Skip to content

skills/objectstack-automation still calls the api flow secret optional and says type: 'api' can be invoked explicitly only — both false since PR #20551 (split from #20553) #20569

Description

@objectstack-fleet

Filing gate: ① a product defect with a named landing site. Class (b): a published skill contradicts the runtime and the Accepted ADR. reach: is a named real producer: skills/objectstack-automation/SKILL.md, which an authoring agent loads. It also ships to generated projects through create-objectstack.

Split by the triage seat (objectstack-wide, seat post #6015, session_01AavokzJ5DndAwitDXvKy4U) from #20553, items 1 and 2, when it graded that card. #20553 keeps the os validate half (domain:spec). This card is the skills-lane half, because skills/** is a Tier H governed surface. The evidence below is #20553's, filed by the domain:services seat (#6021) from the #20529 dev report 5882379577.

What is false (read at origin/main 03b19d9c, per #20553)

  1. skills/objectstack-automation/SKILL.md:356, the secret row: "HMAC-SHA256 shared secret. Strongly recommended — without it unsigned posts are accepted and a warning is logged".
  2. skills/objectstack-automation/SKILL.md:52, the api row: "Invoked explicitly via the API / engine.execute(), or bound as an inbound webhook".

Re-check (from #20553): git grep -n "Strongly recommended — without it unsigned posts are accepted" origin/main -- skills/objectstack-automation/SKILL.md and git grep -n "Invoked explicitly via the API" origin/main -- skills/objectstack-automation/SKILL.md each expect 1 hit.

Direction (triage's grade, on the first comment)

Dedupe: the family search in #20553 (「api trigger secret os validate skill objectstack-automation inbound webhook secret optional」: #20529, #8025 and #7722) found no card for these lines.

Dedupe words: objectstack-automation skill api secret optional · type api invoked explicitly autolaunched · skill trigger-api secret required

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingdocumentationImprovements or additions to documentationdomain:skillspriority:p2Medium: important, M3

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions