diff --git a/README.md b/README.md index 0269afc..3c00593 100644 --- a/README.md +++ b/README.md @@ -83,13 +83,16 @@ not a screenshot. Simultaneous typing races and plugin hot-loading remain unveri ### Want to connect your existing desktop tasks? -[Follow the native-task guide](docs/06-guides/codex-native-tasks.md) to give each -chosen task the workflow and its peer's reference, authorize a narrow scope, -then work normally. No terminal setup is needed for that route. +[Copy the native-task setup prompt](docs/06-guides/codex-native-tasks.md#1-paste-this-into-each-chosen-task) +into each chosen task: fill in the other task's name and the allowed topic. +It uses a pinned public workflow, not a local path or manually copied internal ID. +Setup sends no peer messages; wait for both confirmations, then work normally. +No terminal setup is needed for that route. **Experimental:** the successful case used manager-supplied task references and -a local skill path. Novice pair selection, remote-link retrieval and normal -plugin onboarding remain open. The skill cannot add absent host tools or enforce +a local skill path. The [public-entry check](docs/09-reviews/2026-09-07-native-public-entry.md) +records the newer entry's tested boundary; novice onboarding and normal plugin +installation remain open. The skill cannot add absent host tools or enforce privacy and race-free sending. If native Codex already meets your needs, use it directly; no measured advantage over native-only use is claimed. diff --git a/README.zh-CN.md b/README.zh-CN.md index 3d46a1e..bb9a16c 100644 --- a/README.zh-CN.md +++ b/README.zh-CN.md @@ -77,11 +77,14 @@ B 早已知道按钮名称不能改。明确配对后,只向 A 提出普通业 ### 想连接已有的桌面任务? -按[原生任务指南](docs/zh-CN/codex-native-tasks.md),在选中的任务里提供工作流和对方引用, -授权限定的协作范围,然后正常工作。这条路径不需要终端设置。 - -**实验入口:** 成功案例由管理任务提供引用和本地 Skill 路径;普通用户如何选择任务、 -远程链接读取和常规插件上手仍有缺口。Skill 不能补出缺失的宿主工具,也不能强制 +把[原生任务设置提示词](docs/zh-CN/codex-native-tasks.md#1-分别把下面的提示词发给两个任务) +分别发给选中的两个任务,只填对方名称和允许话题。使用固定版本的公开工作流, +不用本地路径或手抄内部 ID。设置时不向对方发消息,等双方各自确认后正常工作。 +这条路径不需要终端设置。 + +**实验入口:** 成功案例由管理任务提供引用和本地 Skill 路径;新版入口的核验范围见 +[公开入口记录](docs/09-reviews/2026-09-07-native-public-entry.md),新用户上手和常规插件安装 +仍有缺口。Skill 不能补出缺失的宿主工具,也不能强制 保证隐私隔离或无竞争发送。如果原生 Codex 已满足需求,直接使用即可; 目前不声称比原生用法更有效。 diff --git a/ROADMAP.md b/ROADMAP.md index bfd6cd0..42568db 100644 --- a/ROADMAP.md +++ b/ROADMAP.md @@ -45,8 +45,10 @@ is new-session CLI acceptance, not the primary existing-desktop gate. Next native slice: the [skill-only workflow](docs/06-guides/codex-native-tasks.md) uses task tools already exposed by Codex, with an explicitly selected pair. It needs no Node/MCP/hook setup. [One controlled opted-in desktop pair passed](docs/09-reviews/2026-09-07-native-desktop-acceptance.md), -including prior context, B's own edit and busy/stop checks. Novice task selection, -remote skill retrieval and normal plugin activation remain open; sending is not race-free. External adapter/hook adoption is +including prior context, B's own edit and busy/stop checks. A new +[public-entry checkpoint](docs/09-reviews/2026-09-07-native-public-entry.md) verifies +anonymous workflow retrieval; title-based activation, novice task selection and +normal plugin activation remain open. Sending is not race-free. External adapter/hook adoption is a separate portability route, not a prerequisite for trying native guidance. The [desktop-first plan](docs/10-planning/desktop-entry-2026-09-07.md) supersedes diff --git a/docs/06-guides/codex-native-tasks.md b/docs/06-guides/codex-native-tasks.md index 6f8912a..b92e79a 100644 --- a/docs/06-guides/codex-native-tasks.md +++ b/docs/06-guides/codex-native-tasks.md @@ -15,15 +15,48 @@ has the instruction to keep the signup label **Create my workspace**. Keep unrelated business tasks outside the test and don't type into the receiver while the test is running. Normal Codex quota is required. -In each chosen task, provide a native reference to the other task and ask: - -> Read and follow the ThreadMesh for Codex workflow at -> [ThreadMesh workflow](../../plugins/threadmesh-codex/skills/threadmesh-codex/SKILL.md). -> I authorize only this task and the task I selected to share relevant product -> facts automatically. This task handles [its responsibility]; the other handles -> [its responsibility]. Do not read other conversations. Explain the sending -> limits before enabling it; I understand that an idle check cannot eliminate -> concurrent user-input races. Don't change tool permissions or install anything. +### 1. Paste this into each chosen task + +Replace **OTHER TASK TITLE** with the other task's exact sidebar title and +**SHARED TOPIC** with the limited subject they may exchange, such as approved +product names, spelling and free-plan limits. No internal ID, local path, clone +or terminal command is needed in this prompt. + +```text +Use the ThreadMesh workflow at this pinned public URL. Read the complete file: +https://raw.githubusercontent.com/fyaic/threadmesh/592014782d10a8c4b88f46ea23b7cf588ff78355/plugins/threadmesh-codex/skills/threadmesh-codex/SKILL.md + +Pair only this task with "OTHER TASK TITLE". Each keeps its own current job and +earlier decisions. Allowed shared topic: SHARED TOPIC. +I allow one task-list lookup to resolve that title, understanding that the list +also exposes other task titles/summaries. Do not read unrelated conversations. +If the title is missing or ambiguous, ask me; do not guess or scan more history. + +I authorize automatic, relevant peer advice after setup. I understand an idle +check cannot guarantee that sending never races with new user input. +This setup turn must not send any peer messages or change any business files. +Do not install software, change permissions or create tasks. +Confirm the selected peer by title, allowed topic, available native tools and +whether this task is enabled. If anything is unavailable, leave collaboration off. +``` + +If your app has already attached a native task reference, use that instead of +the title and remove the task-list permission paragraph. Do not hunt for IDs +in local files. A native reference picker is host-dependent; this guide does +not assume a particular desktop `@` menu. + +Want to check first without enabling? Replace the two automatic-advice +authorization sentences with: +“Only check readiness. Keep collaboration off, including any previous stop; +do not send messages, edit files or restore pending advice.” Readiness is not +activation and does not verify the peer's quota. + +### 2. Wait for both setup confirmations, then work normally + +Each task must confirm its own setup. Naming the other task does not activate +it. A missing workflow, missing tools or unresolved title is a stopped setup, +not a successful connection. You can say **Stop ThreadMesh collaboration** in +each task to cancel it; no separate control panel is required. This is an explicit workflow request in the existing conversation, **not proof that installing a plugin hot-loads old tasks**. The model must actually retrieve @@ -33,7 +66,7 @@ thread or a private endpoint as a substitute. The skill is also packaged under `plugins/threadmesh-codex` for normal plugin distribution testing; no global plugin installation or marketplace registration is performed by this guide. -Then work normally. In the brand task, for example: +In the brand task, for example: > Rename the product to Member Portal and limit the free plan to five projects. > Use US spelling and keep the paid-plan price unchanged. @@ -70,8 +103,11 @@ The [September 7 controlled run](../09-reviews/2026-09-07-native-desktop-accepta passed this source-read workflow with two disposable tasks that had completed prior context, original B's own correct edit, and busy/stop checks. The manager supplied task references and a local skill path through native task messages; -remote-link retrieval, a novice's task selection and manual GUI onboarding remain -unverified. Native source attribution was read from turn data, not a screenshot. +it did not validate the title-based prompt above. The public source is pinned +so readers can inspect the same workflow rather than a maintainer-local file. +See the [public-entry check](../09-reviews/2026-09-07-native-public-entry.md) for +the exact tested boundary. A novice's manual GUI onboarding remains unverified. +Native source attribution was read from turn data, not a screenshot. Packaging validation and a behavioral tabletop review alone are not live proof. The earlier [hook/MCP adoption attempt](../09-reviews/2026-09-07-desktop-native-adoption.md) diff --git a/docs/09-reviews/2026-09-07-native-public-entry.md b/docs/09-reviews/2026-09-07-native-public-entry.md new file mode 100644 index 0000000..242d220 --- /dev/null +++ b/docs/09-reviews/2026-09-07-native-public-entry.md @@ -0,0 +1,59 @@ +# Native desktop public entry: retrieval and readiness boundary + +Date: 2026-09-07. Status: **public retrieval checked; name-based desktop pairing +and activation not yet accepted**. This record does not replace the earlier +[controlled native business case](2026-09-07-native-desktop-acceptance.md). + +## What changed for a user + +The [English](../06-guides/codex-native-tasks.md) and +[Chinese](../zh-CN/codex-native-tasks.md) entry now has a copyable prompt with two +inputs: the other task's sidebar title and the allowed shared topic. It points +to a fixed public workflow, not a maintainer's local path. Users paste it into +each selected task; each confirms its own scope before ordinary work resumes. +Setup must not send messages or edit business files. An optional readiness-only +request keeps collaboration off, including an existing stop. + +Title lookup explicitly asks for one inventory's visibility: the native tool +also returns other task titles and summaries. It does not authorize reading +unrelated conversation bodies. A missing or ambiguous result needs clarification, +not another scan or guessed identity. An already attached native reference +avoids the inventory; no specific desktop reference-picker UI is asserted. + +## Observations retained + +| Check | Observed result | What it does not establish | +|---|---|---| +| Anonymous public workflow fetch | HTTP 200; 6,569 bytes; byte-for-byte match with source | Another host's network/retrieval ability | +| One measured fetch | 910 ms using Node fetch on the maintainer host | Cold-user timing or an onboarding speed guarantee | +| Skill format validation | Passed the Skill Creator validator in an isolated `uv` dependency environment | Correct model decisions or plugin activation | +| Repository regression | 459 passed, one optional native test skipped; 55 schema cases and seven transitions passed; 146 Markdown files linted cleanly | Live name resolution or autonomous model behavior | +| Existing native task name matching | Not run in this checkpoint | A title-only pairing pass | +| Public-source activation and business edit | Not run in this checkpoint | End-to-end desktop onboarding | + +Public workflow revision: `592014782d10a8c4b88f46ea23b7cf588ff78355`. +SHA-256: `4cbccb083bab61e3433696073d544e39d9d13f7d9d7828d5165d183afcb40470`. +The [pinned source](https://raw.githubusercontent.com/fyaic/threadmesh/592014782d10a8c4b88f46ea23b7cf588ff78355/plugins/threadmesh-codex/skills/threadmesh-codex/SKILL.md) +was fetched without repository credentials and compared in memory with the local +file. No private transcript, task inventory or identifier was published. + +The system and bundled Python interpreters initially lacked PyYAML; validation +then passed using `uv run --with pyyaml python` and the existing validator. +No user-global skill or plugin was installed. The published alpha.3 archive is +unchanged; this revised workflow is reached through the pinned source URL. + +## Next bounded check + +The earlier two dedicated native tasks remain stopped. A request was made for +permission to give each a readiness-only check and one task inventory, without +reactivating collaboration, sending peer advice or changing sample artifacts. +No such check has been dispatched at this checkpoint. + +If authorized, record actual public retrieval, uniquely resolved target title, +available native tools, no outgoing peer message and unchanged business files. +Do not count already known IDs or a local workflow read as evidence for the +new entry. This is still a maintainer check, not an independent GUI-user result. + +Official [skill documentation](https://learn.chatgpt.com/docs/build-skills) +describes reusable instructions and host loading. It does not itself prove this +repository's public-link workflow, native task tools or desktop picker behavior. diff --git a/docs/09-reviews/README.md b/docs/09-reviews/README.md index 969cc24..36957d5 100644 --- a/docs/09-reviews/README.md +++ b/docs/09-reviews/README.md @@ -30,6 +30,7 @@ not count as live-product or independent external-verifier evidence. ## Live attempt audits +- [Native desktop public entry: retrieval checked, title pairing pending](2026-09-07-native-public-entry.md) - [Codex-first installed-package acceptance and retained failures](2026-09-07-codex-first-use-release.md) - [Codex native desktop: prior context, original receiver edit and busy/stop checks](2026-09-07-native-desktop-acceptance.md) - [Codex native-task skill: earlier packaging/tabletop checkpoint](2026-09-07-codex-native-skill.md) diff --git a/docs/10-planning/community-followup-2026-09-07.md b/docs/10-planning/community-followup-2026-09-07.md index bde83bd..d14042c 100644 --- a/docs/10-planning/community-followup-2026-09-07.md +++ b/docs/10-planning/community-followup-2026-09-07.md @@ -92,6 +92,14 @@ scheduled follow-up is configured by this document. ### Proposed reply to #158 — not sent +Public-entry checkpoint: the bilingual title-and-topic prompt now uses a pinned +public workflow; anonymous retrieval and byte parity passed. The readiness-only +mode preserves previous stops. Title matching in the dedicated desktop pair has +not been dispatched pending scoped permission; do not claim the new entry has +passed merely because HTTP retrieval did. See the +[record](../09-reviews/2026-09-07-native-public-entry.md). The draft below remains +unsent, with no scheduled posting. + > Thank you, Andrei. We followed the three concrete priorities in your report. > > [v0.1.0-alpha.3](https://github.com/fyaic/threadmesh/releases/tag/v0.1.0-alpha.3) diff --git a/docs/10-planning/project-status.md b/docs/10-planning/project-status.md index a4649d8..642c216 100644 --- a/docs/10-planning/project-status.md +++ b/docs/10-planning/project-status.md @@ -2,6 +2,13 @@ ## Current product update — 2026-09-07 +**Current onboarding increment:** both languages now provide a copyable +title-and-topic prompt with a pinned public workflow. Anonymous retrieval and +source parity passed; readiness checking is separate from activation. The +[entry record](../09-reviews/2026-09-07-native-public-entry.md) keeps title-only +desktop matching and end-to-end activation open. The earlier test pair remains +stopped; no peer probe or reactivation was dispatched for this checkpoint. + **Value and evidence correction:** the native demo uses Codex's own communication and continuation; the skill adds guidance, not transport. [English responsibility map](../00-overview/native-capabilities-and-value.md) / [中文](../zh-CN/native-capabilities-and-value.md) diff --git a/docs/zh-CN/codex-native-tasks.md b/docs/zh-CN/codex-native-tasks.md index ca32531..05ff42c 100644 --- a/docs/zh-CN/codex-native-tasks.md +++ b/docs/zh-CN/codex-native-tasks.md @@ -11,13 +11,41 @@ 另一个维护网页,且已经约定按钮名称必须保留 **Create my workspace**。 不要选其他业务任务;测试期间不要同时向接收任务输入内容。仍需正常 Codex 额度。 -分别在这两个任务中,附上对方的原生任务引用,然后发送: +### 1. 分别把下面的提示词发给两个任务 -> 读取并遵循这里的 ThreadMesh for Codex 流程: -> [ThreadMesh 流程](../../plugins/threadmesh-codex/skills/threadmesh-codex/SKILL.md)。 -> 我只授权当前任务与我选中的另一个任务自动交流相关产品事实。当前任务负责【职责】, -> 对方负责【职责】。不要读取其他对话。启用前说明发送限制;我理解空闲检查不能完全 -> 避免与用户输入竞争。不要修改工具权限,也不要安装软件。 +把**对方任务名称**换成侧栏中对方的完整标题,**允许交流的话题**换成限定的内容, +例如已批准的产品名称、拼写与免费方案额度。提示词不需要内部 ID、本地路径、 +clone 仓库或终端命令。 + +```text +使用这个固定版本公开链接中的 ThreadMesh 工作流,请完整读取文件: +https://raw.githubusercontent.com/fyaic/threadmesh/592014782d10a8c4b88f46ea23b7cf588ff78355/plugins/threadmesh-codex/skills/threadmesh-codex/SKILL.md + +只把当前任务与“对方任务名称”配对。双方保留自己正在做的工作和此前约定。 +允许交流的话题:允许交流的话题。 +我允许读取一次任务列表来匹配这个名称,理解列表也会显示其他任务的标题和摘要。 +不要读取无关对话正文。找不到或遇到重名就问我,不猜测、不继续扫描历史。 + +我授权设置完成后自动发送相关的同伴建议,理解空闲检查不能保证绝不与新输入竞争。 +本次设置回合不许给对方发消息,也不修改业务文件。 +不要安装软件、修改权限或新建任务。 +请按名称确认选中的对方、允许话题、已有原生工具,以及当前任务是否已启用。 +任何一项不可用,都保持协作关闭。 +``` + +如果当前应用已经附上对方的原生任务引用,可以用它替代名称,并删去读取任务列表 +的授权段落。不要去本地文件找 ID。引用选择器由宿主提供,本指南不假定桌面端 +存在某种固定的 `@` 菜单。 + +想先检查、不启用?把授权自动发送的那一句换成:“只检查是否就绪。保持协作关闭, +保留此前的停止状态;不发消息、不改文件、不恢复待发建议。” +检查就绪不等于启用,也不能证明对方还有可用额度。 + +### 2. 等两个任务各自确认设置后,正常工作 + +每个任务都必须自己确认。写出对方名称不等于对方已经启用。 +流程读不到、工具缺失、名称无法确定,都属于设置未完成,不能当作连接成功。 +要取消,可以分别在两个任务里说“停止 ThreadMesh 协作”,不需要额外控制面板。 这是在已有对话中明确请求使用流程,**不是证明安装插件能热加载旧任务**。 模型应实际读取流程,核对已有原生工具,并确认选择范围。若读取失败或缺少工具, @@ -25,7 +53,7 @@ 仓库也在 `plugins/threadmesh-codex` 中提供了 Skill-only 插件包供正常分发测试; 本指南不会替用户修改全局插件安装或 marketplace 配置。 -然后正常工作。例如,在品牌任务中提出: +例如,在品牌任务中提出: > 产品更名为 Member Portal,免费方案最多五个项目,文案使用美式拼写,付费价格不变。 @@ -53,8 +81,10 @@ [9 月 7 日受控实测](../09-reviews/2026-09-07-native-desktop-acceptance.md)使用两个先完成 原任务、再启用协作的专用桌面任务,验证了原 B 自己改对文件,以及忙碌/停止行为。 -管理任务通过原生消息提供了任务引用和本地 Skill 路径;远程链接读取、新用户选择 -任务、手动 GUI 上手尚未验收。来源归属在原生任务数据中核对,未录制界面。 +管理任务通过原生消息提供了任务引用和本地 Skill 路径,并未验证上面的按名称入口。 +现在将公开流程固定到一个版本,不再依赖维护者的本地文件;具体核验边界见 +[公开入口检查记录](../09-reviews/2026-09-07-native-public-entry.md)。 +新用户的手动 GUI 上手仍未验收。来源归属在原生任务数据中核对,未录制界面。 仅打包校验和规则情景评审不等于真实桌面证明。此前的 [hook/MCP 接入尝试](../09-reviews/2026-09-07-desktop-native-adoption.md)没有通过; diff --git a/plugins/threadmesh-codex/skills/threadmesh-codex/SKILL.md b/plugins/threadmesh-codex/skills/threadmesh-codex/SKILL.md index 6da9a52..433a162 100644 --- a/plugins/threadmesh-codex/skills/threadmesh-codex/SKILL.md +++ b/plugins/threadmesh-codex/skills/threadmesh-codex/SKILL.md @@ -9,6 +9,18 @@ Use the host's existing task tools, not a new model, MCP server or background daemon. This skill is model guidance, not an enforced access-control layer. It does not provide cross-harness transport or transplant private chat history. +## Check without enabling + +A request to check readiness or preview pairing is not consent to enable or +resume collaboration. Retrieve the full workflow when the user provides its +public URL; a search snippet or a local copy does not verify that public entry. +If retrieval fails, report it without installing anything or inventing the rules. +Use the selected reference, or one user-authorized name inventory, to resolve +the peer. Inspect native tool availability and report: workflow read, peer +uniquely identified, required tools available, and collaboration still off. +Missing or ambiguous results are not ready. Do not send a probe to the peer, +read its conversation, change artifacts or restore cancelled suggestions. + ## Establish the selected pair Require the user's authorization covering the two specific tasks, their goals, @@ -21,11 +33,16 @@ host IDs, preserving the host ID when present. Do not ask users to find IDs in files. If names alone are provided, explain that the host's task-list operation also exposes other task titles/summaries; obtain permission for one inventory. Never read unrelated task turns. Confirm ambiguous names instead of guessing. +If the authorized inventory does not contain the target, ask for an app-provided +reference or a more specific selection; do not repeatedly expand the inventory. Keep a concise visible agreement in this conversation: selected task references, their goals, allowed topics and send mode. Prefer native mentions in the UI; never publish private identifiers to a repository. An old or missing agreement after context loss means no automatic sends until the scope is confirmed again. +The setup turn establishes only this task's agreement: no peer messages or +business edits. Tell the user to complete setup in the other task too. Do not +assume that naming a peer has installed the workflow or activated it there. Check the actual tool catalog for native read/status, send and wait operations (for example `read_thread`, `send_message_to_thread`, `wait_threads`, possibly