← YCloud Developer KitCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
Update to YCloud Developer Kit
Snapshot Sep 30, 2026 · 23:15 UTC · version 0.7.9
Collection source: not recorded for this historical snapshot.
First saved snapshot
No earlier snapshot is available to establish a change.
Compare saved observations
Download comparison JSONFull technical diff · 0 changed fields
Full snapshot data
{
"description": "Design, implement locally, or evaluate the two YCloud WhatsApp inbound-message acknowledgement operations for marking a received message as read or showing a typing indicator. Use after verified inbound-message receipt; exclude webhook receiving, message sending, and real API operations.",
"included_files": [
{
"relative_path": "agents/openai.yaml",
"size_in_bytes": 297
},
{
"relative_path": "references/openapi.md",
"size_in_bytes": 9661
},
{
"relative_path": "references/runtime.md",
"size_in_bytes": 16163
},
{
"relative_path": "references/shared/integration-boundaries.md",
"size_in_bytes": 8401
}
],
"name": "ycloud-whatsapp-inbound-messages",
"skill_md_contents": "---\nname: ycloud-whatsapp-inbound-messages\ndescription: Design, implement locally, or evaluate the two YCloud WhatsApp inbound-message acknowledgement operations for marking a received message as read or showing a typing indicator. Use after verified inbound-message receipt; exclude webhook receiving, message sending, and real API operations.\n---\n\n# YCloud WhatsApp Inbound Messages\n\nDesign or implement contract-aware acknowledgement of an already received\nWhatsApp message. Keep all examples synthetic and every operation side effect\nbehind a mock transport; never call YCloud, read credentials or customer data,\nor claim that a real read receipt or typing indicator was produced.\n\n## Execution boundary\n\nThese restrictions govern Skill execution: do not call a YCloud Provider API, access real credentials, or read real business data. The Skill may generate server-side adapter code for an application's runtime, but must not start it or make a live request. Reading public official documentation as contract evidence is allowed and is not a Provider API call or business-data access. A live smoke test is outside the default workflow and requires separate, explicit authorization naming the target/environment, allowed operations, credential boundary, and required result evidence.\n\nHonor an Architect handoff for scope, deliverable, mutation, capability IDs,\nproject seams, and evidence. Without one, default to focused read-only guidance\nunless the user explicitly requests local implementation. Local-write\nauthorization permits server-side request builders, adapters, handlers, mock\ntransport bindings, synthetic fixtures, and no-network tests in the scoped\nproject. It does not authorize a real API call or a browser/mobile integration\nthat exposes `X-API-Key`.\n\n## Scope and handoffs\n\nAfter this Skill is selected, read the generated [OpenAPI\ncontract](references/openapi.md) and reviewed [runtime\nbehavior](references/runtime.md). If retry, idempotency, error translation, or\nproduction architecture is requested, also read\n`references/shared/integration-boundaries.md`. If either generated reference is\nmissing, stale, or conflicts with the pinned source, report the drift and stop\ninstead of guessing.\n\nThe allowlist is exact:\n\n| Intent | Method and path | operationId |\n| --- | --- | --- |\n| Mark received message as read | `POST /whatsapp/inboundMessages/{id}/markAsRead` | `whatsapp_inbound_message-mark-as-read` |\n| Mark as read and show typing | `POST /whatsapp/inboundMessages/{id}/typing` | `whatsapp_inbound_message-typing` |\n\nThe Webhook Receiver owns signature verification, exact raw-body handling,\ndurable acceptance, deduplication, and parsing of\n`whatsapp.inbound_message.received`. This Skill begins only after that boundary.\nConsume `event.whatsappInboundMessage.id` or its `wamid`; never substitute the\nwebhook envelope's `event.id`. Return acknowledgement results to the receiver's\nasynchronous business-processing path without changing its already-issued HTTP\nresponse.\n\nRoute message composition or sending to `ycloud-whatsapp-messages`, API-key\nconfiguration to `ycloud-api-authentication`, webhook endpoint/receiver work to\n`ycloud-webhook-endpoints`, and broad multi-domain work to\n`ycloud-integration-architect`. Readiness and repository-maintenance workflows\nare outside this Skill.\n\n## Contract-first workflow\n\n1. Confirm the selected operation's source hash, exact method/path,\n `operationId`, path parameter, response schemas, and descriptions in the\n generated references. Do not infer SDK methods from operation IDs.\n2. Treat `{id}` as an opaque, case-sensitive path value. The operation accepts\n the YCloud inbound-message ID or the original WhatsApp `wamid`. Preserve the\n value, encode it as one URL-path segment, support contract-compatible future\n formats, and never parse prefixes or impose a local wamid grammar. Neither\n operation has a request body.\n3. Preserve the effects exactly. `markAsRead` also marks earlier messages in\n the conversation as read. `typing` does the same and displays a typing\n indicator until a response is sent or 25 seconds elapse. Repeating `typing`\n refreshes the indicator, and the contract defines no idempotency key.\n4. Interpret responses without filling gaps. `markAsRead` documents an empty\n `200` and a `404 ErrorResponse`. `typing` documents `200\n WhatsappInboundMessageTypingResponse` with `success: true`, plus\n `400`, `401`, `403`, `404`, `429`, and `500` `ErrorResponse` bodies. Preserve\n unknown properties and status/code values. Do not invent response bodies,\n endpoint errors, or delivery/read guarantees.\n5. At the provider adapter, retain the standard error envelope and\n `YCloud-Request-ID` (or `error.requestId`) for redacted correlation. Branch on\n HTTP status and `error.code`, not diagnostic `error.message`. If the project\n translates errors, do so only at its own northbound boundary and label that\n mapping as project policy.\n6. On `429`, honor `Retry-After` before another request and parse beta\n `RateLimit-*` headers defensively. Do not invent an inbound-operation quota.\n A typing repeat is a new visible side effect, not a harmless retry; do not\n automatically replay it after a timeout, connection loss, or ambiguous\n response. The source does not establish idempotency or replay safety for\n `markAsRead` either, so do not blindly replay that POST.\n7. Use only a fake or mock HTTP transport for implementation evidence. Tests\n may assert a captured synthetic request and fixture response, but must fail\n closed if configured with a real base URL, credential, or network transport.\n\n## Illustrative raw HTTP\n\nThese shapes are documentation only; do not execute them:\n\n```http\nPOST <YCLOUD_API_BASE_URL>/whatsapp/inboundMessages/<SYNTHETIC_INBOUND_MESSAGE_ID>/markAsRead\nX-API-Key: <YCLOUD_API_KEY>\n```\n\n```http\nPOST <YCLOUD_API_BASE_URL>/whatsapp/inboundMessages/<SYNTHETIC_WAMID>/typing\nX-API-Key: <YCLOUD_API_KEY>\n```\n\nDo not put real IDs, keys, phone numbers, payloads, or customer identifiers in\nexamples, fixtures, URLs, or logs.\n\n## Outcome requirements\n\nAdapt the result to planning, implementation, or evaluation, while making these\nitems explicit:\n\n1. **Matched contract** — selected operation IDs, methods/paths, source hash,\n path-ID provenance, response shapes, and documented side effects.\n2. **Receiver handoff** — verified/durably accepted event precondition and the\n precise `whatsappInboundMessage.id` or `wamid` field used; keep the event ID\n distinct.\n3. **Integration placement** — trusted-server adapter, mock transport seam,\n placeholder authentication handoff, and redacted request-ID observability.\n4. **Response and rate handling** — exact documented statuses, standard error\n envelope, unknown-value preservation, `Retry-After`, and ambiguous-outcome\n behavior without blind POST replay.\n5. **Tests** — no-body request construction, path-segment encoding, opaque and\n case-sensitive ID preservation, inbound ID versus wamid selection, rejection\n of an event ID substituted for a message ID, empty `200` handling for\n `markAsRead`, `success: true` for `typing`, every documented error fixture,\n request-ID mapping, `429` scheduling, timeout ambiguity, repeated-typing\n semantics, and proof that no network call occurs.\n6. **CANNOT** — real read/typing operations, credentials or customer data,\n webhook verification/acknowledgement, message sending, inferred SDK methods,\n invented quotas/errors, general idempotency, blind replay, or claims about\n what a user actually saw.\n7. **Handoff** — return capability-row status, changed or proposed artifacts,\n tests/results, unknowns, and outgoing Receiver, Authentication, Messages, or\n Architect handoffs. State when no handoff is needed.\n\n## Safety and source priority\n\nUse the pinned OpenAPI source first, generated references second, and this\nworkflow third. Keep provider contract, reviewed runtime facts, and project\npolicy visibly separate. External mutations remain prohibited even when local\nimplementation is authorized.\n"
}SHA-256 of public snapshot: c5dc039ba68d22ca47758f9353b29ba5cd01f1e9573143348c4bad9a7a362456