You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
docs(agents): correct review findings in skills and rules
Scope SSRF, client-boundary, forcedToolUse, canonicalParamId, integration metadata, and HEAD claims to what the code does; fix the ship migration pathspec, the babysit conflict path, enrichment folder placeholders, framer-motion samples, and stale connector and column-type references.
Copy file name to clipboardExpand all lines: .agents/skills/add-column-type/SKILL.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -132,7 +132,7 @@ Registering the *type* is compiler-enforced. Registering its *metadata* is not,
132
132
|`column-types/types.ts``TYPE_SPECIFIC_COLUMN_KEYS`| it is never stripped on conversion, and poisons the target type |
133
133
|`lib/api/contracts/tables.ts` — the schema slot in all three column schemas, plus `refineColumnOptions`| zod strips it at the boundary; silently never saved |
134
134
|`columns/service.ts``addTableColumn` param type | callers cannot pass it |
135
-
| A metadata-only update in `lib/table/columns/service.ts` (`updateColumnCurrency` is the model) + a branch in `updateColumn` in `lib/table/orchestration/columns.ts`| changing it on an existing column is a silent 200 no-op |
135
+
| A metadata-only update in `lib/table/columns/service.ts` (`updateColumnCurrency` is the model) + a branch in `performUpdateTableColumn` in `lib/table/orchestration/columns.ts`| changing it on an existing column is a silent 200 no-op |
136
136
|`column-config-sidebar.tsx`| no UI to set it |
137
137
|`table-grid.tsx` delete-column undo + `use-table-undo.ts` restore | undo silently resets it to the default |
All external API calls must use `fetchWithRetry` from `@/lib/knowledge/documents/secure-fetch.server`(SSRF-guarded) instead of raw `fetch()`; use `secureFetchWithRetry` for user-controlled hosts. This provides exponential backoff with retries on 429/502/503/504 errors. It returns a standard `Response` — all `.ok`, `.json()`, `.text()` checks work unchanged.
518
+
All external API calls must use `fetchWithRetry` from `@/lib/knowledge/documents/secure-fetch.server` instead of raw `fetch()`. It does not validate the host (on a direct outbound route it calls plain `fetch`), so use `secureFetchWithRetry` for user-controlled hosts. This provides exponential backoff with retries on 429/502/503/504 errors. It returns a standard `Response` — all `.ok`, `.json()`, `.text()` checks work unchanged.
519
519
520
520
For `validateConfig` (user-facing, called on save), pass `VALIDATE_RETRY_OPTIONS` to cap wait time at ~7s. Background operations (`listDocuments`, `getDocument`) use the built-in defaults (5 retries within a 150s budget).
-**OAuth + inline content**: `apps/sim/connectors/slack/slack.ts` — list API returns message content inline; `contentHash` hashes that content
608
+
-**OAuth + inline content**: `apps/sim/connectors/airtable/airtable.ts` — list API returns record fields inline; `listDocuments` and `getDocument` share `recordToDocument`, which hashes that content
Copy file name to clipboardExpand all lines: .agents/skills/add-model/SKILL.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -49,7 +49,7 @@ Use a precise WebFetch prompt: *"Extract for {model_id}: exact model id string,
49
49
|---|---|---|
50
50
|`temperature`| All providers (passed through if set) | Safe but inert on always-reasoning models that reject it |
51
51
|`toolUsageControl`| All providers (provider-level default) | Override per model only when that model differs |
52
-
|`forcedToolUse`|Defaults to `toolUsageControl`|Set only when the model cannot force tools |
52
+
|`forcedToolUse`|`anthropic/core.ts` (anthropic, azure-anthropic, kie); defaults to `toolUsageControl`|Ignored by every other provider; set `false`only on a model behind that core that cannot force tools |
53
53
|`promptCaching`| Caller-placed cache breakpoints | Set only where the vendor charges for opt-in caching (absent for OpenAI/Gemini implicit caching) |
54
54
|`reasoningEffort`|`openai/core.ts`, `azure-openai`, `xai`, `deepseek`, `groq`, `zai`, `kimi`, `cerebras`, `meta`, `litellm` (each `index.ts`) | Not read by anthropic/gemini (they use `thinking`) or by mistral, openrouter, fireworks, vertex — re-grep before assuming |
55
55
|`verbosity`|`openai/core.ts`, `azure-openai/index.ts` only | Dead elsewhere |
Copy file name to clipboardExpand all lines: .agents/skills/add-permission-group-item/SKILL.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -60,7 +60,7 @@ Allowlist when the safe posture is "only what the admin named" and the member se
60
60
61
61
The second argument is the field's `feature` (`PlatformFeatureMeta`); `PLATFORM_FEATURES` spreads it and appends `configKey`, so those four values are what the editor renders. `PLATFORM_FEATURES` is *derived* from the registry in `features.ts`, so a boolean key cannot reach the config without reaching the editor.
62
62
63
-
-**Declaration order is the wire order** of `PermissionGroupConfig`, both zod schemas, and every config JSON crossing the API. No test catches a reorder (schemas and defaults all derive from the registry), and `ee/access-control/components/group-detail.tsx` dirty-checks by comparing stringified configs, so a moved key makes every open editor read as unsaved. Extend the tail; do not tidy the middle.
63
+
-**Declaration order is the wire order** of `PermissionGroupConfig`, both zod schemas, and every config JSON crossing the API, since all of them derive from the registry. Extend the tail; do not tidy the middle.
64
64
-**The default must be the permissive value.** Every stored `permission_group.config` row predates your key; `parsePermissionGroupConfig` fills the gap from the default and the update route merges a partial write over the stored config, so a restrictive default silently applies a new restriction to every existing group in every enterprise org. The builders hardcode `false` / `null` / `[]`, so a new key must be *phrased* so the permissive value is falsy: a `requireWidgetApproval` whose safe default is `true` must be inverted before it can use `booleanRestriction`.
65
65
-**The checkbox is inverted.**`group-detail.tsx` renders `checked={!editingConfig[feature.configKey]}` — ticked means *allowed*, so an `allowX` name renders backwards.
66
66
-**The hint must describe access withheld, never a surface hidden.** A `'capability'` key refuses at the API; "Hide the Tables module from the sidebar" tells an admin they are tidying a nav bar while they revoke a module. The same string is read again by `getActivePermissionGroupRestrictions` in `features.ts` as the prose for an *active* restriction — reaching users through the Copilot workspace VFS and the enterprise platform context — where "hide" is simply false. Write "Revoke the Tables module. Members cannot read or write any table." `PlatformFeatureMeta.hint` carries the rule in its TSDoc.
@@ -213,7 +213,7 @@ cd apps/sim && bun run type-check
213
213
bun run --cwd apps/sim test lib/permission-groups
214
214
```
215
215
216
-
Also `bun run check:api-validation:strict` if you touched a contract or the group routes. `bun run check:audits` runs every one of these (including the `:strict` variant); it derives its list from the `check:*` scripts in `package.json`, so a new audit is opted *out* deliberately rather than opted in.
216
+
Also `bun run check:api-validation:strict` if you touched a contract or the group routes. `bun run check:audits` runs every `check:*` command here (including the `:strict` variant) but not type-check or the tests; it derives its list from the `check:*` scripts in `package.json`, so a new audit is opted *out* deliberately rather than opted in.
217
217
218
218
Read the success lines, not the exit codes — compare the counts against the previous run and check they grew by exactly what you added: an operation-declared capability adds one operation and one capability; a raw-route or parameterized capability adds one capability and no operation; an executor-gated or UI-only item adds neither:
description: Anti-slop frontend skill for landing pages, portfolios, and redesigns. The agent reads the brief, infers the right design direction, and ships interfaces that do not look templated. Real design systems when applicable, audit-first on redesigns, strict pre-flight check.
5
5
---
6
6
7
-
> **In this repo:** Tailwind 4 (CSS-first config in `apps/sim/app/_styles/globals.css`); animation via `import { motion } from 'framer-motion'` (not `motion/react` — rewrite every `motion/react` import in the samples below); icons from `@sim/emcn/icons`; colors through the CSS-variable tokens in `.claude/rules/sim-styling.md` (no hardcoded `text-gray-*`/hex/`zinc` utilities, no paired `dark:` utilities). This note overrides any conflicting guidance or code sample anywhere in this file. Fonts are fixed (Season body, Inter); never introduce new families, and never use Martian Mono on landing (`apps/sim/app/(landing)/CLAUDE.md`). Font weight is only `font-normal`/`font-medium`/`font-semibold`. Elevation uses the `shadow-subtle|medium|overlay|card` tokens. Type size uses named tokens, never `text-[Npx]`. Product forms use`ChipModalField`. Use `bunx`, never `npx`. Do not add GSAP, Lenis, Three, or shadcn. Landing copy and SEO follow `.claude/rules/constitution.md` and `.claude/rules/landing-seo-geo.md`.
7
+
> **In this repo:** Tailwind 4 (CSS-first config in `apps/sim/app/_styles/globals.css`); animation via `import { motion } from 'framer-motion'` (not `motion/react`); icons from `@sim/emcn/icons`; colors through the CSS-variable tokens in `.claude/rules/sim-styling.md` (no hardcoded `text-gray-*`/hex/`zinc` utilities, no paired `dark:` utilities). This note overrides any conflicting guidance or code sample anywhere in this file. Fonts are fixed (Season body, Inter); never introduce new families, and never use Martian Mono on landing (`apps/sim/app/(landing)/CLAUDE.md`). Font weight is only `font-normal`/`font-medium`/`font-semibold`. Elevation uses the `shadow-subtle|medium|overlay|card` tokens. Type size uses named tokens, never `text-[Npx]`. Every labeled field inside a `ChipModalBody` is a`ChipModalField`. Use `bunx`, never `npx`. Do not add GSAP, Lenis, Three, or shadcn. Landing copy and SEO follow `.claude/rules/constitution.md` and `.claude/rules/landing-seo-geo.md`.
8
8
9
9
# tasteskill: Anti-Slop Frontend Skill
10
10
@@ -345,7 +345,7 @@ These are tools, not defaults. Use them when the design read calls for them. **N
|**Spring physics**| Yes | No — use `cubic-bezier(0.2, 0, 0, 1)` as approximation |
264
-
|**When to use**| Project already uses `motion/react`| No motion dependency, or keeping bundle small |
264
+
|**When to use**| Project already uses `framer-motion` (or `motion/react`)| No motion dependency, or keeping bundle small |
265
265
266
266
**Rule:** Check the project's `package.json` for `motion` or `framer-motion`. If present, use the Motion approach. If not, use the CSS cross-fade pattern — don't add a dependency just for icon transitions.
Copy file name to clipboardExpand all lines: .agents/skills/memory-load-check/SKILL.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -74,7 +74,7 @@ For those, require all three:
74
74
75
75
Skip the pattern when the source already bounds the payload:
76
76
- pure API/structured-data connectors (Jira, Linear, Sentry, Slack, Zendesk, Gmail, ...) — paginated JSON/text; apply normal pagination + concurrency bounds instead of a per-file byte cap
77
-
- native-document connectors capped by the platform (Evernote ~25 MB/note, ...) — a 100 MB cap can never fire there
77
+
- native-document connectors whose platform caps each document — a 100 MB cap can never fire there
78
78
79
79
Some connectors also budget the response body (google-docs `MAX_DOCS_RESPONSE_BYTES`, google-sheets `MAX_CONTENT_BYTES`, a remaining-bytes budget in notion); Confluence attachments use the full file pattern. Follow the connector's existing approach rather than adding a cap to every `response.json()`.
0 commit comments