{"id":19324,"plugin_id":"plugins_6a9669d9e57c8191a04a3c8951e44401","kind":"skill","collection_source":null,"comparison_source":null,"observed_at":"2026-09-30T23:15:29.868Z","digest":"42b1782e0bb0dbfdfb8684d9932142342abed7c0af252db40f8234cae3731ab9","against":null,"payload":{"description":"Design, implement locally, or evaluate all 9 YCloud WhatsApp Flows operations across draft creation, retrieval, metadata or structure updates, publishing, preview, deprecation, and deletion. Use for Flow lifecycle management; exclude Flow message sending and real API mutations.","included_files":[{"relative_path":"agents/openai.yaml","size_in_bytes":306},{"relative_path":"references/openapi.md","size_in_bytes":15053},{"relative_path":"references/runtime.md","size_in_bytes":14153},{"relative_path":"references/shared/integration-boundaries.md","size_in_bytes":8401},{"relative_path":"references/shared/pagination-contract.md","size_in_bytes":3494}],"name":"ycloud-whatsapp-flows","skill_md_contents":"---\nname: ycloud-whatsapp-flows\ndescription: Design, implement locally, or evaluate all 9 YCloud WhatsApp Flows operations across draft creation, retrieval, metadata or structure updates, publishing, preview, deprecation, and deletion. Use for Flow lifecycle management; exclude Flow message sending and real API mutations.\n---\n\n# YCloud WhatsApp Flows\n\nDesign or implement contract-aware WhatsApp Flow lifecycle management against\nmocks only. Never call YCloud, mutate a real Flow, open a live preview URL, read\ncredentials or customer data, or imply that managing a Flow sent a message.\n\n## Execution and authority boundary\n\nThese restrictions govern Skill execution: do not call a YCloud Provider API, access real credentials, or read real business data. The Skill may generate server-side adapter code for an application's runtime, but must not start it or make a live request. Reading public official documentation as contract evidence is allowed and is not a Provider API call or business-data access. A live smoke test is outside the default workflow and requires separate, explicit authorization naming the target/environment, allowed operations, credential boundary, and required result evidence.\n\nHonor an Architect handoff for `scope`, `deliverable`, `mutation`, capability\nIDs, project seams, and evidence. Without one, default to focused, read-only\nguidance unless the user explicitly requests local implementation. Local-write\nauthorization permits request models/builders, multipart adapters, handlers,\nhandler/service bindings, mocks, fixtures, and no-network tests inside the scoped\nproject. Every create, update, publish, deprecate, delete, or preview-link\ninvalidation remains mock-only; no authorization level in this Skill permits a\nreal API call.\n\nKeep claims in three authority layers:\n\n1. **Provider contract** — [references/openapi.md](references/openapi.md) and\n   [references/runtime.md](references/runtime.md). State these as YCloud behavior.\n2. **Developer Kit policy** — `references/shared/integration-boundaries.md` when\n   retry, idempotency, queueing, error translation, or webhook reliability is in\n   scope. Label its recommendations as local policy.\n3. **Project decisions** — only facts confirmed in the user's scoped project.\n\nDo not promote an `operationId`, generated model name, `x-*` extension, example,\nplatform recommendation, or project convention into provider behavior. If the\ngenerated references are absent, stale, internally inconsistent, or do not list\nall 9 operations below, stop and report the drift.\n\n## Exact operation allowlist\n\nLoad both generated references after this Skill is selected. Match only these\noperations and preserve every source-defined path/query parameter,\nrequest/response schema, content type, status code, and description constraint.\nFor Flow list response adaptation, also read\n[`references/shared/pagination-contract.md`](references/shared/pagination-contract.md).\n\n| Intent | Method and path | operationId |\n| --- | --- | --- |\n| Create Flow | `POST /whatsapp/flows` | `whatsapp_flow-create` |\n| List Flows | `GET /whatsapp/flows` | `whatsapp_flow-list` |\n| Retrieve Flow | `GET /whatsapp/flows/{flowId}` | `whatsapp_flow-retrieve` |\n| Update structure | `PATCH /whatsapp/flows/{flowId}/assets` | `whatsapp_flow-update-structure` |\n| Update metadata | `PATCH /whatsapp/flows/{flowId}/metadata` | `whatsapp_flow-update-metadata` |\n| Publish Flow | `POST /whatsapp/flows/{flowId}/publish` | `whatsapp_flow-publish` |\n| Generate preview URL | `GET /whatsapp/flows/{flowId}/preview` | `whatsapp_flow-preview` |\n| Deprecate Flow | `POST /whatsapp/flows/{flowId}/deprecate` | `whatsapp_flow-deprecate` |\n| Delete Flow | `DELETE /whatsapp/flows/{flowId}` | `whatsapp_flow-delete` |\n\nFlow interactive message composition and sending belong to\n`ycloud-whatsapp-messages`, even when the Flow already exists. This Skill owns\nonly management of the Flow resource and its preview URL.\n\n## Contract-first workflow\n\n1. Confirm the selected operation and server-side project seam. Treat `flowId`,\n   `cloneFlowId`, WABA IDs, request IDs, and later message IDs as opaque,\n   case-sensitive strings; never parse example prefixes or formats. Preserve\n   unknown response properties and enum/status values rather than failing\n   exhaustive decoding or coercing them into a known lifecycle state.\n   `whatsapp_flow-list` returns `{items: [...]}` without the common Page envelope;\n   do not invent `page`, `offset`, `total`, `cursor`, or `data` fields.\n2. Preserve create semantics: `wabaId`, `name`, and `categories` are required;\n   a new Flow defaults to `DRAFT`. `flowJson` and `publish=true` can create it\n   directly as `PUBLISHED`; `cloneFlowId` requires permission to the source Flow.\n   Do not infer clone ownership, copy completeness, validation, or publish\n   success beyond the returned contract.\n3. Send structure updates as `multipart/form-data` with the required binary\n   `flowJson` file field. Do not silently send JSON text under\n   `application/json`. Preserve structured `validationErrors` on create and\n   structure-update HTTP `400` responses, including unknown error codes and\n   source locations. Metadata updates use JSON and only the source fields\n   `name`, `categories`, and `endpointUri`.\n4. Keep lifecycle gates exact: the status schema says `DRAFT` can be modified,\n   `PUBLISHED` cannot be modified, and `DEPRECATED` cannot be used; delete says\n   only `DRAFT` may be deleted; deprecate applies to a published Flow and states\n   that published Flows cannot be modified or deleted. Do not mutate when status\n   is absent or unknown.\n5. Preserve the source conflict: the publish operation description also says a\n   Flow can later be edited and returned to `DRAFT`, while the status and\n   deprecate descriptions say a published Flow cannot be modified. These are\n   equal-authority pinned OpenAPI statements. Report the contradiction and put\n   post-publish editing/return-to-draft behavior in `CANNOT`; do not choose a\n   rule, synthesize an endpoint, or weaken a lifecycle gate.\n6. Preview generation returns a public, shareable URL. The reference says it\n   expires after 30 days by default and `invalidate=true` generates a new link.\n   Treat the URL as sensitive project output: do not open, crawl, log, commit,\n   or expose a real URL. A GET with `invalidate=true` changes link state, so it\n   remains a mock-only mutation despite its HTTP method.\n7. Use placeholders and synthetic Flow JSON/data in examples and tests. Use an\n   SDK method only when a confirmed SDK artifact and version exist in the\n   project; operation IDs are not SDK methods. Keep `X-API-Key` injection on a\n   trusted server through the Authentication handoff without reading a real key.\n8. Treat mutating timeouts or lost responses as ambiguous outcomes. Never\n   blindly replay create, structure/metadata update, publish, deprecate, delete,\n   or preview invalidation. Any idempotency ledger, outbox, retry budget,\n   reconciliation job, rollback artifact, or version history is project\n   architecture unless the generated runtime reference confirms it.\n\n## Lifecycle and message boundary\n\nAn HTTP `200`/`success=true` applies only to the selected Flow management\noperation. It is not proof that a Flow message was submitted, accepted,\ndelivered, opened, completed, or reached any other user state. Publication makes\nthe management operation successful under the returned contract; sending and\ntracking an interactive message remains a separate Messages workflow.\n\nWhen a user wants to send a Flow, hand `ycloud-whatsapp-messages` the opaque Flow\nID, confirmed current status, and only the message-composition fields supported\nby its generated contract. Preserve `DEPRECATED` as unusable and do not infer\nmessage eligibility when status is unknown or when the lifecycle conflict above\nmatters. Messages owns request construction, message acceptance, YCloud message\nID correlation, retrieve/status handling, and accepted-versus-final semantics.\n\n## Mutation safeguards and tests\n\nPublish, deprecate, delete, clone, replacement of Flow JSON, endpoint URI\nchanges, and preview invalidation can be disruptive or irreversible. Implement\nonly local mock behavior and no-network tests. For any future external workflow,\nstop before the call, identify the exact opaque Flow/WABA IDs and impact, require\nexplicit operation-specific confirmation, and treat an ambiguous result as\nunresolved. Never claim rollback is available unless the provider contract or\nproject proves it.\n\nTests should cover every selected route and schema plus relevant negative cases:\nrequired create fields, draft and create-and-publish branches, clone permission\nas an external precondition, category/status unknown handling, exact multipart\nencoding, validation-error preservation, metadata field mapping, each lifecycle\ngate, the post-publish contradiction stop, draft-only delete, preview expiry and\ninvalidation behavior, public-URL redaction, provider error/request-ID mapping,\nambiguous mutation outcomes, and the Flow-to-Messages boundary.\n\n## Outcome requirements\n\nReturn the matched operation IDs and exact method/paths, authority-labeled\ncontract facts, lifecycle preconditions/conflicts, project-local artifacts or\nproposed seams, no-network test evidence, and explicit unknowns. Do not claim an\noperation implemented because only a route label, button, sample JSON, or mock\nresponse exists; link each implemented row to its adapter/handler and behavioral\ntests.\n\n### CANNOT\n\nList unsupported operations, missing project facts, the unresolved published\nFlow editing contradiction, unconfirmed SDK behavior, live preview URLs,\ncredentials/customer data, real API calls, external mutations, blind replay,\ninvented rollback, and message delivery/completion claims. Do not put confirmed\ndraft creation, draft-only deletion, deprecation, preview expiry/invalidation,\nor validation-error behavior into `CANNOT`.\n\n### Handoff\n\nSend Flow message composition, submission, retrieval, and status tracking to\n`ycloud-whatsapp-messages` with Flow ID, status evidence, and message IDs kept as\nseparate opaque values. Send authentication storage to\n`ycloud-api-authentication` and webhook endpoint/receiver work to\n`ycloud-webhook-endpoints`. Return to Architect with capability-row status,\nchanged or proposed artifacts, tests/results, lifecycle evidence and conflicts,\nunknowns, and outgoing handoffs.\n"},"changes":[],"summary":"First saved snapshot. No earlier version is available for comparison.","summary_kind":"deterministic","summary_metadata":{}}