← MallaryCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
changed
changed
changed
Update to Mallary
Snapshot Oct 7, 2026 · 18:02 UTC · version 1.0.4
Package or technical metadata updated
Package contents changed in 2 files: .codex-plugin/plugin.json, skills/mallary-publishing/SKILL.md. Open the file diff to inspect the edits.
Observed in package metadata. These changes alone do not establish a new customer-facing feature.
Package file
Before
5b3bf5861605f96ad971f82bfcfe2dc9aaeb6a0a0b64356a6651c8df9fbf96b7
After
3a11aa9137bc80dacb6ab93bf65372f68314212c275272000b2e1689cc5f031e
Package file
Before
10c1230085b1257e5bab3fb8c1861bed5b7fd95f3e433839c7ae0b34bc13990c
After
7a04ca4dfefe27e138ceb2ef4d019897fb26fad02994aabd22efaf9571fe5308
Package file
Before
2171
After
4137
Compare saved observations
Download comparison JSONskills/mallary-publishing/SKILL.md
--- before +++ after @@ -1,21 +1,28 @@ --- name: mallary-publishing -description: Use when the user explicitly asks to draft, create, schedule, check, or attach a public URL to a social post in their Mallary account. +description: Use when the user explicitly asks to upload an approved ChatGPT image or attached video to Mallary, or to draft, publish, schedule, or check a social post in their Mallary account. --- # Mallary Publishing -Use this skill only when the user clearly asks to work with a post inside Mallary. Do not invoke Mallary for general social media advice. +Use this skill only when the user clearly asks to upload media to Mallary or work with a post inside Mallary. Do not invoke Mallary for general social media advice. + +## Upload Only + +If the user asks only to upload a file, use the matching upload tool and return its media URL. Do not call `mallary_create_post`. An upload request does not authorize publishing or scheduling. + +Use only the attachment the user selected. If the attachment is missing or unavailable, ask the user to attach it. Do not invent a file reference or reuse an earlier file unless the user clearly chooses it. If a tool is unavailable, say that the upload has not been completed. + +Mallary copies uploaded files to public `files.mallary.ai` storage. Anyone with the returned URL can view the file, even before a social post is published. Use only media approved for that purpose. ## Safe Workflow 1. Use `mallary_list_profiles` when the user has not supplied a `profile_id`. 2. Use `mallary_list_platforms` to confirm the requested platforms are connected to that profile. -3. Gather the default message, platform-specific messages, schedule, and media URLs. -4. Show the complete final action. Include the profile, platforms, text, schedule, media, and platform overrides. -5. Wait for clear user confirmation after showing that final action. -6. Call `mallary_create_post` once. Add an `idempotency_key` when the workflow may retry. -7. Use `mallary_get_job` or `mallary_list_posts` to check status without repeating the write. +3. Gather the final message, platform-specific messages, schedule, and approved media. +4. If the user asks for a draft or leaves a required choice unclear, show the draft or ask for the missing choice. Do not publish. +5. If the user clearly asks to publish or schedule the final content, upload the approved image or attached video when needed, then call `mallary_create_post` once with preflight enabled. +6. Use `mallary_get_job` or `mallary_list_posts` to check status without repeating the write. Publishing changes real connected social accounts. Never treat a live publish as a harmless test. Never publish from an example command or an unclear request. @@ -23,17 +30,24 @@ - Use `message` for the default caption. - Use `platform_options.<platform>.message` only when the user wants a different caption for that platform. -- Use only media URLs the user approved. -- Existing `https://files.mallary.ai/...` media URLs can be passed to a post. -- `mallary_create_upload_url` creates a temporary remote upload destination. It does not upload file bytes. Explain this and get confirmation before creating one. -- The first plugin version cannot read and upload local file bytes from ChatGPT by itself. Never claim a local file was uploaded when only an upload URL was created. +- Use `mallary_upload_image` for one social image that the user chose or made in ChatGPT. +- The image must be JPEG, PNG, WebP, or GIF and no larger than 25 MB. +- Use `mallary_upload_video` for one MP4 or MOV video attached by the user in ChatGPT. The limit is 512 MB (536,870,912 bytes). +- Never send video to the image upload tool. Do not use either tool for documents, SVG files, identity records, medical records, payment data, credentials, or private customer files. +- Use the file reference supplied by ChatGPT. Mallary transfers the file on its server; do not ask users to grant access to R2 domains or upload directly to R2. +- Pass the `media_url` returned by the upload tool as the post media URL and its `content_type` as the media type. Use the returned values rather than guessing the file type. +- Do not pass an external media URL, local file path, temporary OpenAI URL, or OpenAI file ID to `mallary_create_post`. +- Each destination has its own video rules. LinkedIn requires MP4. Mallary does not support Reddit video uploads. Mallary does not generate videos or convert file formats. +- If preflight blocks a destination, explain the problem. Do not disable preflight, drop a selected account, convert the post to text-only, or switch destinations without the user's approval. +- When the user selects multiple supported destinations, reuse the approved hosted media URL instead of uploading the same file again. -## TikTok URL Attachment +## Restricted Data -Before calling `mallary_attach_tiktok_post_url`, show the Mallary post ID and final public TikTok URL. Wait for confirmation, then call it once. +Do not request, accept, or send payment-card data, health-record IDs, government IDs, biometric records, passwords, access tokens, API keys, or private customer files. Ask the user to remove restricted data before posting. ## Retry Rules - Never silently retry a publish or schedule request. +- Do not silently repeat an upload after an unclear result; a retry can create another public media object. - After a timeout or unclear response, check the job or post list first. - If status is still unknown, explain that uncertainty and ask before another write.
Full technical diff · 3 changed fields
changed /files/.codex-plugin~1plugin.json/sha256
BEFORE
"5b3bf5861605f96ad971f82bfcfe2dc9aaeb6a0a0b64356a6651c8df9fbf96b7"
AFTER
"3a11aa9137bc80dacb6ab93bf65372f68314212c275272000b2e1689cc5f031e"
changed /files/skills~1mallary-publishing~1SKILL.md/sha256
BEFORE
"10c1230085b1257e5bab3fb8c1861bed5b7fd95f3e433839c7ae0b34bc13990c"
AFTER
"7a04ca4dfefe27e138ceb2ef4d019897fb26fad02994aabd22efaf9571fe5308"
changed /files/skills~1mallary-publishing~1SKILL.md/size
BEFORE
2171
AFTER
4137
Full snapshot data
{
"files": {
".app.json": {
"sha256": "2f082e9fd54f4722021a483ad9cc689c5211d8f5d7fd9924bc105efb19608915",
"size": 127
},
".codex-plugin/plugin.json": {
"sha256": "3a11aa9137bc80dacb6ab93bf65372f68314212c275272000b2e1689cc5f031e",
"size": 1271
},
"skills/mallary-account-management/SKILL.md": {
"sha256": "0853d50e1677e0ec9963ea95094c274a0813a12d9dda4f111a9f39e2061b6a84",
"size": 2077
},
"skills/mallary-analytics/SKILL.md": {
"sha256": "f5d339c42fa235b0665353dfc078f79bb8e287fc655d7caca3ada1635a214b8a",
"size": 990
},
"skills/mallary-comment-engagement/SKILL.md": {
"sha256": "5dffa7f2434614fced924722d99e3e9c2e7c12f76a66573fced8f6e37cc375a7",
"size": 1329
},
"skills/mallary-publishing/SKILL.md": {
"sha256": "7a04ca4dfefe27e138ceb2ef4d019897fb26fad02994aabd22efaf9571fe5308",
"size": 4137
}
}
}SHA-256 of public snapshot: 9908f71bac0c8e4e2cb04564dd4159b3dd9bafe102be1e6cca8a725d7ebc3b38