fix(#2857): prevent npm scoped package paths from being resolved as skill paths

resolveSkillPathReferences: add looksLikeFilePath() guard that requires
a file extension or trailing slash before resolving @scope/package
references. npm packages like @mycom/my_mcp_tools@beta were incorrectly
being rewritten to absolute paths in skill templates.

2 new tests.
This commit is contained in:
YeonGyu-Kim
2026-03-27 16:59:04 +09:00
parent c41e59e9ab
commit ec7a2e3eae
2 changed files with 35 additions and 1 deletions
+24
View File
@@ -90,6 +90,30 @@ describe("resolveSkillPathReferences", () => {
expect(result).toBe("No path references here")
})
it("does not resolve npm scoped packages in commands", () => {
//#given
const content = "npx --package=@mycom/my_mcp_tools@beta cli my_cmd_tool XXX"
const basePath = "C:/Users/Admin/.config/opencode/skills/my_skills"
//#when
const result = resolveSkillPathReferences(content, basePath)
//#then
expect(result).toBe("npx --package=@mycom/my_mcp_tools@beta cli my_cmd_tool XXX")
})
it("does not resolve npm scoped packages without version suffix", () => {
//#given
const content = "npm install @angular/core @types/node"
const basePath = "/skills/frontend"
//#when
const result = resolveSkillPathReferences(content, basePath)
//#then
expect(result).toBe("npm install @angular/core @types/node")
})
it("handles basePath with trailing slash", () => {
//#given
const content = "@scripts/search.py"