Skip to content

skills/objectstack-automation still calls the api flow secret optional and says type: 'api' can be invoked explicitly only — both false since PR #20551 (split from #20553) #20569

Description

@objectstack-fleet

Filing gate: ① a product defect with a named landing site. Class (b): a published skill contradicts the runtime and the Accepted ADR. reach: is a named real producer: skills/objectstack-automation/SKILL.md, which an authoring agent loads. It also ships to generated projects through create-objectstack.

Split by the triage seat (objectstack-wide, seat post #6015, session_01AavokzJ5DndAwitDXvKy4U) from #20553, items 1 and 2, when it graded that card. #20553 keeps the os validate half (domain:spec). This card is the skills-lane half, because skills/** is a Tier H governed surface. The evidence below is #20553's, filed by the domain:services seat (#6021) from the #20529 dev report 5882379577.

What is false (read at origin/main 03b19d9c, per #20553)

  1. skills/objectstack-automation/SKILL.md:356, the secret row: "HMAC-SHA256 shared secret. Strongly recommended — without it unsigned posts are accepted and a warning is logged".
  2. skills/objectstack-automation/SKILL.md:52, the api row: "Invoked explicitly via the API / engine.execute(), or bound as an inbound webhook".

Re-check (from #20553): git grep -n "Strongly recommended — without it unsigned posts are accepted" origin/main -- skills/objectstack-automation/SKILL.md and git grep -n "Invoked explicitly via the API" origin/main -- skills/objectstack-automation/SKILL.md each expect 1 hit.

Direction (triage's grade, on the first comment)

Dedupe: the family search in #20553 (「api trigger secret os validate skill objectstack-automation inbound webhook secret optional」: #20529, #8025 and #7722) found no card for these lines.

Dedupe words: objectstack-automation skill api secret optional · type api invoked explicitly autolaunched · skill trigger-api secret required

Activity

  1. objectstack-fleet commented on Sep 29, 2026

    @objectstack-fleet
    ContributorAuthor

    Reading for this card, from the domain:engine seat (session_01DEvba2nBuD4tWzfq8r8NFY) · 2026-09-29T18:41Z. ⛔ Not a claim.

    PR #20692 (#20611) landed as 31ed06763: /meta now also refuses a secretless api flow, answering 422 INVALID_METADATA with flow-api-trigger-secret-missing, and nothing is stored (pinned in protocol.metadata-redaction.test.ts). With the engine's registration refusal (17.5.0) and os validate (#20553), every door now refuses the flow that skills/objectstack-automation/SKILL.md still describes.

    • Line 356 says secret is "Strongly recommended — without it unsigned posts are accepted and a warning is logged".
    • Line 52 says a type: 'api' flow can be "Invoked explicitly via the API / engine.execute()" (an explicit-only flow is autolaunched).

    The at-tier record 5895956737 on PR #20692 judged both lines false on main. This card's reach is now every authoring door. skills/** is Tier H.


    Generated by Claude Code

  2. objectstack-fleet commented on Sep 30, 2026

    @objectstack-fleet
    ContributorAuthor

    Claim: PM loop round 2
    Session: session_01KTZmMfzVzjNvyaLyQ8mHvg
    Account: os-warren (the seat's linked user as GET /user answers it; the card's assignee)
    Branch: claude/issue-20569-automation-skill-api-secret
    Worktree: objectstack-issue-20569
    Domain: domain:skills
    Seat: domain:skills#1
    File surface: skills/objectstack-automation/SKILL.md (the Flow Types api row :51 and the inbound-webhook secret row :350, plus any other sentence under skills/objectstack-automation/** that describes the api trigger or its secret); scripts/check-skills-token-ratchet.mjs only if a ceiling row is lowered. content/docs/** is read for the census only, ⛔ not edited (another lane; hits are reported for the seat to card). Stop on breach; explain in the report.
    Container & model: S, not mechanical ⇒ M treatment, mode:subagent, model: claude-fable-5-1 (dispatch-gates --tier: Model tier — MANDATORY: claude-fable-5-1 (derived from the file surface, not recalled); skills/** clause ①)
    Clause-②: no
    Thread-read: 5896413536
    Serial constraints cleared: the serial predecessor on this file, #20657, merged as 7a09eee1 (PR #20778, same-day churn) — its rows :51 / :350 were left for this card; token ceiling now 5777 / 5785, headroom 8; no open PR touches skills/objectstack-automation/** (the twelve open PRs' file lists read at the R2 marker 5905508713); this lane's other in-flight cards (#20571, #20465, #20575) touch no path here.

    Readings at 2026-09-30T06:34Z on origin/main 7a09eee1: :51 still reads "Invoked explicitly via the API / engine.execute(), or bound as an inbound webhook"; :350 still reads "Strongly recommended — without it unsigned posts are accepted and a warning is logged". The security card on the same secret, #20552, is closed completed.


    Generated by Claude Code

  3. objectstack-fleet commented on Sep 30, 2026

    @objectstack-fleet
    ContributorAuthor

    os-dev-report

    {
      "issue": 20569,
      "status": "done",
      "branch": "claude/issue-20569-automation-skill-api-secret",
      "pr": "https://github.com/objectstack-ai/objectstack/pull/20796",
      "head": "32847a291404fbe17511948eff46011083008f10",
      "base": "7a09eee1b12a010f5e2c1749ff4dc7d9376516ad",
      "session": "session_01KTZmMfzVzjNvyaLyQ8mHvg",
      "premise_still_valid": true,
      "summary": "Rewrote the two false sentences in skills/objectstack-automation/SKILL.md (origin/main 7a09eee1; the card's :52/:356 are :51/:350 there): the Flow Types `api` row now says every `api` flow is bound to its inbound hook endpoint and needs a start-node `secret`, with `autolaunched` named as the explicit-only form; the `secret` row now says Required, that a flow without a non-blank one is refused at registration (os validate too) and never armed at boot, and names `x-objectstack-signature`, read from packages/triggers/trigger-api/src/plugin.ts:89. Three in-file payments for the token ceiling: the hook route is stated once (:343, the section the row points to), the Signature bullet keeps only the value shape (`sha256=` plus hex), and the :344-345 clause 'so these keys are read at runtime, not Zod-validated' (now false for `secret`) is cut to 'with no Zod shape'; :342 'can be bound' became 'is bound'. Every claim measured at code: spec enum flow.zod.ts:1060; resolveFlowTriggerKind flow-trigger-kind.ts:83-84 (type 'api' always resolves to the api trigger; autolaunched with no binding resolves to none); engine.ts:4311 + :10036-10052 validateApiTriggerSecret (throw, skipped loudly at boot); trigger-api api-trigger.ts:133-143 start() refuses ('not armed'); /automation door runtime/src/domains/automation.ts:2174-2178 answers VALIDATION_FAILED_STATUS; os validate cli/src/commands/validate.ts:461 runAuthoringRules over AUTHORING_RULES carrying validateFlowApiTriggerSecret (lint/src/authoring-rules.ts:1184, gating, ALL commands; finding flow-api-trigger-secret-missing at validate-flow-trigger-readiness.ts:881); /meta metadata-protocol/src/protocol.ts:4934 runs the same table and throws 422 INVALID_METADATA; flow-credential-projection.ts:129 withholds the start-node secret on serve (already stated at :87, not repeated). Draft PR #20796 (Tier H, skills/**) left for the maintainer; http row :87 and the examples-flows Slack node untouched.",
      "files_changed": [
        "skills/objectstack-automation/SKILL.md (+5 / -6; lines 439 -> 438)"
      ],
      "line_budget": "PM-set net +2 max across the published package: measured net -1 (SKILL.md 439 -> 438; all SKILL.md 4395 -> 4394; the 54 ratchet-covered files 12786 -> 12785). No re-wrap: the removed line is the :345 clause replaced by its true half.",
      "token_ceiling": "skills/objectstack-automation/SKILL.md 5777 -> 5782 tokens (ceil(bytes/4): 23106 -> 23125 bytes), ceiling 5785 unchanged, headroom 3; package 143329 -> 143334. Paid by the three in-file deletions above, each with a home in the same file; scripts/check-skills-token-ratchet.mjs untouched (no ceiling lowered or raised).",
      "tests": "No package touched, so no pnpm test / typecheck owed. Gates: node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands at 32847a29 (no paths; change set from the merge base) derived 24; each run with the exit captured before any pipe (cmd > log 2>&1; EXIT=$?); reconciled with --ran: '24 derived famil(ies) accounted for — 24 run, 0 NOT-MEASURED'. check:doc-formula-expressions first answered exit 3 (PREREQUISITE NOT MET: @objectstack/formula and @objectstack/lint unbuilt); built both under os-verify-lock (OS_VERIFY_LOCK_SLOT=issue-20569; 'pnpm exec turbo run build --filter=@objectstack/formula --filter=@objectstack/lint --concurrency=2'; 'VERDICT command-exit 0 · held the lock 95s · waited 1s') and re-ran: exit 0. Token ratchet verdict line: 'check-skills-token-ratchet: skills/objectstack-automation/SKILL.md is 5782 tokens (ceiling 5785; headroom 3)' and '54 authored bundle file(s) within their ceilings'. spec check:skill-docs: 'Skill docs in sync'; spec check:skill-refs: '9 generated files in sync with packages/spec' (both echoed their script name; outside the derivation, run because the dispatch named it). check:skill-examples not owed: no edited block carries an os:check marker. Control-byte grep over the file and the PR body: no hit. No ablation: docs-only diff, no test asserts the changed text. CI on PR #20796: in_progress at report time (not waited on).",
      "gates": [
        "node scripts/check-ci-filter-parity.mjs :: exit 0",
        "node scripts/check-closing-keyword-parity.mjs :: exit 0",
        "node scripts/check-closing-keyword-parity.mjs --self-test :: exit 0",
        "node scripts/check-comment-mask-corpus.mjs :: exit 0",
        "node scripts/check-doc-route-spelling.mjs --advisory :: exit 0",
        "node scripts/check-doc-route-spelling.mjs --self-test :: exit 0",
        "node scripts/check-skills-token-ratchet.mjs :: exit 0",
        "node scripts/check-skills-token-ratchet.mjs --self-test :: exit 0",
        "pnpm --filter @objectstack/spec run check:skill-docs :: exit 0",
        "pnpm --filter @objectstack/spec run check:skill-refs :: exit 0",
        "pnpm --filter @objectstack/lint run check:doc-formula-expressions :: exit 0",
        "pnpm check:agent-test-spelling :: exit 0",
        "pnpm check:corpus-claim-drift :: exit 0",
        "pnpm check:cross-package-test-inputs :: exit 0",
        "pnpm check:doc-authoring :: exit 0",
        "pnpm check:driver-memory-census :: exit 0",
        "pnpm check:gitlink-declared :: exit 0",
        "pnpm check:nul-bytes :: exit 0",
        "pnpm check:pm-governed-merges :: exit 0",
        "pnpm check:refd-timer-probe :: exit 0",
        "pnpm check:role-word :: exit 0",
        "pnpm check:skill-compatibility :: exit 0",
        "pnpm check:skill-frame-sync :: exit 0",
        "pnpm check:skill-identifier-liveness :: exit 0",
        "pnpm check:watch-hint-literal :: exit 0"
      ],
      "census": "skills/** and content/docs/** grepped (case-insensitive) for unsigned post | strongly recommended | invoked explicitly | explicit-only | hooks/:flowName | x-objectstack-signature | inbound webhook | type: 'api' | api...secret | autolaunched, excluding content/docs/references (generated) and content/docs/releases (release-owned). skills/** outside the edited file: zero sentences on the api flow trigger or its secret (the type: 'api' hits in objectstack-ui/rules/actions.md:22,38 and objectstack-ai/SKILL.md:158 are the UI action kind; references/* and evals/* carry none). content/docs/**: no sentence calls the secret optional or type: 'api' explicit-only; two observations only, listed under out_of_scope_findings. content/docs/releases/v17/17-5.mdx:133,764-771,1696-1698 already states the requirement correctly.",
      "deviations": [
        "gh CLI is absent in this container; the card, its two comments and the PR read-back were plain REST reads via curl (no writes). MCP GitHub tools not used.",
        "Beyond the two rows the card names, three neighbouring sentences in the same section were edited (:342 'can be'->'is', :344-345 clause, :352 bullet) — within the dispatch's file surface ('any other sentence describing the api trigger or its secret') and needed to pay the token ceiling; each deletion keeps its home in the same file, listed in the PR body for the seat's per-deletion check.",
        "The security disclosure rule: no request recipe added; the Signature bullet lost text (header name moved into the secret row, format kept as it was on main)."
      ],
      "mcp_calls": "0 — no MCP GitHub tool called",
      "api_writes": "3 write calls / 4 REST endpoints, all via scripts/pm tools on the fleet relay as objectstack-fleet[bot]: (1) POST /repos/objectstack-ai/objectstack/pulls via with-fleet --via dispatch (pr_create, draft forced; relay run 36681144017 success) -> PR #20796, body read back byte-identical; (2) label-write --issue 20796 --assign os-warren --add skip-changeset = POST /issues/20796/labels + POST /issues/20796/assignees in one relay dispatch (run 36681337278 success), read back MATCHES: labels documentation, size/s, skip-changeset; assignee os-warren; (3) POST /repos/objectstack-ai/objectstack/issues/20569/comments via post-stamped (this report). Plus git push x2 (the empty-branch probe, then 32847a29) — not REST. No PATCH of the PR body; no card assignee write; no retry loops.",
      "open_questions": [],
      "out_of_scope_findings": [
        "carrier: none · noted, not filed (observation, not one of the three classes) — content/docs/automation/webhooks.mdx:733-736: the outbound protocol's non-goals note ('Inbound webhooks … reintroduce it only alongside a real inbound runtime') predates trigger-api (ADR-0041 Tier 1) and reads as if no inbound runtime existed; stale, not false. dedupe: webhooks.mdx non-goals inbound runtime trigger-api",
        "carrier: none · noted, not filed (omission, true text) — content/docs/automation/flows.mdx:92 Flow Types `api` row ('Exposed as an API endpoint' / 'HTTP request') names neither the inbound hook nor the required start-node secret. dedupe: flows.mdx flow types api row secret"
      ]
    }

    Generated by Claude Code

  4. objectstack-fleet commented on Sep 30, 2026

    @objectstack-fleet
    ContributorAuthor

    ACCEPT — PR #20796 @ 32847a29 (skills seat 1, session_01KTZmMfzVzjNvyaLyQ8mHvg, 2026-09-30T07:15Z)

    Implemented-by: claude/issue-20569-automation-skill-api-secret (dev report 5905964684). Reviewed-by: session_01KTZmMfzVzjNvyaLyQ8mHvg.

    Review checklist, read on GitHub (not the report):

    • Shape: draft, base main, first body line Fixes #20569, Clause-②: no at a line start. One file, skills/objectstack-automation/SKILL.md, +5 / −6 — inside the claim surface; Tier H (skills/**). The http row and the examples-flows Slack node (PR docs(skills): objectstack-automation routes an outbound credential to a connector credentialRef and drops the Slack webhook-url example #20778's) are untouched.
    • Diff read by the seat against the card's direction: the api row names the inbound hook, the required start-node secret and autolaunched as the explicit-only form; the secret row says Required, refused at registration (os validate too) and never armed at boot, and names x-objectstack-signature (packages/triggers/trigger-api/src/plugin.ts:89 on main); three in-file token payments, each with a home in the same file. No request recipe beyond what main already stated.
    • Budgets: net −1 line (budget +2); SKILL.md 5782 / 5785 tokens, no ceiling moved.
    • Changeset: skip-changeset on the PR (the dev's label write succeeded this round), assignee os-warren. The one Check Changeset red is the opened-event run that predates the label; the labeled run is skipped.
    • CI on 32847a29 at this ACCEPT: 22 success, 11 path-filtered skipped, Lint & Repo Gates still in_progress (a required context — not a pass; it must conclude success before landing), 1 stale Check Changeset red as above.
    • ## Contract review PASS on this head: 5906148151 (rendered at CONTRACT_REVIEW_TIER by an isolated subagent — this seat is below tier — and adopted by the seat; its transcript served claude-fable-5-1). It judged every changed statement at the code on every door (engine registration, boot, trigger-api, the /automation write door, os validate, /meta) and found every deletion homed and no contradiction in the skill or content/docs/automation/**.
    • Report: mcp_calls 0; api_writes three relay writes (pr_create, label-write, the report) plus two pushes.

    Out-of-scope findings: content/docs/automation/flows.mdx:92 (the api row names neither the hook nor the required secret — true but incomplete) and webhooks.mdx:733–:736 (a stale non-goals note, not false) → dropped: neither is a false statement, and an incomplete sentence is a coverage gap, not a defect card; noted in this ACCEPT for the docs lane's next edit of those pages.

    Landing: Tier H — the PR stays draft and awaits an authorized APPROVED review; needs-user-decision goes on the PR and review is requested from os-zhuang and hotlong in this same act; the final 维护者速读 is posted on the PR.


    Generated by Claude Code

  5. objectstack-fleet commented on Sep 30, 2026

    @objectstack-fleet
    ContributorAuthor

    Closed completed — skills seat 1, session_01KTZmMfzVzjNvyaLyQ8mHvg, 2026-09-30T08:56Z.

    Delivered by PR #20796, MERGED 2026-09-30T08:52Z through the merge queue as eac538c9.

    • Content confirmed on origin/main:
      • skills/objectstack-automation/SKILL.md:51 calls api the inbound-webhook kind that needs a start-node secret, and names autolaunched as the explicit-only form;
      • :349 says the secret is Required: refused at registration (os validate too), never armed at boot, signature in x-objectstack-signature.
    • Landing record: ## Contract review PASS 5906148151 on 32847a29 (the landing head), ACCEPT 5906165199, and authorized approval by os-zhuang (5363562821, a GOVERNED_APPROVERS account). The approver readied it, armed auto-merge and queued it.
    • Fixes #20569 did not close this card at merge (the fifth queue merge in a row this shift), so the seat closes it here; pm:dispatched comes off and the assignee is cleared.

    Generated by Claude Code

  6. added a commit that references this issue on Oct 7, 2026
    eac538c
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingdocumentationImprovements or additions to documentationdomain:skillspriority:p2Medium: important, M3

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions