You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit c307193
Browse filesBrowse the repository at this point in the historyBrowse files
docs(agents): correct audit findings in guidance and gate docs
Restore the connector byte-cap rule's skip list, list every CI gate step,
name the real baseline flags and generated-artifact checks, make
api-validation strict-only guidance explicit, pass a base ref to
check-block-registry, and teach check:guidance-refs about bun run --cwd.
**Critical:**A subblock `id` is unique per condition. The only sanctioned cross-condition reuse is the hosted-key `apiKey` pair (`add-hosted-key` skill), where both fields deliberately share one value. `blocks.test.ts` fails same-condition duplicates.
76
+
**Critical:**Give every subblock a unique `id`: duplicates collide silently (the last definition wins). `blocks.test.ts` fails a duplicate within one condition unless the copies are a basic/advanced mode-swap pair, one basic plus trigger-mode copies, or all carry `canonicalParamId`. The only sanctioned cross-condition reuse is the hosted-key `apiKey` pair (`add-hosted-key` skill), where both fields deliberately share one value.
77
77
78
78
### Text Inputs
79
79
```typescript
@@ -959,7 +959,7 @@ But if the same change also adds, edits **or removes** a tool, run `bun run tool
959
959
A visible integration block does require the generated integration catalog and docs to be refreshed:
960
960
`bun run tool-metadata:generate` (only when a tool changed), `bun run scripts/generate-docs.ts`,
961
961
`bun run deployment-config:generate`, then `bun run check:audits`. Also run
962
-
`bun run apps/sim/scripts/check-block-registry.ts` (CI runs it outside `check:audits`). Commit the
962
+
`bun run apps/sim/scripts/check-block-registry.ts origin/staging` (CI runs it outside `check:audits`). Commit the
963
963
full generator output. For what each check verifies, see the `validate-integration` skill →
964
964
Regenerate Derived Artifacts.
965
965
@@ -1002,7 +1002,7 @@ Validate the block against every tool in `tools.access`:
1002
1002
2.**For each tool, verify the block has correct:**
1003
1003
- SubBlock inputs that cover all required tool params (with correct `condition` to show for that operation)
1004
1004
- SubBlock input types that match the tool param types (e.g., dropdown for enums, short-input for strings)
1005
-
- Each subBlock (or its `canonicalParamId`) is named exactly after the tool param it fills. A required `user-only` param that is only renamed in `tools.config.params` fails `bun run apps/sim/scripts/check-block-registry.ts`; remap only optional or `user-or-llm` params
1005
+
- Each subBlock (or its `canonicalParamId`) is named exactly after the tool param it fills. A required `user-only` param that is only renamed in `tools.config.params` fails `bun run apps/sim/scripts/check-block-registry.ts origin/staging`; remap only optional or `user-or-llm` params
1006
1006
- Type coercions in `tools.config.params` for any params that need conversion (Number(), Boolean(), JSON.parse())
1007
1007
3.**Verify block outputs** cover the key fields returned by all tools
1008
1008
4.**Verify conditions** — each subBlock should only show for the operations that actually use it
-[ ]`listDocuments` handles pagination; deferred-content connectors use metadata-based content hashes
628
628
-[ ]`syncContext.listingCapped = true` set whenever the listing is truncated (max-items cap or transient per-item error) — required to prevent the engine's deletion reconciliation from removing unseen documents
629
629
-[ ]`contentDeferred: true` used if content requires per-doc API calls (file download, export, blocks fetch)
630
-
-[ ]`contentHash` is metadata-based (not content-based) and identical between stub and `getDocument`
630
+
-[ ]`contentHash` is metadata-based for deferred-content connectors (inline-content ones may use `computeContentHash`) and identical between stub and `getDocument`
631
631
-[ ]`sourceUrl` set on each ExternalDocument (full URL, not relative)
632
632
-[ ]`metadata` includes source-specific data for tag mapping
633
633
-[ ]`tagDefinitions` declared for each semantic key returned by `mapTags`
description: Anti-slop frontend skill for landing pages, portfolios, and redesigns. The agent reads the brief, infers the right design direction, and ships interfaces that do not look templated. Real design systems when applicable, audit-first on redesigns, strict pre-flight check.
5
5
---
6
6
7
-
> **In this repo:** Tailwind 4 (CSS-first config in `apps/sim/app/_styles/globals.css`); animation via `import { motion } from 'framer-motion'` (not `motion/react` — rewrite every `motion/react` import in the samples below); icons from `@sim/emcn/icons`; colors through the CSS-variable tokens in `.claude/rules/sim-styling.md` (no hardcoded `text-gray-*`/hex/`zinc` utilities, no paired `dark:` utilities). This note overrides any conflicting guidance or code sample anywhere in this file. Fonts are fixed (Season body, Inter, Martian Mono); never introduce new families. Font weight is only `font-normal`/`font-medium`/`font-semibold`. Elevation uses the `shadow-subtle|medium|overlay|card` tokens. Type size uses named tokens, never `text-[Npx]`. Product forms use `ChipModalField`. Use `bunx`, never `npx`. Do not add GSAP, Lenis, Three, or shadcn. Landing copy and SEO follow `.claude/rules/constitution.md` and `.claude/rules/landing-seo-geo.md`.
7
+
> **In this repo:** Tailwind 4 (CSS-first config in `apps/sim/app/_styles/globals.css`); animation via `import { motion } from 'framer-motion'` (not `motion/react` — rewrite every `motion/react` import in the samples below); icons from `@sim/emcn/icons`; colors through the CSS-variable tokens in `.claude/rules/sim-styling.md` (no hardcoded `text-gray-*`/hex/`zinc` utilities, no paired `dark:` utilities). This note overrides any conflicting guidance or code sample anywhere in this file. Fonts are fixed (Season body, Inter); never introduce new families, and never use Martian Mono on landing (`apps/sim/app/(landing)/CLAUDE.md`). Font weight is only `font-normal`/`font-medium`/`font-semibold`. Elevation uses the `shadow-subtle|medium|overlay|card` tokens. Type size uses named tokens, never `text-[Npx]`. Product forms use `ChipModalField`. Use `bunx`, never `npx`. Do not add GSAP, Lenis, Three, or shadcn. Landing copy and SEO follow `.claude/rules/constitution.md` and `.claude/rules/landing-seo-geo.md`.
Copy file name to clipboardExpand all lines: .agents/skills/memory-load-check/SKILL.md
+5-1Lines changed: 5 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -72,7 +72,11 @@ For those, require all three:
72
72
- skip oversize at listing (`stubOrSkipBySize` with the reported size) and again at fetch time (overflow -> `markSkipped`), since the listing size can be missing or under-reported
73
73
- never drop/truncate silently — oversized files become content-less failed rows carrying `skippedReason`, so they stay visible in the KB UI instead of vanishing from the index
74
74
75
-
Skip the *per-file `CONNECTOR_MAX_FILE_BYTES` + skipped-row* pattern when the source bounds the item count (paginated JSON: Jira, Linear, Sentry, Slack, Zendesk, Gmail, ...). Every response body is still read through `readBodyWithLimit` with a connector-specific budget (`MAX_DOCS_RESPONSE_BYTES` in google-docs, `MAX_CONTENT_BYTES` in google-sheets, a remaining-bytes budget in notion). Confluence attachments use the full file pattern.
75
+
Skip the pattern when the source already bounds the payload:
76
+
- pure API/structured-data connectors (Jira, Linear, Sentry, Slack, Zendesk, Gmail, ...) — paginated JSON/text; apply normal pagination + concurrency bounds instead of a per-file byte cap
77
+
- native-document connectors capped by the platform (Evernote ~25 MB/note, ...) — a 100 MB cap can never fire there
78
+
79
+
Some connectors also budget the response body (google-docs `MAX_DOCS_RESPONSE_BYTES`, google-sheets `MAX_CONTENT_BYTES`, a remaining-bytes budget in notion); Confluence attachments use the full file pattern. Follow the connector's existing approach rather than adding a cap to every `response.json()`.
76
80
77
81
Litmus test: "Can a user make this one fetch arbitrarily large, with nothing upstream stopping it?" Yes -> use the pattern. No (platform hard-cap, or already paginated) -> a per-file byte cap adds noise, not safety. Borderline: a user-configured/self-hosted endpoint with no platform cap (e.g. Obsidian) — bound it only if the content is genuinely unbounded.
Copy file name to clipboardExpand all lines: .agents/skills/v2-api-conventions/SKILL.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -30,7 +30,7 @@ Each rule below guards a caller-visible failure: a non-integer `limit` reaching
30
30
31
31
## Rule 1 — the envelope is produced by helpers, never by hand
32
32
33
-
`v2Data`, `v2Error`, and the typed error helpers in `response.ts` (`v2ValidationError`, `v2RateLimitError`, `v2HttpError`) are the only things that build a v2 body. They also set `Cache-Control: private, no-store`, which every v2 response needs because every v2 response is authed per-caller data.
33
+
`v2Data`, `v2Error`, and the typed error helpers in `response.ts` (`v2ValidationError`, `v2RateLimitError`, `v2HttpError`, `v2InsufficientScope`, `v2HeadNoEffect`, `v2UploadDataPlaneError`) are the only things that build a v2 body. They also set `Cache-Control: private, no-store`, which every v2 response needs because every v2 response is authed per-caller data.
34
34
35
35
A route built with `defineV2JsonRoute` gets this for free: its `present` returns the *body shape* and the builder renders it. Never call `NextResponse.json` from a v2 route.
Copy file name to clipboardExpand all lines: .agents/skills/validate-integration/SKILL.md
+4-4Lines changed: 4 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -198,9 +198,9 @@ For **each tool** in `tools.access`:
198
198
- Shown when that operation is selected (correct `condition`)
199
199
- Marked as `required: true` (or conditionally required)
200
200
-[ ] Every **optional** tool param has a corresponding subBlock input (or is intentionally omitted if truly never needed)
201
-
-[ ]A subBlock `id` is unique per condition. The only sanctioned cross-condition reuse is the hosted-key `apiKey` pair (`add-hosted-key` skill), where both fields deliberately share one value. `blocks.test.ts` fails same-condition duplicates
201
+
-[ ]Every subBlock `id` is unique (duplicates collide silently; the last definition wins). `blocks.test.ts` fails a duplicate within one condition unless the copies are a basic/advanced mode-swap pair, one basic plus trigger-mode copies, or all carry `canonicalParamId`. The only sanctioned cross-condition reuse is the hosted-key `apiKey` pair (`add-hosted-key` skill)
202
202
-[ ] The `tools.config.tool` function returns the correct tool ID for every possible operation value
203
-
-[ ] Each subBlock (or its `canonicalParamId`) is named exactly after the tool param it fills. A required `user-only` param that is only renamed in `tools.config.params` fails `bun run apps/sim/scripts/check-block-registry.ts`; remap only optional or `user-or-llm` params
203
+
-[ ] Each subBlock (or its `canonicalParamId`) is named exactly after the tool param it fills. A required `user-only` param that is only renamed in `tools.config.params` fails `bun run apps/sim/scripts/check-block-registry.ts origin/staging`; remap only optional or `user-or-llm` params
204
204
205
205
### SubBlocks
206
206
-[ ] Operation dropdown lists ALL tool operations available in `tools.access`
@@ -435,7 +435,7 @@ bun run integration-catalog:check # registry ↔ committed deployment metadat
435
435
bun run docs:check # committed docs ↔ what the generator renders today
436
436
bun run deployment-config:check # OAuth registry/catalog ↔ provider-ID fact drift
437
437
bun run check:audits # every audit CI enforces, including docs:check
438
-
bun run apps/sim/scripts/check-block-registry.ts # block ↔ tool param coverage (CI, not in check:audits)
438
+
bun run apps/sim/scripts/check-block-registry.ts origin/staging # block ↔ tool param coverage (CI, not in check:audits)
439
439
```
440
440
441
441
-**`tool-metadata:generate`** — required whenever a tool's `outputs`, `params`, or descriptions change. CI enforces this with `bun run tool-metadata:check`, which fails with *"Generated tool metadata is stale"*. This is the easiest gate to miss, because nothing in the tool file hints that a generated artifact mirrors it.
@@ -471,7 +471,7 @@ After fixing, confirm:
471
471
4. Derived artifacts regenerated and their diffs reviewed (see above)
472
472
5.`bun run integration-catalog:check` passes
473
473
6.`bun run docs:check` passes
474
-
7.`bun run apps/sim/scripts/check-block-registry.ts` passes
474
+
7.`bun run apps/sim/scripts/check-block-registry.ts origin/staging` passes
475
475
8. For OAuth or service-account changes, `bun run deployment-config:check` passes
476
476
9. For OAuth or service-account changes, `bun run --cwd apps/sim test lib/integrations/availability.server.test.ts` passes
477
477
10. Re-read all modified files to verify fixes are correct
Copy file name to clipboardExpand all lines: .claude/rules/sim-api-contracts.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -18,7 +18,7 @@ Boundary HTTP request and response shapes for all routes under `apps/sim/app/api
18
18
19
19
## Enforcement
20
20
21
-
`bun run check:api-validation:strict` is the gate (it runs in `check:audits`): it enforces boundary policy, prints ratchet metrics (route Zod imports, route-local schema constructors, route `ZodError` references, client hook Zod imports), and fails on annotations with empty reasons. `check:api-validation`is the same audit without the strict reason check.
21
+
`bun run check:api-validation:strict` is the gate (it runs in `check:audits`): it enforces boundary policy, prints ratchet metrics (route Zod imports, route-local schema constructors, route `ZodError` references, client hook Zod imports), and fails on annotations with empty reasons. `check:api-validation`(non-strict) only fails when the non-Zod route count grows; every boundary ratchet, including the reason check, is strict-only, so always run the `:strict` variant.
22
22
23
23
Whole-file allowlists for routes that legitimately import Zod for non-boundary reasons go through `INDIRECT_ZOD_ROUTES` in `scripts/check-api-validation-contracts.ts`, not per-line annotations.
0 commit comments