From 8f4222b5c95d648ce13e0653a81ff7a5157dcb5b Mon Sep 17 00:00:00 2001 From: Claude Date: Fri, 2 Oct 2026 02:23:15 +0000 Subject: [PATCH] docs(skills): objectstack-ai says guardrails is enforced per turn and output validation lives on action.ai.outputSchema The ToolSchema paragraph no longer says a tool's outputSchema keys are folded into the model-facing description; it says nothing reads the key on a tool record and steers the author to ai.outputSchema on the action, which the AI runtime enforces by withholding a non-conforming result. Common Pitfalls 1 no longer lists guardrails as declared-only: it is enforced per user turn (token and time limits, blocked tool names and categories refused) but is a limit, not an approval. memory stays described as declared-only. Co-authored-by: Claude Claude-Session: https://claude.ai/code/session_01FNKm1SmPpuJASnbjxWGtsJ --- skills/objectstack-ai/SKILL.md | 12 +++++++----- 1 file changed, 7 insertions(+), 5 deletions(-) diff --git a/skills/objectstack-ai/SKILL.md b/skills/objectstack-ai/SKILL.md index 13bca2af2c2..b0b39c921ea 100644 --- a/skills/objectstack-ai/SKILL.md +++ b/skills/objectstack-ai/SKILL.md @@ -277,8 +277,9 @@ no framework executor loads a metadata-authored tool. `ToolSchema` is **strict** — an unknown key (a typo, or a retired one) is a parse error, not a silent strip. Required `name` / `label` / `description` and a JSON Schema `parameters` object; optional `objectName` and `outputSchema` (⚠️ -experimental — its top-level keys are folded into the tool description shown to -the model, and outputs are **not** validated). Retired in protocol 17: +experimental — nothing reads it on a tool record; declare the schema as +`ai.outputSchema` on the **action** instead, which the AI runtime ☁️ enforces +by withholding a result that does not conform). Retired in protocol 17: `category`, `permissions`, `active`, `builtIn` — all authorable and inert — joining `requiresConfirmation`; each rejection carries its replacement. @@ -306,9 +307,10 @@ there is **no top-level `temperature` / `maxTokens`** on an agent ## Common Pitfalls -1. **Mistaking `guardrails` for a gate.** `guardrails` / `memory` / - `structuredOutput` are declared only — no runtime reads them, and real limits - come from the quota service. For a gate that is **enforced**, use +1. **Mistaking `guardrails` for a gate.** `guardrails` is enforced per user turn + by the AI runtime ☁️ — token and time limits, blocked tool names and categories + refused — but it is a limit, not an approval; `memory` is declared only — no + runtime reads it. For a gate that is **enforced**, use `enableActionApproval: true` (approval queue ☁️), `ai.requiresConfirmation` on the **action**, or `approval: 'always'` on an MCP tool binding. AI metadata edits are already gated: they land as drafts a human must publish (ADR-0033).