Repository navigation
skills/objectstack-automation still calls the api flow secret optional and says type: 'api' can be invoked explicitly only — both false since PR #20551 (split from #20553) #20569
Description
Activity
- addedbugSomething isn't workingSomething isn't workingdocumentationImprovements or additions to documentationImprovements or additions to documentationpriority:p2Medium: important, M3Medium: important, M3
on Sep 29, 2026 - added a commit that references this issue
on Sep 29, 2026 objectstack-fleet commented
on Sep 29, 2026 ContributorAuthorMore actionsReading for this card, from the
domain:engineseat (session_01DEvba2nBuD4tWzfq8r8NFY) · 2026-09-29T18:41Z. ⛔ Not a claim.PR #20692 (#20611) landed as
31ed06763:/metanow also refuses a secretlessapiflow, answering422 INVALID_METADATAwithflow-api-trigger-secret-missing, and nothing is stored (pinned inprotocol.metadata-redaction.test.ts). With the engine's registration refusal (17.5.0) andos validate(#20553), every door now refuses the flow thatskills/objectstack-automation/SKILL.mdstill describes.- Line 356 says
secretis "Strongly recommended — without it unsigned posts are accepted and a warning is logged". - Line 52 says a
type: 'api'flow can be "Invoked explicitly via the API /engine.execute()" (an explicit-only flow isautolaunched).
The at-tier record 5895956737 on PR #20692 judged both lines false on
main. This card's reach is now every authoring door.skills/**is Tier H.
Generated by Claude Code
- Line 356 says
- added a commit that references this issue
on Sep 30, 2026 objectstack-fleet commented
on Sep 30, 2026 ContributorAuthorMore actionsClaim: PM loop round 2
Session:session_01KTZmMfzVzjNvyaLyQ8mHvg
Account:os-warren(the seat's linked user asGET /useranswers it; the card's assignee)
Branch:claude/issue-20569-automation-skill-api-secret
Worktree:objectstack-issue-20569
Domain:domain:skills
Seat:domain:skills#1
File surface:skills/objectstack-automation/SKILL.md(the Flow Typesapirow:51and the inbound-webhooksecretrow:350, plus any other sentence underskills/objectstack-automation/**that describes theapitrigger or its secret);scripts/check-skills-token-ratchet.mjsonly if a ceiling row is lowered.content/docs/**is read for the census only, ⛔ not edited (another lane; hits are reported for the seat to card). Stop on breach; explain in the report.
Container & model:S, not mechanical ⇒ M treatment,mode:subagent,model: claude-fable-5-1(dispatch-gates --tier: Model tier — MANDATORY: claude-fable-5-1 (derived from the file surface, not recalled);skills/**clause ①)
Clause-②: no
Thread-read: 5896413536
Serial constraints cleared: the serial predecessor on this file, #20657, merged as7a09eee1(PR #20778, same-day churn) — its rows:51/:350were left for this card; token ceiling now 5777 / 5785, headroom 8; no open PR touchesskills/objectstack-automation/**(the twelve open PRs' file lists read at the R2 marker 5905508713); this lane's other in-flight cards (#20571, #20465, #20575) touch no path here.Readings at 2026-09-30T06:34Z on
origin/main7a09eee1::51still reads "Invoked explicitly via the API /engine.execute(), or bound as an inbound webhook";:350still reads "Strongly recommended — without it unsigned posts are accepted and a warning is logged". The security card on the same secret, #20552, is closedcompleted.
Generated by Claude Code
objectstack-fleet commented
on Sep 30, 2026 ContributorAuthorMore actionsos-dev-report
{ "issue": 20569, "status": "done", "branch": "claude/issue-20569-automation-skill-api-secret", "pr": "https://github.com/objectstack-ai/objectstack/pull/20796", "head": "32847a291404fbe17511948eff46011083008f10", "base": "7a09eee1b12a010f5e2c1749ff4dc7d9376516ad", "session": "session_01KTZmMfzVzjNvyaLyQ8mHvg", "premise_still_valid": true, "summary": "Rewrote the two false sentences in skills/objectstack-automation/SKILL.md (origin/main 7a09eee1; the card's :52/:356 are :51/:350 there): the Flow Types `api` row now says every `api` flow is bound to its inbound hook endpoint and needs a start-node `secret`, with `autolaunched` named as the explicit-only form; the `secret` row now says Required, that a flow without a non-blank one is refused at registration (os validate too) and never armed at boot, and names `x-objectstack-signature`, read from packages/triggers/trigger-api/src/plugin.ts:89. Three in-file payments for the token ceiling: the hook route is stated once (:343, the section the row points to), the Signature bullet keeps only the value shape (`sha256=` plus hex), and the :344-345 clause 'so these keys are read at runtime, not Zod-validated' (now false for `secret`) is cut to 'with no Zod shape'; :342 'can be bound' became 'is bound'. Every claim measured at code: spec enum flow.zod.ts:1060; resolveFlowTriggerKind flow-trigger-kind.ts:83-84 (type 'api' always resolves to the api trigger; autolaunched with no binding resolves to none); engine.ts:4311 + :10036-10052 validateApiTriggerSecret (throw, skipped loudly at boot); trigger-api api-trigger.ts:133-143 start() refuses ('not armed'); /automation door runtime/src/domains/automation.ts:2174-2178 answers VALIDATION_FAILED_STATUS; os validate cli/src/commands/validate.ts:461 runAuthoringRules over AUTHORING_RULES carrying validateFlowApiTriggerSecret (lint/src/authoring-rules.ts:1184, gating, ALL commands; finding flow-api-trigger-secret-missing at validate-flow-trigger-readiness.ts:881); /meta metadata-protocol/src/protocol.ts:4934 runs the same table and throws 422 INVALID_METADATA; flow-credential-projection.ts:129 withholds the start-node secret on serve (already stated at :87, not repeated). Draft PR #20796 (Tier H, skills/**) left for the maintainer; http row :87 and the examples-flows Slack node untouched.", "files_changed": [ "skills/objectstack-automation/SKILL.md (+5 / -6; lines 439 -> 438)" ], "line_budget": "PM-set net +2 max across the published package: measured net -1 (SKILL.md 439 -> 438; all SKILL.md 4395 -> 4394; the 54 ratchet-covered files 12786 -> 12785). No re-wrap: the removed line is the :345 clause replaced by its true half.", "token_ceiling": "skills/objectstack-automation/SKILL.md 5777 -> 5782 tokens (ceil(bytes/4): 23106 -> 23125 bytes), ceiling 5785 unchanged, headroom 3; package 143329 -> 143334. Paid by the three in-file deletions above, each with a home in the same file; scripts/check-skills-token-ratchet.mjs untouched (no ceiling lowered or raised).", "tests": "No package touched, so no pnpm test / typecheck owed. Gates: node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands at 32847a29 (no paths; change set from the merge base) derived 24; each run with the exit captured before any pipe (cmd > log 2>&1; EXIT=$?); reconciled with --ran: '24 derived famil(ies) accounted for — 24 run, 0 NOT-MEASURED'. check:doc-formula-expressions first answered exit 3 (PREREQUISITE NOT MET: @objectstack/formula and @objectstack/lint unbuilt); built both under os-verify-lock (OS_VERIFY_LOCK_SLOT=issue-20569; 'pnpm exec turbo run build --filter=@objectstack/formula --filter=@objectstack/lint --concurrency=2'; 'VERDICT command-exit 0 · held the lock 95s · waited 1s') and re-ran: exit 0. Token ratchet verdict line: 'check-skills-token-ratchet: skills/objectstack-automation/SKILL.md is 5782 tokens (ceiling 5785; headroom 3)' and '54 authored bundle file(s) within their ceilings'. spec check:skill-docs: 'Skill docs in sync'; spec check:skill-refs: '9 generated files in sync with packages/spec' (both echoed their script name; outside the derivation, run because the dispatch named it). check:skill-examples not owed: no edited block carries an os:check marker. Control-byte grep over the file and the PR body: no hit. No ablation: docs-only diff, no test asserts the changed text. CI on PR #20796: in_progress at report time (not waited on).", "gates": [ "node scripts/check-ci-filter-parity.mjs :: exit 0", "node scripts/check-closing-keyword-parity.mjs :: exit 0", "node scripts/check-closing-keyword-parity.mjs --self-test :: exit 0", "node scripts/check-comment-mask-corpus.mjs :: exit 0", "node scripts/check-doc-route-spelling.mjs --advisory :: exit 0", "node scripts/check-doc-route-spelling.mjs --self-test :: exit 0", "node scripts/check-skills-token-ratchet.mjs :: exit 0", "node scripts/check-skills-token-ratchet.mjs --self-test :: exit 0", "pnpm --filter @objectstack/spec run check:skill-docs :: exit 0", "pnpm --filter @objectstack/spec run check:skill-refs :: exit 0", "pnpm --filter @objectstack/lint run check:doc-formula-expressions :: exit 0", "pnpm check:agent-test-spelling :: exit 0", "pnpm check:corpus-claim-drift :: exit 0", "pnpm check:cross-package-test-inputs :: exit 0", "pnpm check:doc-authoring :: exit 0", "pnpm check:driver-memory-census :: exit 0", "pnpm check:gitlink-declared :: exit 0", "pnpm check:nul-bytes :: exit 0", "pnpm check:pm-governed-merges :: exit 0", "pnpm check:refd-timer-probe :: exit 0", "pnpm check:role-word :: exit 0", "pnpm check:skill-compatibility :: exit 0", "pnpm check:skill-frame-sync :: exit 0", "pnpm check:skill-identifier-liveness :: exit 0", "pnpm check:watch-hint-literal :: exit 0" ], "census": "skills/** and content/docs/** grepped (case-insensitive) for unsigned post | strongly recommended | invoked explicitly | explicit-only | hooks/:flowName | x-objectstack-signature | inbound webhook | type: 'api' | api...secret | autolaunched, excluding content/docs/references (generated) and content/docs/releases (release-owned). skills/** outside the edited file: zero sentences on the api flow trigger or its secret (the type: 'api' hits in objectstack-ui/rules/actions.md:22,38 and objectstack-ai/SKILL.md:158 are the UI action kind; references/* and evals/* carry none). content/docs/**: no sentence calls the secret optional or type: 'api' explicit-only; two observations only, listed under out_of_scope_findings. content/docs/releases/v17/17-5.mdx:133,764-771,1696-1698 already states the requirement correctly.", "deviations": [ "gh CLI is absent in this container; the card, its two comments and the PR read-back were plain REST reads via curl (no writes). MCP GitHub tools not used.", "Beyond the two rows the card names, three neighbouring sentences in the same section were edited (:342 'can be'->'is', :344-345 clause, :352 bullet) — within the dispatch's file surface ('any other sentence describing the api trigger or its secret') and needed to pay the token ceiling; each deletion keeps its home in the same file, listed in the PR body for the seat's per-deletion check.", "The security disclosure rule: no request recipe added; the Signature bullet lost text (header name moved into the secret row, format kept as it was on main)." ], "mcp_calls": "0 — no MCP GitHub tool called", "api_writes": "3 write calls / 4 REST endpoints, all via scripts/pm tools on the fleet relay as objectstack-fleet[bot]: (1) POST /repos/objectstack-ai/objectstack/pulls via with-fleet --via dispatch (pr_create, draft forced; relay run 36681144017 success) -> PR #20796, body read back byte-identical; (2) label-write --issue 20796 --assign os-warren --add skip-changeset = POST /issues/20796/labels + POST /issues/20796/assignees in one relay dispatch (run 36681337278 success), read back MATCHES: labels documentation, size/s, skip-changeset; assignee os-warren; (3) POST /repos/objectstack-ai/objectstack/issues/20569/comments via post-stamped (this report). Plus git push x2 (the empty-branch probe, then 32847a29) — not REST. No PATCH of the PR body; no card assignee write; no retry loops.", "open_questions": [], "out_of_scope_findings": [ "carrier: none · noted, not filed (observation, not one of the three classes) — content/docs/automation/webhooks.mdx:733-736: the outbound protocol's non-goals note ('Inbound webhooks … reintroduce it only alongside a real inbound runtime') predates trigger-api (ADR-0041 Tier 1) and reads as if no inbound runtime existed; stale, not false. dedupe: webhooks.mdx non-goals inbound runtime trigger-api", "carrier: none · noted, not filed (omission, true text) — content/docs/automation/flows.mdx:92 Flow Types `api` row ('Exposed as an API endpoint' / 'HTTP request') names neither the inbound hook nor the required start-node secret. dedupe: flows.mdx flow types api row secret" ] }
Generated by Claude Code
objectstack-fleet commented
on Sep 30, 2026 ContributorAuthorMore actionsACCEPT — PR #20796 @
32847a29(skills seat 1,session_01KTZmMfzVzjNvyaLyQ8mHvg, 2026-09-30T07:15Z)Implemented-by:
claude/issue-20569-automation-skill-api-secret(dev report 5905964684). Reviewed-by:session_01KTZmMfzVzjNvyaLyQ8mHvg.Review checklist, read on GitHub (not the report):
- Shape: draft, base
main, first body lineFixes #20569,Clause-②: noat a line start. One file,skills/objectstack-automation/SKILL.md, +5 / −6 — inside the claim surface; Tier H (skills/**). Thehttprow and the examples-flows Slack node (PR docs(skills): objectstack-automation routes an outbound credential to a connector credentialRef and drops the Slack webhook-url example #20778's) are untouched. - Diff read by the seat against the card's direction: the
apirow names the inbound hook, the required start-nodesecretandautolaunchedas the explicit-only form; thesecretrow says Required, refused at registration (os validatetoo) and never armed at boot, and namesx-objectstack-signature(packages/triggers/trigger-api/src/plugin.ts:89onmain); three in-file token payments, each with a home in the same file. No request recipe beyond whatmainalready stated. - Budgets: net −1 line (budget +2);
SKILL.md5782 / 5785 tokens, no ceiling moved. - Changeset:
skip-changeseton the PR (the dev's label write succeeded this round), assigneeos-warren. The oneCheck Changesetred is theopened-event run that predates the label; thelabeledrun isskipped. - CI on
32847a29at this ACCEPT: 22success, 11 path-filteredskipped,Lint & Repo Gatesstillin_progress(a required context — not a pass; it must concludesuccessbefore landing), 1 staleCheck Changesetred as above. ## Contract reviewPASS on this head: 5906148151 (rendered atCONTRACT_REVIEW_TIERby an isolated subagent — this seat is below tier — and adopted by the seat; its transcript servedclaude-fable-5-1). It judged every changed statement at the code on every door (engine registration, boot,trigger-api, the/automationwrite door,os validate,/meta) and found every deletion homed and no contradiction in the skill orcontent/docs/automation/**.- Report:
mcp_calls0;api_writesthree relay writes (pr_create,label-write, the report) plus two pushes.
Out-of-scope findings:
content/docs/automation/flows.mdx:92(theapirow names neither the hook nor the required secret — true but incomplete) andwebhooks.mdx:733–:736(a stale non-goals note, not false) → dropped: neither is a false statement, and an incomplete sentence is a coverage gap, not a defect card; noted in this ACCEPT for the docs lane's next edit of those pages.Landing: Tier H — the PR stays draft and awaits an authorized APPROVED review;
needs-user-decisiongoes on the PR and review is requested fromos-zhuangandhotlongin this same act; the final 维护者速读 is posted on the PR.
Generated by Claude Code
- Shape: draft, base
objectstack-fleet commented
on Sep 30, 2026 ContributorAuthorMore actionsClosed
completed— skills seat 1,session_01KTZmMfzVzjNvyaLyQ8mHvg, 2026-09-30T08:56Z.Delivered by PR #20796, MERGED 2026-09-30T08:52Z through the merge queue as
eac538c9.- Content confirmed on
origin/main:skills/objectstack-automation/SKILL.md:51callsapithe inbound-webhook kind that needs a start-nodesecret, and namesautolaunchedas the explicit-only form;:349says the secret is Required: refused at registration (os validatetoo), never armed at boot, signature inx-objectstack-signature.
- Landing record:
## Contract reviewPASS 5906148151 on32847a29(the landing head), ACCEPT 5906165199, and authorized approval byos-zhuang(5363562821, aGOVERNED_APPROVERSaccount). The approver readied it, armed auto-merge and queued it. Fixes #20569did not close this card at merge (the fifth queue merge in a row this shift), so the seat closes it here;pm:dispatchedcomes off and the assignee is cleared.
Generated by Claude Code
- Content confirmed on
- added a commit that references this issue
on Oct 7, 2026
Filing gate: ① a product defect with a named landing site. Class (b): a published skill contradicts the runtime and the Accepted ADR.
reach:is a named real producer:skills/objectstack-automation/SKILL.md, which an authoring agent loads. It also ships to generated projects throughcreate-objectstack.Split by the triage seat (objectstack-wide, seat post #6015,
session_01AavokzJ5DndAwitDXvKy4U) from #20553, items 1 and 2, when it graded that card. #20553 keeps theos validatehalf (domain:spec). This card is the skills-lane half, becauseskills/**is a Tier H governed surface. The evidence below is #20553's, filed by thedomain:servicesseat (#6021) from the #20529 dev report5882379577.What is false (read at
origin/main03b19d9c, per #20553)skills/objectstack-automation/SKILL.md:356, thesecretrow: "HMAC-SHA256 shared secret. Strongly recommended — without it unsigned posts are accepted and a warning is logged".apiflow with no non-blankconfig.secret: 400VALIDATION_FAILEDon the/automationwrite doors, and a skip with a warning at boot.skills/objectstack-automation/SKILL.md:52, theapirow: "Invoked explicitly via the API /engine.execute(), or bound as an inbound webhook".api-kind flow to the inbound trigger, so no "invoked explicitly only" form oftype: 'api'exists.type: 'autolaunched', as PR fix(trigger-api,service-automation): refuse an api flow with no per-flow secret, at arm time and at registration (#20529) #20551's changeset says.Re-check (from #20553):
git grep -n "Strongly recommended — without it unsigned posts are accepted" origin/main -- skills/objectstack-automation/SKILL.mdandgit grep -n "Invoked explicitly via the API" origin/main -- skills/objectstack-automation/SKILL.mdeach expect 1 hit.Direction (triage's grade, on the first comment)
:356: the secret is required. The row says what happens without one, which is refused at registration and not armed at boot, and names the header the signature goes in.:52:apiis the inbound-webhook kind and always needs a secret. The explicit-only form isautolaunched.skills/**andcontent/docs/**lines that describe theapitrigger or its secret.config.secreton the start node) is served in cleartext by the flow-definition read; after #20529 every armed hook carries one #20552 is the open security card on the same secret).Dedupe: the family search in #20553 (「api trigger secret os validate skill objectstack-automation inbound webhook secret optional」: #20529, #8025 and #7722) found no card for these lines.
Dedupe words:
objectstack-automation skill api secret optional·type api invoked explicitly autolaunched·skill trigger-api secret required