mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-07 07:23:08 +02:00
Builds onc46092f202, which landed the discovery-URL guard and the citation and visibility work in parallel. These are the Enterpret acceptance findings that commit did not cover, plus one claim of its own that turned out wrong. - **The ingestion corpus is not a gate on authoring, and the skill said it was.** Both files told an external contributor that without the non-public `paperclip-content` corpus "this whole path is closed to you". Executed at `066a4e8019`: `node scripts/ingest-app-definitions.mjs --definitions-only`, with no corpus present and `PAPERCLIP_CONTENT_TEMPLATES` unset, reproduced all 72 checked-in `app-definitions/<slug>.json` files and `app-definitions.generated.ts` byte-for-byte — `git status` clean. Adding a throwaway provider tuple and re-running emitted 73 and changed exactly the new `<slug>.json` and the positional registry. The flag costs only `app-definitions.ingestion-report.json`, which is built from captures and so is correctly unchanged by a provider that has none. This is the single largest barrier the acceptance test found for a contributor outside Paperclip, and it was not real. Also records that a missing default corpus path raises a raw `ENOENT` from `fs.readdirSync` before the documented `Expected 99 captures` guard can run. - **Executing the unlisted path.**c46092f202documents the three visibility states, which is the better framing, but not the mechanics of taking the second one — the finding was that the reference does not enumerate them. Now it does: both slug sets, the sorted literal in the test, and `catalogVisible: false` on the manifest row, plus the instruction *not* to bump the store count, which is the opposite of what the store-visible path says. Checked against `18dac1e1`: all 20 hidden slugs already have a manifest row, all carry `catalogVisible: false`, and the 56 rows marked visible are exactly `APP_STORE_DEFINITIONS`. - **Asserting absence, with a canary that works.** The obvious credential canary fires on all 72 shipped definitions, because `keyPlacement` legitimately carries `"prefix": "Bearer "`. A value-shaped pattern fires on 0 of 72 and still matches `sk-…`, `ghp_…` and `xoxb-…`. Both measured; the worked example is in the skill. - **`method()`'s `ownershipModes` default is a silent capability claim.** Using the helper asserts both `customer` and `dcr`. Say which one you observed advertised, or pass the set explicitly. - The offline harness now says when it is not worth building: it protects a checkout other people depend on, and an author in their own disposable worktree does not have one. Regenerated the catalog manifest: 19 skills, validate clean, 19/20 package tests pass. The one failure is `packaged-artifacts.test.ts`, which shells out to `pnpm --filter … build`; it fails identically at unmodified HEAD in this worktree because the worktree has no pnpm install of its own. Seventeen packaged relative links, none broken, no private references. Both packages stay markdown_only. Co-Authored-By: Paperclip <noreply@paperclip.ing>