← YCloud Developer KitCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
Update to YCloud Developer Kit
Snapshot Sep 30, 2026 · 23:15 UTC · version 0.7.9
Collection source: not recorded for this historical snapshot.
First saved snapshot
No earlier snapshot is available to establish a change.
Compare saved observations
Download comparison JSONFull technical diff · 0 changed fields
Full snapshot data
{
"description": "Design, implement locally, or evaluate YCloud WhatsApp Business Account listing, retrieval, and automatic creative optimization operations. Use for WABA inventory or ACO integration; exclude phone-number management, messaging, template lifecycle, broad planning, and real API mutations.",
"included_files": [
{
"relative_path": "agents/openai.yaml",
"size_in_bytes": 301
},
{
"relative_path": "references/openapi.md",
"size_in_bytes": 28881
},
{
"relative_path": "references/runtime.md",
"size_in_bytes": 13589
},
{
"relative_path": "references/shared/integration-boundaries.md",
"size_in_bytes": 8401
},
{
"relative_path": "references/shared/pagination-contract.md",
"size_in_bytes": 3494
}
],
"name": "ycloud-whatsapp-business-accounts",
"skill_md_contents": "---\nname: ycloud-whatsapp-business-accounts\ndescription: Design, implement locally, or evaluate YCloud WhatsApp Business Account listing, retrieval, and automatic creative optimization operations. Use for WABA inventory or ACO integration; exclude phone-number management, messaging, template lifecycle, broad planning, and real API mutations.\n---\n\n# YCloud WhatsApp Business Accounts\n\nDesign or implement contract-aware support for the four WABA operations in the\ngenerated reference. Never call YCloud or Meta, read credentials or customer\ndata, or mutate a real WABA.\n\n## Execution boundary\n\nThese restrictions govern Skill execution: do not call a YCloud Provider API, access real credentials, or read real business data. The Skill may generate server-side adapter code for an application's runtime, but must not start it or make a live request. Reading public official documentation as contract evidence is allowed and is not a Provider API call or business-data access. A live smoke test is outside the default workflow and requires separate, explicit authorization naming the target/environment, allowed operations, credential boundary, and required result evidence.\n\nHonor Architect handoffs for `scope`, `deliverable`, `mutation`, capability IDs,\nproject seams, and expected evidence. Without one, default to focused,\nread-only guidance unless the user explicitly requests local implementation.\nLocal-write authorization permits request models/builders, adapters, handlers,\nservice bindings, mocks, synthetic fixtures, and no-network tests inside\nthe scoped project. The ACO PATCH operation is mock-only: local implementation\ndoes not authorize a real enrollment update. Reuse the project's existing\ninterface stack and preserve concurrent work.\n\nLoad [the generated OpenAPI reference](references/openapi.md) and\n[the reviewed runtime reference](references/runtime.md) only after this skill is\nselected. If retry, idempotency, queueing, or error translation is requested,\nalso read `references/shared/integration-boundaries.md`. Exact paths, schemas,\nresponses, and descriptions come from `openapi.md`; cross-cutting pagination,\nerror, request-ID, rate-limit, and compatibility behavior comes from\n`runtime.md`. If either generated reference is missing, stale, or inconsistent\nwith its recorded source hash and operation count, report drift and stop rather\nthan reconstructing the contract from memory.\nFor WABA list work, also read\n[`references/shared/pagination-contract.md`](references/shared/pagination-contract.md).\n\n## Exact operation scope\n\n| Intent | Method and path | operationId |\n| --- | --- | --- |\n| List WABAs | `GET /whatsapp/businessAccounts` | `whatsapp_business_account-list` |\n| Retrieve one WABA | `GET /whatsapp/businessAccounts/{id}` | `whatsapp_business_account-retrieve` |\n| Retrieve ACO enrollment | `GET /whatsapp/businessAccounts/{wabaId}/automatic-creative-optimizations` | `whatsapp_waba-retrieve-automatic-creative-optimizations` |\n| Partially update ACO enrollment | `PATCH /whatsapp/businessAccounts/{wabaId}/automatic-creative-optimizations` | `whatsapp_waba-update-automatic-creative-optimizations` |\n\nPhone-number inventory and configuration belong to\n`ycloud-whatsapp-phone-numbers`. Message submission/retrieval belongs to\n`ycloud-whatsapp-messages`; template lifecycle and analytics belong to\n`ycloud-whatsapp-templates`; authentication-only work belongs to\n`ycloud-api-authentication`; broad multi-domain planning belongs to\n`ycloud-integration-architect`. Readiness, repository maintenance, and issue\ntracking are out of scope.\n\n## Contract-first workflow\n\n1. Match only an allowlisted operation and report its exact method, path,\n operationId, parameters, request/response schemas, and documented responses.\n Treat `operationId` and `x-*` fields as identifiers or codegen hints, not SDK\n method names or business rules. Use a project SDK only when its actual\n artifact, version, and method are confirmed.\n2. Keep every WABA ID as an opaque, case-sensitive string. Do not parse prefixes,\n coerce it to a number, infer ownership, or rewrite it. Preserve the source's\n exact path parameter name: `{id}` for retrieve and `{wabaId}` for ACO.\n3. For list, use 1-based `page`, `limit` from 1 through 100, and the documented\n defaults. Request `includeTotal=true` only when a count is needed, and apply\n `filter.accountReviewStatus` only as the source-defined string filter. Do not\n invent an enum or infer account eligibility from a review status. Parse the\n response as the merged Page envelope with required `offset`, `limit`,\n `length`, WABA `items`, and optional `total`; do not use response `offset` as\n a request parameter. Preserve\n unknown response properties and enum/status values.\n4. For ACO GET, preserve the distinction between the response's extensible map\n and the PATCH request's closed map. GET returns Meta string fields without\n feature-key filtering, status validation, or case normalization; a successful\n response without the expected upstream object yields an empty\n `creativeOptimizationFeatures` object. Do not silently discard unknown keys\n or normalize unknown values.\n5. For ACO PATCH, require the non-empty `creativeOptimizationFeatures` object,\n accept only the feature keys and `OPT_IN`/`OPT_OUT` values enumerated by the\n generated schema, and send only intended changes. The operation is a partial\n update: omitted keys are not a request to reset them. The contract says\n YCloud does not persist enrollment locally and does not pre-check Meta MM\n Lite/ACO onboarding; do not add either behavior as a claimed YCloud rule.\n6. Keep contract facts separate from project policy. Input validation, approval\n UX, an audit record, an idempotency ledger, retry budgets, and rollback\n controls may be recommended or implemented locally when requested, but must\n be labeled application-owned. A mutating timeout is ambiguous; never replay\n ACO PATCH automatically. Honor documented `Retry-After` before later traffic\n without treating it as proof that replay is safe.\n7. Use placeholders such as `<YCLOUD_API_KEY>`, `<WABA_ID>`, and synthetic\n feature values. Keep authentication server-side and hand credential storage\n to `ycloud-api-authentication`; do not inspect `.env`, secret stores, logs, or\n live responses.\n\n## Validation and evidence\n\nFor local implementation, add no-network tests for operation routing, exact\nparameter names, opaque/string IDs, pagination boundaries/defaults, optional\ntotals, filter encoding, standard error/request-ID mapping, unknown response\nfields and enum values, ACO GET's extensible/empty map behavior, and ACO PATCH's\nnon-empty closed-key map, enum validation, partial-update construction, and\nambiguous-timeout/no-replay behavior. Mocks must prove that no network client is\ninvoked.\n\nReturn these sections, adapted to the requested deliverable:\n\n1. **Matched contract** — source hash, selected operations, exact request and\n response shapes, and description-only constraints.\n2. **Construction or implementation** — placeholder HTTP/project-local design,\n changed artifacts, and project facts still needed.\n3. **Contract versus policy** — identify YCloud guarantees separately from local\n validation, approvals, persistence, retries, and rollback choices.\n4. **Tests and evidence** — synthetic cases and actual no-network results.\n5. **CANNOT** — real API/Meta calls, credentials/customer data, guessed SDK\n methods, unsupported operations, unknown lifecycle behavior, and any missing\n facts. Do not put confirmed pagination, error-envelope, request-ID, or ACO\n behavior in `CANNOT`.\n6. **Handoff** — pass the selected opaque WABA ID to\n `ycloud-whatsapp-phone-numbers`; after a phone number is selected, route\n sending/retrieval to `ycloud-whatsapp-messages` and template lifecycle or\n analytics to `ycloud-whatsapp-templates`. Return to Architect with capability\n status, artifacts, tests, unknowns, and outgoing handoffs.\n\n## Safety stop\n\nYCloud Provider API calls are prohibited during Skill execution, including\nnominally read-only GETs. All mutations are mock-only. Stop before any request\nthat would use a real API key, WABA/customer identifier, or live YCloud/Meta\nresource.\n"
}SHA-256 of public snapshot: e5c0bbcfc1bfb45039de4159f6e92016941cb2fc4f1a380cad17b4ff786de69d