Make .claude/skills a real folder for claude sandbox to work (#1674)

### What does this PR do?

Type of change: ?  Bug fix

replace .claude/skills dir-symlink with real dir + per-skill symlinks

Claude Code hardcodes .claude/skills in its sandbox denyWithinAllow
list. bwrap enforces this by creating a mount point at that path, but
fails with "Can't create file: Is a directory" when the path is a
symlink to a directory — breaking all sandboxed commands, not just
writes.

Fix by making .claude/skills a real directory containing per-skill
symlinks into .agents/skills/. Add a pre-commit hook that automatically
creates and stages a new symlink whenever a skill directory is added to
.agents/skills/, so authors need no extra steps.

### Usage

claude with sandbox

### Testing
tried on local.

### Before your PR is "*Ready for review*"

Make sure you read and follow [Contributor
guidelines](https://github.com/NVIDIA/Model-Optimizer/blob/main/CONTRIBUTING.md)
and your commits are signed (`git commit -s -S`).

Make sure you read and follow the [Security Best
Practices](https://github.com/NVIDIA/Model-Optimizer/blob/main/SECURITY.md#security-coding-practices-for-contributors)
(e.g. avoiding hardcoded `trust_remote_code=True`, `torch.load(...,
weights_only=False)`, `pickle`, etc.).

- Is this change backward compatible?: ✅
- If you copied code from any other sources or added a new PIP
dependency, did you follow guidance in `CONTRIBUTING.md`: ✅
- Did you write any new necessary tests?: N/A 
- Did you update
[Changelog](https://github.com/NVIDIA/Model-Optimizer/blob/main/CHANGELOG.rst)?:
N/A
- Did you get Claude approval on this PR?: ✅ / ❌ / N/A <!--- Run
`/claude review`. NVIDIA org members can self-trigger for complex
changes; orthogonal to CodeRabbit. -->

### Additional Information
<!-- E.g. related issue. -->


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
* Updated internal development tooling to streamline workflow automation
and improve developer processes.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Signed-off-by: Shiyang Chen <shiychen@nvidia.com>
This commit is contained in:
sychen52
2026-06-10 15:00:48 -07:00
committed by GitHub
parent 06af68cbdb
commit 808e8b3320
19 changed files with 58 additions and 1 deletions
-1
View File
@@ -1 +0,0 @@
../.agents/skills
+1
View File
@@ -0,0 +1 @@
../../.agents/skills/accessing-mlflow
+1
View File
@@ -0,0 +1 @@
../../.agents/skills/common
+1
View File
@@ -0,0 +1 @@
../../.agents/skills/compare-results
+1
View File
@@ -0,0 +1 @@
../../.agents/skills/day0-release
+1
View File
@@ -0,0 +1 @@
../../.agents/skills/debug
+1
View File
@@ -0,0 +1 @@
../../.agents/skills/deployment
+1
View File
@@ -0,0 +1 @@
../../.agents/skills/eagle3-new-model
+1
View File
@@ -0,0 +1 @@
../../.agents/skills/eagle3-review-logs
+1
View File
@@ -0,0 +1 @@
../../.agents/skills/eagle3-triage
+1
View File
@@ -0,0 +1 @@
../../.agents/skills/eagle3-validate
+1
View File
@@ -0,0 +1 @@
../../.agents/skills/evaluation
+1
View File
@@ -0,0 +1 @@
../../.agents/skills/launching-evals
+1
View File
@@ -0,0 +1 @@
../../.agents/skills/monitor
+1
View File
@@ -0,0 +1 @@
../../.agents/skills/ptq
+1
View File
@@ -0,0 +1 @@
../../.agents/skills/quant-recipe-search
+1
View File
@@ -0,0 +1 @@
../../.agents/skills/release-cherry-pick
+7
View File
@@ -71,6 +71,13 @@ repos:
# configs/ contains reusable snippets (not full recipes) — skip recipe validation
exclude: ^modelopt_recipes/configs/
- id: sync-claude-skills
name: sync .claude/skills/ symlinks from .agents/skills/
entry: bash tools/precommit/sync_claude_skills.sh
language: system
files: ^\.agents/skills/
pass_filenames: false
# Instructions to change license file if ever needed:
# https://github.com/Lucas-C/pre-commit-hooks#removing-old-license-and-replacing-it-with-a-new-one
- repo: https://github.com/Lucas-C/pre-commit-hooks
+35
View File
@@ -0,0 +1,35 @@
#!/bin/bash
# SPDX-FileCopyrightText: Copyright (c) 2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
# SPDX-License-Identifier: Apache-2.0
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
set -euo pipefail
repo_root=$(git rev-parse --show-toplevel)
skills_src="$repo_root/.agents/skills"
skills_dst="$repo_root/.claude/skills"
added=()
for d in "$skills_src"/*/; do
[ -d "$d" ] || continue
name=$(basename "$d")
link="$skills_dst/$name"
if [ ! -e "$link" ] && [ ! -L "$link" ]; then
ln -s "../../.agents/skills/$name" "$link"
added+=("$link")
fi
done
if [ "${#added[@]}" -gt 0 ]; then
git add "${added[@]}"
echo "claude-skills-sync: staged ${#added[@]} new symlink(s) in .claude/skills/"
fi