Skip to content

v0.2.3: add Kimi Code as a fourth scanned harness - #16

Merged
AnobleSCM merged 1 commit into
mainfrom
kimi-support-023
Aug 3, 2026
Merged

AnobleSCM merged 1 commit into
mainfrom
kimi-support-023

Conversation

@AnobleSCM

Copy link
Copy Markdown
Owner

Summary

  • Detects Kimi Code (Moonshot's kimi-code CLI) as a fourth scanned harness alongside Claude Code, Codex, and Cursor — detection parity only, zero product expansion, per the adopted "basic compatibility maintenance for major coding agents" scope.
  • New scanner (src/manifest/kimi.ts, modeled on codex.ts) detects MCP servers and skills.
  • Ground-truth correction: MCP servers live in mcp.json (JSON, { "mcpServers": {...} } shape) — not config.toml, which holds only Kimi's own settings. Verified against the installed CLI's own bundled import-from-cc-codex skill source and its resolveMcpJsonPaths resolver (kimi 0.31.1). Three files exist; only two are scanned:
    • ~/.kimi-code/mcp.json (user)
    • <cwd>/.kimi-code/mcp.json (project — read from the literal working directory, not an upward walk, matching Kimi's own documented behavior)
    • <git-root>/.mcp.json (project-root) is real but deliberately not re-scanned here — it's the same file Claude Code's project detector already reads, Claude Code is scanned first, and a second read would only ever dedupe away.
  • Skills are read from both roots Kimi auto-discovers (verified via PROJECT_BRAND_DIRS/PROJECT_GENERIC_DIRS/USER_BRAND_DIRS/USER_GENERIC_DIRS embedded in the installed binary): .kimi-code/skills and .agents/skills, at both scopes. ~/.agents/skills is the same shared shelf Claude Code and Codex already reach through their own link farms — the existing canonical-path dedupe now collapses a skill across all three harnesses, deterministically, under whichever client detect() scans first (Claude Code).
  • Every surface updated: terminal report (new Kimi Code section, existing type accents, no new colors), --markdown, --json (schema shape unchanged — just another clients[] entry), the empty-state "Looked in" listing and closing hint, README (supported-tools claims, "What it reads" table, scan-order/dedupe docs, demo example + SVG regenerated byte-verbatim from a real run), CHANGELOG.
  • Not scanned: Kimi's .agents/agents / .kimi-code/agents subagent roots. Confirmed real and auto-discovered the same way the skill roots are, but subagent detection is outside this change's scope — flagged for a follow-up, not silently dropped.
  • Privacy invariants unchanged: config files are parsed for names only; skill/subagent file contents are never opened; nothing under credentials/, oauth/, sessions/, logs/, or user-history/ is ever touched; the compile-time no-skills-to-server guarantee (skills/subagents never reach /api/sync) is untouched.
  • Version 0.2.3 + lockfile (parity test passes).
  • No new dependencies, flags, or commands.

Verified kimi surfaces (evidence)

Investigated the real installed ~/.kimi-code/ on this machine (kimi 0.31.1) — inspected config.toml's actual schema, ran kimi --help / kimi doctor --help, and reverse-checked the installed binary's embedded skill source and path-resolution code. No real config values were copied into code, tests, fixtures, or this PR — all fixture/demo values are invented placeholders.

Test plan

  • npm run lint — clean
  • npm run build — clean
  • npm test — 306/306 passing (30 new: kimi.test.ts, kimi.skills.test.ts, +1 three-way dedupe test in dedupe.test.ts, +1 empty-state string update in report.test.ts)
  • New test proves the "no upward walk" behavior for <cwd>/.kimi-code/mcp.json (a parent directory's file is correctly invisible)
  • New test proves a shelf skill visible to Claude Code + Codex + Kimi Code dedupes to one entry, deterministically under Claude Code
  • npm pack --dry-run + real-tarball extraction grep — no leaked credentials/oauth/sessions/logs/user-history paths, no real config values
  • README demo example (plain-text block) and assets/devcat-report.svg regenerated from one real run of the built CLI against an isolated placeholder-value fixture (not this machine's real config); cross-reviewed by extracting the SVG's visible text and byte-diffing it against the real captured plain output — exact match. The unchanged Claude Code/Codex portion of the SVG diffs byte-identical against the prior file (only the genuinely-changed total/dimensions/new section differ)
  • CI: 6 lanes (ubuntu/macos/windows × node 20/22) — pushed, awaiting results. Windows has no real kimi-code install; the scanner already handles absence the same way every other detector does (graceful empty result on ENOENT), no platform-specific code paths introduced

Judgment calls (flagged for review, not silently decided)

  1. Project-root .mcp.json not re-scanned under the kimi-code client — real (Kimi does read it, confirmed via git-root walk in the binary), but always dedupes away since Claude Code's existing detector already covers it and scans first. Modeling Kimi's git-root walk a second time for an always-redundant result felt like scope creep; flagging in case a reviewer wants explicit kimi-code-attributed coverage of that file regardless.
  2. .agents/agents / .kimi-code/agents subagent roots deliberately excluded — confirmed real and auto-discovered by Kimi, symmetric with the skill roots, but the mission scope was MCP + skills only. Natural follow-up if subagent parity is wanted.
  3. merge_all_available_skills / extra_skill_dirs config.toml settings not modeled — the scanner always checks both .kimi-code/skills and .agents/skills unconditionally, same as how no other scanner in this codebase reads a client's own settings to conditionally change what it looks for.
  4. Project skill-root resolution approximated with the existing findUpwardDir walk, not Kimi's real git-root resolution — this mirrors the codebase's existing, pre-existing simplification for every other client's project-scope resolution (none of which are git-root-exact either), not a new approximation introduced here.

🤖 Generated with Claude Code

Kimi Code joins Claude Code, Codex, and Cursor as a fourth scanned harness
across the terminal report, --markdown, --json, and the empty-state
listing — detection parity only, no product expansion.

MCP servers are read from mcp.json (Kimi's actual config shape — JSON, not
TOML; config.toml holds Kimi's own settings and never MCP declarations,
verified against the installed CLI's own bundled skill source and MCP path
resolver): ~/.kimi-code/mcp.json at user scope, and a literal
<cwd>/.kimi-code/mcp.json at project scope, read from the exact working
directory rather than found by an upward walk, matching Kimi's documented
behavior. Skills are read from both roots Kimi auto-discovers —
.kimi-code/skills and .agents/skills — at user and project scope.
~/.agents/skills is the same shared shelf Claude Code and Codex already
reach through their own link farms, so the existing canonical-path dedupe
now collapses a skill across all three harnesses.

Not scanned: Kimi's .agents/agents / .kimi-code/agents subagent roots
(real and auto-discovered the same way, but out of this change's scope).

Version 0.2.3.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@gemini-code-assist

Copy link
Copy Markdown

Caution

The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased.

@AnobleSCM
AnobleSCM marked this pull request as ready for review August 3, 2026 22:02
@gemini-code-assist

Copy link
Copy Markdown

Caution

The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased.

@AnobleSCM
AnobleSCM merged commit bd5a78a into main Aug 3, 2026
6 checks passed

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 53c4c30ec9

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/manifest/kimi.ts
Comment on lines +31 to +33
* Claude Code's project detector already reads. Not re-scanned here:
* Claude Code is scanned before Kimi Code in detect(), so a second
* read of this file would only ever dedupe away on the (type, name)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Scan Kimi's git-root MCP file independently

When a directory between the current working directory and the Git root contains its own .mcp.json, Claude's upward scan stops at that nearer file, so it does not cover Kimi's <git-root>/.mcp.json as claimed here. Skipping Kimi's scan then omits any uniquely named servers from the Git-root file; resolve the Git root and scan that file rather than relying on Claude's nearest-file result.

Useful? React with 👍 / 👎.

Comment thread src/manifest/kimi.ts
Comment on lines +86 to +87
if (opts.scope === 'user') {
return readMcpServersJson(join(homedir(), '.kimi-code', 'mcp.json'), 'user');

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Honor KIMI_CODE_HOME when locating user config

When Kimi is configured with KIMI_CODE_HOME, its user-global MCP file lives at $KIMI_CODE_HOME/mcp.json, but this branch always reads ~/.kimi-code/mcp.json. Those users therefore get a false empty Kimi MCP inventory and an incorrect pathsScanned entry despite the supported override being documented above.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant