diff --git a/README.md b/README.md index 9c1cc95..50b763c 100644 --- a/README.md +++ b/README.md @@ -5,14 +5,22 @@ > **Alpha · v0.1.1 · Node.js 20+** > SkillSync performs offline checks of local Skill content. It does not execute Skill scripts, does not read credentials, and does not enable live provider, remote-worker, or runtime capabilities. -[![Terminal demo](https://raw.githubusercontent.com/Chumaniac/skillsync/main/docs/assets/verify-demo.png)](https://github.com/Chumaniac/skillsync/blob/main/docs/assets/verify-demo.png) +[![Terminal demo](https://raw.githubusercontent.com/Chumaniac/skillsync/main/docs/assets/verify-demo.svg)](https://github.com/Chumaniac/skillsync/blob/main/docs/assets/verify-demo.svg) -Run this from a directory containing `SKILL.md`: +## Run it from source + +The npm package publish for `0.1.1` is currently paused. Clone this repository to run the current Alpha build: ```bash -npx --yes --package=@chumanic/skillsync@0.1.1 --call 'skillsync verify --path . --target codex' +git clone https://github.com/Chumaniac/skillsync.git +cd skillsync +npm ci +npm run build +node dist/cli/index.js verify --path fixtures/product/trust-loop/review --target codex ``` +The command above verifies the included sample Skill. Replace the fixture path with a directory containing your own `SKILL.md` when you are ready. + ## What you get - `verify` reviews one local Skill for provenance, target compatibility, and changes without running its scripts. diff --git a/docs/assets/verify-demo.png b/docs/assets/verify-demo.png index ffb20c8..a4fdabd 100644 Binary files a/docs/assets/verify-demo.png and b/docs/assets/verify-demo.png differ diff --git a/docs/assets/verify-demo.svg b/docs/assets/verify-demo.svg index 6453e76..19de607 100644 --- a/docs/assets/verify-demo.svg +++ b/docs/assets/verify-demo.svg @@ -1,6 +1,6 @@ SkillSync verification terminal demo - A terminal showing a public SkillSync verification command and its real output excerpt. + A terminal showing how to run a source checkout of SkillSync and its real verification output excerpt. @@ -8,12 +8,14 @@ skillsync — verify a local Skill - $ npx --yes --package=@chumanic/skillsync@0.1.1 --call 'skillsync verify --path . --target codex' - Real output excerpt - - SkillSync verification: 4 findings - pass=3 warn=1 fail=0 unknown=0 - issueId=iss_cf8df2b07cab35d52d3e1cf9dba965a81ab6ce59e60dfc0c9384d83f4d319030 status=open code=provenance.local-only Skill=review - impact: Record a repository URL and resolved commit when publishing the Skill. + $ git clone https://github.com/Chumaniac/skillsync.git + $ cd skillsync && npm ci && npm run build + $ node dist/cli/index.js verify --path fixtures/product/trust-loop/review --target codex + Real output excerpt + + SkillSync verification: 4 findings + pass=3 warn=1 fail=0 unknown=0 + issueId=iss_cf8df2b07cab35d52d3e1cf9dba965a81ab6ce59e60dfc0c9384d83f4d319030 status=open code=provenance.local-only Skill=review + impact: Record a repository URL and resolved commit when publishing the Skill. Offline inspection only — no Skill scripts or credentials are executed or read. diff --git a/tests/docs/documentation.test.ts b/tests/docs/documentation.test.ts index 7150409..0af2ee3 100644 --- a/tests/docs/documentation.test.ts +++ b/tests/docs/documentation.test.ts @@ -40,22 +40,33 @@ describe("release documentation", () => { expect(readme).toContain("Verify Agent Skills before you trust them."); expect(readme).toContain("Alpha · v0.1.1 · Node.js 20+"); + expect(readme).toContain("## Run it from source"); + expect(readme).toContain([ + "```bash", + "git clone https://github.com/Chumaniac/skillsync.git", + "cd skillsync", + "npm ci", + "npm run build", + "node dist/cli/index.js verify --path fixtures/product/trust-loop/review --target codex", + "```", + ].join("\n")); + expect(readme).toContain("The npm package publish for `0.1.1` is currently paused."); + expect(readme).not.toMatch(/@chumanic\/skillsync@0\.1\.1/); expect(readme).toContain( - "npx --yes --package=@chumanic/skillsync@0.1.1 --call 'skillsync verify --path . --target codex'", - ); - expect(readme).toContain( - "https://raw.githubusercontent.com/Chumaniac/skillsync/main/docs/assets/verify-demo.png", + "https://raw.githubusercontent.com/Chumaniac/skillsync/main/docs/assets/verify-demo.svg", ); + expect(terminalDemo).toContain("$ git clone https://github.com/Chumaniac/skillsync.git"); expect(terminalDemo).toContain( - "npx --yes --package=@chumanic/skillsync@0.1.1 --call 'skillsync verify --path . --target codex'", + "$ node dist/cli/index.js verify --path fixtures/product/trust-loop/review --target codex", ); + expect(terminalDemo).not.toContain("@chumanic/skillsync@0.1.1"); expect(readme).toContain("does not execute Skill scripts"); expect(readme).toContain("does not read credentials"); expect(readme).not.toContain("## Documentation index"); expect(readme).not.toContain("## Recommended reading order"); expect(readme).not.toContain("Local release-candidate validation"); - expect(existsSync("docs/assets/verify-demo.png")).toBe(true); - expect(statSync("docs/assets/verify-demo.png").size).toBeGreaterThan(1_000); + expect(existsSync("docs/assets/verify-demo.svg")).toBe(true); + expect(statSync("docs/assets/verify-demo.svg").size).toBeGreaterThan(1_000); expect(security).toContain("not a security certification"); expect(security).toContain("reporting.include_local_paths"); expect(security).toContain("");