fix(skill-author): fail loudly when scaffold repair cannot substitute

Why: repair_placeholders ran inside a command substitution, so a failing
sed left an emptied file behind and the script still exited 0 reporting
success.

- write via tmp file and abort on sed or mv failure
- re-check the target before moving staging into place
- stage in a dot-prefixed mktemp dir so a killed run leaves no fake skill
- source apm claims in deployment-modes.md; tag untyped code blocks

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KkT7RSDwDbmrM9T34b6sTi
This commit is contained in:
2026-09-29 08:00:22 +00:00
parent 9285b29e3c
commit 36723ae3fc
5 changed files with 142 additions and 17 deletions

View File

@@ -1,6 +1,7 @@
---
source_keys:
- agentskills-spec
- apm-docs-llms-full
---
# Deployment Modes
@@ -11,7 +12,7 @@ Skills deploy standalone, or as part of an APM package (an `apm.yml`-governed `.
When a host installs a plugin, it copies the plugin directory to a cache. Only the plugin's own files are copied. **Any path that leaves the skill directory breaks post-install:**
```
```text
../other-skill/validate.sh # breaks
plugins/<plugin>/.apm/skills/other/ # breaks
../../shared/utils.sh # breaks
@@ -23,7 +24,7 @@ Fix: duplicate the file into the skill's own `scripts/` or `assets/`. There is n
For a package (an `apm.yml`-governed `.apm/` source tree), the deployable artifact is generated by `apm compile` per target harness — not produced by copying the raw `.apm/` directory wholesale the way a plugin cache install copies a plugin directory. The same self-containment rule still applies at the skill level: **file references inside `.apm/skills/<name>/` must not reach outside that skill's own directory.**
```
```text
../other-skill/validate.sh # breaks
.apm/skills/other-skill/ # breaks
../../shared/utils.sh # breaks