From 1e8f0571cfac4e1ad1ee0943cc2bfc95d5fb0b46 Mon Sep 17 00:00:00 2001 From: Defame1297 Date: Tue, 29 Sep 2026 08:00:32 +0000 Subject: [PATCH] fix(kyberforge): route primitive authoring from apm-workflow and agent-author - reach the MCP ${VAR} secrets rule from the compile flow - restore the Gotcha remedy for type: coverage - route .apm/instructions and .apm/prompts to primitive-author - agent-author: add the primitive-author boundary and the already-bumped skip, bump to 1.0.4 Co-Authored-By: Claude Opus 5.5 (1M context) Claude-Session: https://claude.ai/code/session_01KkT7RSDwDbmrM9T34b6sTi --- plugins/kyberforge/.apm/skills/agent-author/SKILL.md | 9 +++++---- plugins/kyberforge/.apm/skills/apm-workflow/SKILL.md | 4 ++-- .../.apm/skills/apm-workflow/references/compile.md | 2 ++ .../.apm/skills/apm-workflow/references/configure.md | 6 +++--- 4 files changed, 12 insertions(+), 9 deletions(-) diff --git a/plugins/kyberforge/.apm/skills/agent-author/SKILL.md b/plugins/kyberforge/.apm/skills/agent-author/SKILL.md index 826a38c..671acec 100644 --- a/plugins/kyberforge/.apm/skills/agent-author/SKILL.md +++ b/plugins/kyberforge/.apm/skills/agent-author/SKILL.md @@ -1,12 +1,13 @@ --- name: agent-author description: > - Use when the user wants to create a new agent definition file from scratch, or - apply grill findings, audit findings, or inline feedback to an existing one. + Use when the user wants a new agent definition created, or grill, audit + or inline feedback applied to an existing one. Not read-only review -> `factory-audit`. Not skills -> `skill-author`. + Not hooks, instructions or prompts -> `primitive-author`. allowed-tools: Bash Read Write Edit metadata: - version: "1.0.3" + version: "1.0.4" category: factory source_keys: - context7-websites-code-claude @@ -60,6 +61,6 @@ At every scope, five tools reach no subagent whatever `tools` says — `AskUserQ Invoke `factory-audit` on each file written and resolve every FAIL before reporting done. It checks the field allowlist, name-to-stem match, leftover placeholders and template comments, the description budget and the Copilot body limit — do not hand-check those. -At plugin/APM scope bump the resolved package's `apm.yml` `version` — **minor** on create, **patch** on improve — because consumers compare it to detect updates. Project and user scope have no manifest. +At plugin/APM scope bump the resolved package's `apm.yml` `version` — **minor** on create, **patch** on improve — because consumers compare it to detect updates. Skip, and say so, if this branch already bumped it: `git diff $(git merge-base HEAD ) -- /apm.yml` shows a changed `version:` line, and one bump covers a branch. Project and user scope have no manifest. **Commit verification.** Once the audit is clean, run `rtk git add` and `rtk git commit` — do not stop at staging. Re-run `rtk git log --oneline -1` and confirm the hash changed from Step 1's. A non-empty `git diff --stat` is not proof: staged-but-uncommitted work is part of no commit and is lost if the tree is cleaned up. Report done only once the hash has changed. diff --git a/plugins/kyberforge/.apm/skills/apm-workflow/SKILL.md b/plugins/kyberforge/.apm/skills/apm-workflow/SKILL.md index 8f11622..ce4c22c 100644 --- a/plugins/kyberforge/.apm/skills/apm-workflow/SKILL.md +++ b/plugins/kyberforge/.apm/skills/apm-workflow/SKILL.md @@ -15,13 +15,13 @@ metadata: ## Gotchas - `apm experimental enable registries` must run before a `registries:` block or `registry.*` config takes effect in any flow; without it they silently do nothing. -- `apm.yml`'s `type:` is never checked against what `.apm/` holds, so `apm install` and `apm compile` can exit 0 shipping none of the primitives you expected. Confirm the deployed output, not the exit code (`references/configure.md`). +- `apm.yml`'s `type:` is never checked against `.apm/`, so `apm install` and `apm compile` can exit 0 shipping none of the expected primitives. Set `type:` to cover every primitive shipped; confirm the deployed output, not the exit code (`references/configure.md`). ## Step 1 — Dispatch | Condition | Flow | Reference | |---|---|---| -| Author or edit `apm.yml`, or scaffold a new package (`apm plugin init`) | configure | `references/configure.md` | +| Author or edit `apm.yml`, or scaffold a new package (`apm plugin init`); skill, agent, hook, instruction or prompt content goes to the matching author skill | configure | `references/configure.md` | | Resolve or fetch the dependencies `apm.yml` declares (`apm install`, `apm install [PACKAGE_REF]`) | install | `references/install.md` | | Build a marketplace, register a package into it (local: hand-edit `apm.yml`; remote: `apm marketplace package add`), or register someone else's as a consumer (`apm marketplace init/check/package add/add`) | marketplace | `references/marketplace.md` | | Generate per-target output, bundle, or publish (`apm compile`, `apm pack`, `apm publish`) | compile | `references/compile.md` | diff --git a/plugins/kyberforge/.apm/skills/apm-workflow/references/compile.md b/plugins/kyberforge/.apm/skills/apm-workflow/references/compile.md index 0780f24..68b31bc 100644 --- a/plugins/kyberforge/.apm/skills/apm-workflow/references/compile.md +++ b/plugins/kyberforge/.apm/skills/apm-workflow/references/compile.md @@ -34,6 +34,8 @@ Bundles a producer package into a distributable artifact. Default to `--dry-run - A populated one gets its `mcpServers` content merged directly into the compiled `plugin.json`, but only for the `claude` target. - The `copilot` target's compiled `plugin.json` OMITS `mcpServers` entirely — it isn't part of Copilot's plugin manifest schema. +`mcpServers` headers and env must use `${VAR}` indirection — the content is merged verbatim into the published `plugin.json`, so a literal secret ships with the package. + `dependencies.mcp` in `apm.yml` is for a different purpose — declaring a remote MCP-server package as an APM dependency — not local `.mcp.json` passthrough. ### `includes: auto` and the packed bundle diff --git a/plugins/kyberforge/.apm/skills/apm-workflow/references/configure.md b/plugins/kyberforge/.apm/skills/apm-workflow/references/configure.md index bc96b19..7bbb0b0 100644 --- a/plugins/kyberforge/.apm/skills/apm-workflow/references/configure.md +++ b/plugins/kyberforge/.apm/skills/apm-workflow/references/configure.md @@ -10,7 +10,7 @@ source_keys: apm plugin init --yes --target claude,copilot ``` -Run from inside the target package directory, with no positional name argument (see Gotchas). Creates `apm.yml` + `plugin.json` in the current directory — it does NOT scaffold a `.apm/` skeleton. Primitive subdirectories (`.apm/skills/`, `.apm/agents/`, `.apm/hooks/`) must be created manually as content is migrated into them. Run this once per package (e.g. once per `plugins//` directory in a monorepo-hybrid layout), not once for the whole repo. +Run from inside the target package directory, with no positional name argument (see this file's Gotchas). Creates `apm.yml` + `plugin.json` in the current directory — it does NOT scaffold a `.apm/` skeleton. Create each primitive subdirectory (`.apm/skills/`, `.apm/agents/`, `.apm/hooks/`, `.apm/instructions/`, `.apm/prompts/`) through its author skill as content lands in it: skills via `skill-author`, agents via `agent-author`, hooks, instructions and prompts via `primitive-author`. Run this once per package (e.g. once per `plugins//` directory in a monorepo-hybrid layout), not once for the whole repo. ## `apm.yml` — required fields @@ -25,7 +25,7 @@ version: 1.0.0 - `name`, `version` — required (see above) - `description`, `author`, `license`, `homepage`, `repository`, `keywords` — standard package metadata -- `type` — `instructions | skill | hybrid | prompts`; selects how the package is processed at install/compile time. It is a routing selector, not a constraint on what `.apm/` may contain (see Gotchas) +- `type` — `instructions | skill | hybrid | prompts`; selects how the package is processed at install/compile time. It is a routing selector, not a constraint on what `.apm/` may contain (see this file's Gotchas) - `targets` — which harnesses this package compiles to (plural list form preferred; legacy singular `target: copilot,claude` CSV form still accepted) - `includes` — `auto` publishes the authoritative local layout as-is; it is not scoped down to what's relevant, so anything narrower needs an explicit repo-path list. Note: `auto` also does not sweep generic root-level passthrough files (README.md, docs/, sources.md, config files) into the `apm pack` distribution bundle — see `references/compile.md` - `dependencies`/`devDependencies` — `apm`/`mcp`/`lsp` entries; `devDependencies` share the same shape but are excluded from the shipped artifact @@ -80,7 +80,7 @@ MCP server secrets (headers, env vars) in `apm.yml` must use `${VAR}` indirectio Any git repo is a valid package source by default — no registry required. To declare named registries for shorthand dependency resolution: ```bash -apm experimental enable registries # required first — see Gotchas +apm experimental enable registries # required first — see this file's Gotchas apm config set registry.corp-main.url https://artifactory.corp.example.com/apm apm config set registry.corp-main.token "$CORP_APM_TOKEN" apm config set registry.corp-main.default true