← RevylCONTENT HISTORY

Update to Revyl

Snapshot Sep 30, 2026 · 23:15 UTC · version 0.1.0

Collection source: not recorded for this historical snapshot.

WHAT CHANGED · RULE-BASED ANALYSIS

First saved snapshot

No earlier snapshot is available to establish a change.

Compare saved observations

Download comparison JSON
Full technical diff · 0 changed fields
Full snapshot data
{
  "name": "revyl-codex-proof-ci",
  "description": "Verify a mobile pull request using an exact-SHA match among its app's recent CI-uploaded Revyl builds, collect device evidence, and prepare a proof summary without rebuilding.",
  "included_files": [],
  "skill_md_contents": "---\nname: revyl-codex-proof-ci\ndescription: Verify a mobile pull request using an exact-SHA match among its app's recent CI-uploaded Revyl builds, collect device evidence, and prepare a proof summary without rebuilding.\n---\n\n# Revyl Codex Proof from CI Builds\n\nUse this skill only for an authorized proof of a pull request whose artifact\nwas already uploaded by CI. It does not build, upload, or configure an app.\n\n## Launcher and authorization\n\nResolve the launcher from this skill's own absolute directory before changing\nto the app directory. On POSIX use `../../scripts/launch-revyl`; on Windows use\n`../../scripts/launch-revyl.cmd`. Invoke that absolute launcher for **every**\nRevyl command; never use `revyl` from `PATH`, `PLUGIN_ROOT`, or another\ninstalled CLI.\n\n```sh\nSKILL_DIR=\"<absolute directory containing this SKILL.md>\"\nLAUNCHER=\"$(cd \"$SKILL_DIR/../../scripts\" && pwd)/launch-revyl\"\n\"$LAUNCHER\" --version\n\"$LAUNCHER\" auth status\n```\n\n```bat\nREM Windows cmd.exe\nset \"SKILL_DIR=<absolute directory containing this SKILL.md>\"\nset \"LAUNCHER=%SKILL_DIR%\\..\\..\\scripts\\launch-revyl.cmd\"\n\"%LAUNCHER%\" --version\n\"%LAUNCHER%\" auth status\n```\n\nUse normal `\"$LAUNCHER\" auth login` only when authentication is needed. An\nexisting environment secret may be used without placing its value in a command,\nchat, or artifact. Do not run credential-provisioning or secret-bridge\ncommands. Post the normal login approval URL as a clickable link and wait for\napproval; do not claim that a browser opened.\n\nBefore starting a device or another paid action, require authorization naming\nthe app, environment, and paid operation. Resolve the pull request's **full**\nhead SHA and platform from read-only PR, repository, and user context; ask only\nwhen ambiguous. Do not treat a short SHA, branch name, or version label as a\nmatch. Run from the app directory that owns `.revyl/config.yaml` so the\nproject's existing launch configuration applies.\n\n## Proof loop\n\n1. Find a CI-uploaded build whose `metadata.scm_head_sha` exactly equals the\n   full PR SHA. For example:\n\n   ```sh\n   \"$LAUNCHER\" build list --app <app-id> --json\n   ```\n\n   This pinned CLI lists only the newest 20 versions and does not expose\n   pagination. A match in this window is usable; no match does not establish\n   that the artifact is absent. While the named CI upload is pending, make at\n   most three retries, ten seconds apart. If no exact match arrives, stop and\n   report **proof not run: recent-build lookup incomplete**. Explain the\n   20-version limit, without claiming a full-history search. Do not invent\n   pagination flags, bypass CLI authentication, rebuild, re-upload, or use an\n   unrelated artifact as a fallback.\n2. With explicit authorization, start a device on the matching build and save\n   its exact session ID:\n\n   ```sh\n   \"$LAUNCHER\" device start --build-version-id <matching-build-id> --json\n   ```\n\n   Return the viewer URL immediately as a clickable link when one is present.\n   Exercise only the changed behavior. Target every device command with\n   `-s <session-id>`, save concise screenshots, and open each screenshot before\n   describing it. A false or missing semantic verdict is a failed proof, but\n   still stop that exact session with `\"$LAUNCHER\" device stop -s <session-id>`.\n   Never use global cleanup.\n3. Obtain a report with `\"$LAUNCHER\" device report -s <session-id> --json` and\n   report success only when a matching device session produced the evidence. A\n   missing device session is never a passed proof.\n\n## Reporting and publication\n\nWhen an authorized PR-comment surface is available, use that surface to add or\nupdate the proof. Otherwise return a ready-to-post draft headed\n`## Revyl device proof` with the full SHA, matching build ID, device result,\nand only the evidence actually collected.\n\nSession sharing and screenshot/report publication are separate external\nactions. Run `session share` or `session publish` only after the user explicitly\napproves publication and its audience; otherwise keep the evidence local and\nreturn the draft without public links. Never include credentials, launch-var\nvalues, or signed URLs.\n"
}

SHA-256: 15bf9bf08fb697194c51b3f7d93abc4597b81b2d5b14836e259888315a77f531