Migrate To Codex
Haohao-end/openagent
Migrate supported instruction files, skills, agents, and MCP config into Codex project and global files.
升级 CodeBuddy IDE(genie 扩展)内置的 CloudBase MCP,以及 MCP 发版时同步 IDE 侧白名单。当用户提到「更新 IDE 里的 MCP」「内置 MCP 版本太老」「IDE 集成的 CloudBase 功能不足」「改工具白名单 toolWhiteList」「把新 bundle 打进 CodeBuddy」「白名单漂移」「MCP…
$ npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill codebuddy-ide-mcp-upgrade -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install TencentCloudBase/CloudBase-AI-Toolkit codebuddy-ide-mcp-upgrade --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/TencentCloudBase/CloudBase-AI-Toolkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/codebuddy-ide-mcp-upgrade .claude/skills/codebuddy-ide-mcp-upgrade && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "codebuddy-ide-mcp-upgrade" agent skill from https://github.com/TencentCloudBase/CloudBase-AI-Toolkit/tree/main/skills/codebuddy-ide-mcp-upgrade into .claude/skills/codebuddy-ide-mcp-upgrade/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codebuddy-ide-mcp-upgrade", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/TencentCloudBase/CloudBase-AI-Toolkit/tree/main/skills/codebuddy-ide-mcp-upgradeType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill codebuddy-ide-mcp-upgrade -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install TencentCloudBase/CloudBase-AI-Toolkit codebuddy-ide-mcp-upgrade --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/TencentCloudBase/CloudBase-AI-Toolkit.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/codebuddy-ide-mcp-upgrade .agents/skills/codebuddy-ide-mcp-upgrade && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "codebuddy-ide-mcp-upgrade" agent skill from https://github.com/TencentCloudBase/CloudBase-AI-Toolkit/tree/main/skills/codebuddy-ide-mcp-upgrade into .agents/skills/codebuddy-ide-mcp-upgrade/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codebuddy-ide-mcp-upgrade", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill codebuddy-ide-mcp-upgrade -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install TencentCloudBase/CloudBase-AI-Toolkit codebuddy-ide-mcp-upgrade --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/TencentCloudBase/CloudBase-AI-Toolkit.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/codebuddy-ide-mcp-upgrade .cursor/skills/codebuddy-ide-mcp-upgrade && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "codebuddy-ide-mcp-upgrade" agent skill from https://github.com/TencentCloudBase/CloudBase-AI-Toolkit/tree/main/skills/codebuddy-ide-mcp-upgrade into .cursor/skills/codebuddy-ide-mcp-upgrade/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codebuddy-ide-mcp-upgrade", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/TencentCloudBase/CloudBase-AI-Toolkit.git --path skills/codebuddy-ide-mcp-upgrade--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill codebuddy-ide-mcp-upgrade -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install TencentCloudBase/CloudBase-AI-Toolkit codebuddy-ide-mcp-upgrade --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/TencentCloudBase/CloudBase-AI-Toolkit.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/codebuddy-ide-mcp-upgrade .gemini/skills/codebuddy-ide-mcp-upgrade && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "codebuddy-ide-mcp-upgrade" agent skill from https://github.com/TencentCloudBase/CloudBase-AI-Toolkit/tree/main/skills/codebuddy-ide-mcp-upgrade into .gemini/skills/codebuddy-ide-mcp-upgrade/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codebuddy-ide-mcp-upgrade", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install TencentCloudBase/CloudBase-AI-Toolkit codebuddy-ide-mcp-upgradeInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill codebuddy-ide-mcp-upgrade -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/TencentCloudBase/CloudBase-AI-Toolkit.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/codebuddy-ide-mcp-upgrade .github/skills/codebuddy-ide-mcp-upgrade && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "codebuddy-ide-mcp-upgrade" agent skill from https://github.com/TencentCloudBase/CloudBase-AI-Toolkit/tree/main/skills/codebuddy-ide-mcp-upgrade into .github/skills/codebuddy-ide-mcp-upgrade/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codebuddy-ide-mcp-upgrade", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill codebuddy-ide-mcp-upgrade -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install TencentCloudBase/CloudBase-AI-Toolkit codebuddy-ide-mcp-upgrade --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/TencentCloudBase/CloudBase-AI-Toolkit.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/codebuddy-ide-mcp-upgrade .opencode/skills/codebuddy-ide-mcp-upgrade && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "codebuddy-ide-mcp-upgrade" agent skill from https://github.com/TencentCloudBase/CloudBase-AI-Toolkit/tree/main/skills/codebuddy-ide-mcp-upgrade into .opencode/skills/codebuddy-ide-mcp-upgrade/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codebuddy-ide-mcp-upgrade", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
codebuddy-ide-mcp-upgrade升级 CodeBuddy IDE(genie 扩展)内置的 CloudBase MCP,以及 MCP 发版时同步 IDE 侧白名单。当用户提到「更新 IDE 里的 MCP」「内置 MCP 版本太老」「IDE 集成的 CloudBase 功能不足」「改工具白名单 toolWhiteList」「把新 bundle 打进 CodeBuddy」「白名单漂移」「MCP…
Codebuddy Ide MCP Upgrade is an agent skill from TencentCloudBase/CloudBase-AI-Toolkit. 升级 CodeBuddy IDE(genie 扩展)内置的 CloudBase MCP,以及 MCP 发版时同步 IDE 侧白名单。当用户提到「更新 IDE 里的 MCP」「内置 MCP 版本太老」「IDE 集成的 CloudBase 功能不足」「改工具白名单 toolWhiteList」「把新 bundle 打进 CodeBuddy」「白名单漂移」「MCP 发版要同步什么」时使用。覆盖:解包定位内置 bundle 与内嵌配置、重新构建 mcp bundle、生成新的工具白名单与系统提示词、安全注入 IDE 并备份、用 MCP 协议验证工具清单、人工端到端验收、一键回滚。
Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including scripts.
It sits in Agent Workflows, covering MCP servers. It works with Model Context Protocol. The repository describes itself as: Backend for AI coding agents on CloudBase — database, auth, functions via Plugin, Skills & MCP. The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit ea2c202. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (JavaScript), which the agent can run.
Shell commands in SKILL.md call:
nodenpmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Codebuddy Ide MCP Upgrade loads about 3k tokens when it runs. Until then it costs about 79 tokens; SKILL.md has 764 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from TencentCloudBase/CloudBase-AI-Toolkit at commit ea2c202, republished under its MIT licence (© TencentCloudBase). 764 words, ~2,965 tokens.
.claude/skills/codebuddy-ide-mcp-upgrade/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.toolWhiteList / systemPrompt / attatchPromptCodeBuddy IDE 的内置 CloudBase MCP 由 genie 扩展承载,改一处不生效,必须同时改两个文件:
| 文件 | 内容 | 等价来源 |
|---|---|---|
Contents/Resources/app/extensions/genie/integration-mcp/tcb/index.cjs | MCP Server bundle | 仓库 mcp/dist/cli.cjs 改名 |
Contents/Resources/app/extensions/genie/out/extension/index.js | 内嵌的 tcb 集成配置(webpack module,ir.exports=JSON.parse('{...}')) | 无仓库对版,需就地解包 |
默认 IDE 路径:/Applications/CodeBuddy CN.app。同目录还有 anydev、eop、lighthouse 三个集成,别改错。
加载与启动契约:
// TcbIntegration
mcpServer: {
path: path.join("integration-mcp", "tcb", "index.cjs"),
envMapper: (r) => ({ TENCENTCLOUD_SECRETID: r.tmp_secret_id,
TENCENTCLOUD_SECRETKEY: r.tmp_secret_key,
TENCENTCLOUD_SESSIONTOKEN: r.token }),
toolWhiteList: config.toolWhiteList,
}
// StdioClientTransport
{ command: process.execPath, args: [mcpPath],
env: { ...envMapper(), INTEGRATION_IDE: "CodeBuddy",
ELECTRON_RUN_AS_NODE: "1", WORKSPACE_FOLDER_PATHS } }不传任何命令行参数(--cloud-mode / --integration-ide 都没用),凭据全靠环境变量,MCP 侧 mcp/src/auth.ts 直接读 TENCENTCLOUD_SECRETID/SECRETKEY。
配置内嵌在 21MB 的 out/extension/index.js 里,用 JSON.parse('...') 包着,必须按 JS 字符串语义 eval 才能解析:
const i = s.indexOf('"id":"tcb"');
const st = s.lastIndexOf("JSON.parse('", i) + 12;
let cursor = st, cfg;
for (;;) {
cursor = s.indexOf("')", cursor + 1);
try { cfg = JSON.parse(eval("'" + s.slice(st, cursor) + "'")); break; } catch {}
}拿到后先数一遍白名单,并和仓库 scripts/tools.json 比对。九成问题出在这里:白名单停留在旧版本,里面全是已被 MCP 改名的死条目。
cd <repo>/mcp && npm run build:webpack # 产物 dist/cli.cjs,约 4.6 MiB只跑 build:webpack,不要跑 npm run build(会触发 prebuild 的 rm -rf dist,可能被 safe-delete hook 拦截)。
白名单真源是 scripts/tools.json,不要手写清单。配置改动落在:
toolWhiteList ← tools.json 全部工具名(全量,不要裁剪,理由见「白名单裁剪的前提已不存在」)systemPrompt.login / .logout、userPrompt.*、attatchPrompt.* ← 提示词id、displayName、description、descriptionMap、types、ruleZipUrl、loginOnlyChinese、loginType、toolTimeout)保持原值(1)PG 模式 = Supabase 同构,不是「多了一种数据库」
判定为 PG 环境后,认证、存储、权限、迁移四项全部改道:
| 能力层 | Supabase | CloudBase PG 模式 | 工具 |
|---|---|---|---|
| 数据库 | Postgres | PostgreSQL | queryPgDatabase / managePgDatabase |
| Schema 变更 | Migration | applyMigration(须带 migrationVersion) | managePgDatabase |
| 行级授权 | RLS Policies | RLS | managePgDatabase + rls-patterns.md |
| 存储 | Storage Buckets | pgstore(与 legacy COS 是两套系统) | queryPgStorage(不是 queryStorage) |
| 认证 | anon/service key | 应用认证(publishable key / API key) | queryAppAuth / manageAppAuth |
PG 环境里引导错路径(用 NoSQL/MySQL 工具,或用 queryStorage 而非 queryPgStorage)是最高频的跑偏方式。
(2)提示词看配重,不看总长
systemPrompt.login 约 10.6k 字符 ≈ 3.5k token,在 Tool Search + 长上下文下不构成负担。为「看起来短」删引导 = 丢掉关键分叉点的判断质量。改完提示词用这个脚本量化配重,别靠感觉:
node -e '
const s=require("fs").readFileSync("config/prompts/systemPrompt.login.md","utf8"),L=s.split("\n");
let c="(开头)",a={[c]:0},o=[c];
for(const l of L){if(/^## /.test(l)){c=l.slice(3);if(!(c in a)){a[c]=0;o.push(c)}continue}
if(/^### /.test(l)){c=l.slice(4);if(!(c in a)){a[c]=0;o.push(c)}continue}a[c]+=l.length+1}
for(const k of o)console.log(String(a[k]).padStart(6),(a[k]/s.length*100).toFixed(1).padStart(5)+"% ",k.slice(0,50))'node scripts/apply-to-ide.mjs --dry-run # 只看差异
node scripts/apply-to-ide.mjs # 备份到 backup/<时间戳>/ 后写入
node scripts/patch-tool-timeout.mjs --timeout 300000 # 接通 toolTimeout(见 Pitfalls)写配置的替换逻辑:生成紧凑 JSON(JSON.stringify(cfg),无裸换行),再按 JS 单引号字符串转义(先 \\ 再 '),替换 JSON.parse('...') 区间。转义顺序错了会破坏 JS 字符串。
边界语义(踩过坑,勿改错):start = raw 起点(slice(0, start) 里已包含 JSON.parse('),end = ') 之后。所以替换时只能拼 escaped raw + '),绝不能再拼一次 JSON.parse('。
node scripts/verify-ide-config.mjs # 从 IDE 回读配置,逐字段比对
node scripts/verify-bundle.mjs # 按 IDE 方式启动 bundle,拉 tools/listverify-bundle.mjs 复刻 IDE 的启动参数(stdio + INTEGRATION_IDE=CodeBuddy + ELECTRON_RUN_AS_NODE=1 + 临时密钥占位值),比对三件事:暴露的工具是否全在白名单内、白名单是否有悬空条目、PG 工具是否注册。
node scripts/rollback-ide.mjs --latest白名单漂移是「IDE 里 CloudBase 功能不足」的唯一根因,不是 MCP 能力问题。线上实测:21 条白名单里 12 条是已被 MCP 删除或改名的死条目,用户实际只能用 9 个。
因此 MCP 每次发版(工具增删改名)都必须重新生成 IDE 侧白名单,否则新版本 MCP 发得再勤,IDE 里还是老的。
发版 checklist:
scripts/tools.json 是否已更新(工具清单真源)scripts/build-config.mjs 重新生成 IDE 配置,产出新 toolWhiteList建议把这个 checklist 挂到 MCP 发版流程里(release workflow 或发版 checklist 文档),不要靠人工记忆。 靠人记的后果就是这次的 12 条死条目。
defer_loading。toolWhiteList 的唯一理由就是省上下文,这个前提现在没了。tools.json 全量生成。继续裁剪的唯一后果就是随 MCP 发版漂移成死条目。out/extension/index.js —— 那里搜不到 ToolSearch 字符串(实测 0 命中)。Tool Search 属 Agent CLI 内核层,证据在 CLI 进程参数(--tools 白名单含 ToolSearch)和 mcp-config 的 defer_loading 里。') 序列,必须用「eval + JSON.parse 能否成功」来判断结束位置,不能用第一个 ')。"id":"tcb" 做锚点。 全文 toolWhiteList 出现 13 次,用 toolWhiteList 搜会抓到 eop(EdgeOne)的配置块——症状是解出来的 raw 只有 1,015 字符(正常应 ~16,000)。msg-push)不在 DEFAULT_PLUGINS 里,白名单写了也不会注册,需注入 CLOUDBASE_MCP_PLUGINS_ENABLED=msg-push。白名单 40 条、实际暴露 38 条是正常现象,不是 bug。曾发生的事故:替换时重复拼接 JSON.parse(' 前缀,生成 JSON.parse('JSON.parse('{...}'),第二个 ' 提前闭合字符串,整文件 SyntaxError。但 verify 脚本的 JSON 字段比对全部显示 ✅ —— 因为定位用 lastIndexOf("JSON.parse('"),恰好命中了第二个前缀,照样能解析出正确 JSON。
铁律:改动这种大打包产物后,必须对整文件做真实编译:
import vm from "node:vm";
try { new vm.Script(source, { filename: "index.js" }); }
catch (e) { /* 立即回滚备份 */ }exit 1,只打印 ❌ 而不改变退出码等于没有检查node --check <file>,不要只信自己的脚本toolTimeout 未接通,实际只有 60 秒TcbIntegration 的配置对象没有 toolTimeout 字段(EopIntegration 传了)callTool 用 this.config.toolTimeout → undefinedconst Sn = sn?.timeout ?? DEFAULT_REQUEST_TIMEOUT_MSEC,而 DEFAULT_REQUEST_TIMEOUT_MSEC = 6e4"toolTimeout":120000 从未生效,实际 60 秒就掐断 PG applyMigration / CloudRun 部署修复(scripts/patch-tool-timeout.mjs):
TcbIntegration 配置对象补 toolTimeout:hn.toolTimeout(锚点 attatchPrompt:hn.attatchPrompt,loginOnlyChinese:hn.loginOnlyChinese},全文唯一 1 处)((ir?.tools) || []).filter((ir) => this.config.mcpServer.toolWhiteList.includes(ir.name))遍历的是 server 实际返回的 tools/list,白名单只做 includes 判定。多出的条目静默跳过、不报错、不产生悬空工具。所以白名单按 tools.json 全量下发是安全的,插件后续启用也无需再改配置。
mcp/src/server.ts 用 ide === "CodeBuddy" 判定 logging capability,大小写敏感;IDE 传的正是 "CodeBuddy",别改成小写。executeReadOnlySQL、createFunction、uploadFiles、writeSecurityRule 等),新 bundle 里这些名字已全部消失,提示词里如果还在引用就会引导模型调用不存在的工具。交付前必须同时满足:
node --check "<genie>/out/extension/index.js" 通过(最关键,能抓住回读校验掩盖的语法错误)apply-to-ide.mjs 输出「语法有效」+「回读校验通过」verify-ide-config.mjs 结构完整性三项 ✅ + 七个字段 ✅,echo $? 为 0verify-bundle.mjs 显示「所有暴露的工具都在白名单内」且 PG 三件套(queryPgDatabase / managePgDatabase / queryPgStorage)已注册verify-ide-config.mjs 反向测试:喂已知损坏文件必须 exit 1脚本只能证明「bundle 与配置文件本身是对的」,证明不了 IDE 加载后用户真的能用。重启后逐项跑:
| # | 用例 | 预期 |
|---|---|---|
| E1 | 完全退出后重启 IDE | 集成面板正常渲染,无 SyntaxError、genie 扩展不报错 |
| E2 | 集成面板连接 CloudBase | 登录成功,显示环境信息 |
| E3 | 让 Agent 列出可用的 CloudBase 工具 | 数量与新白名单一致(不是旧版数量) |
| E4 | PG 环境让 Agent 建表 | 走 managePgDatabase 的 applyMigration,提示词先引导读 postgresql-development-cloudbase 规则 |
| E5 | 执行一条只读 SQL | 走 queryMysqlDatabase(不再是 executeReadOnlySQL) |
| E6 | 部署一个 Node.js 云函数 | 走 manageFunctions(不再是 createFunction) |
| E7 | PG 模式下访问存储 | 走 queryPgStorage 而非 queryStorage |
| E8 | 查看/修改安全规则 | 走 queryPermissions / managePermissions(不再是 writeSecurityRule) |
| E9 | PG 执行耗时 >1 分钟的迁移 | 不中断,5 分钟超时生效(验证 toolTimeout 修复) |
| E10 | 正常对话观察上下文占用 | 工具全量放开后无明显膨胀(验证 Tool Search 结论) |
验证时的两个坑:
Authorization cache loaded for tcb, tempKey expires at: <过去时间>,必须在集成面板重新登录,MCP 才起来。tools/list 属正常,别据此判定 bundle 没生效。日志位置:~/Library/Application Support/CodeBuddy CN/logs/<时间戳>/window1/exthost/Tencent-Cloud.coding-copilot/腾讯云代码助手.log(搜 [Integration] / tcb)。
如果要顺带评估 MCP 工具层本身,这几项是实测通过的基线,达不到说明有回归:
queryPgDatabase(action=sql) 必须拦截 DELETE / UPDATE / DROP / 多语句注入,且返回带 nextActions 的可执行建议managePgDatabase(execute)、manageFunctions(deleteFunction) 缺 confirm 时必须拒绝queryPermissions 应返回「不支持 PostgreSQL 类型环境」,而不是假装成功首次实操的完整交付物(文档 + 配置 + 脚本)模板在 CloudBase-MCP 仓库的 specs/cb-ide-mcp-upgrade/(worktree chore/cb-ide-mcp-upgrade)。
凡「改配置 + 再打独立 patch」的两步流程,patch 改的标量必须回流到配置生成脚本。
实例:本任务里 toolTimeout 先从 120000 提到 300000 是靠 patch-tool-timeout.mjs 单独 patch 的,而 build-config.mjs 生成的 tcb-config.new.json 里仍是 120000。交付物自带旧值,IDE 侧直接拿配置去用就会退回两分钟。
自查项:
Markdown 交付物不要放在点开头的隐藏目录下。git worktree 常用 .worktrees/<name>/,预览器常因安全策略拒绝加载隐藏目录资源,表现是「文件能读到、点击却打不开/报错」。
交付前做两件事:
~/Projects/cb-ide-mcp-upgrade/),present_files 指向该路径present_files 第一个传它(HTML 会同时开预览面板 + 列 artifact card,最稳)渲染脚本在本 skill 的 scripts/render-html.mjs,依赖 marked:
mkdir -p /tmp/mdrender && cd /tmp/mdrender
echo '{"name":"mdrender","private":true}' > package.json
npm install marked
NODE_PATH=/tmp/mdrender/node_modules node <skill>/scripts/render-html.mjs \
"<交付目录>/README.md" "<交付目录>/README.html" "文档标题"注意:npm install 别在 ~/.workbuddy/binaries/node/workspace 里跑——没有 package.json 时 npm 会向上找到 ~/node_modules 并因 ENOTEMPTY 失败。装到带 package.json 的临时目录最省事。
产物自带侧边目录导航(从 h2/h3 生成)、表格与代码高亮样式、@media print 打印规则(可直接导出 PDF 交给外部团队)。
© TencentCloudBase, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (scripts) in skills/codebuddy-ide-mcp-upgrade of TencentCloudBase/CloudBase-AI-Toolkit.
Open the folder on GitHubat commit ea2c202
Codebuddy Ide MCP Upgrade next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Codebuddy Ide MCP Upgrade this skillTencentCloudBase/CloudBase-AI-Toolkit | 1.1k | — | ~3k | Automated safety check: Pass | MIT | |
| Migrate To CodexHaohao-end/openagent | 807 | 1 repos | ~2k | Automated safety check: Pass | Apache-2.0 | |
| Openai DocsHaohao-end/openagent | 807 | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Use Gfs MCPGuepard-Corp/gfs | 158 | — | ~4k | Automated safety check: Pass | MIT | |
| Ogham Recallogham-mcp/ogham-mcp | 115 | — | ~1k | Automated safety check: Pass | MIT | |
| Memmesh CLIThinkfleetAI/memmesh | 419 | — | ~855 | Automated safety check: Pass | Apache-2.0 |
Haohao-end/openagent
Migrate supported instruction files, skills, agents, and MCP config into Codex project and global files.
Haohao-end/openagent
A skill your agent uses when the user asks how to build with OpenAI products or APIs and needs up-to-date official documentation with citations, help choosing the latest model for a use case, or…
Guepard-Corp/gfs
GFS MCP Server for AI agent integration. An agent skill from Guepard-Corp/gfs.
ogham-mcp/ogham-mcp
Smart retrieval from Ogham shared memory. An agent skill from ogham-mcp/ogham-mcp.
ThinkfleetAI/memmesh
MemMesh CLI + local MCP server — the zero-infra, no-API-key path to the same engine as the hosted SDK.
sickn33/agentic-awesome-skills
Analyze a warehouse for stale, unused, or redundant tables via the analyzestoragecosts MCP tool.
TencentCloudBase/CloudBase-AI-Toolkit
A skill your agent uses for Node.js backend AI via @cloudbase/node-sdk (=3.16.0) — cloud functions, CloudRun, Express/Koa/NestJS, serverless APIs, scheduled jobs, LLM proxies, agent orchestration.
TencentCloudBase/CloudBase-AI-Toolkit
CloudBase official HTTP API client guide. An agent skill from TencentCloudBase/CloudBase-AI-Toolkit.
TencentCloudBase/CloudBase-AI-Toolkit
Author or revise a cloud-api-operations recipe (config/source/skills/cloud-api-operations/references/recipes/).
TencentCloudBase/CloudBase-AI-Toolkit
Analyze, standardize, validate, and sync locally maintained skills into agent skill directories with a skills CLI-aligned workflow.
TencentCloudBase/CloudBase-AI-Toolkit
Build production-ready AI agent backends using the CloudBase Agent Python SDK — create agents with LangGraph/CrewAI/LlamaIndex, serve them via FastAPI with AG-UI protocol streaming +…
TencentCloudBase/CloudBase-AI-Toolkit
A skill your agent uses when you develop, design, build, deploy, debug, migrate, or troubleshoot CloudBase (腾讯云开发, 云开发, TCB, 微信云开发) projects — Web, 微信小程序, 小程序, uni-app, mobile (iOS, Android…
Works with
Categories
升级 CodeBuddy IDE(genie 扩展)内置的 CloudBase MCP,以及 MCP 发版时同步 IDE 侧白名单。当用户提到「更新 IDE 里的 MCP」「内置 MCP 版本太老」「IDE 集成的 CloudBase 功能不足」「改工具白名单 toolWhiteList」「把新 bundle 打进 CodeBuddy」「白名单漂移」「MCP…. Codebuddy Ide MCP Upgrade is an agent skill from TencentCloudBase/CloudBase-AI-Toolkit.
Codebuddy Ide MCP Upgrade fits situations like: tasks that involve MCP servers.
Run `npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill codebuddy-ide-mcp-upgrade -a claude-code`. Or copy the skill folder (skills/codebuddy-ide-mcp-upgrade in TencentCloudBase/CloudBase-AI-Toolkit) into .claude/skills/codebuddy-ide-mcp-upgrade in your project. Claude Code loads it when a task matches its description.
Run `npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill codebuddy-ide-mcp-upgrade -a codex`. Or copy the skill folder (skills/codebuddy-ide-mcp-upgrade in TencentCloudBase/CloudBase-AI-Toolkit) into .agents/skills/codebuddy-ide-mcp-upgrade in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill codebuddy-ide-mcp-upgrade -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/codebuddy-ide-mcp-upgrade, .gemini/skills/codebuddy-ide-mcp-upgrade, .github/skills/codebuddy-ide-mcp-upgrade and .opencode/skills/codebuddy-ide-mcp-upgrade in your project.
Going by SKILL.md and its folder, Codebuddy Ide MCP Upgrade needs JavaScript for the scripts in its folder and the command-line tools its instructions call (node and npm). Our summary lists: Node.js.
SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Codebuddy Ide MCP Upgrade is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Codebuddy Ide MCP Upgrade: Migrate To Codex (Haohao-end/openagent, 807 stars), Openai Docs (Haohao-end/openagent, 807 stars), Use Gfs MCP (Guepard-Corp/gfs, 158 stars) and Ogham Recall (ogham-mcp/ogham-mcp, 115 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
TencentCloudBase (a GitHub organization) maintains it in TencentCloudBase/CloudBase-AI-Toolkit, which has 1,132 GitHub stars. The repository holds 49 skills in this directory. The repository was last updated on October 6, 2026.
Source: TencentCloudBase/CloudBase-AI-Toolkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.