- factory-audit: hook events judged per deployed target after apm's rename (Claude/Copilot event sets FAIL, others SUGGESTION); Claude plugin layouts accepted as hook sources; interpreter options and sh -c strings checked; bats 378 -> 386 - primitive-author: Must 4/5 match the audit; reference hand-back points at the right steps; Step 4.2 --target all fallback - skill-author: new-skill.sh repair only on the template marker line, so complete skills stay a no-op; provenance and calibration text - forge: restore "already named" qualifier; drop false HITL claim - apm-workflow: token example uses an env var - docs/hooks.md: the apm-hooks.json sidecar is committed, not ignored Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01KkT7RSDwDbmrM9T34b6sTi
2.2 KiB
source_keys
| source_keys | |
|---|---|
|
Routing a plugin or marketplace entry to apm-workflow
Reached from SKILL.md Step 2 when the classified artifact is a plugin or a marketplace entry.
Both route to apm-workflow — a plugin to its configure flow (apm plugin init), a marketplace
entry to its marketplace flow (apm marketplace package add).
No other skill is a candidate for these two rows: plugin-author and marketplace-author were
removed per ADR-0015 once issue #90 landed, and apm-workflow is their sole successor.
Always inline, never forked
Run these routes inline, in the current conversation. Their flows are short, prompt-heavy or
gated — apm publish is not trivially reversible and removing a marketplace entry takes a
conversational confirmation — and a backgrounded fork cannot surface those checkpoints to the
user in real time.
No clean-context recheck, and no automatic audit
Skill, agent and primitive routes close with a clean-context audit rerun; these two do not, and the omission is deliberate rather than an oversight. Neither artifact type has an audit skill counterpart to re-run, so detaching the route to earn a recheck it would never get buys nothing.
These routes get no automated terminal check either. apm audit is a separate action on
apm-workflow's own dispatch table, not a closing step of the configure or marketplace flow a
forge route lands in, so a completion message from either says nothing about it. Do not wait for
one and do not report one you did not see.
Verify by hand instead. Read back what the route wrote against what the grill settled:
- Plugin — the package directory exists where the intent said it should, and its
apm.ymlcarries the intendedname, a top-leveltype:field, and aversion. - Marketplace entry — the entry names that package, points at the source the intent settled on, and carries the version the package actually declares.
If the change warrants the full integrity and policy check rather than a read-back, invoke
apm-workflow again for its audit action and run apm audit deliberately. Then return to
SKILL.md Step 3 for the closing gates common to every route.