Conversation
88205b7 to
a10492d
Compare
Agents cannot inspect BrowserSkill's own debug console: the extension debug page is served under a chrome-extension:// URL that the Agent Window sandbox refuses to observe, so a failed tool call has no matching local diagnostics. Export what the CLI can see instead. The bundle contains the daemon log tail, daemon status, the `bsk doctor` checks and the active session list. Values of credential keys (token, cookie, authorization, password, …) become `[REDACTED]` by default; credential headers are redacted to end of line so `Bearer` tokens never survive. Every source degrades to a README note when the daemon or log file is absent, so a bundle is always writable. doctor::checks() exposes the check list without rendering so the export reuses the same daemon-state resolution `bsk doctor` does.
a10492d to
658fd4e
Compare
|
Thanks for adding this. A diagnostics bundle would make BrowserSkill failures much easier for users and agents to investigate, especially when the extension is disconnected. The CLI-visible scope is a useful first step,I like this PR. The patch applies to main 1. Make diagnostics collection passive
Exporting diagnostics should preserve the failure state. Please separate passive collection and check evaluation from startup, synchronization, and repair behavior. A missing daemon should be recorded as missing, without starting it. Likewise, installed skills should remain unchanged. Please reuse the check logic where possible, while keeping the existing 2. Fix redaction and apply it to every exported file The current log redactor misses common credential formats. These examples retain secrets: The Cookie example only redacts the first value. Escaped quotes also cause partial redaction. Conversely, There is also a separate coverage gap: only Please establish one sanitization boundary for all exported content. Structured JSON should be sanitized structurally, dynamic strings should receive text sanitization, and credential headers should have their complete values removed. The extension’s existing redaction implementation can inform the policy and shared test cases. 3. Keep the Please retain For consistency with existing exports, please use: bsk diagnostics export --output diagnostics.zipPlease add The documentation should explain collection scope, offline behavior, missing sources, redaction limits, and that exporting does not upload anything. Please explicitly state that the current bundle includes daemon-wide session summaries and logs; adding session filtering is not required for this PR. 4. Make output handling and size limits reliable
The advertised 4 MiB log limit is also exceeded: a test with long lines exported 4,259,839 bytes. Please enforce the documented limit on the final exported log, handle partial leading lines safely, and report truncation. Missing or failed sources should remain explicit in the bundle. 5. Add focused regression tests and clarify issue coverage Please cover the redaction cases above, secrets in doctor/error output, export without a daemon, unchanged installed skills, missing/unreadable sources, oversized logs, and existing output files. Since the original report is from Windows, please include relevant Windows validation. The current CLI/daemon bundle is useful, but it does not provide all extension-side diagnostics described in #335. Please clarify that this is a partial resolution and adjust the closing reference accordingly, keeping any remaining extension-side work tracked separately. There is no need to expand browser-page permissions for this PR. Once passive collection, bundle-wide redaction, reliable file handling, and the corresponding tests are in place, this would be a valuable addition to merge. |
What problem this solves
Fixes #335.
An agent that sees BrowserSkill fail has no supported way to inspect
BrowserSkill's own state: the extension debug page is served under a
chrome-extension://URL, which the Agent Window sandbox deliberatelyrefuses to observe, and borrowing the user's debug tab can fail when no
tab can show the confirmation. Recovery then depends on the user
manually reading debug output. This adds a CLI command that exports
what the CLI can see — daemon log tail, daemon status, the
bsk doctorchecks, and the active session list — as a single zip an agent can
attach to an issue report.
How this fixes it
bsk diagnostics export [--out <path>] [--log-lines <n>]writes a zip:metadata.json— CLI/daemon versions, platform, timestamp.doctor.json— the checksbsk doctorruns, with repair hints.status.json— daemon info, status and active sessions (nullwitha README note when no daemon is running).
daemon-log.txt— trailing log lines (default 500, capped at 4 MiB).README.md— contents, missing parts, redaction note, scope limits.Redaction is on by default: values of credential keys (token, cookie,
authorization, password, …) become
[REDACTED]in both JSON and shellspellings; credential headers are redacted to end of line so
Authorization: Bearer <token>never survives. Ordinary lines (URLs,session ids, tab ids) pass through unchanged, and keys embedded in
larger identifiers (
secretive,tokens_seen) are not touched. Theone residual gap — a raw credential with no key, e.g. a token inside a
URL — is called out in the README.
Every source is best-effort: a missing daemon or log file is recorded in
the README's "Missing parts" section instead of failing, so a bundle is
always writable.
doctor::checks()is extracted so the export reusesthe exact daemon-state resolution
bsk doctorruns.User impact
bsk diagnostics export --out diag.zipAgents and users get one file to attach when reporting problems, with
credential values removed. Scope is deliberately the CLI-visible
surface; the extension's own debug page remains out of reach by design
and is called out in the README.
Validation
cargo fmt --all -- --check,cargo clippy --workspace --all-targets --locked -- -D warnings,cargo test --workspace --locked(green;no new tests included in this PR).
session (Chrome for Testing 154 + unpacked extension) —
status.jsoncontains the session anddaemon-log.txtis redacted;with no daemon — all optional parts recorded as README notes.