跳到主要内容
知仓学习社ZHICANG

senpi-qa

QA the omo Senpi adapter (packages/omo-senpi, packages/senpi-task) against the REAL senpi binary in strict isolation, and write every artifact to th…

改身份文件执行命令严重 0 · 高危 7code-yeongyu/oh-my-openagent

它会碰到什么

扫了多少3 个文本文件,13 KB
它会碰到什么改身份文件执行命令
命中总数7 处
命中统计严重 0 · 高 7 · 中 0 · 低 0
逐条看命中(7 条严重或高危)
  • scripts/resolve-evidence-dir.mjs:5identity-write
    // That path is the repository-standard location every reviewer and AGENTS.md rule points at, so a
  • scripts/resolve-evidence-dir.test.mjs:2exec-spawn
    import { spawnSync } from "node:child_process"
  • scripts/resolve-evidence-dir.test.mjs:2exec-spawn
    import { spawnSync } from "node:child_process"
  • scripts/resolve-evidence-dir.test.mjs:116exec-spawn
    const valid = spawnSync("node", [cliPath, "--repo-root", repoRoot, "--slug", "20260820-node-cli"], {
  • scripts/resolve-evidence-dir.test.mjs:119exec-spawn
    const invalid = spawnSync(
  • scripts/resolve-evidence-dir.test.mjs:139exec-spawn
    const result = spawnSync(
  • scripts/resolve-evidence-dir.test.mjs:156exec-spawn
    const result = spawnSync(

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Senpi QA

QA the omo Senpi adapter (packages/omo-senpi/) and the task engine

(packages/senpi-task/) by driving the REAL senpi binary. Unit tests never

count as live QA here: bun run test:senpi is the package gate, the drivers in

packages/omo-senpi/scripts/qa/ are the harness proof.

Golden rules

  • Evidence lives at exactly one path. Every artifact goes under

.omo/evidence/omo-senpi-adapter/<slug>/. Pick it with

scripts/resolve-evidence-dir.mjs and nothing else — a hand-typed path is how

runs end up somewhere like local-ignore/qa-evidence/, which no reviewer reads

and the PR cannot cite.

  • The real agent dir stays untouched. The live drivers build their own

isolated SENPI_CODING_AGENT_DIR and deliberately IGNORE a caller-provided

one, so ~/.senpi/agent is never used as the sandbox. Report the driver's

realSenpiUntouched / changed-path fields and the isolated agent-dir path;

treat a whole-directory digest as supporting evidence, not proof by itself.

  • No binary means SKIP, not silence. When senpi is absent the live drivers

report SKIP or FAIL in their final JSON rather than degrading to the real

home. A SKIP is not a pass — say so in the evidence README.

  • The captured JSON is the evidence. No file on disk means the QA did not

happen, which means no commit and no push.

Resolve the evidence directory first

ev="$(node .agents/skills/senpi-qa/scripts/resolve-evidence-dir.mjs \
  --repo-root "$(git rev-parse --show-toplevel)" --slug <YYYYMMDD>-<short-slug>)"
mkdir -p "$ev"

The resolver returns an absolute path and creates nothing, so the caller decides

when the directory appears. A slug is ONE relative segment of lowercase letters,

digits, and hyphens (20260820-senpi-qa-contract). Separators, ./..,

traversal, absolute paths, and a non-git root are rejected with a non-zero exit

and a message naming the offending slug.

Router: pick your case

| You changed… | Run | Proves |

|---|---|---|

| Any adapter code, as the fast precondition | node packages/omo-senpi/scripts/qa/drive.mjs --self-test | the driver + isolation harness itself works |

| Adapter wiring reaching a live session | node packages/omo-senpi/scripts/qa/drive.mjs | a real senpi run with the plugin loaded, isolated agent dir, and no attributed real-home changes |

| Task lifecycle (single + batch) | SENPI_BIN="$(command -v senpi)" node packages/omo-senpi/scripts/qa/task-e2e.mjs | live task start/stream/terminal states |

| Team delivery, shutdown, reclaim, restart recovery | SENPI_BIN="$(command -v senpi)" node packages/omo-senpi/scripts/qa/team-e2e.mjs | injection delivery and exactly-once recovery |

| Task RPC driver scripts | node packages/omo-senpi/scripts/qa/task-rpc-e2e.mjs --self-test | the RPC surface contract |

| Skill delivery into a task | SENPI_BIN="$(command -v senpi)" node packages/omo-senpi/scripts/qa/task-load-skills-e2e.mjs | skills reach the child |

| Continuation behavior | node packages/omo-senpi/scripts/qa/probe-continuation.mjs | turns continue as expected |

| DAG state machine / runners | bun test packages/senpi-task | unit + chaos invariants (NOT live proof) |

Point a driver's output at the resolved directory, e.g.:

TASK_E2E_OUT_DIR="$ev/live-task-dag" SENPI_BIN="$(command -v senpi)" \
  node packages/omo-senpi/scripts/qa/task-e2e.mjs

Package gate

tsgo --noEmit -p packages/omo-senpi/tsconfig.json
bun run test:senpi

Write the evidence README

Every run leaves $ev/README.md a reviewer can read without rerunning anything.

The required sections are the repo-wide evidence rules in the root

[AGENTS.md](../../../AGENTS.md) (what was tested / observed / why it is enough /

what was omitted). For Senpi, record the driver's changed-path/isolation fields

and sandbox agent-dir path. Some drivers report sandbox paths without removing

them; the caller must delete every task-owned sandbox and verify child PIDs are

terminal before writing the cleanup receipt.

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。

它属于哪个仓库

星标★ 69,100
本站分层T1
该仓技能数62
原文件路径.agents/skills/senpi-qa/SKILL.md

同一个仓库里的其他技能

看这个仓库的全部 62 个技能