make-ai-assistant
Use when integrating, upgrading, debugging, or reviewing @qfei-design/make-ai-assistant in a Make App: Agent discovery, multi-session chat, streaming, file/image input, Service gateway routes, and package-owned UI. Does not own generic dialogs, model behavior, authentication or permission policy, DSL, or publishing.
How do I install this agent skill?
npx skills add https://github.com/qfeius/make-platform-skills --skill make-ai-assistantIs this agent skill safe to install?
- Gen Agent Trust Hubwarn
The skill provides an audit script that dynamically loads and executes code from a project's node_modules directory using computed paths. This creates a risk of arbitrary code execution if the audited project contains malicious code. Furthermore, the skill involves processing untrusted source code, which represents an indirect prompt injection risk.
- Socketpass
No alerts
- Snykwarn
Risk: MEDIUM · 1 issue
What does this agent skill do?
Make AI Assistant
This Skill owns the host integration contract, not the package's internal UI or
state machine. The Make App host owns identity, bounded page context, one
authenticated raw-byte transport, explicit Service routes, and deployment
configuration.
This Skill's Make App v1 reference is aligned with the Agent Public API v1
OpenAPI revision 60bbbcfe90c6defce46a0ed715e008fa4db20deb and the
package's public v1 entry points. The Skill version and npm package version
are independent; verify the actual installed version before implementation.
Workflow
- Inspect the target host's package manager, authenticated shell and identity, shared auth adapter, UI/Service routes, permission checks, runtime origin, tests, and existing assistant integration. Preserve stable call chains.
- Read
references/package-integration.md. For a new installation or a requested latest upgrade, query the configured registry, install the latest published package in the consumer UI workspace, and verify its exact lockfile version, public export map and declarations. If the installed version does not expose this Skill's required public contract, stop with the missing export/type and version; do not synthesize compatibility from another project or package prose. - Use the versioned Make App AI Chat contract in
references/make-app-protocol.md, including schemas, limits, extensible public errors and the pinned backend revision. Check the current backend contract/deployed behavior before claiming production readiness. If that check is unavailable or differs, retain the documented v1 implementation but report runtime compatibility as unverified; never infer an older API from another project. - For a full integration, read the package, host, protocol, stream/attachment, UI, and test references below. For a targeted fix, read only the relevant references. Use TDD: failing contract/behavior test, minimal implementation, then refactor with tests green.
- Use only public imports and import
styles.cssonce. Create the public/clientwith a host-authenticatedAuthenticatedTransport, discover the unique current-Appapp_internalAgent across complete pagination, thenawait createMakeAppAssistantTransport({ client, agentId, signal }). The SDK owns v1 DTOs, decoding, retries, uploads, SSE and UI transport mapping. - Expose only the 18 documented Make App v1 Service operations. Validate App scope, method/path/query/body, a single same-origin HTTP(S) Origin for every non-GET/HEAD request, sizes and upstream target before forwarding.
- Keep package UI internals package-owned. Use public props/theme variables for host placement and presentation; never copy its reducer, stream parser, upload engine, task list, composer or CSS.
- Run the static audit, focused UI/Service tests, typecheck, build and an authenticated existing-route smoke test. A static preflight pass cannot prove all 18 Service operations, runtime correctness or deployment readiness.
For a Skill contract release, complete the independent forward test in
references/testing-and-pitfalls.md before declaring this guidance ready.
node skills/make-ai-assistant/scripts/audit-make-ai-assistant-project.mjs <project-root> \
--expected-package-version=<resolved-exact-version>
The expected version is the actual installed resolution, not a range. A claim of broader model-input support needs separate deployed-model evidence. Verify published same-origin requests and response streaming against the target Dev App before reporting an integration complete.
Reference map
| Topic | Read |
|---|---|
| Package resolution, public types and React props | references/package-integration.md |
| Make App host composition, Agent discovery and identity | references/make-app-host-integration.md |
| Make App v1 18-operation API and Service boundary | references/make-app-protocol.md |
| SDK stream recovery and file/image behavior | references/make-app-stream-and-attachments.md |
| Package UI, theme and accessibility | references/ui-and-templates.md |
| Tests and delivery gates | references/testing-and-pitfalls.md |
Hard boundaries and handoffs
- Browser Make App requests use same-origin
/api/make/app/ai/v1/**. The SDK appends/v1to its path-free version base; do not append it twice. Local preview upstream usesmake_api_origin + /api/make/app/ai/v1/**; published Service uses the configured Make Gateway origin plus/make/app/ai/v1/**. Never add a separate Agent Gateway origin, token or hard-coded Agent ID. - The selected App Agent must have
agentType === "app_internal"and an exact currentappKey. Ignore channel and unknown Agent types, but fail on zero or multiple matching App-internal Agents. Read every page before accepting one. AuthenticatedTransport.requestperforms one credentialed same-origin I/O and yields status, headers and rawAsyncIterable<Uint8Array>; it never reads a browser token or unwraps SSE/bytes as JSON. SetretryOwnerto exactly one owner. Preserve 201/202/204,Make-AI-Api-Version, AbortSignal and 401/403 login/permission handling.- Capabilities are fetched by the package at adapter creation. They gate optional UI features and supply model input kinds/limits; they are not authorization. Upload availability does not prove the model can interpret a file or image. The current Make App adapter does not carry Artifact; do not add unsupported context, Artifact or negotiation fields or promise Artifact UI.
- App, tenant or user changes abort old discovery and dispose the old client. A panel close is local UI state, not a remote run cancellation. Keep a retryable launcher on Agent/capabilities discovery failure.
makeuiowns surrounding App shell and external placement; this Skill and the package own assistant-internal behavior/styles.make-app-serviceowns the explicit proxy, validation and safe errors.make-app-authowns unified login and the narrow AI raw-byte bridge rule.make-app-permissionowns access and action authorization.make-app-runtimeowns preview/published origins and build contracts.make-env-setupowns Skill installation/sync;makecliowns platform inspection, not runtime Service requests.- Keep page context bounded and non-secret. Never treat it as authorization or execute server-provided HTML, JSX, CSS, JavaScript or unvalidated action URLs. Testing mocks are opt-in and cannot establish backend readiness.
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/qfeius/make-platform-skills/make-ai-assistant">View make-ai-assistant on skillZs</a>