{"id":27142,"plugin_id":"plugin_asdk_app_6abff028aac08191a6b14836de724ac5","kind":"skill","collection_source":"plugin_package","comparison_source":null,"observed_at":"2026-10-06T18:05:19.926Z","digest":"2ce8f21f7009de41c31913f6d0fd2bab1f1f59e1f2c4efd68723e538124f7861","against":null,"payload":{"description":"Hand a finished report or proposal to a client at a private link. Use when the user says \"send this to the client\", \"share this with <company>\", \"this is for a customer\", or is handing a polished deliverable to someone outside their team. Produces a page in the Client deliverable shape (a clean editorial \"sheet\" prepared-for-a-named-recipient), gates it to the recipient, removes the auto-expiry so the link stays live, and refuses to ship if the page leaks PII.","included_files":[],"name":"stacktree-deliverable","skill_md_contents":"---\nname: stacktree-deliverable\ndescription: 'Hand a finished report or proposal to a client at a private link. Use when the user says \"send this to the client\", \"share this with <company>\", \"this is for a customer\", or is handing a polished deliverable to someone outside their team. Produces a page in the Client deliverable shape (a clean editorial \"sheet\" prepared-for-a-named-recipient), gates it to the recipient, removes the auto-expiry so the link stays live, and refuses to ship if the page leaks PII.'\n---\n\n# stacktree-deliverable\n\nPublish a client-facing deliverable to **stacktr.ee** and return a private link the\nclient can open in a browser, no account needed. This is the publish path for the\n`client-deliverable` job: work that leaves the building and should look finished,\nstay reachable, and only open for the intended recipient.\n\n## When to invoke\n\n- User is handing a finished artifact to a named client or customer (\"send this to\n  Acme\", \"this goes to the client tomorrow\").\n- The page is a deliverable, not a scratch draft: a proposal, audit, report, or\n  pitch.\n- The recipient is outside the user's own org and will not have a Stacktree account.\n\nFor an agent-generated report meant for \"anyone with the link\", use\n`stacktree-agent-run-report`. For a dated digest refreshed in place, use\n`stacktree-daily-brief`. For a public status page, use `stacktree-status-dashboard`.\n\n## The page shape\n\nProduce a single self-contained HTML document in the Client deliverable shape: a\ncentered white `.sheet` with a `.topbar` (the studio/sender name on the left, a\n`.pill` reading \"Private deliverable\" on the right), then a `.pad` body with an\n`.eyebrow` \"Prepared for <Client>\", an `<h1>` title, a `.lede`, and a `.meta` row\n(prepared by, date, version). Use `.section` blocks for Overview, the one\nrecommendation (in a `.callout`), an at-a-glance `<dl>`, and next steps\n(`<ol class=\"steps\">`). Close with a `.foot`. The published page is what the client\nsees, so the craft is the point: keep it editorial, content-first, no broken\nassets. The canonical reference is the `client-deliverable` template in the\nStacktree app (`apps/web/src/templates.ts`); match its structure and restraint.\n\n## Account\n\nThe Stacktree tools in this plugin publish under the user's own Stacktree\naccount, so they keep ownership and can revoke the link later. If the tools are\nnot connected yet, ask the user to connect Stacktree rather than publishing any\nother way.\n\n## The judgment this skill encodes\n\n1. **It must not auto-delete.** Publish with `--expires-never` (or `set_expiry` to\n   never). A link that 404s a week after you send it is worse than not sending it.\n   Only set an expiry if the user wants access to lapse on purpose (e.g. \"this quote\n   is valid 30 days\"), then set it to that date, not the 7-day default.\n\n2. **It must be gated to the recipient, not the whole internet.** The unlisted token\n   alone is \"anyone with the link\", and links get forwarded. Pick the gate from what\n   the user has:\n   - **Recipient email or company domain known:** use the email gate\n     (`set_email_gate`). The client enters their email, gets a one-time code, and is\n     in. This ties access to a person and gives the user a record of who opened it.\n   - **Only a side channel (the user will pass a secret over Slack/SMS):** use a\n     password (`--password` or `set_password`). Generate a strong one, never reuse\n     the user's own secrets, and surface it on its own line so it travels separately\n     from the link.\n   The template's footer line (\"This link is unguessable. Add a password if it\n   should be.\") is the prompt: act on it, do not ship a bare link for a real\n   deliverable unless the user says \"anyone with the link is fine\".\n\n3. **It must not leak PII.** Keep the PII scan in `block` mode (the default). Client\n   deliverables are exactly where an embedded API key, internal thread, or customer\n   record does real damage. If the scan trips, stop and show the user what it caught\n   before relaxing anything. Only drop to `--pii-check warn` when the user confirms\n   the flagged content is intentional and safe (e.g. the client's own contact\n   details on the proposal).\n\n4. **The URL can read as professional.** A raw `stacktr.ee/p/<token>/` link is fine\n   and private, but for an external deliverable a custom domain (e.g.\n   `proposals.theiragency.com`) reads better. A custom domain is set up in the\n   Stacktree dashboard, not with a tool, and depends on the account's plan. Do not\n   block the hand-off on it; ship the private link now and mention the domain as a\n   follow-up.\n\n## Steps\n\n1. Build the deliverable as a complete HTML document in the page shape above. If you\n   only have Markdown or a fragment, wrap and style it so it renders standalone.\n2. Decide the gate from what the user has. If unclear, ask one short question: \"Do\n   you have the client's email, or will you send them a password separately?\"\n3. Publish with `publish_html`, `expires_in_hours: 'never'`, and the PII scan on\n   (the default). Capture the `id` and `url`.\n4. Apply the gate:\n   - Email gate: `set_email_gate` on the returned id with the client's email or\n     `@their-domain.com`.\n   - Password: pass `password` to `publish_html` in step 3, or call\n     `set_password` after. Prefer generating the password over asking the user\n     to invent one.\n5. For a draft the client should review, call `set_client_feedback` with\n   `comments: true` (skip it for a final, signed deliverable). The client selects\n   words or clicks an image, chart or video and comments, with no account. Own the\n   loop: pull their comments with `list_feedback`, apply the changes with\n   `update_site` so the revision lands at the link they already have (its response\n   says which open comments no longer match the page), then `resolve_feedback` each\n   answered item with a short note: the client sees it next to their comment.\n6. Reply with: the link, the gate type and how the client gets in (the allowed\n   email/domain, or the password on its own line), the fact that it will not expire,\n   and any PII warning that was surfaced.\n   If the page has a page video (the owner adds one from the dashboard), the link\n   ending `#watch` opens straight into it, and the dashboard gives a picture of it\n   to paste into the email above that link.\n\n## What to tell the user\n\nState plainly who can open it (the gate), that the link will stay live, and what the\nPII scan caught if anything. If they wanted a custom domain, say it is set up in\nthe Stacktree dashboard rather than holding up the hand-off.\n"},"changes":[],"summary":"First saved snapshot. No earlier version is available for comparison.","summary_kind":"deterministic","summary_metadata":{}}