Repository navigation
Umbrella: scoped + shareable custom skills and custom agents (company-wide by default) #11277
Description
Activity
- addedenhancementNew feature or requestNew feature or request
on Jul 8, 2026 - added 11 commits that reference this issue
on Jul 8, 2026 T0 + T1 implemented → PR #11287 (spec+plan already merged in #11281).
- T0: Boot-reload fix —
register_declarative()+SkillManager._load_custom_definitions()at boot. Custom/hub skills no longer vanish on restart. - T1: Shared scope/authz core —
ScopeLevelenum,resource_grantstable + migration20260708_068,is_visible()rule,ResourceGrantStore,can_access()resolver + cache.
Built via subagent-driven TDD (per-task spec+quality reviews + final opus whole-branch review = READY TO MERGE). 21 tests pass. Default-deny authz verified (null-company cross-tenant guard). Awaiting CI + review.
Carry-forward to T2 (tracked):
- Every grant/revoke/scope-change write path MUST call
resource_visibility.invalidate()(decision cache has no TTL). - Add a
can_accessdenial test + assert permission-mutation in the grant idempotency test.
Remaining: T2 (skills adopt scoping), T3 (agents), T4 (docs/closure).
- T0: Boot-reload fix —
- added a commit that references this issue
on Jul 8, 2026 Worktree-audit status (2026-07-11): T0+T1 landed via #11287 (boot-reload fix + scope/granularity). The stale local
issue-11277worktree (its merged content) has been pruned. T2–T4 remain open under this umbrella — no change to scope.- addedarea: agent-seamWave 3 · cluster H — Agent seam & tool governanceWave 3 · cluster H — Agent seam & tool governance
on Sep 1, 2026 Follow-ups from #16927. #11277's "single access entry point" (
can_access()overresource_grants) is read by no production access check, and after #16927 nothing writes to it either. That is filed as #16981 (wire it or retire it). Related: #16982, whereSecret.is_accessible_byalso has no production caller.
Design owner: mrveiss. Spec:
docs/superpowers/specs/2026-07-08-scoped-shareable-skills-agents-design.md(added by this umbrella).Gives custom (user-created / imported / hub) skills and custom agents a scope + grant model mirroring secrets, so a skill/agent is created once and shared company-wide by default, narrowable to group/user — preventing duplication. Definitions persist to Postgres (survive
/opt/autobotgit-pull), governance/trust gating retained. Absorbs #11141 (cross-source conflict/dedup).Decisions (brainstormed)
SecretScope: USER / SESSION / SHARED / GROUP / ORGANIZATION. Default = ORGANIZATION (company-wide), narrowable down. ORG is the ceiling; truly-global = builtin/code viapromoter.py.resource_grantstable; definitions stored plaintext in Postgres (no secrets DEK envelope).visible_to(principal)filter at list/route/execute; execute-time is the hard gate. Single canonical instance = natural dedup.agent_org_nodes.company_id(Company OS) for the ORG default; useresource_grantsonly when limited below company-wide.Tasks
SkillManager.initialize()). Standalone bug fix; prerequisite seam for T2.ScopeLevelenum,resource_grantstable + migration,visible_to(principal)resolver + resolution cache, authz service + unit tests. No behavior change.skill_definitionstable + migration; custom-skill persistence Redis-only → Postgres (Redis = cache/config)SkillsViewscope badge & "Limit access" (i18n ×11)resource_grants(resource_type=agent) for limiting; ORG default staysagent_org_nodes.company_idEach T is one PR-sized deliverable (T2 splits into ~6 sub-PRs).
Discovered during T0+T1 (closure audit, PR #11287)
_load_custom_definitions()re-registers hub skills only. Externally-imported skills (external_importer→/var/lib/autobot/skill_cache) and generated skills are still not re-registered at boot. Fold into T2.2 (registry loads custom defs from DB at boot) — DB-backed reload will cover all sources uniformly.ScopeLevel/Principal/is_visible/resource_grantsoverlap withSecretScope, knowledgeVisibilityLevel+OwnershipManager.check_access, andPrincipalFacts. Consolidation is a scoped, owner-gated follow-up (Canonical debt: 3 overlapping visibility-scope enums + parallel principal/visibility/grant implementations #11290), not part of this umbrella.autobot-backend/autobot_shared/dir (namespace-package trap — new shared code must go in repo-rootautobot_shared/); repo has no shared async-DB test fixture (each DB test builds its own in-memory sqlite fixture).resource_visibility.invalidate()(cache has no TTL); add acan_accessdenial test + assert permission mutation in the grant idempotency test.