Skip to content

Sync vendored skills with skills main (d9aadab3 / #60–#61) - #22

Merged
davidmytton merged 1 commit into
mainfrom
david/cursor/vendor-skills-d9aadab3-9db9
Sep 4, 2026
Merged

davidmytton merged 1 commit into
mainfrom
david/cursor/vendor-skills-d9aadab3-9db9

Conversation

@davidmytton

@davidmytton davidmytton commented Sep 4, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Updates the vendored skill tree to match current arcjet/skills main at d9aadab3c6e54603a7380ff1b497432047fe7368 (arcjet/skills#61, merged 2026-09-04).

That SHA is skills main after:

This is a follow-up to #21, which synced 677f177. Did not wait for open arcjet/skills#59 (Python ADK + Cloudflare Think) — that PR is not on main yet.

Files were fetched from GitHub (cloned arcjet/skills at that SHA) rather than rewritten by hand. After copy, this repo’s dprint formatter was applied so CI’s format check passes.

What changed

Canonical copy is plugins/arcjet/skills/ (skills/ is the inbound symlink). Only that tree was updated.

New guards_js_* files (from skills#61)

guards_javascript.md is fundamentals + a routing table. One file per JS adapter:

  • guards_js_vercel_ai.md
  • guards_js_vercel_eve.md
  • guards_js_mastra.md
  • guards_js_langchain.md
  • guards_js_langgraph.md
  • guards_js_openai_agents.md
  • guards_js_genkit.md
  • guards_js_google_adk.md
  • guards_js_strands_agents.md
  • guards_js_tanstack_ai.md
  • guards_js_claude_agent_sdk.md
  • guards_js_claude_managed_agents.md

Skills main still has no JS integrate-arcjet-guard-* dirs. JS adapters stay in arcjet/. HTTP frameworks stay in the request references.

Also included from skills#60

  • Version stamps are published @arcjet/* 1.11.0 and Python arcjet 1.0.0
  • Docs URLs point at the merged tab pages from docs#921
  • Existing Python adapter skills updated in place (integrate-arcjet-guard-langchain-py, integrate-arcjet-guard-crewai, integrate-arcjet-guard-openai-agents-py, integrate-arcjet-guard-claude-agent-sdk-py, integrate-arcjet-guard-claude-managed-agents-py, integrate-arcjet-guard-strands-agents-py)

No extra remote-policy teaching (actor / inputs / policyInput). Existing remote-rules mentions in the copied files were left as they are.

What was left alone

Deprecated alias skill directories are not generated from the canonical skill. They are standalone deprecation stubs (add-request-protection, add-guard-protection, protect-route, add-ai-protection) and were left unchanged.

No marketplace catalog or plugin-manifest work. Hosts discover skills by scanning plugins/arcjet/skills/ (./skills/ in the Codex manifest).

Formatter note

dprint table alignment treats unescaped || inside backticks as a column break (same issue as prior sync PRs). The Node version-range cells keep the escapes (\|\|) so the upstream ranges survive formatting:

  • Node >=22.21.0 <23 || >=24.5.0 (requests + guards JS tables)

Test plan

  • dprint check
  • bash scripts/validate.sh
  • Vendored skill dirs match skills main at d9aadab3 (arcjet/ + the six integrate-arcjet-guard-* dirs; twelve new guards_js_*.md files; no JS integrate dirs on skills main)
  • Confirmed Node version-range \|\| escapes survived dprint
  • Confirmed no extra remote-policy actor / inputs / policyInput teaching
  • Confirmed alias skill directories unchanged
  • CI lint + validate jobs
Open in Web Open in Cursor 

Vendor arcjet/skills at d9aadab3 (skills#60 published 1.11.0/1.0.0 +
docs#921, skills#61 JS Guard per-file references). Apply this repo's
dprint formatter after copy.

Co-authored-by: David Mytton <davidmytton@users.noreply.github.com>
@davidmytton
davidmytton marked this pull request as ready for review September 4, 2026 21:32

@arcjet-review arcjet-review Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Arcjet Review — 🟢 Low Risk

Decision: Checked

Rationale: This PR is a documentation-only sync of vendored skill markdown files under plugins/arcjet/skills/ to match the upstream arcjet/skills repo at commit d9aadab3. No executable code, dependency manifests, CI/CD, infrastructure, or database changes. The bulk of the diff is a refactor of guards_javascript.md — the large per-adapter tables and code samples were extracted into 12 new per-adapter reference files (guards_js_.md), matching upstream skills#61. Version stamps updated to @arcjet/ 1.11.0 and Python arcjet 1.0.0 to reflect skills#60. The changes are internally consistent (SKILL.md now points at the new adapter files; CHANGELOG describes the sync; formatter escapes for Node version ranges preserved). No secrets, no auth logic, no input handling changes.

Summary of Changes

Syncs the vendored plugins/arcjet/skills/ tree to upstream arcjet/skills main at d9aadab3. Splits the JS Guard adapter section of guards_javascript.md into 12 new per-adapter reference files (vercel_ai, vercel_eve, mastra, langchain, langgraph, openai_agents, genkit, google_adk, strands_agents, tanstack_ai, claude_agent_sdk, claude_managed_agents); updates version stamps to @arcjet/* 1.11.0 / Python arcjet 1.0.0; updates six Python integrate-arcjet-guard-*-py SKILL.md files in place; adds a CHANGELOG entry. Documentation-only; no code changes.

Notes

PR size exceeds the 500-line threshold, but the changes are entirely markdown content in a vendored skill tree and are largely a mechanical extraction/split of an existing reference file into per-adapter siblings, so the size does not materially reduce review confidence. Did not load the security-review skill because there is no executable code, configuration, dependency, or input-handling change in scope for it — all changes are documentation strings inside vendored SKILL.md/reference files.

The AI assessed this PR as approvable, but the trust level (1) does not allow auto-approval. A human reviewer must approve this PR.

Review: e7ad2cb9 | Model: anthropic/claude-opus-4-7 | Powered by Arcjet Review

@davidmytton
davidmytton merged commit 2c95022 into main Sep 4, 2026
4 checks passed
@davidmytton
davidmytton deleted the david/cursor/vendor-skills-d9aadab3-9db9 branch September 4, 2026 21:37
@arcjet-review arcjet-review Bot removed the needs review Awaiting human review label Sep 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants