fix(kyberforge): resolve PR #144 review and audit round 2

- factory-audit: ./ and bare/absolute script checks scoped to command
  position (no false FAILs on ./src or printf); hook sources limited to
  .apm/hooks or package-root hooks/; Kiro-aware lowercase events;
  unfilled template placeholders FAIL; repo-only instructions FAIL at
  any scope; Vale description FAIL documented; bats 367 -> 378
- primitive-author: split-quote/spaced paths and handler-less entries
  promoted to Must; Step 4.2 renders into a scratch consumer instead of
  a no-op dry run; dispatch and gate hand-off trimmed
- apm-workflow 1.0.2: mutual boundary with primitive-author
- forge: no double package bump; gotcha wording
- skill-author: create keeps seeded 0.1.0 (ADR-0022); portable,
  retry-safe new-skill.sh; template and flow consistency fixes
- hook docs: cite the ADR-0019 correction; guard caveat

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KkT7RSDwDbmrM9T34b6sTi
This commit is contained in:
2026-09-28 20:50:22 +00:00
parent df28351d3e
commit 965208bddd
29 changed files with 462 additions and 156 deletions

View File

@@ -1,11 +1,12 @@
---
name: apm-workflow
description: >
Use when authoring, installing, or publishing an apm package, its apm.yml and
the dependencies it declares, or an apm marketplace — even when the user does
not say "apm". Not the apm binary or an agent runtime -> `apm-install`.
Use when authoring, installing or publishing an apm package, its apm.yml and
dependencies, or a marketplace, even if "apm" goes unsaid.
Not the apm binary or an agent runtime -> apm-install.
Not a hook, instruction or prompt file -> primitive-author.
metadata:
version: "1.0.1"
version: "1.0.2"
category: apm
source_keys:
- context7-microsoft-apm
@@ -13,9 +14,8 @@ metadata:
## Gotchas
- MCP server secrets in `apm.yml` (headers, env vars) must use `${VAR}` indirection, never literal values, so they resolve at install or runtime and are never committed.
- `apm experimental enable registries` must run before a `registries:` block or `registry.*` config takes effect anywhere — configure, install or publish. Without it, declaring one silently does nothing: no error, no warning.
- `apm.yml`'s `type:` selects which primitives are processed and is never checked against what `.apm/` holds, so `apm install` and `apm compile` can exit 0 having shipped none of the ones you expected. Set it to cover every primitive the package ships, and confirm the deployed output, not the exit code. Mechanics: `references/configure.md`.
- `apm experimental enable registries` must run before a `registries:` block or `registry.*` config takes effect in any flow; without it they silently do nothing.
- `apm.yml`'s `type:` is never checked against what `.apm/` holds, so `apm install` and `apm compile` can exit 0 shipping none of the primitives you expected. Confirm the deployed output, not the exit code (`references/configure.md`).
## Step 1 — Dispatch

View File

@@ -73,7 +73,7 @@ version follows a separate rule — see `references/marketplace.md`.
## MCP server secrets
`${VAR}` indirection is required for MCP server secrets (headers, env vars) in `apm.yml`, never literal values — see SKILL.md Gotchas.
MCP server secrets (headers, env vars) in `apm.yml` must use `${VAR}` indirection, never literal values, so they resolve at install or runtime and are never committed.
## Registries (config-level, not `apm.yml`)