Skip to content

fix(mcp): load skills on Windows - #102

Open
asasemahmed wants to merge 1 commit into
CopilotKit:mainfrom
asasemahmed:fix/mcp-windows-skill-paths
Open

asasemahmed wants to merge 1 commit into
CopilotKit:mainfrom
asasemahmed:fix/mcp-windows-skill-paths

Conversation

@asasemahmed

Copy link
Copy Markdown

loadSkill() rejects every name on Windows, so every skills://{name} resource and all three prompts (create_widget, create_svg_diagram, create_visualization) fail with Invalid skill name. Only skills://list keeps working. This hits stdio users on Windows, such as Claude Desktop.

The traversal check compares the resolved path against resolve(SKILLS_DIR) + "/". On Windows, resolve() returns backslash paths, so that prefix never matches.

The check now compares dirname(resolved) with the skills directory. That works on both platforms and still rejects ../x, nested paths and absolute paths.

Tests: added loadSkill cases to tests/skills.test.ts, covering a bundled skill that loads plus three rejected names. CI runs on Linux only, so the loading case only fails on Windows, which is where I reproduced it.

pnpm --filter open-intelligent-ui-mcp test
pnpm --filter open-intelligent-ui-mcp lint

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant