ci(pi): publish @tiny-fish/pi to npm (PF-3852) - #42
Merged
Merged
Conversation
|
Warning Review limit reached
On-demand reviews are free for the next 6 days. After that, they cost $0.25 per reviewed file. Or wait 54 minutes for your next included review. View limit detailsLimit details: You’ve used all 2 included reviews currently available. Your 55 included PR review attempts over the past 7 days set your current allowance at 2 reviews per hour. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Essentials Run ID: 📒 Files selected for processing (1)
Comment |
Zechereh
force-pushed
the
zach/pf-3852-pi-skills
branch
from
September 11, 2026 20:13
a9aa667 to
3b5a9d1
Compare
Zechereh
force-pushed
the
zach/pf-3852-pi-publish
branch
from
September 11, 2026 20:13
2301226 to
2f12aab
Compare
KateZhang98
approved these changes
Sep 11, 2026
Zechereh
force-pushed
the
zach/pf-3852-pi-publish
branch
from
September 11, 2026 22:45
2f12aab to
70664be
Compare
Zechereh
force-pushed
the
zach/pf-3852-pi-skills
branch
from
September 11, 2026 22:54
3b5a9d1 to
fc5eb03
Compare
Zechereh
force-pushed
the
zach/pf-3852-pi-publish
branch
from
September 11, 2026 22:54
70664be to
a45adb1
Compare
londondavila
approved these changes
Sep 14, 2026
Zechereh
force-pushed
the
zach/pf-3852-pi-skills
branch
from
September 14, 2026 17:33
fc5eb03 to
cd11196
Compare
Zechereh
force-pushed
the
zach/pf-3852-pi-publish
branch
from
September 14, 2026 17:33
a45adb1 to
af63024
Compare
Zechereh
force-pushed
the
zach/pf-3852-pi-skills
branch
from
September 14, 2026 17:35
cd11196 to
602cf1f
Compare
Zechereh
force-pushed
the
zach/pf-3852-pi-publish
branch
from
September 14, 2026 17:35
af63024 to
7dd382a
Compare
Zechereh
force-pushed
the
zach/pf-3852-pi-skills
branch
from
September 14, 2026 17:57
602cf1f to
38298c2
Compare
Zechereh
force-pushed
the
zach/pf-3852-pi-publish
branch
from
September 14, 2026 17:57
7dd382a to
fc00d50
Compare
Zechereh
force-pushed
the
zach/pf-3852-pi-skills
branch
from
September 14, 2026 18:00
38298c2 to
b9f326a
Compare
Zechereh
force-pushed
the
zach/pf-3852-pi-publish
branch
from
September 14, 2026 18:00
fc00d50 to
38347c1
Compare
Zechereh
force-pushed
the
zach/pf-3852-pi-skills
branch
from
September 14, 2026 18:53
b9f326a to
c96a5ed
Compare
Zechereh
force-pushed
the
zach/pf-3852-pi-publish
branch
from
September 14, 2026 18:54
38347c1 to
023b6ca
Compare
Zechereh
force-pushed
the
zach/pf-3852-pi-skills
branch
from
September 14, 2026 19:03
c96a5ed to
c0ca5d5
Compare
Zechereh
force-pushed
the
zach/pf-3852-pi-publish
branch
from
September 14, 2026 19:03
023b6ca to
1949f09
Compare
Zechereh
force-pushed
the
zach/pf-3852-pi-skills
branch
from
September 14, 2026 19:13
c0ca5d5 to
a1e9c86
Compare
Zechereh
force-pushed
the
zach/pf-3852-pi-publish
branch
from
September 14, 2026 19:13
1949f09 to
f581015
Compare
Zechereh
force-pushed
the
zach/pf-3852-pi-skills
branch
from
September 14, 2026 19:28
a1e9c86 to
6364d72
Compare
Zechereh
force-pushed
the
zach/pf-3852-pi-publish
branch
from
September 14, 2026 19:28
f581015 to
15945df
Compare
Zechereh
force-pushed
the
zach/pf-3852-pi-skills
branch
from
September 14, 2026 19:39
6364d72 to
1b07022
Compare
Zechereh
force-pushed
the
zach/pf-3852-pi-publish
branch
from
September 14, 2026 19:39
15945df to
4e7f2b2
Compare
Zechereh
force-pushed
the
zach/pf-3852-pi-skills
branch
from
September 14, 2026 19:54
1b07022 to
4c6fc61
Compare
Zechereh
force-pushed
the
zach/pf-3852-pi-publish
branch
from
September 14, 2026 19:54
4e7f2b2 to
88789a7
Compare
Ports the five skills from `grok/` — router plus research, automation,
authenticated and browser — with their `references/` subdirs, which pi supports
natively. Prefixed names are kept deliberately: pi skills land in the shared
`~/.agents/skills` namespace alongside every other package's, where `search`
would be ambiguous and would also collide with the CLI-installed `use-tinyfish`.
Most of the diff is a verbatim port. The adaptations are:
| Change | Why |
|---|---|
| New "Finding the tools" section in the router | Same tool has three names depending on install path. The suffix is the tool, the prefix names the install. |
| New CLI-fallback section with a mapping table | Pi ships no MCP client, so most users have no TinyFish tools at all. The CLI grammar is two-level (`tinyfish search query "<q>"`) and does not mirror the tool names, so without the table a model invents `tinyfish run_web_automation`. |
| Rewrote both Auth sections | grok's said the server is "configured by this plugin, authenticated by OAuth on first connection" — the exact opposite of the truth on this route, which is key-only with no OAuth. |
| `rules/security.md` -> `../../rules/security.md` | Pi resolves skill references relative to the skill directory, so the bare path dangled. |
| "plugin" -> "package" throughout | This is an npm package, not a plugin; pi users would not recognise the term. |
The auth failure mode is quieter than expected and the copy reflects it. With
`TINYFISH_API_KEY` unset the server never finishes connecting, so no metadata
cache is built and *no tools register at all* — no 401, no error text, nothing at
startup. That is indistinguishable at a glance from having no adapter installed,
so the router carries a two-branch diagnostic: no `mcp` tool at all means no
adapter; `mcp` present but `mcp({ search: "tinyfish" })` empty means the key.
Verified in an isolated `PI_CODING_AGENT_DIR` against a live pi session: all five
skills load, all eight MCP tools register top-level, a real search call returns
through the package's own registration, and with the adapter removed the model
reaches `tinyfish search query "..."` unaided — then recovers to
`npx -y @tiny-fish/cli@latest` when the binary is absent too.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CBf5rnVYQYcxE8bLjfQuUP
Follows ux-labs CD_cli.yml rather than the PyPI workflows in this repo, because
it is the house pattern for npm here.
**Auth is npm Trusted Publisher (OIDC), so there is no NPM_TOKEN secret.** The
job requests `id-token: write` and npm verifies the workflow identity directly.
This repo has no npm secret and did not need to grow one.
Bootstrap is manual and one-time, because a trusted publisher cannot be
configured against a package that does not exist yet:
1. `cd pi && npm publish --access public`
2. npmjs.com -> @tiny-fish/pi -> Settings -> Trusted Publisher -> GitHub
Actions, repo tinyfish-io/tinyfish-web-agent-integrations, workflow
pi-publish.yml
3. every release after that is this workflow, triggered by a version bump
Documented in the workflow header so the next person does not have to
reconstruct it.
Publishing is gated on the version in pi/package.json not already existing on
the registry, so content-only edits do not require a version bump and a re-run
is a no-op rather than an error. An unexpected registry response fails the job
instead of reading as "already published".
Borrowed from CD_cli.yml, and the most valuable part here: verifying tarball
contents before publishing. This package ships no code, so a dropped `files`
entry is the entire failure mode — the tarball still publishes and still
installs, just with skills silently missing. The job asserts every SKILL.md,
mcp.json, the README and rules/security.md are present, and that the
references/ docs the skills link to came along. Negative-tested by removing
`rules` from `files`, which fails the job naming the missing path.
Node 24 for npm >= 11.5.1, which trusted publishing requires. Action refs use
tags to match every other hand-written workflow here; the one pinned SHA in the
repo is in Terraform-managed secrets-scanner.yml.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CBf5rnVYQYcxE8bLjfQuUP
Zechereh
force-pushed
the
zach/pf-3852-pi-skills
branch
from
September 14, 2026 21:01
4c6fc61 to
0c97464
Compare
Zechereh
force-pushed
the
zach/pf-3852-pi-publish
branch
from
September 14, 2026 21:01
88789a7 to
fb470eb
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stacked on #41. Release control for
@tiny-fish/pi, kept separate so the content PRs can merge independently.Modelled on ux-labs
CD_cli.ymlrather than the PyPI workflows in this repo — it is the house pattern for npm publishing.No
NPM_TOKENneededAuth is npm Trusted Publisher (OIDC), same as the CLI. The job requests
id-token: writeand npm verifies the workflow identity directly, so this repo does not grow an npm secret. (An earlier revision of this PR asked forNPM_TOKEN; that ask is withdrawn.)A trusted publisher cannot be configured against a package that does not exist yet, so the first release is by hand:
cd pi && npm publish --access public@tiny-fish/pi→ Settings → Trusted Publisher → GitHub Actionsrepo
tinyfish-io/tinyfish-web-agent-integrations, workflowpi-publish.ymlSteps 1–2 are yours to run — I can't publish to the
@tiny-fishscope. The same steps are in the workflow header so the next person doesn't have to reconstruct them.@tiny-fish/piis currently unclaimed (registry 404).When it publishes
Gated on the version in
pi/package.jsonnot already existing on the registry, so content-only edits don't need a version bump and a re-run is a no-op rather than an error. An unexpected registry response fails the job instead of reading as "already published".workflow_dispatchis there as a re-run escape hatch.Tarball verification — the part worth reviewing
Borrowed from
CD_cli.yml's "Verify npm package contents" step, and it matters more here than there. This package ships no code, so a droppedfilesentry is the entire failure mode: the tarball still publishes, still installs, and pi just silently has fewer skills. Nothing else would catch it.The job asserts
mcp.json, the README,rules/security.mdand all fiveSKILL.mdfiles are present, plus that thereferences/docs the skills link to came along — a skill pointing at a file that isn't in the tarball is worse than no pointer.Negative-tested: removing
rulesfromfilesfails the job withMissing from tarball: rules/security.md.Smaller notes
secrets-scanner.yml, which is Terraform-managed.concurrencywithcancel-in-progress: false— a publish must never be cancelled mid-upload.🤖 Generated with Claude Code
https://claude.ai/code/session_01CBf5rnVYQYcxE8bLjfQuUP