Replace the greenfield Python hello world with a Node.js 22/TypeScript/npm toolchain while preserving the existing greeting behavior.
Co-authored-by: Cursor <cursoragent@cursor.com>
Enable local workshop readiness with executable SQLite migrations, OpenTelemetry hello signals, and a provisioned Grafana demo dashboard over Tempo/Loki/Prometheus.
Co-authored-by: Cursor <cursoragent@cursor.com>
The Test-Path call at line 189 checks for feature.json without -LiteralPath, while other path checks in the same file consistently use -LiteralPath. If the repository root path contains wildcard characters (e.g., square brackets), this check could misinterpret the path and fail to locate the file, breaking feature resolution for projects in such directories.
The skill instructs the agent to run mkdir -p SPECIFY_FEATURE_DIRECTORY, which is a Unix command. In PowerShell, mkdir is an alias for New-Item and does not accept the -p flag. This will cause a parameter binding error and break the spec creation workflow on Windows/PowerShell environments.
The regex \.\.[\\/] at line 686 only catches parent directory traversal when followed by a path separator. It misses .. at the end of a path without a trailing separator (e.g., foo/..). While manifests are typically trusted, this could allow path traversal if an attacker can influence the manifest file path to reference files outside the preset directory.
## PR Reviewer Guide 🔍
Here are some key observations to aid the review process:
<table>
<tr><td>⏱️ <strong>Estimated effort to review</strong>: 3 🔵🔵🔵⚪⚪</td></tr>
<tr><td>🧪 <strong>No relevant tests</strong></td></tr>
<tr><td>🔒 <strong>No security concerns identified</strong></td></tr>
<tr><td>⚡ <strong>Recommended focus areas for review</strong><br><br>
<details><summary><a href='https://gitea.app.andreferraro.com/andreferraro/TicketLab_MCP/src/branch/feature/migrate-python-to-typescript/.specify/scripts/powershell/common.ps1#L189-L189'><strong>Missing -LiteralPath</strong></a>
The Test-Path call at line 189 checks for feature.json without -LiteralPath, while other path checks in the same file consistently use -LiteralPath. If the repository root path contains wildcard characters (e.g., square brackets), this check could misinterpret the path and fail to locate the file, breaking feature resolution for projects in such directories.
</summary>
```powershell
} elseif (Test-Path $featureJson) {
```
</details>
<details><summary><a href='https://gitea.app.andreferraro.com/andreferraro/TicketLab_MCP/src/branch/feature/migrate-python-to-typescript/.cursor/skills/speckit-specify/SKILL.md#L94-L94'><strong>Invalid PowerShell command</strong></a>
The skill instructs the agent to run `mkdir -p SPECIFY_FEATURE_DIRECTORY`, which is a Unix command. In PowerShell, `mkdir` is an alias for New-Item and does not accept the `-p` flag. This will cause a parameter binding error and break the spec creation workflow on Windows/PowerShell environments.
</summary>
```markdown
- `mkdir -p SPECIFY_FEATURE_DIRECTORY`
```
</details>
<details><summary><a href='https://gitea.app.andreferraro.com/andreferraro/TicketLab_MCP/src/branch/feature/migrate-python-to-typescript/.specify/scripts/powershell/common.ps1#L686-L686'><strong>Incomplete path traversal check</strong></a>
The regex `\.\.[\\/]` at line 686 only catches parent directory traversal when followed by a path separator. It misses `..` at the end of a path without a trailing separator (e.g., `foo/..`). While manifests are typically trusted, this could allow path traversal if an attacker can influence the manifest file path to reference files outside the preset directory.
</summary>
```powershell
if ([System.IO.Path]::IsPathRooted($manifestFilePath) -or $manifestFilePath -match '\.\.[\\/]') {
```
</details>
</td></tr>
</table>
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
PR Type
Enhancement, Documentation
Description
Bootstrap Spec Kit SDD workflow with PowerShell scripts
Add Cursor skills for Spec Kit command integration
Include TicketLab constitution and project templates
Configure Spec Kit integration and initialization options
Diagram Walkthrough
File Walkthrough
3 files
Add common PowerShell functions for Spec KitAdd feature creation scriptAdd prerequisites check script7 files
Add specify skill documentationAdd clarify skill documentationAdd analyze skill documentationAdd checklist skill documentationAdd TicketLab constitutionAdd checklist templateAdd SDD workflow rules2 files
Add Spec Kit integration configAdd initialization options config16 files
PR Reviewer Guide 🔍
Here are some key observations to aid the review process:
Missing -LiteralPath
The Test-Path call at line 189 checks for feature.json without -LiteralPath, while other path checks in the same file consistently use -LiteralPath. If the repository root path contains wildcard characters (e.g., square brackets), this check could misinterpret the path and fail to locate the file, breaking feature resolution for projects in such directories.
Invalid PowerShell command
The skill instructs the agent to run
mkdir -p SPECIFY_FEATURE_DIRECTORY, which is a Unix command. In PowerShell,mkdiris an alias for New-Item and does not accept the-pflag. This will cause a parameter binding error and break the spec creation workflow on Windows/PowerShell environments.Incomplete path traversal check
The regex
\.\.[\\/]at line 686 only catches parent directory traversal when followed by a path separator. It misses..at the end of a path without a trailing separator (e.g.,foo/..). While manifests are typically trusted, this could allow path traversal if an attacker can influence the manifest file path to reference files outside the preset directory.Failed to generate code suggestions for PR
Pull request closed