Files
openhuman/src
2876f4468e Feat/zeroclaw x alphahuman (#140)
* feat(runtime): add skill_type to SkillManifest for unified registry

Add optional skill_type field (alphahuman | openclaw) with serde default
'alphahuman' so existing manifest.json files remain valid. Enables
type-based dispatch in the unified skill system.

* feat(runtime): add UnifiedSkillEntry and UnifiedSkillResult types

UnifiedSkillEntry provides a common interface for both alphahuman (QuickJS)
and openclaw (SKILL.md/TOML) skills: id, name, skill_type, version,
description, status, tools. UnifiedSkillResult standardizes execution
responses (skill_id, tool_name, content, is_error, executed_at) and is
MCP-spec compatible for content blocks.

* feat(runtime): expose skills_source_dir() on RuntimeEngine

Public getter for the skill source directory so the unified skill
generator can write new alphahuman skills (manifest.json + index.js)
to the same directory the runtime discovers skills from.

* feat(skills): add unified skill registry, openclaw executor, generator

- UnifiedSkillRegistry: merges alphahuman (RuntimeEngine::discover_skills)
  and openclaw (load_skills from ~/.alphahuman/workspace/skills/), dispatches
  execute by skill_type, supports generate from GenerateSkillSpec.
- openclaw_executor: runs SKILL.toml tools via shell (sh -c) or http
  (reqwest), returns SKILL.md prompt as text when no tools;  interpolation.
- generator: generate_alphahuman writes manifest.json + index.js to skills dir;
  generate_openclaw writes SKILL.md or SKILL.toml to workspace/skills/<name>/.

* feat(commands): add Tauri commands for unified skill API

- unified_list_skills: returns Vec<UnifiedSkillEntry> (alphahuman + openclaw).
- unified_execute_skill: dispatches by skill_type to QuickJS or openclaw
  executor, returns UnifiedSkillResult.
- unified_generate_skill: generates skill from spec, returns new UnifiedSkillEntry.
Desktop implementations use UnifiedSkillRegistry; mobile stubs return
empty/error (QuickJS not available on Android/iOS).

* feat(tauri): register unified skill commands in generate_handler

Wire unified_list_skills, unified_execute_skill, and unified_generate_skill
into both desktop and mobile generate_handler![] blocks so the frontend
can invoke them via Tauri IPC.

* feat(skills): add skill_type to frontend skill types

- SkillManifest (lib/skills/types.ts): optional skill_type 'alphahuman' | 'openclaw'.
- SkillListEntry (skills/shared.tsx): same for list entries so the grid
  can show type badges and handle openclaw vs alphahuman differently if needed.

* feat(SkillsGrid): use unified registry, type badges, generate button

- Load skills via unified_list_skills (fallback to runtime_discover_skills
  when unavailable, e.g. mobile).
- Show SkillTypeBadge per row: blue for alphahuman, purple for openclaw.
- Add Generate button that calls unified_generate_skill with a demo
  alphahuman spec and refreshes the list so the new skill appears.

* feat(skills): unified skill registry with security hardening and PR fixes

- Add UnifiedSkillRegistry merging alphahuman (QuickJS) and openclaw (SKILL.md/TOML) skill types
- Add three Tauri commands: unified_list_skills, unified_execute_skill, unified_generate_skill
- Add skill_type field to SkillManifest and UnifiedSkillEntry
- Add SkillTypeBadge (blue=alphahuman, sage=openclaw) and Generate button in SkillsGrid

Security fixes from PR review:
- Fix shell injection in openclaw_executor: POSIX single-quote escaping + 30s timeout
- Fix SSRF in run_http_tool: URL scheme validation + DNS resolution + private IP blocking
- Add EscapeContext enum (Shell/Url/None) for context-aware arg interpolation

Generator fixes:
- Guard sanitize_id empty result with early Err in generate_alphahuman/generate_openclaw
- Fix JS description embedding via serde_json::to_string (proper newline/backslash escaping)
- Fix sanitize_fn_name to prepend _ when result starts with digit
- Replace manual TOML format! with serde structs + toml::to_string for correct escaping

Frontend fixes:
- Extract normalizeUnifiedEntry helper shared by initial load and post-generate refresh
- Replace hardcoded hasSetup/ignoreInProduction in refreshed mapping with data-driven values
- Use SkillType alias centralising 'alphahuman' | 'openclaw' union in types.ts and shared.tsx
- Fix SkillTypeBadge colors to approved palette (sage) and radius token (rounded-md)

Nitpick: remove status from UnifiedSkillEntry (frontend derives status from Redux)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-02-25 10:43:49 +04:00
..
2026-02-16 17:10:06 +05:30
2026-02-25 10:43:49 +04:00
2026-02-03 15:26:38 +05:30
2026-02-16 17:10:06 +05:30
2026-02-18 09:18:43 +05:30
2026-02-21 10:56:49 +04:00
2026-02-18 09:18:43 +05:30
2026-02-18 09:18:43 +05:30