Follow-up to PR #966 review comment: #966 (comment)
Background
install_skill() currently combines skill-resource discovery, path-safety checks, directory handling, and file copying. As more skill validation or installation behavior is added, this makes the function harder to test and maintain.
Proposed work
- Split
install_skill() into smaller focused helpers.
- Extract reusable filesystem/path-safety checks where appropriate.
- Keep protection against path traversal, symlinked paths, symlink replacement, and non-directory targets.
- Preserve the current public behavior and error messages unless a deliberate API change is documented.
- Add targeted unit tests for the extracted helpers and keep an integration test for end-to-end skill installation.
Scope
This is intentionally separate from PR #966 to avoid expanding that PR beyond packaged-skill support.
Follow-up to PR #966 review comment: #966 (comment)
Background
install_skill()currently combines skill-resource discovery, path-safety checks, directory handling, and file copying. As more skill validation or installation behavior is added, this makes the function harder to test and maintain.Proposed work
install_skill()into smaller focused helpers.Scope
This is intentionally separate from PR #966 to avoid expanding that PR beyond packaged-skill support.