Skip to content

feat(cli): export a redacted diagnostics bundle (bsk diagnostics export) - #356

Open
dangzitou wants to merge 1 commit into
Tencent:mainfrom
dangzitou:feat/diagnostics-export
Open

dangzitou wants to merge 1 commit into
Tencent:mainfrom
dangzitou:feat/diagnostics-export

Conversation

@dangzitou

@dangzitou dangzitou commented Sep 27, 2026 •

Copy link
Copy Markdown

What problem this solves

Fixes #335.

An agent that sees BrowserSkill fail has no supported way to inspect
BrowserSkill's own state: the extension debug page is served under a
chrome-extension:// URL, which the Agent Window sandbox deliberately
refuses to observe, and borrowing the user's debug tab can fail when no
tab can show the confirmation. Recovery then depends on the user
manually reading debug output. This adds a CLI command that exports
what the CLI can see — daemon log tail, daemon status, the bsk doctor
checks, and the active session list — as a single zip an agent can
attach to an issue report.

How this fixes it

bsk diagnostics export [--out <path>] [--log-lines <n>] writes a zip:

  • metadata.json — CLI/daemon versions, platform, timestamp.
  • doctor.json — the checks bsk doctor runs, with repair hints.
  • status.json — daemon info, status and active sessions (null with
    a README note when no daemon is running).
  • daemon-log.txt — trailing log lines (default 500, capped at 4 MiB).
  • README.md — contents, missing parts, redaction note, scope limits.

Redaction is on by default: values of credential keys (token, cookie,
authorization, password, …) become [REDACTED] in both JSON and shell
spellings; credential headers are redacted to end of line so
Authorization: Bearer <token> never survives. Ordinary lines (URLs,
session ids, tab ids) pass through unchanged, and keys embedded in
larger identifiers (secretive, tokens_seen) are not touched. The
one residual gap — a raw credential with no key, e.g. a token inside a
URL — is called out in the README.

Every source is best-effort: a missing daemon or log file is recorded in
the README's "Missing parts" section instead of failing, so a bundle is
always writable. doctor::checks() is extracted so the export reuses
the exact daemon-state resolution bsk doctor runs.

User impact

bsk diagnostics export --out diag.zip

Agents and users get one file to attach when reporting problems, with
credential values removed. Scope is deliberately the CLI-visible
surface; the extension's own debug page remains out of reach by design
and is called out in the README.

Validation

  • cargo fmt --all -- --check, cargo clippy --workspace --all-targets --locked -- -D warnings, cargo test --workspace --locked (green;
    no new tests included in this PR).
  • Local end-to-end runs (macOS): against a live daemon with an active
    session (Chrome for Testing 154 + unpacked extension) —
    status.json contains the session and daemon-log.txt is redacted;
    with no daemon — all optional parts recorded as README notes.

@dangzitou
dangzitou force-pushed the feat/diagnostics-export branch from 88205b7 to a10492d Compare September 27, 2026 18:07
Agents cannot inspect BrowserSkill's own debug console: the extension
debug page is served under a chrome-extension:// URL that the Agent
Window sandbox refuses to observe, so a failed tool call has no
matching local diagnostics. Export what the CLI can see instead.

The bundle contains the daemon log tail, daemon status, the `bsk doctor`
checks and the active session list. Values of credential keys (token,
cookie, authorization, password, …) become `[REDACTED]` by default;
credential headers are redacted to end of line so `Bearer` tokens never
survive. Every source degrades to a README note when the daemon or log
file is absent, so a bundle is always writable.

doctor::checks() exposes the check list without rendering so the export
reuses the same daemon-state resolution `bsk doctor` does.
@dangzitou
dangzitou force-pushed the feat/diagnostics-export branch from a10492d to 658fd4e Compare September 27, 2026 18:13

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

LLM agents cannot inspect the BrowserSkill debug console

1 participant