bl currently self-updates silently and then unconditionally re-runs bl skill init, with no persistent way to opt out of either step.
What happens
- Any command (e.g. a scheduled
bl usage token-plan) triggers shouldAutoUpdate() when the installed version is a major behind, or more than 3 minors behind (packages/runtime/src/utils/update-checker.ts). It then runs npm install -g bailian-cli@latest in the middle of the user's command.
- On success,
syncAgentSkillsAfterUpdate() runs bl skill init, which symlinks every bailian-* skill into every detected agent directory (~/.claude/skills, ~/.codex/skills, ~/.config/opencode/skills, ~/.pi/agent/skills, ~/.agents/skills, …). bl update does the same via updateAgentSkill() (packages/commands/src/commands/update.ts).
- The only gate is
ctx.settings.quiet, which comes from the per-invocation --quiet flag and is not a config.json key (packages/core/src/config/loader.ts), so it cannot be made persistent. bl skill init itself has no flags to limit targets.
Why this is a problem
Users who manage their agent skill directories elsewhere (dotfiles, a config-as-code repo) have their removals silently reverted on the next update. In my case 10 skills I had removed came back into five agent homes because a cron-style quota probe happened to run after 1.24.0 was published (telemetry: skill init at 2026-09-11T13:48:04Z, cliVersion 1.24.0, immediately after an in-flight 1.20.0 usage token-plan).
Request
Two independent, persistent switches (config.json key and/or env var), e.g.:
BAILIAN_AUTO_UPDATE=0 / "auto_update": false — never run npm install -g implicitly; only print the "update available" notice.
BAILIAN_SKILL_SYNC=0 / "skill_sync": false — never run bl skill init implicitly after an update (both the auto path and bl update).
Optionally, bl skill init --agent <list> so the sync can be scoped even when enabled.
Environment: bl 1.24.0, npm global install, macOS 26.6, node v26.8.2.
blcurrently self-updates silently and then unconditionally re-runsbl skill init, with no persistent way to opt out of either step.What happens
bl usage token-plan) triggersshouldAutoUpdate()when the installed version is a major behind, or more than 3 minors behind (packages/runtime/src/utils/update-checker.ts). It then runsnpm install -g bailian-cli@latestin the middle of the user's command.syncAgentSkillsAfterUpdate()runsbl skill init, which symlinks everybailian-*skill into every detected agent directory (~/.claude/skills,~/.codex/skills,~/.config/opencode/skills,~/.pi/agent/skills,~/.agents/skills, …).bl updatedoes the same viaupdateAgentSkill()(packages/commands/src/commands/update.ts).ctx.settings.quiet, which comes from the per-invocation--quietflag and is not aconfig.jsonkey (packages/core/src/config/loader.ts), so it cannot be made persistent.bl skill inititself has no flags to limit targets.Why this is a problem
Users who manage their agent skill directories elsewhere (dotfiles, a config-as-code repo) have their removals silently reverted on the next update. In my case 10 skills I had removed came back into five agent homes because a cron-style quota probe happened to run after 1.24.0 was published (telemetry:
skill initat 2026-09-11T13:48:04Z, cliVersion 1.24.0, immediately after an in-flight 1.20.0usage token-plan).Request
Two independent, persistent switches (config.json key and/or env var), e.g.:
BAILIAN_AUTO_UPDATE=0/"auto_update": false— never runnpm install -gimplicitly; only print the "update available" notice.BAILIAN_SKILL_SYNC=0/"skill_sync": false— never runbl skill initimplicitly after an update (both the auto path andbl update).Optionally,
bl skill init --agent <list>so the sync can be scoped even when enabled.Environment: bl 1.24.0, npm global install, macOS 26.6, node v26.8.2.