### 1. Overall Summary
此次文档更新主要优化了 CLI 交互体验(建议补全流程),增强了 MCP 配置与规范的兼容性,明确了插件系统特别是 `skills` 字段的路径合并逻辑,并为 `autoMode` 引入了更严格的拒绝权限控制。
### 2. Key Themes
* **插件系统行为变更**:明确 `skills` 配置项现在是“追加”而非“替换”默认目录,这与其他资源类型(如 `commands`)的行为不同。
* **安全与权限增强**:在 `autoMode` 中引入了 `hard_deny` 规则数组,并澄清了在非交互模式下使用 `--worktree` 时仍需信任验证。
* **交互体验 (UX) 调整**:修改了接受建议的操作描述,明确了 Tab/Right Arrow 仅是将建议放入输入框,仍需按 Enter 才能提交。
* **配置标准化**:MCP 配置中的 `type` 字段现在接受 `streamable-http` 作为 `http` 的别名,以符合 MCP 规范。
### 3. Impact Level: Medium
**理由**:
* **中等**:插件开发者需要注意 `skills` 路径行为的变更(由替换变为叠加),这可能会影响现有插件的技能加载逻辑。
* 其他变更主要是新增功能(如 `hard_deny`)、便利性改进或文档澄清,通常不会破坏现有功能。
### 4. Action Items for Developers
* **检查插件配置**:如果你是插件作者,请检查 `manifest.json` 中的 `skills` 配置。如果原意是替换默认技能,现在需要显式处理或清理默认目录,因为现在是叠加加载。
* **利用 `hard_deny`**:在 `settings.json` 的 `autoMode` 配置中,可以使用新的 `hard_deny` 数组来实施更严格的安全策略,确保特定操作绝对不被允许。
* **审查 CI 脚本**:如果你在自动化脚本(`-p` 标志)中使用了 `--worktree`,请注意这不再自动绕过信任验证,需要确保信任已被预先接受。
* **更新 MCP 配置**:可以直接使用 MCP 服务器文档中提供的 `streamable-http` 类型,无需修改为 `http`。
💭 Model Reasoning
1. **Analyze the Request**:
* **Role**: World-class programmer analyzing documentation changes.
* **Format**: Markdown.
* **Tone/Style**: Concise, insightful, focused on developer impact.
* **Language**: Chinese (requested: "请用中文回复").
* **Input**: Diffs from 5 documentation pages (`interactive-mode.md`, `mcp.md`, `plugins-reference.md`, `security.md`, `settings.md`).
* **Output Structure**:
1. Overall Summary (1-2 sentences).
2. Key Themes (bullets).
3. Impact Level (with reasoning).
4. Action Items (max 5).
2. **Analyze the Diffs**:
* **Page: `interactive-mode.md`**:
* *Change*: Text clarification on accepting suggestions. Old: Press Tab/Right arrow to accept, Enter to accept and submit. New: Press Tab/Right arrow to *place* suggestion in input, *then* Enter to submit.
* *Implication*: It clarifies the UX workflow. It's a distinction between "auto-submit" and "edit-then-submit". This is likely correcting a misunderstanding or a feature change where it no longer auto-submits on accept.
* *Developer Impact*: UX change in CLI usage.
* **Page: `mcp.md`**:
* *Change*: Added note about `type` field in JSON config accepting `streamable-http` as an alias for `http`.
* *Implication*: Better compatibility with the MCP spec. Makes copy-pasting config from docs easier.
* *Developer Impact*: Convenience, configuration standardization.
* **Page: `plugins-reference.md`**:
* *Change*:
* `skills` field description changed from "replaces default" to "in addition to default".
* "Path behavior rules" section significantly rewritten to distinguish between fields that *replace* defaults vs those that *add* to them.
* Clarifies that `skills` now merges, while `commands`, `agents`, etc., still replace unless the default is explicitly listed.
* Removed a generic tip about including defaults in arrays (replaced with specific field behaviors).
* *Implication*: This is a behavioral change/clarification for plugin authors. `skills` behavior is different from other resource paths.
* *Developer Impact*: Plugin development, plugin configuration. Significant if developers relied on `skills` replacing defaults.
* **Page: `security.md`**:
* *Change*: Added a note about `--worktree`. Trust verification is usually disabled with `-p`, *except* when using `--worktree`.
* *Implication`: CI/CD or automation scripts using worktrees will still need trust verification handling.
* *Developer Impact*: Security automation, CI pipelines using worktrees.
* **Page: `settings.md`**:
* *Change*: `autoMode` setting description mentions `hard_deny` array in addition to `soft_deny`.
* *Implication*: New feature in the permission/auto-mode classifier. Developers can now define hard denies (rules that block even if auto-mode might otherwise allow, or stricter enforcement).
* *Developer Impact`: Security policy configuration.
3. **Synthesize Key Themes**:
* **UX/Workflow**: Interactive mode prompt acceptance flow.
* **Compatibility/Standards**: MCP `streamable-http` alias.
* **Plugin System Behavior**: Specifically how `skills` paths are merged vs replaced compared to other resources.
* **Security/Permissions**: Hard denies in auto-mode, trust verification edge cases with worktrees.
4. **Determine Impact Level**:
* *Low*: MCP alias (convenience), Interactive mode text (UX clarification).
* *Medium*: Settings `hard_deny` (new feature, opt-in).
* *High/Potential Breaking*: Plugin `skills` path behavior. If a plugin relied on `skills` replacing the default directory, it might now load unexpected skills or cause conflicts. However, the doc says "in addition to", which implies an additive change (usually safe but changes behavior).
* *Conclusion*: **Medium**. The plugin behavior change is notable for plugin authors, but mostly additive. The `hard_deny` is a feature addition.
5. **Draft Action Items**:
* Plugin authors need to check if their `skills` config relies on replacing defaults.
* Admins can update `autoMode` to use `hard_deny` for stricter policies.
* MCP config can be updated to use standard spec names.
* CI pipelines using `--worktree` need to ensure trust is handled (no longer bypassed).
6. **Translate to Chinese & Refine**:
* *Summary*: This update refines CLI interaction flows, adds compatibility for MCP specifications, clarifies plugin path merging logic (specifically for skills), and expands permission control capabilities with hard denies.
* *Themes*:
* 插件系统行为变更
* 安全与权限增强
* 交互体验 (UX) 澄清
* 配置兼容性
* *Impact*: Medium. Plugin authors need to be aware of the `skills` path behavior change. Others are enhancements or clarifications.
* *Action Items*:
* Review plugin manifests if you customize `skills` paths.
* Utilize `hard_deny` in `autoMode` for stricter security.
* Check CI scripts using `--worktree` for trust requirements.
* Update MCP configs to use `streamable-http` if desired.
7. **Final Polish (Markdown)**: Ensure the tone is professional and concise.
* *Self-Correction on `interactive-mode.md`*: The change is subtle. It changes "accept and submit" to "place ... then enter". This means the user *must* press enter again. It's a slight UX friction change or safety feature (prevents accidental submission).
* *Self-Correction on `plugins-reference.md`*: The change is definitely a behavior shift. `skills` used to behave like `commands` (replace by default). Now it merges. This is the most impactful change for developers building plugins.
8. **Final Output Generation** (Mental Draft -> Final Output).
* Summary: 此次更新主要优化了 CLI 交互流程,增强了 MCP 配置的兼容性,明确并变更了插件路径合并逻辑(特别是 `skills` 字段),并扩展了权限控制的粒度。
* Themes: 插件系统逻辑变更, 权限与安全增强, 用户体验 (UX) 调整, 配置标准化。
* Impact: Medium. 插件开发者需关注 `skills` 路径行为变更(从替换变为叠加),其他主要为新增功能或说明修正。
* Action Items: 检查插件配置, 利用 `hard_deny`, 审查 CI 脚本, 更新 MCP 配置。
9. **Proceed to generate response.**