Skip to content

fix: cursorrules and mdc support, report markdown escaping, and output flag validation - #109

Merged
sx4im merged 4 commits into
mainfrom
fix/cursorrules-markdown-escape-flags-docs
Oct 9, 2026
Merged

sx4im merged 4 commits into
mainfrom
fix/cursorrules-markdown-escape-flags-docs

Conversation

@sx4im

@sx4im sx4im commented Oct 7, 2026

Copy link
Copy Markdown
Owner

Summary

This pull request resolves four targeted issues:

  1. Accept .cursorrules and .cursor/rules/*.mdc files:

    • Updates validateSkillInput in packages/cli/src/ui/picker.ts and resolveSkillFile in packages/cli/src/normalize.ts to accept .cursorrules and .mdc files directly and in folders.
    • Adds 'mdc' to SkillFormat in types.ts.
    • Updates README accepted inputs documentation.
  2. Sanitize skill names and prompt excerpts in Markdown reports:

    • Escapes @, [, ], <, >, backticks, pipes, and newlines in packages/cli/src/ui/markdown.ts.
    • Prevents GitHub user/team mentions, link injections, HTML injections, code span injections, and table/header breakouts.
  3. Reject combining --markdown and --json flags:

    • Raises an explicit error in parseCheckOptions when both flags are supplied instead of silently choosing JSON.
  4. Document checkpoint retention:

    • Updates README.md to clarify that check stores nothing locally except for checkpoints retained after interrupted runs for --resume.

Assumptions

  • GitHub Mention Neutralization: CommonMark and GFM autolink processors run post-parse on text nodes, meaning backslash escapes (\@) and numeric entities (&#64;) still trigger user mention pings. Inserting a zero-width space (@\u200b) neutralizes the mention regex without impacting visual formatting.
  • Flag Exclusivity Timing: Flag exclusivity for --markdown and --json is validated immediately during CLI option parsing (parseCheckOptions).
  • MDC Format Classification: Added 'mdc' to SkillFormat in types.ts to align normalization and discovery conventions.

🤖 Generated with Claude Code

sx4im and others added 4 commits October 7, 2026 21:07
Co-Authored-By: Claude Code <noreply@anthropic.com>
Escape mentions, links, HTML tags, code spans, pipes, and newlines
in skill names and task prompts when generating markdown reports.

Co-Authored-By: Claude Code <noreply@anthropic.com>
Raise an error when both --markdown and --json are passed to check,
preventing the CLI from silently selecting JSON output.

Co-Authored-By: Claude Code <noreply@anthropic.com>
Clarify that check stores nothing locally except for checkpoints retained
after an interrupted run for resume support.

Co-Authored-By: Claude Code <noreply@anthropic.com>
@vercel

vercel Bot commented Oct 7, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
dashboard-skillcheck Ready Ready Preview Oct 7, 2026 4:22pm UTC

@sx4im
sx4im merged commit 1d61e2e into main Oct 9, 2026
7 checks passed
@sx4im
sx4im deleted the fix/cursorrules-markdown-escape-flags-docs branch October 9, 2026 15:48

This branch was successfully deployed

1 active deployment
Preview — 757e4d16 Deployed Oct 7, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant