Escape lineage metadata and surface actionable diagnostics - #41
Merged
Merged
Conversation
Escape short names, branch fallbacks, and test counts at rendering boundaries. Add parser and CLI regressions while preserving metadata and count display semantics. Fixes #37 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Report required input/output failures with repair guidance, replace silent optional-data fallbacks with contextual warnings, and keep ordinary escaped metadata successful. Document stderr forwarding and agent-managed retries. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Xingdi (Eric) Yuan (xingdi-eric-yuan)
requested a review
from Chinmay Singh (chisingh)
September 24, 2026 00:19
Chinmay Singh (chisingh)
approved these changes
Sep 24, 2026
Chinmay Singh (chisingh)
left a comment
Contributor
There was a problem hiding this comment.
Looks good!
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes #37.
Escape untrusted experiment short names, branch-name fallbacks, and manifest test counts when rendering timeline cards and compact lineage trees. These values now appear as literal text rather than becoming active HTML in the generated local artifact.
Escaping stays at the output boundary: stored metadata is unchanged, existing report/title escaping is retained, and ordinary numeric, zero, missing, and empty count behavior is preserved.
Actionable feedback
HTML-like metadata is valid text and is escaped without reporting an error. Actual generation problems are surfaced to the host agent:
ERRORmessages on stderr and exit 1, without a traceback or a success message. An invalid explicit--shadow-diris not replaced with a different shadow.WARNINGmessages with paths, fields or line numbers and repair/retry guidance. These recoverable cases can still produce a partial view.The skill instructs the host to forward stderr even on a successful exit and repair the reported input before rerunning. The helper does not invoke a model or retry automatically.
Verification
298 Viewer/lineage tests passed. Coverage includes both renderers, generated chain/fresh/tree views, both manifest count fields, branch fallbacks, Unicode/quotes/ampersands, input immutability, and the real CLI. HTML parser assertions verify literal rendered text and the absence of injected elements/attributes; the original 16 escaping regressions failed before the fix.
Real-file CLI regressions also cover required read/write/encoding failures, wrong explicit shadow paths, warnings for invalid optional metadata and index rows, absent optional inputs, and safe literal metadata producing no error.
This addresses script injection into the generated local HTML artifact. Verification uses parser and CLI tests rather than interactive browser automation.
Based directly on current
main; independent of #33 and the reconciler path-containment fix for #36.