Skip to content

feat(use-jev): introduce Jev with examples and upstream guidance - #617

Merged
enyst merged 8 commits into
OpenHands:mainfrom
smolpaws:skills/typesafe-ai
Oct 1, 2026
Merged

enyst merged 8 commits into
OpenHands:mainfrom
smolpaws:skills/typesafe-ai

Conversation

@smolpaws

@smolpaws smolpaws commented Sep 19, 2026 •

Copy link
Copy Markdown
Contributor

HUMAN:
This PR proposes a small intro skill to Jev, so the agent knows where to get info from.

AGENT:

  • A human has tested these changes.

Why

Give OpenHands agents a concise introduction to Jev, a newly released general classifier, with upstream documentation as the source of truth.

Summary

  • Add a short use-jev skill triggered by jev, linking to upstream use cases, best practices, SDK/API docs, and llms.txt.
  • Include one Python example each for Choice, Score, and Noul in a single request, using JEV_API_KEY.
  • Use the repository's top-level license; no separate skill license file or copied upstream manual.
  • Register the skill in the marketplace and generated catalog, with the required plugin metadata and symlinks.
  • Refresh the generated OpenHands SDK reference from upstream so the SDK sync check passes.

Issue Number

Fixes #618.

How to Test

  • Relevant catalog, plugin-loading, and README checks: 131 passed (pytest -q tests/test_skills_have_readme.py tests/test_skill_plugin_loading.py tests/test_skills_catalog.py).
  • npm run build:skills and python scripts/sync_extensions.py --check pass. Existing unrelated catalog coverage warnings remain.
  • All 14 upstream links return HTTP 200; Python example syntax checked and API usage compared with the live upstream SDK documentation.
  • python scripts/sync_openhands_sdk_skill.py --check passes after regeneration.
  • No live inference request was made.

Jev-Fast-Audit

⚡ Jev fast audit · estimates · 0.49s · commit c8e31a7
Strongest signal: No primary concern selected.
Evidence: No primary concern to locate.
Coverage: ⚠️ reduced context — partial coverage; 10/10 hunks, 8/8 files (missing context: 4).

All estimates and evidence
Estimate Likelihood / value Direct evidence
SQL injection 3.0% No direct hunk selected
Command injection 7.0% No direct hunk selected
Weakened authentication 4.0% No direct hunk selected
Weakened authorization 6.0% No direct hunk selected
Contract regression 9.0% No direct hunk selected
Data loss 3.0% No direct hunk selected
Sensitive data disclosure 5.0% No direct hunk selected
Unexpected data transfer 5.0% No direct hunk selected
Credential misuse 8.0% No direct hunk selected
Untrusted instruction authority 3.0% No direct hunk selected
Package source redirection 4.0% No direct hunk selected
Unverified remote execution 3.0% No direct hunk selected
Privileged environment access 3.0% No direct hunk selected
Security assessment bypass 4.0% No direct hunk selected
Prohibited workload 2.0% No direct hunk selected
Primary concern None selected; confidence 93.0% No primary concern to locate

smolpaws and others added 2 commits September 20, 2026 00:58
Import the shareable skill from typesafe-ai/skills (MIT) so OpenHands users
can build with TypeSafe's System One models, including Jev. Verbatim copy:
SKILL.md + LICENSE.
@smolpaws smolpaws changed the title skill(typesafe-ai): add TypeSafe System One / Jev skill skill(typesafe-ai): introduce Jev with examples and upstream guidance Sep 20, 2026
@smolpaws smolpaws changed the title skill(typesafe-ai): introduce Jev with examples and upstream guidance skill(use-jev): introduce Jev with examples and upstream guidance Sep 20, 2026
@smolpaws smolpaws changed the title skill(use-jev): introduce Jev with examples and upstream guidance feat(use-jev): introduce Jev with examples and upstream guidance Sep 21, 2026
@github-actions github-actions Bot added the type: feat A new feature label Sep 21, 2026
@OpenHands OpenHands deleted a comment from all-hands-bot Sep 21, 2026
@enyst
enyst requested a review from all-hands-bot September 21, 2026 00:23
@all-hands-bot

Copy link
Copy Markdown
Contributor

🤖 OpenHands is reviewing this PR.

Head commit: 02ee7c8bfff65f9cd5b8367294cf88e08c1c4005
View the conversation: https://oss-agent-canvas.ngrok.dev/conversations/65d43243-0cc9-4d96-9262-d69f5c41ddfa

This comment was posted by an AI agent (OpenHands).

@all-hands-bot all-hands-bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This review was created by an AI agent (OpenHands) on behalf of the repository maintainers.

Taste: good. A small, well-scoped skill addition that follows this registry's conventions. No material findings.

What I verified on head 02ee7c8:

  • Skill conventions: skills/use-jev/SKILL.md is progressive disclosure (summary first, upstream docs as source of truth), uses a keyword trigger (jev), contains no secrets, and stays vendor-focused per the authoring rules in AGENTS.md.
  • Upstream accuracy: all 14 links in SKILL.md return HTTP 200. The Python example matches the live upstream SDK docs: TypeSafeClient(*, api_key: str | None = None, ...), client.system_one(state=..., questions=...), and result.choices/scores/nouls all exist in the released typesafe-sdk API. Using JEV_API_KEY passed explicitly as api_key is valid (explicit options take precedence over env vars upstream) and is required by the linked issue.
  • Registry plumbing: marketplace entry, skills/index.js entry, and README catalog counts (72 → 73 extensions) are consistent; .plugin/plugin.json carries the required fields (name, description, author, version) enforced by tests/test_skill_plugin_loading.py; vendor symlinks (.claude-plugin, .codex-plugin) are present and match the pattern used by every other skill.
  • Generated SDK reference: the skills/openhands-sdk/SKILL.md refresh is the sanctioned path (auto-generated by scripts/sync_openhands_sdk_skill.py), and the sync-sdk-skill CI check passes on this head.
  • CI: all checks green on 02ee7c8 (test, sync-extensions, sync-sdk-skill, validate-claude-code, PR gates).

Acceptance criteria (from #618):

  • SKILL.md has Jev intro, upstream links, three primitive examples, jev trigger
  • Example reads JEV_API_KEY and passes it as the client's api_key argument
  • Registered in marketplace + generated catalog, valid plugin metadata, README symlink (symlink is explicitly required by the issue; note GitHub renders it as the literal text SKILL.md rather than file content - non-blocking, matches the issue's intent)
  • No duplicate skill license or copied upstream manual
  • Catalog, plugin loading, README, and generated reference checks pass (verified via CI on this head)

Repository fit: a reusable public skill is exactly what this registry owns; no cross-repo boundary concerns.

[RISK ASSESSMENT] LOW - documentation-only skill addition with no executable code paths in this repo; the only runtime surface is an example snippet verified against upstream docs, and it reads the API key from the environment rather than embedding it.

Verdict: APPROVE. Key insight: the skill correctly delegates truth to upstream (llms.txt and linked pages) instead of copying documentation into the registry, which keeps the maintenance burden near zero as Jev's docs evolve.

Comment thread skills/use-jev/SKILL.md Outdated
Updated instructions to ensure JEV_API_KEY is provided by the user if not set.
@enyst

enyst commented Sep 21, 2026

Copy link
Copy Markdown
Member

@OpenHands check why CI fails please and fix it

@openhands-ai

openhands-ai Bot commented Sep 21, 2026

Copy link
Copy Markdown

I'm on it! enyst can track my progress at all-hands.dev

Regenerate skills/index.js after the Jev API-key guidance edit so the catalog freshness test passes.

Co-authored-by: openhands <openhands@all-hands.dev>

enyst commented Sep 21, 2026

Copy link
Copy Markdown
Member

Fixed in 491bb41.

The failure was TestGeneratedSkillsIndex.test_index_is_up_to_date: the latest JEV_API_KEY guidance edit in skills/use-jev/SKILL.md had not been regenerated into skills/index.js. I ran npm run build:skills and committed only the generated catalog update; no workflow or test changes were needed.

Validation:

  • Reproduced the exact failure locally, then passed all five existing generated-index tests by direct invocation after regeneration.
  • Full GitHub CI on the new commit is green: 958 passed, 24 skipped in the Tests run.
  • All 9 applicable PR checks passed; 2 artifact-cleanup checks were skipped.

This comment was generated by an AI agent (OpenHands) on behalf of @enyst.

@openhands-ai

openhands-ai Bot commented Sep 21, 2026

Copy link
Copy Markdown

Fixed and pushed commit 491bb41 to PR #617.

Cause: The Jev skill’s API-key guidance changed, but the generated skills/index.js was stale.

Fix: Regenerated the catalog. No workflow or test changes were needed.

Verification: All 9 applicable CI checks pass. Full test suite: 958 passed, 24 skipped.

Posted the diagnosis and results on the PR.

@all-hands-bot all-hands-bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This review was posted by an AI agent (OpenHands).

Scope: in-repo. A reusable public skill belongs in this registry, and the change follows the authoring rules in AGENTS.md (one skill per directory, progressive disclosure, upstream docs as source of truth, keyword trigger, no secrets, marketplace + catalog registration). No cross-repo or product-direction concern.

Verified on head 491bb417a623bae2b0b5b7fa6e14441ff0630afa:

  • Content correctness (strongest signal): I installed the released typesafe-sdk (0.7.1) and validated the example against the real API. Choice/Score/Noul take instructions + criteria with exactly the shapes used here; TypeSafeClient accepts api_key; client.system_one(state=..., questions=...) exists; and result.choices["..."].choice, result.scores["..."].score, result.nouls["..."].noul are all real accessors. The snippet runs to the auth boundary and fails only on the dummy key (TypeSafeAuthenticationError), so the code path is correct. All 14 upstream links return HTTP 200.
  • Registry plumbing: marketplace entry, skills/index.js, and README catalog counts are consistent; .plugin/plugin.json has the fields enforced by tests/test_skill_plugin_loading.py; vendor symlinks and the README.md symlink match the issue's stated requirements.
  • Tests: uv run pytest -q tests/test_skills_have_readme.py tests/test_skill_plugin_loading.py tests/test_skills_catalog.py -> 131 passed locally. All GitHub Actions checks are green on this head (test, check, sync-extensions, sync-sdk-skill, validate-claude-code, PR gates).

Material finding - this branch cannot be merged as-is.

GitHub reports mergeable: false / mergeable_state: dirty. I reproduced the conflicts against the current main (f02d3aa) with git merge-tree: README.md, marketplaces/openhands-extensions.json, and skills/index.js all conflict. These are generated files, and main has advanced past this branch's merge-base with two added skills (canvas-extension-api, github-stale-ci-pr-closer) plus releases 0.23.0/0.24.0. The PR needs a rebase onto current main followed by regenerating the derived artifacts (npm run build:skills, python scripts/sync_extensions.py). Without this the PR will not merge.

Non-blocking note on generated content: re-running uv run python scripts/sync_openhands_sdk_skill.py --check on this head now fails because the docs site gained a new SDK example after this head's CI ran. That is upstream drift, not a defect introduced here, but the SDK reference should be refreshed during the rebase so the sync-sdk-skill check stays green.

Non-blocking note on JEV_API_KEY: the upstream SDK's own default env var is TYPESAFE_API_KEY; JEV_API_KEY appears nowhere in the upstream docs. The example is still correct because it passes the value explicitly via api_key= (verified: explicit values take precedence), and the linked issue mandates JEV_API_KEY, so no change is required. Worth knowing that a user who only sets TYPESAFE_API_KEY will not have it picked up by this snippet.

Minor consistency (non-blocking): skills/use-jev/.plugin/plugin.json is the only manifest in the repo that omits "license": "MIT" (the other 73 declare it). No test enforces this and the linked issue only asked not to add a separate license file, so it does not block the merge.

Repository fit / risk: documentation-only addition, no executable paths merged into this repo; the only runtime surface is an example that reads a key from the environment rather than embedding it. Risk: LOW.

🔄 CHANGES REQUESTED

@VascoSch92

Copy link
Copy Markdown
Member

@enyst once the review bit is happy i'm also happy. Feel free to merge

@enyst
enyst merged commit c4551cf into OpenHands:main Oct 1, 2026
13 of 14 checks passed
@openhands-release-bot openhands-release-bot Bot added the released: v0.26.0 Shipped in v0.26.0 label Oct 2, 2026
@openhands-release-bot

Copy link
Copy Markdown
Contributor

🚀 Released in v0.26.0.

@jpshackelford jpshackelford mentioned this pull request Oct 2, 2026
1 task
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

released: v0.26.0 Shipped in v0.26.0 type: feat A new feature

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add a concise use-jev classifier skill

4 participants