Repository navigation
Sync vendored skills with skills main (d9aadab3 / #60–#61) - #22
Conversation
Vendor arcjet/skills at d9aadab3 (skills#60 published 1.11.0/1.0.0 + docs#921, skills#61 JS Guard per-file references). Apply this repo's dprint formatter after copy. Co-authored-by: David Mytton <davidmytton@users.noreply.github.com>
There was a problem hiding this comment.
Arcjet Review — 🟢 Low Risk
Decision: Checked
Rationale: This PR is a documentation-only sync of vendored skill markdown files under plugins/arcjet/skills/ to match the upstream arcjet/skills repo at commit d9aadab3. No executable code, dependency manifests, CI/CD, infrastructure, or database changes. The bulk of the diff is a refactor of guards_javascript.md — the large per-adapter tables and code samples were extracted into 12 new per-adapter reference files (guards_js_.md), matching upstream skills#61. Version stamps updated to @arcjet/ 1.11.0 and Python arcjet 1.0.0 to reflect skills#60. The changes are internally consistent (SKILL.md now points at the new adapter files; CHANGELOG describes the sync; formatter escapes for Node version ranges preserved). No secrets, no auth logic, no input handling changes.
Summary of Changes
Syncs the vendored plugins/arcjet/skills/ tree to upstream arcjet/skills main at d9aadab3. Splits the JS Guard adapter section of guards_javascript.md into 12 new per-adapter reference files (vercel_ai, vercel_eve, mastra, langchain, langgraph, openai_agents, genkit, google_adk, strands_agents, tanstack_ai, claude_agent_sdk, claude_managed_agents); updates version stamps to @arcjet/* 1.11.0 / Python arcjet 1.0.0; updates six Python integrate-arcjet-guard-*-py SKILL.md files in place; adds a CHANGELOG entry. Documentation-only; no code changes.
Notes
PR size exceeds the 500-line threshold, but the changes are entirely markdown content in a vendored skill tree and are largely a mechanical extraction/split of an existing reference file into per-adapter siblings, so the size does not materially reduce review confidence. Did not load the security-review skill because there is no executable code, configuration, dependency, or input-handling change in scope for it — all changes are documentation strings inside vendored SKILL.md/reference files.
The AI assessed this PR as approvable, but the trust level (1) does not allow auto-approval. A human reviewer must approve this PR.
Review: e7ad2cb9 | Model: anthropic/claude-opus-4-7 | Powered by Arcjet Review
Summary
Updates the vendored skill tree to match current
arcjet/skillsmainatd9aadab3c6e54603a7380ff1b497432047fe7368(arcjet/skills#61, merged 2026-09-04).That SHA is skills
mainafter:@arcjet/*1.11.0 / Pythonarcjet1.0.0 + arcjet-docs#921references/guards_js_*.mdThis is a follow-up to #21, which synced
677f177. Did not wait for open arcjet/skills#59 (Python ADK + Cloudflare Think) — that PR is not onmainyet.Files were fetched from GitHub (cloned
arcjet/skillsat that SHA) rather than rewritten by hand. After copy, this repo’sdprintformatter was applied so CI’s format check passes.What changed
Canonical copy is
plugins/arcjet/skills/(skills/is the inbound symlink). Only that tree was updated.New
guards_js_*files (from skills#61)guards_javascript.mdis fundamentals + a routing table. One file per JS adapter:guards_js_vercel_ai.mdguards_js_vercel_eve.mdguards_js_mastra.mdguards_js_langchain.mdguards_js_langgraph.mdguards_js_openai_agents.mdguards_js_genkit.mdguards_js_google_adk.mdguards_js_strands_agents.mdguards_js_tanstack_ai.mdguards_js_claude_agent_sdk.mdguards_js_claude_managed_agents.mdSkills
mainstill has no JSintegrate-arcjet-guard-*dirs. JS adapters stay inarcjet/. HTTP frameworks stay in the request references.Also included from skills#60
@arcjet/*1.11.0 and Pythonarcjet1.0.0integrate-arcjet-guard-langchain-py,integrate-arcjet-guard-crewai,integrate-arcjet-guard-openai-agents-py,integrate-arcjet-guard-claude-agent-sdk-py,integrate-arcjet-guard-claude-managed-agents-py,integrate-arcjet-guard-strands-agents-py)No extra remote-policy teaching (
actor/inputs/policyInput). Existing remote-rules mentions in the copied files were left as they are.What was left alone
Deprecated alias skill directories are not generated from the canonical skill. They are standalone deprecation stubs (
add-request-protection,add-guard-protection,protect-route,add-ai-protection) and were left unchanged.No marketplace catalog or plugin-manifest work. Hosts discover skills by scanning
plugins/arcjet/skills/(./skills/in the Codex manifest).Formatter note
dprinttable alignment treats unescaped||inside backticks as a column break (same issue as prior sync PRs). The Node version-range cells keep the escapes (\|\|) so the upstream ranges survive formatting:Node >=22.21.0 <23 || >=24.5.0(requests + guards JS tables)Test plan
dprint checkbash scripts/validate.shmainatd9aadab3(arcjet/+ the sixintegrate-arcjet-guard-*dirs; twelve newguards_js_*.mdfiles; no JS integrate dirs on skills main)\|\|escapes survived dprintactor/inputs/policyInputteaching