IUV-02-01: Replace raw CORS origin prompt with a friendly hostname input - Add `deriveCorsOrigin(hostname, webUiPort, useHttps?)` pure function - Prompt asks "Web UI hostname" (default: localhost) instead of "CORS origin" - Auto-detects http vs https: localhost/127.0.0.1 always http, remote defaults to https - For remote hosts, asks "Is HTTPS enabled?" (defaults to yes) - Headless: MOSAIC_HOSTNAME env var as friendly alternative to MOSAIC_CORS_ORIGIN - GatewayState gains optional `hostname` field to track the raw input - Fallback paths now read GATEWAY_CORS_ORIGIN from .env instead of hardcoding IUV-02-02: Diagnose skill installer failure modes (documented in PR body) - Selection → installation gap: syncSkills() ignored state.selectedSkills entirely - Silent failure: missing catalog directory had no user-visible error - No per-skill granularity: all-or-nothing rsync with no whitelist concept IUV-02-03: Rework skill installer end-to-end - syncSkills() now accepts selectedSkills[] and passes MOSAIC_INSTALL_SKILLS (colon-separated) to the bash script - Script filters linking to only the whitelisted skills when MOSAIC_INSTALL_SKILLS is set - Missing script surfaced clearly instead of silently swallowed - Non-zero exit captured from stderr and shown to the user - Post-install summary reports "N installed" or failure reason IUV-02-04: Tests + gates - 13 unit tests for deriveCorsOrigin covering localhost, remote, https override - 5 integration tests for finalize skill installer (selection, skip, failure, missing script) - pnpm typecheck + lint + format:check all green - 237 tests passing (26 test files) Co-Authored-By: Claude Sonnet 4.6 <[email protected]>