← YCloud Developer KitCONTENT HISTORY

Update to YCloud Developer Kit

Snapshot Sep 30, 2026 · 23:15 UTC · version 0.7.9

Collection source: not recorded for this historical snapshot.

WHAT CHANGED · RULE-BASED ANALYSIS

First saved snapshot

No earlier snapshot is available to establish a change.

Compare saved observations

Download comparison JSON
Full technical diff · 0 changed fields
Full snapshot data
{
  "description": "Design, implement locally, or evaluate YCloud WhatsApp template create, list, retrieve, edit, delete, and analytics operations. Use for template lifecycle integration; do not use for sending template messages, media uploads, readiness, broad integration planning, or real template/API mutations.",
  "included_files": [
    {
      "relative_path": "agents/openai.yaml",
      "size_in_bytes": 288
    },
    {
      "relative_path": "references/create-examples.json",
      "size_in_bytes": 1706
    },
    {
      "relative_path": "references/openapi.md",
      "size_in_bytes": 57360
    },
    {
      "relative_path": "references/runtime.md",
      "size_in_bytes": 17926
    },
    {
      "relative_path": "references/shared/integration-boundaries.md",
      "size_in_bytes": 8401
    },
    {
      "relative_path": "references/shared/pagination-contract.md",
      "size_in_bytes": 3494
    }
  ],
  "name": "ycloud-whatsapp-templates",
  "skill_md_contents": "---\nname: ycloud-whatsapp-templates\ndescription: Design, implement locally, or evaluate YCloud WhatsApp template create, list, retrieve, edit, delete, and analytics operations. Use for template lifecycle integration; do not use for sending template messages, media uploads, readiness, broad integration planning, or real template/API mutations.\n---\n\n# YCloud WhatsApp Templates\n\nDesign or implement safe, contract-aware WhatsApp template lifecycle and\nanalytics work. This skill never mutates a real template.\n\n## Execution boundary\n\nThese restrictions govern Skill execution: do not call a YCloud Provider API, access real credentials, or read real business data. The Skill may generate server-side adapter code for an application's runtime, but must not start it or make a live request. Reading public official documentation as contract evidence is allowed and is not a Provider API call or business-data access. A live smoke test is outside the default workflow and requires separate, explicit authorization naming the target/environment, allowed operations, credential boundary, and required result evidence.\n\nHonor Architect handoffs for `scope`, `deliverable`, `mutation`, capability IDs,\nproject seams, and expected evidence. Without one, default to focused scope and\nread-only guidance unless the user explicitly requests local implementation.\nLocal-write authorization permits request models/builders, adapters, handlers,\ncomponent editors, test-console bindings, mocks, and no-network tests in the\nscoped project. It does not authorize create, edit, delete, analytics, or any\nother real API call. Reuse the project's existing UI/interface stack and do not\ngenerate a dashboard or bind a framework without user/project support.\n\n## Trigger boundary\n\nUse this skill for template creation, listing, retrieval, editing, deletion, or\nanalytics. A request to send a message that happens to use a template belongs to\n`ycloud-whatsapp-messages`, even when the template already exists. A request to\nupload media belongs to `ycloud-whatsapp-media`. Broad integration design belongs\nto `ycloud-integration-architect`; readiness, repository-maintenance, and issue-tracker prompts do\nnot trigger this skill.\n\nRead only `references/openapi.md` and `references/runtime.md` after selection.\nFor create requests, component editors, or template smoke tests, also read\n`references/create-examples.json`. If retry, idempotency, queueing, or error\ntranslation is requested, also read `references/shared/integration-boundaries.md`. The generated OpenAPI reference is\nthe contract index for the seven allowlisted template operations: create, list,\nretrieve, edit, delete-by-name, delete-by-name-and-language, and analytics. Use\nthe exact source-derived path, method, operationId, parameter, schema, response,\nand descriptions from the reference; do not guess names or paths from prose.\nFor template-list work, also read `references/shared/pagination-contract.md`.\nInterpret `allOf` as schema composition and `x-*` extensions or generated model\nnames as codegen hints, not additional lifecycle behavior.\nIf source hash, operation coverage, or reference content drifts, report the drift\nand stop.\n\n## Workflow\n\n1. Establish the user’s intended lifecycle operation and the target server-side\n   project context. Ask for missing language, framework, environment, or\n   template identity rather than inferring them.\n2. Match exactly one of the seven operations in the generated reference. Keep\n   lifecycle operations separate from message sending. Preserve source-defined\n   path parameters, request/response schemas, enum values, and description-only\n   constraints. Use the runtime reference for the shared Management API quota,\n   standard error envelope, request ID, pagination behavior, edit replacement\n   semantics, extensible status handling, and documented template error codes.\n   Do not fill gaps with imagined safe replay, idempotency, approval states,\n   delivery semantics, or analytics meanings.\n3. Generate raw HTTP or contract-aware typed request examples, or implement\n   project-local request construction when authorized, with placeholders\n   such as `<YCLOUD_API_KEY>`, `<TEMPLATE_NAME>`, `<LANGUAGE>`, and synthetic\n   values. Use an SDK-specific method only when a confirmed SDK artifact/version\n   and documentation are present in the user’s project; `operationId` is not an\n   SDK method name.\n   For the default create smoke test, use the documented\n   `utility-order-confirmation` fixture unchanged except for replacing\n   `<WABA_ID>` and, when collision avoidance is required, the template name.\n   Use the documented `authentication-copy-code` fixture for authentication\n   shape tests. `AUTHENTICATION`, `MARKETING`, and `UTILITY` are top-level\n   category values, never component types. Do not manufacture a kitchen-sink\n   request by adding one instance of every component enum; component\n   combinations have cross-field constraints and must come from a selected\n   documented example or a user-supplied valid design.\n   Keep `wabaId` as part of template identity across list, retrieve, and edit.\n   A UI or local route may encode a composite key, but its provider adapter must\n   preserve the exact `/whatsapp/templates/{wabaId}/{name}/{language}` path for\n   retrieve and edit; `name|language` alone is not a provider identity.\n   Keep template definition components separate from message-send parameters:\n   Generate template definitions using the canonical uppercase `CAROUSEL`,\n   `HEADER`, `BODY`, and `BUTTONS` spellings (including nested `buttons`).\n   Preserve case-insensitive parsing of definition component types, formats,\n   and button types; capitalization alone does not distinguish a definition\n   from a send payload. Route message parameter composition to\n   `ycloud-whatsapp-messages`, which generates the lowercase send component model.\n   For carousel create/edit fixtures, include 2..10 cards, a media `HEADER`\n   and a `BUTTONS` component containing 1..2 buttons per card. Supply media\n   examples as a non-empty `example.header_url` string array. The service uses\n   its first URL, which must be HTTP(S) with `.jpg`, `.jpeg`, or `.png` for\n   `IMAGE` and `.mp4` for `VIDEO`. If a card\n   includes `BODY`, its text must be non-blank and at most 160 characters.\n   The two-card minimum is a definition constraint, not a minimum count for\n   the parameter overrides included in a later send request.\n   Apply the same request validator before both sandbox storage and live\n   transport so live mode cannot bypass component/category/button validation.\n4. Keep API keys server-side and out of browser/mobile code, URLs, logs, source\n   control, and snippets. Do not read `.env`, secret stores, logs, customer\n   templates, or live analytics.\n5. For create/edit/delete, describe the planned change and its validation and\n   rollback considerations. An edit is a full content replacement: include all\n   components that must survive, and allow it only for `APPROVED`, `REJECTED`,\n   or `PAUSED`; never edit `ARCHIVED`. For list, use 1-based `page`, `limit`\n   1..100, and `includeTotal` only when a count is required; archived matches\n   remain visible. Parse the response as the merged Page envelope with required\n   `offset`, `limit`, `length`, template `items`, and optional `total`; `offset`\n   is response metadata, not a query parameter. Preserve unfamiliar status values and stop state-dependent\n   mutation rather than mapping them to a known state.\n6. Build synthetic tests for request/schema validation, full-replacement edits,\n   editable/archived/unknown status gates, pagination boundaries and optional\n   totals, path/query parameters, response mapping, and the selected lifecycle\n   branch. Create tests must assert that category values never appear in\n   `components[*].type` and that the selected documented example survives\n   request construction without extra components. Retrieve/edit tests must\n   assert that the captured provider path includes the WABA ID. Also test that\n   live and sandbox handlers reject the same invalid component payload before\n   transport. Do not call YCloud or alter a template.\n7. Treat create/edit/delete timeouts as ambiguous outcomes and never replay\n   automatically. Any project idempotency ledger, outbox, retry budget, or RFC\n   9457 response is local architecture, not a YCloud contract.\n\n## High-risk delete handling\n\nTreat both delete operations as high-risk. Stop before execution, state the\ntarget and potential impact, request explicit confirmation in a future approved\nworkflow, and outline a verification/rollback plan only where the source or\nproject facts support it. The MVP performs no delete, create, edit, or other\nexternal API action. Never imply that deleting a template withdraws or changes\nalready-submitted messages.\n\n## Outcome requirements\n\nAdapt the result to planning, implementation, or evaluation. Preserve these\ncontract and evidence outcomes:\n\n1. **Matched contract** — source hash, selected operation, exact path/method,\n   parameters, request/response schemas, and confirmed constraints.\n2. **Lifecycle plan** — placeholder raw HTTP or project-local construction and\n   the intended create/list/retrieve/edit/delete/analytics behavior.\n3. **Safety and integration placement** — server-side boundary, credential\n   handling, validation, and (for delete) high-risk confirmation stop.\n4. **Tests** — synthetic contract, mapping, and negative tests with no live call.\n5. **CANNOT** — unknown metrics or runtime behavior, unsupported operations,\n   unconfirmed SDK methods, missing project facts, and actions not performed.\n6. **Handoff** — route template message composition/sending to\n   `ycloud-whatsapp-messages`; return to Architect with each selected operation's\n   row status, changed or proposed artifacts, tests/results, lifecycle/status\n   preconditions, unknowns, and outgoing handoffs.\n\n## Non-goals\n\nDo not consume webhook payloads, verify signatures, upload media, send messages,\nread credentials, make unrequested local changes, or invoke a remote API. A\ntemplate lifecycle result is not a sent or delivered message; keep that\ndistinction in every example and handoff.\n"
}

SHA-256 of public snapshot: b149d4c924d834432ca98323de812b3dc0512f399c973ca5363b31bd6d07d14c