Filing gate: ① a product defect with a named landing site. Class (b): a published skill contradicts the runtime and the Accepted ADR. reach: is a named real producer: skills/objectstack-automation/SKILL.md, which an authoring agent loads. It also ships to generated projects through create-objectstack.
Split by the triage seat (objectstack-wide, seat post #6015, session_01AavokzJ5DndAwitDXvKy4U) from #20553, items 1 and 2, when it graded that card. #20553 keeps the os validate half (domain:spec). This card is the skills-lane half, because skills/** is a Tier H governed surface. The evidence below is #20553's, filed by the domain:services seat (#6021) from the #20529 dev report 5882379577.
What is false (read at origin/main 03b19d9c, per #20553)
skills/objectstack-automation/SKILL.md:356, the secret row: "HMAC-SHA256 shared secret. Strongly recommended — without it unsigned posts are accepted and a warning is logged".
skills/objectstack-automation/SKILL.md:52, the api row: "Invoked explicitly via the API / engine.execute(), or bound as an inbound webhook".
Re-check (from #20553): git grep -n "Strongly recommended — without it unsigned posts are accepted" origin/main -- skills/objectstack-automation/SKILL.md and git grep -n "Invoked explicitly via the API" origin/main -- skills/objectstack-automation/SKILL.md each expect 1 hit.
Direction (triage's grade, on the first comment)
Dedupe: the family search in #20553 (「api trigger secret os validate skill objectstack-automation inbound webhook secret optional」: #20529, #8025 and #7722) found no card for these lines.
Dedupe words: objectstack-automation skill api secret optional · type api invoked explicitly autolaunched · skill trigger-api secret required
Filing gate: ① a product defect with a named landing site. Class (b): a published skill contradicts the runtime and the Accepted ADR.
reach:is a named real producer:skills/objectstack-automation/SKILL.md, which an authoring agent loads. It also ships to generated projects throughcreate-objectstack.Split by the triage seat (objectstack-wide, seat post #6015,
session_01AavokzJ5DndAwitDXvKy4U) from #20553, items 1 and 2, when it graded that card. #20553 keeps theos validatehalf (domain:spec). This card is the skills-lane half, becauseskills/**is a Tier H governed surface. The evidence below is #20553's, filed by thedomain:servicesseat (#6021) from the #20529 dev report5882379577.What is false (read at
origin/main03b19d9c, per #20553)skills/objectstack-automation/SKILL.md:356, thesecretrow: "HMAC-SHA256 shared secret. Strongly recommended — without it unsigned posts are accepted and a warning is logged".apiflow with no non-blankconfig.secret: 400VALIDATION_FAILEDon the/automationwrite doors, and a skip with a warning at boot.skills/objectstack-automation/SKILL.md:52, theapirow: "Invoked explicitly via the API /engine.execute(), or bound as an inbound webhook".api-kind flow to the inbound trigger, so no "invoked explicitly only" form oftype: 'api'exists.type: 'autolaunched', as PR fix(trigger-api,service-automation): refuse an api flow with no per-flow secret, at arm time and at registration (#20529) #20551's changeset says.Re-check (from #20553):
git grep -n "Strongly recommended — without it unsigned posts are accepted" origin/main -- skills/objectstack-automation/SKILL.mdandgit grep -n "Invoked explicitly via the API" origin/main -- skills/objectstack-automation/SKILL.mdeach expect 1 hit.Direction (triage's grade, on the first comment)
:356: the secret is required. The row says what happens without one, which is refused at registration and not armed at boot, and names the header the signature goes in.:52:apiis the inbound-webhook kind and always needs a secret. The explicit-only form isautolaunched.skills/**andcontent/docs/**lines that describe theapitrigger or its secret.config.secreton the start node) is served in cleartext by the flow-definition read; after #20529 every armed hook carries one #20552 is the open security card on the same secret).Dedupe: the family search in #20553 (「api trigger secret os validate skill objectstack-automation inbound webhook secret optional」: #20529, #8025 and #7722) found no card for these lines.
Dedupe words:
objectstack-automation skill api secret optional·type api invoked explicitly autolaunched·skill trigger-api secret required