fix(dashboard): skill installs from the dashboard silently auto-cancel (#45150)

The dashboard's /api/skills/hub/install (and the new-profile hub_skills
path) spawned `hermes skills install <id>` with stdin=DEVNULL but
without --yes. do_install()'s 'Confirm [y/N]' prompt hit EOF, defaulted
to 'n', and printed 'Installation cancelled.' into a background log the
user never sees — every dashboard install no-opped.

Pass --yes on both spawn sites, matching the uninstall endpoint which
already passed --yes. The dashboard install button is the explicit user
consent, same as the TUI/slash-command skip_confirm rationale.

Repro: spawned the exact argv with stdin=DEVNULL against a temp
HERMES_HOME — without --yes it cancels, with --yes the skill installs.
This commit is contained in:
Teknium
2026-06-12 12:58:36 -07:00
committed by GitHub
parent bba9b519aa
commit a118b94a85
3 changed files with 14 additions and 5 deletions
+6 -1
View File
@@ -2690,7 +2690,12 @@ class TestNewEndpoints:
assert data["hub_installs"] == [{"identifier": "someuser/some-skill", "pid": 4321}]
# Hub install was scoped to the new profile.
assert spawned == [(["-p", "builder", "skills", "install", "someuser/some-skill"], "skills-install")]
assert spawned == [
(
["-p", "builder", "skills", "install", "someuser/some-skill", "--yes"],
"skills-install",
)
]
# Verify the writes landed in the NEW profile's config, not the root.
prof_dir = get_hermes_home() / "profiles" / "builder"