Files
PaperClipAI/packages
nguyenm7andPaperclip eb32c6cc91 fix(skills-catalog): the corpus is not a gate, and three smaller findings
Builds on c46092f202, which landed the discovery-URL guard and the citation
and visibility work in parallel. These are the Enterpret acceptance findings
that commit did not cover, plus one claim of its own that turned out wrong.

- **The ingestion corpus is not a gate on authoring, and the skill said it
  was.** Both files told an external contributor that without the non-public
  `paperclip-content` corpus "this whole path is closed to you". Executed at
  `066a4e8019`: `node scripts/ingest-app-definitions.mjs --definitions-only`,
  with no corpus present and `PAPERCLIP_CONTENT_TEMPLATES` unset, reproduced
  all 72 checked-in `app-definitions/<slug>.json` files and
  `app-definitions.generated.ts` byte-for-byte — `git status` clean. Adding a
  throwaway provider tuple and re-running emitted 73 and changed exactly the
  new `<slug>.json` and the positional registry. The flag costs only
  `app-definitions.ingestion-report.json`, which is built from captures and so
  is correctly unchanged by a provider that has none. This is the single
  largest barrier the acceptance test found for a contributor outside
  Paperclip, and it was not real. Also records that a missing default corpus
  path raises a raw `ENOENT` from `fs.readdirSync` before the documented
  `Expected 99 captures` guard can run.

- **Executing the unlisted path.** c46092f202 documents the three visibility
  states, which is the better framing, but not the mechanics of taking the
  second one — the finding was that the reference does not enumerate them.
  Now it does: both slug sets, the sorted literal in the test, and
  `catalogVisible: false` on the manifest row, plus the instruction *not* to
  bump the store count, which is the opposite of what the store-visible path
  says. Checked against `18dac1e1`: all 20 hidden slugs already have a
  manifest row, all carry `catalogVisible: false`, and the 56 rows marked
  visible are exactly `APP_STORE_DEFINITIONS`.

- **Asserting absence, with a canary that works.** The obvious credential
  canary fires on all 72 shipped definitions, because `keyPlacement`
  legitimately carries `"prefix": "Bearer "`. A value-shaped pattern fires on
  0 of 72 and still matches `sk-…`, `ghp_…` and `xoxb-…`. Both measured; the
  worked example is in the skill.

- **`method()`'s `ownershipModes` default is a silent capability claim.**
  Using the helper asserts both `customer` and `dcr`. Say which one you
  observed advertised, or pass the set explicitly.

- The offline harness now says when it is not worth building: it protects a
  checkout other people depend on, and an author in their own disposable
  worktree does not have one.

Regenerated the catalog manifest: 19 skills, validate clean, 19/20 package
tests pass. The one failure is `packaged-artifacts.test.ts`, which shells out
to `pnpm --filter … build`; it fails identically at unmodified HEAD in this
worktree because the worktree has no pnpm install of its own. Seventeen
packaged relative links, none broken, no private references. Both packages
stay markdown_only.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-24 21:14:17 +00:00
..