Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
79 commits
Select commit Hold shift + click to select a range
5f4dc19
fix(sidebar): pluralize the Knowledge bases nav label (#6514)
j15z Aug 11, 2026
4bafd14
improvement(provenance): name every guard that can latch a registry (…
icecrasher321 Aug 11, 2026
4d37572
fix(knowledge): pluralize the module header and root breadcrumb (#6516)
j15z Aug 11, 2026
c5db403
feat(comparisons): add code-sandbox and session-policy rows (#6517)
waleedlatif1 Aug 11, 2026
fff6606
fix(folders): show the folder trail in table and knowledge base heade…
waleedlatif1 Aug 11, 2026
f5c06d4
fix(tables): handle row deletion during cell execution (#6520)
TheodoreSpeaks Aug 11, 2026
245ad1b
feat(workflows): new workflow block card, progress indicator, colors,…
icecrasher321 Aug 11, 2026
ba5dfb1
feat(salesforce): add JWT bearer flow and sandbox OAuth support (#6508)
waleedlatif1 Aug 11, 2026
507def6
fix(workflows): port the canvas card icons off lucide-react (#6523)
icecrasher321 Aug 11, 2026
daac4f3
docs(salesforce): correct the setup steps that would strand an admin …
waleedlatif1 Aug 11, 2026
5478a69
improvement(setup): complete knowledge and update flows (#6521)
TheodoreSpeaks Aug 11, 2026
ff64389
fix(logs): keep run provenance when compaction drops the execution st…
waleedlatif1 Aug 11, 2026
1a39e29
fix(chat): stop the streaming transcript floor inventing scroll space…
waleedlatif1 Aug 11, 2026
a64ce49
feat(incidentio): add on-call, alert, catalog, and team tools (#6529)
waleedlatif1 Aug 11, 2026
1551923
fix(chat): stop losing sends aborted during mount-settling (#6525)
j15z Aug 11, 2026
2f43148
improvement(ui): align terminal with the workflow design system, fix …
waleedlatif1 Aug 11, 2026
9277e7d
feat(search): page-aware cmd+k palette with ask-Sim mode (#6518)
j15z Aug 11, 2026
263e3ca
improvement(external-endpoints): v2 versions with clean signatures + …
icecrasher321 Aug 11, 2026
7c75061
fix(ci): include auth package in app prune (#6538)
TheodoreSpeaks Aug 11, 2026
783e1b5
fix(executor): restore delegated workflow execution (#6539)
TheodoreSpeaks Aug 11, 2026
f8644cc
fix(chat): deduplicate chat sends server-side instead of probing for …
waleedlatif1 Aug 11, 2026
ff378fa
fix(knowledge): retain model input provenance (#6540)
TheodoreSpeaks Aug 11, 2026
71ea7e5
fix(cmdk): New Chat -> New chat (#6543)
j15z Aug 11, 2026
6fdb145
fix(v2-api): standardization (#6542)
waleedlatif1 Aug 11, 2026
fee45e2
fix(atlassian): share one cached, retrying cloudId resolver across Ji…
waleedlatif1 Aug 11, 2026
2f1bb5a
fix(cmdk): update search-modal assertions to the renamed New chat lab…
waleedlatif1 Aug 11, 2026
c365b14
feat(calendly): extend tools with booking, availability, no-shows, an…
waleedlatif1 Aug 11, 2026
bf82512
fix(auth): let Microsoft sign-in link via Entra's domain-verified ema…
waleedlatif1 Aug 11, 2026
df052ac
fix(tools): bound internal tool calls by the plan deadline, not Bun's…
icecrasher321 Aug 11, 2026
440a68b
improvement(audits): skip the sql-date-binding parse for files withou…
waleedlatif1 Aug 11, 2026
061ecd3
fix(api): restore legacy endpoint compatibility (#6552)
TheodoreSpeaks Aug 11, 2026
31bfcdd
fix(auth): rate limit the password reset endpoints (#6553)
waleedlatif1 Aug 11, 2026
596bf4f
feat(library): What Is Retrieval-Augmented Generation (RAG)? (#6555)
icecrasher321 Aug 11, 2026
b879960
fix(provenance): make one length floor the whole substitution rule (#…
icecrasher321 Aug 11, 2026
bd91ab7
fix(files): restore horizontal scroll in CSV and XLSX preview tables …
waleedlatif1 Aug 11, 2026
81e04a8
fix(agiloft): align the integration with the documented ewws REST int…
waleedlatif1 Aug 11, 2026
ae1f62d
improvement(provenance): make the incompleteness reason set closed an…
icecrasher321 Aug 11, 2026
d6505f6
feat(blog): Tracking Secrets Through an Agent Run (#6558)
icecrasher321 Aug 11, 2026
6d3e484
fix(api): align v2 permissions and resource behavior (#6557)
TheodoreSpeaks Aug 11, 2026
1dd85eb
improvement(desktop): add apple signing, fix some bugs (#6519)
Sg312 Aug 11, 2026
e31d2a9
fix(files): let a mouse wheel scroll CSV and XLSX previews horizontal…
waleedlatif1 Aug 11, 2026
ec8b988
fix(forks): detect secrets referenced from advanced-mode fields (#6566)
icecrasher321 Aug 11, 2026
be5db68
fix(agiloft): repoint the block at the alrest surface and fix EWLogin…
waleedlatif1 Aug 11, 2026
3595fa2
fix(credentials): authorize shared credentials without requiring a wo…
waleedlatif1 Aug 11, 2026
9b9f4ee
fix(v2-api): close three secret disclosures, make the surface consist…
waleedlatif1 Aug 11, 2026
05de463
fix(agiloft): resolve attachment MIME type instead of trusting the he…
waleedlatif1 Aug 12, 2026
cb28090
fix(mship, desktop): fix bugs (#6572)
Sg312 Aug 12, 2026
092311e
fix(api): restore migrated endpoint and SDK compatibility (#6564)
TheodoreSpeaks Aug 12, 2026
e7590c8
improvement(desktop): help menu
Sg312 Aug 12, 2026
7f39678
improvement(desktop, executions): fix desktop update script and throw…
Sg312 Aug 12, 2026
2a5e29a
improvement(updates): validate update path and fix native mac help (#…
Sg312 Aug 12, 2026
9f3c202
fix(tables): cap row pages and use native cursors (#6582)
TheodoreSpeaks Aug 12, 2026
1874cec
fix(api): collapse the internal error envelope and restore requestId …
waleedlatif1 Aug 12, 2026
261435c
fix(authz): enforce credential and workspace boundaries (#6585)
icecrasher321 Aug 12, 2026
7c05e36
fix(api): close five defects found auditing the v2 migration against …
waleedlatif1 Aug 12, 2026
a72457b
fix(docs): preserve items response fields (#6587)
j15z Aug 12, 2026
5e1862e
fix(tables): preserve group auto-run semantics (#6579)
TheodoreSpeaks Aug 12, 2026
083319b
fix(api): conceal cross-tenant resource denials on internal routes (#…
waleedlatif1 Aug 12, 2026
766526b
fix(logs): restore narrow v1 detail query (#6588)
TheodoreSpeaks Aug 12, 2026
f306b51
fix(files): preserve slashes in folder paths (#6589)
TheodoreSpeaks Aug 12, 2026
23318a1
fix(security): redact workflow snapshot secrets (#6581)
TheodoreSpeaks Aug 12, 2026
380aca2
fix(desktop): fix background tab spawning (#6590)
Sg312 Aug 12, 2026
91f31a4
fix(api): wait for knowledge dispatch and encode filenames (#6583)
TheodoreSpeaks Aug 12, 2026
a1a05c6
fix(api): widen the cancel-execution reason contract to what the rout…
waleedlatif1 Aug 12, 2026
a61cbf7
fix(tools): bind schema-enrichment reads to executor delegations (#6593)
waleedlatif1 Aug 12, 2026
eb26b42
fix(logs, workflows): snapshot fetch optionality, restore consistent …
icecrasher321 Aug 12, 2026
9923faf
fix(tables): prevent legacy group auto-run dispatch (#6595)
TheodoreSpeaks Aug 12, 2026
50e5dff
fix(workflows): redact run and export secrets (#6591)
TheodoreSpeaks Aug 12, 2026
326cb94
fix(knowledge): return pending status for new documents (#6597)
TheodoreSpeaks Aug 12, 2026
933eea5
fix(mcp): audit the columns an MCP server update wrote, not the param…
waleedlatif1 Aug 12, 2026
22b3569
fix(files): order file folders in SQL like every other folder list (#…
waleedlatif1 Aug 12, 2026
0877ecb
fix(tables): tolerate row deletion during run cancellation (#6600)
TheodoreSpeaks Aug 12, 2026
a6ebfec
fix(files): restore CSV preview cancellation (#6596)
icecrasher321 Aug 12, 2026
0d640aa
fix(uploads): make execution attachment completion replay-safe (#6601)
waleedlatif1 Aug 12, 2026
e65345b
test(table): pin the executor auth pairing on the table read route (#…
waleedlatif1 Aug 12, 2026
a40e379
chore: remove the stray .agiloft-spec working notes (#6605)
waleedlatif1 Aug 12, 2026
068422b
refactor(audit): derive updatedFields through one shared helper (#6604)
waleedlatif1 Aug 12, 2026
b5d9e93
fix(mcp): audit an upsert that rewrites or revives a server (#6602)
waleedlatif1 Aug 12, 2026
892401a
fix(uploads): sign Azure upload URLs create-only (#6607)
waleedlatif1 Aug 12, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
37 changes: 36 additions & 1 deletion .agents/skills/add-block/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -52,6 +52,12 @@ export const {ServiceName}Block: BlockConfig = {
// Auth mode
authMode: AuthMode.OAuth, // or AuthMode.ApiKey

// Card summary sentences — see "Canvas Sentences" below
canvasPresentation: {
defaultTitle: '{Default Operation}',
sentences: { byOperation: { /* one per operation dropdown option id */ } },
},

subBlocks: [
// Define all UI fields here
],
Expand Down Expand Up @@ -945,6 +951,35 @@ Derive templates from the service's real use cases. Each prompt should name a co
- **Ground every skill in operations the block actually exposes** — cross-check each skill's steps against `tools.access`. Never describe an action the integration cannot perform.
- **Derive skills from real, popular use cases found online — never invent them.** Web-search the service's documented use cases (vendor use-case/solutions pages, official docs describing the workflow, reputable "top automations for X" articles) and only add a skill you can source as something people genuinely do with the service. Do not hallucinate skills.

## Canvas Sentences

Every block declares a one-line prose summary that replaces its card's field rows:

```
Slack ← header (already names the block)
Posts ⟨Ship it 🚀⟩ to ⟨#eng⟩ ← the sentence; ⟨…⟩ are live value chips
```

Write one `byOperation` entry per operation dropdown option (or a single `default`
when the block has no operation dropdown).

**The full authoring contract — voice, structure, and the two mistakes that break
cards silently — is `apps/sim/blocks/AGENTS.md` → "Canvas sentences". Read it
before writing any.** The two failures worth repeating here, because both are
invisible at runtime:

1. A clause naming only one member of a `canonicalParamId` pair drops the sentence
for every advanced-mode user. List all members:
`field: ['channelSelector', 'manualChannel']`.
2. A clause referencing a subblock whose `condition` excludes that operation can
never render.

Validate before finishing:

```bash
bun run apps/sim/scripts/check-canvas-sentences.ts --block={service}
```

## Generated artifacts

Adding a block on its own needs no **tool metadata** regeneration — a block references existing
Expand All @@ -963,7 +998,6 @@ bun run integration-catalog:check
The catalog check independently derives deployment metadata from the executable block registry and
compares it with the committed `apps/sim/lib/integrations/integrations.json`. Review the generated
diff and keep only intentional changes.

## Checklist Before Finishing

- [ ] `integrationType` is set to the correct `IntegrationType` enum value
Expand Down Expand Up @@ -991,6 +1025,7 @@ diff and keep only intentional changes.
- [ ] Exported `{Service}BlockMeta` with at least 7 templates
- [ ] `url` set on `{Service}BlockMeta` to the external service's verified homepage (omit only for first-party blocks with no external service)
- [ ] `skills` added to `{Service}BlockMeta`, each grounded in `tools.access` and sourced from a real online use case (not invented)
- [ ] `canvasPresentation.sentences` covers every operation, and `bun run apps/sim/scripts/check-canvas-sentences.ts --block={service}` passes with 100% coverage

## Final Validation (Required)

Expand Down
6 changes: 4 additions & 2 deletions .agents/skills/add-integration/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -768,9 +768,11 @@ tools: {
}
```

#### 3. Create Internal API Route
#### 3. Create Special Internal Tool Execution Route

Create `apps/sim/app/api/tools/{service}/{action}/route.ts`. Internal tool routes are HTTP boundaries and follow the same contract policy as public routes — define the request/response shape in `apps/sim/lib/api/contracts/tools/{service}.ts` (or an existing aggregate) and validate with canonical helpers from `@/lib/api/server`. Never write a route-local Zod schema.
Create `apps/sim/app/api/tools/{service}/{action}/route.ts`. This raw route pattern is only for an integration's provider-execution boundary when it needs special file normalization, large-body handling, or protocol behavior. It is not the pattern for CRUD or other operations on protected Sim resources. For those, use the `migrate-application-operation` skill and an authorized application use case with the ordinary internal/v2 route builders.

Internal tool routes are HTTP boundaries and follow the same contract policy as public routes — define the request/response shape in `apps/sim/lib/api/contracts/tools/{service}.ts` (or an existing aggregate) and validate with canonical helpers from `@/lib/api/server`. Never write a route-local Zod schema. Authenticate and perform cheap admission before parsing or downloading files.

```typescript
// apps/sim/lib/api/contracts/tools/{service}.ts
Expand Down
Loading
Loading