Skip to content
Back to skills

1001 Group Plugin Global Merge Fix 45aa30cb

ASecurity

Fixed/Implemented in version: **0.233.164**

  • 9 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 11, 2026
toolstestingapi

Works with

  • api

Security analysis

A100/100

Scanned October 11, 2026

npx -y skills add tools-only/X-Skills --skill 1001-group_plugin_global_merge_fix_45aa30cb --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of 1001 Group Plugin Global Merge Fix 45aa30cb?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for 1001 Group Plugin Global Merge Fix 45aa30cb
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/tools-only-1001-group-plugin-global-merge-fix-45aa30cb/badge)](https://www.skillsdirectory.com/skills/tools-only-1001-group-plugin-global-merge-fix-45aa30cb)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

SKILL.md
# Group Plugin Global Merge Fix

Fixed/Implemented in version: **0.233.164**

## Issue Description
Group workspaces were unable to see or select globally managed actions when the
`merge_global_semantic_kernel_with_workspace` setting was enabled. The group
plugins API only returned group-scoped actions, which left the agent creation
modal without access to global plugins.

## Root Cause
The `/api/group/plugins` endpoint did not append global actions to its response
payload. Because of this, the front-end never received the global entries and
could not surface them inside the selection modal.

## Code Changes Summary
- Merge global actions into the group plugins API response while marking them as
  read-only.
- Prevent group routes from creating, updating, or deleting globally managed
  actions.
- Update the group workspace UI to badge global plugins and block edit/delete
  attempts.
- Preserve global flags in the agent modal so the selection flow displays
  accurate scope metadata.

## Testing Approach
- Added functional test `test_group_plugin_global_merge_fix.py` covering the
  merge helper and normalization logic.

## Impact Analysis
Users in group workspaces can now select and use global actions when the merge
setting is enabled, while global assets remain protected from modification at
the group level.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…