Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
65 commits
Select commit Hold shift + click to select a range
c9aed7a
fix(jsm): accept the numeric pagination the JSM tools actually send (…
waleedlatif1 Aug 7, 2026
de5fcf9
fix(providers): stop reporting an absent Ollama as an error (#6387)
waleedlatif1 Aug 7, 2026
a84260f
improvement(mship): questions improvement (#6385)
Sg312 Aug 7, 2026
73bac1a
improvement(admin): move user row actions into an overflow menu with …
waleedlatif1 Aug 7, 2026
9b80fdd
fix(chunkers): preserve FAQ prose in docs chunks (#6383)
j15z Aug 7, 2026
40c0a57
fix(files): stop the file-viewer image reshift on open (#6390)
waleedlatif1 Aug 7, 2026
5cf1f9b
improvement(provenance): cleanup secrets boundary (#6374)
icecrasher321 Aug 8, 2026
2e7e5ae
feat(dynatrace): add the Dynatrace integration (#6393)
waleedlatif1 Aug 8, 2026
d317607
feat(dynatrace): add the write and configuration surfaces (#6398)
waleedlatif1 Aug 8, 2026
1c5393a
feat(workspaces): pin workspaces and widen the switcher to six rows (…
waleedlatif1 Aug 8, 2026
3b4d587
feat(demo): fire the X conversion event when a demo is booked (#6401)
waleedlatif1 Aug 8, 2026
08af7db
improvement(ui): unbold the app, align the folder chevron, tidy the f…
waleedlatif1 Aug 8, 2026
457170b
fix(agent): overly broad check for secrets protection (#6399)
icecrasher321 Aug 8, 2026
cb8338c
fix(workspaces): give the pin and options button one shared slot (#6402)
waleedlatif1 Aug 8, 2026
b5e5ca5
improvement(ci): run the CodeQL cron weekly and cancel superseded sca…
waleedlatif1 Aug 8, 2026
8c6166e
fix(mship): return the chat connect flow to the tab that started it (…
j15z Aug 8, 2026
3b0651e
feat(library): Best AI Agents for Customer Support Ticket Triage and …
icecrasher321 Aug 8, 2026
8a224be
fix(files): read the Files prefetch from the data layer and bound inv…
waleedlatif1 Aug 8, 2026
6c6d8a5
improvement(chat): rename "Branch in new chat" to "Fork in new chat" …
j15z Aug 8, 2026
4f5ad20
fix(tables): keep row context menu labels on one line (#6418)
waleedlatif1 Aug 8, 2026
0aae736
fix(provenance): stop short secret values from rewriting unrelated lo…
icecrasher321 Aug 8, 2026
533afaa
fix(docs): stop the pinned sidebar running under the site footer (#6422)
waleedlatif1 Aug 8, 2026
9f8368e
fix(files): anchor the editor bubble menus to the selection on scroll…
waleedlatif1 Aug 8, 2026
3726bd2
fix(knowledge): apply knowledge-base access checks consistently acros…
waleedlatif1 Aug 8, 2026
52be28e
improvement(execute): enforce workspace permissions on function file …
waleedlatif1 Aug 8, 2026
441004a
improvement(file-parsers): bound PDF text extraction (#6425)
waleedlatif1 Aug 8, 2026
1d67e01
fix(webhooks): centralize the path-delivery rule for trigger provider…
waleedlatif1 Aug 8, 2026
05aabc3
fix(mcp): apply the workspace personal API key setting to MCP serve a…
waleedlatif1 Aug 8, 2026
a2ad4b6
fix(files): escape user filenames in the Content-Disposition header (…
waleedlatif1 Aug 8, 2026
87b7b4b
improvement(files): harden untrusted document preview and parsing (#6…
waleedlatif1 Aug 8, 2026
5a9f64a
fix(files): bound HTML parser input before building the DOM (#6423)
waleedlatif1 Aug 8, 2026
ea5df41
fix(webhooks): resolve the AgentMail tenant before verifying the sign…
waleedlatif1 Aug 8, 2026
9f50508
fix(files): pin editor bubble menus to the cursor during scroll (#6434)
waleedlatif1 Aug 8, 2026
33fe043
fix(cli): generate per-install secrets instead of using fixed values …
waleedlatif1 Aug 8, 2026
a7b016b
fix(files): make the rich-markdown-field container a positioning cont…
waleedlatif1 Aug 8, 2026
0b016c2
fix(webhooks): drop the AgentMail-specific webhook body cap (#6436)
waleedlatif1 Aug 8, 2026
77bc8ba
test(triggers): guard the provider granularity the path route depends…
waleedlatif1 Aug 8, 2026
cb63eca
fix(inbox): disable the inbox atomically and simplify its webhook tes…
waleedlatif1 Aug 8, 2026
9cd2e7f
fix(cli): validate each install secret against its own requirement (#…
waleedlatif1 Aug 8, 2026
815a960
improvement(api): share the API key workspace policy messages and ali…
waleedlatif1 Aug 8, 2026
1b5ba82
improvement(files): share bubble-menu chrome and stabilize shouldShow…
waleedlatif1 Aug 8, 2026
9395f0e
fix(file-parsers): stop deleting non-BMP characters when sanitizing p…
waleedlatif1 Aug 8, 2026
e7e8811
improvement(execute): reuse the resolved workspace access and dedupe …
waleedlatif1 Aug 8, 2026
585541a
improvement(files): extend the OOXML size limits to the client previe…
waleedlatif1 Aug 8, 2026
86ac309
fix(knowledge): validate tag slots and share the tag-name length limi…
waleedlatif1 Aug 8, 2026
28f5e50
fix(files): stop rejecting ordinary HTML documents at the parser limi…
waleedlatif1 Aug 8, 2026
107748d
improvement(ui): consolidate the disclosure chevron and order resourc…
waleedlatif1 Aug 8, 2026
c5499f7
refactor(instagram): align publishing with codebase patterns (#6270)
BillLeoutsakosvl346 Aug 8, 2026
a477a52
chore(pi): organize mode implementations (#6362)
BillLeoutsakosvl346 Aug 8, 2026
9883543
fix(knowledge): stop listing workspace knowledge bases on stale creat…
waleedlatif1 Aug 8, 2026
fb6e18f
refactor(tiktok): align webhook routing with shared dispatcher (#6261)
BillLeoutsakosvl346 Aug 8, 2026
8a312a7
improvement(copilot): bound image decode work on the VFS file read pa…
waleedlatif1 Aug 8, 2026
ff1ea21
fix(uploads): bound the HEIF fallback decode by declared pixels, not …
waleedlatif1 Aug 8, 2026
5620017
feat(mintlify): add Mintlify integration (#6457)
waleedlatif1 Aug 8, 2026
3096de8
feat(integrations): add Snowflake PAT integration (#6407)
BillLeoutsakosvl346 Aug 8, 2026
76b535f
chore(snowflake): drop the local write caps in favor of the shared li…
waleedlatif1 Aug 8, 2026
e6485f5
fix(dynatrace): send the only unmute reason the API accepts and reque…
waleedlatif1 Aug 9, 2026
220495c
fix(pi): compact cloud event streams before sandbox retention (#6464)
BillLeoutsakosvl346 Aug 9, 2026
19c3171
fix(condition): stop shipping all block outputs in every evaluation (…
icecrasher321 Aug 9, 2026
d382761
feat(pi): add plan mode (#6372)
BillLeoutsakosvl346 Aug 9, 2026
38f9d57
feat(library): Best AI Agent Platforms for Enterprise Teams in 2026 (…
icecrasher321 Aug 9, 2026
64fb8f0
fix(og): read OG fonts from the repo instead of fetching Google Fonts…
waleedlatif1 Aug 9, 2026
29cfb85
feat(mship): mship sysprompt override (#6469)
Sg312 Aug 9, 2026
303986f
feat(snowflake): credential-based auth, object pickers, and 9 new ope…
waleedlatif1 Aug 9, 2026
4475686
fix(snowflake): drop the oversized credential modal help text (#6475)
waleedlatif1 Aug 9, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
43 changes: 23 additions & 20 deletions .agents/skills/add-integration/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -131,20 +131,24 @@ service's official documentation or an unambiguous local execution path proves t
field is consumed by an AI model. If that cannot be established, preserve existing tool behavior
and leave the field unannotated.

- **Ordinary provider/API input:** leave it unchanged. Do not add blanket result sanitization.
- **Ordinary provider/API input:** leave it unchanged. Explicit `{{...}}` references resolve and are
sent with their normal request semantics. A URL, domain, resource ID, control field, or opaque
payload is not model-visible merely because the provider is AI-backed or may process the
referenced resource later.
- **Text or structured content consumed by an AI model:** declare `request.modelInput` with
`mode: 'project'` and select only the exact model-visible fields. The shared executor replaces
activated Sim secrets with canonical `{{NAME}}` labels before request formatting. For nested or
JSON-string fields, use a small shared selector plus `applyProjected`; verify that selecting the
rebuilt params reproduces the projected selection.
- **Opaque model input sent directly to an external provider** such as a model-read URL or image
payload: declare `request.opaqueModelInput` with `mode: 'reject-resolved-secrets'` and select only
the exact effective value. The shared `executeTool` preflight rejects incomplete or secret-bearing
committed provenance before URL/body formatting or network I/O, preserves safe request bytes,
and sends no provenance metadata to the provider.
- **Opaque model input owned by an authenticated internal route** such as uploaded audio, image,
video, file bytes, or signed URLs: add `privateProvenance` to a projected request, or use
`mode: 'private-provenance'` when there is no textual projection. The route must call
- **Serialized model content sent directly to an external provider:** include the serialized
top-level param in `request.modelInput`. Project the private copy before the existing request
formatter parses it; keep formatter behavior deterministic when a whole-value placeholder is not
valid in the serialized grammar. Do not introduce a second hard-rejection path.
- **Opaque model input owned by an authenticated internal route** such as inline audio, image,
video, or document bytes: add `privateProvenance` to a projected request, or use
`mode: 'private-provenance'` when there is no textual projection. Do not select storage keys,
paths, signed URLs, or ordinary remote URLs as byte provenance; the owning route must authorize
stored bytes independently at model egress. The route must call
`validateOpaqueModelInputProvenance` before downloading or sending content to the model and must
apply the workspace-file provenance guard before reading a persisted workspace file.
- **Sim-owned durable storage or internal execution handoff** that can later enter a workflow/model
Expand All @@ -160,9 +164,9 @@ Hard rules:
- Never substitute secret plaintext into source or serialize plaintext provenance.
- Never hand-roll private provenance headers/envelopes; the shared `executeTool` boundary owns
transport and strips private metadata from functional results.
- Never attach private provenance to an external URL or to `directExecution`. Use the centralized
`opaqueModelInput` rejection mode for external/direct opaque model inputs, or an authenticated
internal route when encrypted provenance must cross the boundary.
- Never attach private provenance to an external URL or to `directExecution`. Project proven
model-visible external fields with `request.modelInput`; otherwise preserve ordinary request
semantics. Use an authenticated internal route when encrypted provenance must cross the boundary.
- Never sanitize arbitrary third-party tool results. Projection applies only to secrets activated
by Sim's resolved-secret provenance for that execution/tool call.
- Do not add provenance merely because a value is persisted, returned by a tool, or appears in a
Expand All @@ -173,12 +177,11 @@ Hard rules:
provider responses, filenames, URLs, and errors remain unchanged when Sim did not resolve a
secret into them.

Add focused tests covering named projection, ordinary identical text without provenance, nested
shape preservation, malformed/incomplete private metadata failing closed, centralized external
opaque rejection before formatting/I/O without byte changes or metadata transport, headerless
legacy requests, and absence of private metadata in the public tool result. For durable sinks, also
cover legacy `NULL` markers, exact-empty new writes, tracked secret writes, stale/missing sidecars,
and scope isolation.
Add focused tests covering named projection, ordinary identical text without provenance, nested and
serialized shape handling, unchanged ordinary external inputs, malformed/incomplete private metadata
failing closed, headerless legacy requests, and absence of private metadata in the public tool result.
For durable sinks, also cover legacy `NULL` markers, exact-empty new writes, tracked secret writes,
stale/missing sidecars, and scope isolation.

## Step 3: Create Block

Expand Down Expand Up @@ -594,8 +597,8 @@ If creating V2 versions (API-aligned outputs):
- [ ] Registered all tools in `tools/registry.ts`
- [ ] Ran `bun run tool-metadata:generate` and committed the regenerated artifacts
- [ ] Classified every model-visible, opaque, Sim-durable, and internal-execution request field
- [ ] Added shared model-input projection, centralized opaque rejection, or private provenance only
where required
- [ ] Added shared model-input projection or private provenance only where required; ordinary
external resource locators and control inputs retain their request semantics
- [ ] Confirmed ordinary third-party tool results are not generically sanitized
- [ ] Added provenance compatibility and fail-closed boundary tests where applicable

Expand Down
16 changes: 10 additions & 6 deletions .agents/skills/add-tools/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -150,12 +150,16 @@ export const {serviceName}{Action}Tool: ToolConfig<
- Leave ordinary external API inputs and third-party results unchanged. Add provenance handling only
when an exact field is proven to cross a Sim model, durable-storage, or internal-execution boundary.
- Project AI-consumed text/structured fields with the smallest exact `request.modelInput` selector.
- Reject resolved secrets in opaque model input sent directly to an external provider with
`request.opaqueModelInput`; never attach private metadata to an external URL or `directExecution`.
- For authenticated internal routes, use `privateProvenance` for opaque model input or
`request.secretProvenance` for durable writes and execution handoffs. Authenticate first, validate
the exact selection and scope, strip the private envelope, then import or propagate provenance at
the receiving boundary. Preserve documented headerless legacy behavior.
- Treat URLs, domains, resource IDs, and control fields as ordinary request values unless the exact
field is proven model-visible. For serialized external model content, project the serialized
top-level param through `request.modelInput` before the existing formatter parses it; do not add a
separate hard-rejection mechanism.
- For authenticated internal routes, use `privateProvenance` for actual inline/raw model bytes or
`request.secretProvenance` for durable writes and execution handoffs. Do not treat a storage key,
path, signed URL, or remote URL as provenance for fetched bytes; authorize tracked stored bytes at
the owning model-egress boundary. Authenticate first, validate the exact selection and scope,
strip the private envelope, then import or propagate provenance at the receiving boundary.
Preserve documented headerless legacy behavior.
- Never substitute secret plaintext into source, serialize plaintext provenance, hand-roll private
headers, or blanket-sanitize tool results.
- Add focused tests for named projection, identical unproven public text, malformed/incomplete
Expand Down
30 changes: 16 additions & 14 deletions .agents/skills/validate-integration/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -141,21 +141,25 @@ search, extraction, or "AI-powered" marketing terminology.

- [ ] AI-consumed text/structured fields use `request.modelInput` with `mode: 'project'` and a
minimal exact selector; nested/JSON-string adapters preserve shape through `applyProjected`
- [ ] Opaque AI-consumed values sent directly to an external provider or `directExecution` use
`request.opaqueModelInput` with `mode: 'reject-resolved-secrets'` and an exact effective-value
selector; the central executor rejects incomplete/secret-bearing committed provenance before
formatting or I/O, leaves safe bytes unchanged, and sends no provenance metadata externally
- [ ] Opaque AI-consumed files/bytes/URLs owned by an authenticated internal route use
- [ ] Ordinary external URLs, domains, resource IDs, and control fields retain normal request
semantics unless the exact field is proven model-visible; an AI-backed provider or later model
processing of the referenced resource is not sufficient evidence
- [ ] Serialized content proven to be sent directly to an external model is selected by
`request.modelInput`, projected before the existing formatter parses it, and has deterministic
formatter behavior when a whole-value placeholder is invalid for the serialized grammar
- [ ] Actual inline/raw AI-consumed bytes owned by an authenticated internal route use
`privateProvenance` (or `mode: 'private-provenance'`), and the route validates
`validateOpaqueModelInputProvenance` before any download or model call
`validateOpaqueModelInputProvenance` before model egress; storage keys, paths, signed URLs,
and ordinary remote URLs are not treated as byte provenance, while tracked stored bytes are
authorized independently at the owning model-egress boundary
- [ ] Persisted workspace-file contents are checked with the shared provenance guard only when
their bytes or decoded content cross into a model/tool-result boundary; ordinary file APIs
remain unchanged. Unsupported secret-bearing file paths are rejected at `file_write`
- [ ] Sim-owned durable writes and internal execution handoffs that can enter workflows/models use
field-scoped `request.secretProvenance`; authenticated receivers validate the exact selection
and scope, strip private metadata, and persist, import, or propagate it at the owning boundary
- [ ] Private provenance is never attached to external URLs or `directExecution`; those paths use
centralized `opaqueModelInput` rejection when their opaque values are model-bound
- [ ] Private provenance is never attached to external URLs or `directExecution`; proven
model-visible external fields use projection, while other external inputs remain unchanged
- [ ] No tool performs raw secret plaintext/source substitution or serializes plaintext provenance
- [ ] No `transformResponse` or tool-local helper blanket-sanitizes ordinary third-party results;
only execution-scoped, activated Sim provenance is projected at shared model/log boundaries
Expand All @@ -166,10 +170,9 @@ search, extraction, or "AI-powered" marketing terminology.
metadata, provider results, or API payloads
- [ ] Diagnostic projection is applied only to values carrying execution-scoped provenance;
ordinary provider responses, filenames, URLs, and errors are unchanged
- [ ] Tests cover named `{{NAME}}` projection, unproven identical public text, nested shape
preservation, malformed/incomplete metadata, centralized opaque rejection before formatting
or I/O with safe-byte preservation, headerless legacy requests, metadata stripping, and
durable legacy/stale/scope cases when applicable
- [ ] Tests cover named `{{NAME}}` projection, unproven identical public text, nested and serialized
shape handling, unchanged ordinary external inputs, malformed/incomplete metadata, headerless
legacy requests, metadata stripping, and durable legacy/stale/scope cases when applicable

Treat a missing or bypassed model, durable, or internal-execution provenance boundary as
**critical**. Do not fix it with a tool-specific string replacer or by sanitizing every provider
Expand Down Expand Up @@ -348,8 +351,7 @@ Group findings by severity:
- Service-account metadata disagrees with the canonical OAuth service configuration
- `tools.config.tool` returning wrong tool ID for an operation
- Type coercions in `tools.config.tool` instead of `tools.config.params`
- AI-consumed request fields bypass the shared projection, centralized opaque rejection, or
private-provenance boundary
- Proven model-visible request fields bypass the shared projection or private-provenance boundary
- Opaque model input is downloaded or sent before provenance and workspace-file checks
- A Sim-owned durable sink or internal execution handoff drops encrypted provenance or breaks
legacy headerless/`NULL` data
Expand Down
43 changes: 23 additions & 20 deletions .claude/commands/add-integration.md
Original file line number Diff line number Diff line change
Expand Up @@ -130,20 +130,24 @@ service's official documentation or an unambiguous local execution path proves t
field is consumed by an AI model. If that cannot be established, preserve existing tool behavior
and leave the field unannotated.

- **Ordinary provider/API input:** leave it unchanged. Do not add blanket result sanitization.
- **Ordinary provider/API input:** leave it unchanged. Explicit `{{...}}` references resolve and are
sent with their normal request semantics. A URL, domain, resource ID, control field, or opaque
payload is not model-visible merely because the provider is AI-backed or may process the
referenced resource later.
- **Text or structured content consumed by an AI model:** declare `request.modelInput` with
`mode: 'project'` and select only the exact model-visible fields. The shared executor replaces
activated Sim secrets with canonical `{{NAME}}` labels before request formatting. For nested or
JSON-string fields, use a small shared selector plus `applyProjected`; verify that selecting the
rebuilt params reproduces the projected selection.
- **Opaque model input sent directly to an external provider** such as a model-read URL or image
payload: declare `request.opaqueModelInput` with `mode: 'reject-resolved-secrets'` and select only
the exact effective value. The shared `executeTool` preflight rejects incomplete or secret-bearing
committed provenance before URL/body formatting or network I/O, preserves safe request bytes,
and sends no provenance metadata to the provider.
- **Opaque model input owned by an authenticated internal route** such as uploaded audio, image,
video, file bytes, or signed URLs: add `privateProvenance` to a projected request, or use
`mode: 'private-provenance'` when there is no textual projection. The route must call
- **Serialized model content sent directly to an external provider:** include the serialized
top-level param in `request.modelInput`. Project the private copy before the existing request
formatter parses it; keep formatter behavior deterministic when a whole-value placeholder is not
valid in the serialized grammar. Do not introduce a second hard-rejection path.
- **Opaque model input owned by an authenticated internal route** such as inline audio, image,
video, or document bytes: add `privateProvenance` to a projected request, or use
`mode: 'private-provenance'` when there is no textual projection. Do not select storage keys,
paths, signed URLs, or ordinary remote URLs as byte provenance; the owning route must authorize
stored bytes independently at model egress. The route must call
`validateOpaqueModelInputProvenance` before downloading or sending content to the model and must
apply the workspace-file provenance guard before reading a persisted workspace file.
- **Sim-owned durable storage or internal execution handoff** that can later enter a workflow/model
Expand All @@ -159,9 +163,9 @@ Hard rules:
- Never substitute secret plaintext into source or serialize plaintext provenance.
- Never hand-roll private provenance headers/envelopes; the shared `executeTool` boundary owns
transport and strips private metadata from functional results.
- Never attach private provenance to an external URL or to `directExecution`. Use the centralized
`opaqueModelInput` rejection mode for external/direct opaque model inputs, or an authenticated
internal route when encrypted provenance must cross the boundary.
- Never attach private provenance to an external URL or to `directExecution`. Project proven
model-visible external fields with `request.modelInput`; otherwise preserve ordinary request
semantics. Use an authenticated internal route when encrypted provenance must cross the boundary.
- Never sanitize arbitrary third-party tool results. Projection applies only to secrets activated
by Sim's resolved-secret provenance for that execution/tool call.
- Do not add provenance merely because a value is persisted, returned by a tool, or appears in a
Expand All @@ -172,12 +176,11 @@ Hard rules:
provider responses, filenames, URLs, and errors remain unchanged when Sim did not resolve a
secret into them.

Add focused tests covering named projection, ordinary identical text without provenance, nested
shape preservation, malformed/incomplete private metadata failing closed, centralized external
opaque rejection before formatting/I/O without byte changes or metadata transport, headerless
legacy requests, and absence of private metadata in the public tool result. For durable sinks, also
cover legacy `NULL` markers, exact-empty new writes, tracked secret writes, stale/missing sidecars,
and scope isolation.
Add focused tests covering named projection, ordinary identical text without provenance, nested and
serialized shape handling, unchanged ordinary external inputs, malformed/incomplete private metadata
failing closed, headerless legacy requests, and absence of private metadata in the public tool result.
For durable sinks, also cover legacy `NULL` markers, exact-empty new writes, tracked secret writes,
stale/missing sidecars, and scope isolation.

## Step 3: Create Block

Expand Down Expand Up @@ -593,8 +596,8 @@ If creating V2 versions (API-aligned outputs):
- [ ] Registered all tools in `tools/registry.ts`
- [ ] Ran `bun run tool-metadata:generate` and committed the regenerated artifacts
- [ ] Classified every model-visible, opaque, Sim-durable, and internal-execution request field
- [ ] Added shared model-input projection, centralized opaque rejection, or private provenance only
where required
- [ ] Added shared model-input projection or private provenance only where required; ordinary
external resource locators and control inputs retain their request semantics
- [ ] Confirmed ordinary third-party tool results are not generically sanitized
- [ ] Added provenance compatibility and fail-closed boundary tests where applicable

Expand Down
Loading
Loading