Daily harness signal

A missing filter
must not mean “all.”

September 6, 2026 · JST · One fresh finding · Skill distribution
A skill installer’s argument parser is part of your capability boundary. A fresh downstream failure shows why installation scope must survive parsing, target selection, and the final filesystem diff.
Fresh · source date September 2, 2026

Validate selectors before installation

Use when: an agent, CI job, or script installs selected skills through Vercel’s skills CLI. In version 1.5.23, --skill=grill-me is silently discarded; with non-interactive selection, the missing filter can install every discovered skill. An ignored --agent=claude-code can also broaden destination agents.

Action: for already-approved installs, replace equals-form selectors with separate arguments: --skill grill-with-docs --agent claude-code. Pin the reviewed CLI version; do not treat @latest as a reproducibility pin. Before calling the installer, make your launcher reject unknown options, empty selectors, and unapproved wildcards. Construct an argument array from explicit approved skill and destination lists; never interpret a lost filter as bulk consent. Stage under an isolated home and workspace before promoting anything into a live profile.

Acceptance check: use an owned fixture repository containing independent skills alpha and beta. The space-form request for alpha must materialize only that skill at approved destinations. Through your launcher, try --skill=alpha, --skils, an empty selector, and --agent=claude-code: each must either normalize unambiguously to the approved request or fail before installer dispatch. Compare files, symlinks, and lock entries against the approved manifest; unexpected skills or cross-agent writes fail acceptance, even with exit code zero.

Evidence: September 2’s Pocock-repository report includes the install transcript and documentation diff. An independent August 23 report names 1.5.23, sandbox reproductions, and cross-agent effects. The inspected tagged parseAddOptions drops unknown dash-prefixed tokens; runAdd selects all skills when the filter is absent and yes is enabled. The proposed repair contains inspectable equals-form parser tests.

Caveat: PR #2086 remains open in the retrieved record; its test claims are not a shipped fix. Supporting equals syntax alone does not prove unknown-option rejection. Shared agent directories can expose staged skills beyond one named client, so inspect actual paths. Exact selection proves scope, not skill safety or dependency completeness. No installer, skill, or runtime canary was executed for this issue.

Compact source notes

  1. erdtsieck, mattpocock/skills #1012 — September 2, 2026. The current canonical install block still exposes the problematic spelling in the retrieved source.
  2. mr-h12, vercel-labs/skills #2039 — August 23, 2026. Versioned reproduction and additional malformed-option/destination cases; no maintainer confirmation shown.
  3. Tagged add.ts and cli.ts — release dated August 18, 2026. Raw files inspected: exact-token parser, all-skills fallback, and existing pre-dispatch parser-error handling. Retrieved main retains the relevant parser behavior.
  4. Proposed fix #2086 — August 28, 2026, open. Proposal tests inspected, not run. The page’s “merge commit” metadata is not evidence of an actual merge; no merged timestamp or shipped repair was found.
  5. Anchor lens: source-level loss of selectors plus two inspectable field reports. Unity lens: installation scope must remain invariant across parsing and materialization. confidence_confirmed for tagged parser behavior; confidence_likely for reported cross-agent effects. Falsifier for the proposed control: any malformed request produces an unapproved installed identity or destination.