Files
holocron/plugins/kyberforge/.apm/skills/forge/references/apm-routes.md
Defame1297 9ac5340e15 fix(kyberforge): resolve clean-context audit findings on primitive support
primitive-author:
- description excludes read-only review (-> factory-audit)
- validation Gotcha now matches the research: compile never reads
  prompts, install fails only on a bad Copilot hook payload and warns on
  prompt input names and dropped keys
- instruction fold-in into AGENTS.md/CLAUDE.md stated as conditional on
  dedup and --force-instructions
- hook checklist gains the wrapped-shape Must, drops hardlinks, notes
  why executable is stricter than the research, and states the
  separate Copilot-targeted package route instead of a blanket "don't"
- prompt Must 5 keeps the research's Copilot-only-key exception; adds
  model-slug and 250-char Shoulds; descriptions name skills or agents
- placeholder instruction covers both FILL IN and FILL_IN_ tokens

factory-audit: hardlink FAIL scoped to instructions and prompts
(find_hook_files skips symlinks only), with bats cases; prompt-flow
description rubric names skills or agents.

forge: version-bump, apm-routes and sources references updated for the
primitive route.

Refs #94

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KkT7RSDwDbmrM9T34b6sTi
2026-09-28 17:40:12 +00:00

2.2 KiB

source_keys
source_keys
claude-code-subagents-docs

Routing a plugin or marketplace entry to apm-workflow

Reached from SKILL.md Step 2 when the classified artifact is a plugin or a marketplace entry. Both route to apm-workflow — a plugin to its configure flow (apm plugin init), a marketplace entry to its marketplace flow (apm marketplace package add).

No other skill is a candidate for these two rows: plugin-author and marketplace-author were removed per ADR-0015 once issue #90 landed, and apm-workflow is their sole successor.

Always inline, never forked

Run these routes inline, in the current conversation. Their flows are short, prompt-heavy or gated — apm-workflow's publish and release steps take a HITL gate, and removing a marketplace entry takes a conversational confirmation — and a backgrounded fork cannot surface those checkpoints to the user in real time.

No clean-context recheck, and no automatic audit

Skill, agent and primitive routes close with a clean-context audit rerun; these two do not, and the omission is deliberate rather than an oversight. Neither artifact type has an audit skill counterpart to re-run, so detaching the route to earn a recheck it would never get buys nothing.

These routes get no automated terminal check either. apm audit is a separate action on apm-workflow's own dispatch table, not a closing step of the configure or marketplace flow a forge route lands in, so a completion message from either says nothing about it. Do not wait for one and do not report one you did not see.

Verify by hand instead. Read back what the route wrote against what the grill settled:

  • Plugin — the package directory exists where the intent said it should, and its apm.yml carries the intended name, a top-level type: field, and a version.
  • Marketplace entry — the entry names that package, points at the source the intent settled on, and carries the version the package actually declares.

If the change warrants the full integrity and policy check rather than a read-back, invoke apm-workflow again for its audit action and run apm audit deliberately. Then return to SKILL.md Step 3 for the closing gates common to every route.