `packageStorage()`.
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

		// Seed the package's own bucket for `packageStorage()`.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@packages/worker/src/package-runtime/package-storage.workers.test.ts` around
lines 250 - 251, Update the comment near the package-storage test setup to state
that package invocations leave ambient storage unbound and that the runner seeds
the package’s bucket for packageStorage(). Remove the outdated claim that
invocations bind ambient storage to the same ID.

Validate Cloudflare docs paths against the canonical URL pathname, and
correct the package-storage test comment about unbound ambient storage.
Comment thread docs/contributing/execute-patterns/cloudflare-developer-docs.md
Also require the resolved URL origin to match developers.cloudflare.com
so allowlisting cannot be bypassed via //evil.com/... paths.

@cursor cursor Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 5778b17. Configure here.

Comment thread docs/contributing/execute-patterns/cloudflare-developer-docs.md Outdated
Reject raw .. / %2e segments and require both the input path and the
resolved pathname to start with an allowlisted prefix.
@kody-bot
kody-bot merged commit 3dde84c into main Jul 21, 2026
5 checks passed
@kody-bot
kody-bot deleted the cursor/remove-legacy-skills-c476 branch July 21, 2026 22:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants