{"id":27634,"plugin_id":"plugin_asdk_app_6ac3d7b5fe88819198d51c023f1e8e96","kind":"skill","collection_source":"plugin_package","comparison_source":null,"observed_at":"2026-10-07T18:03:12.648Z","digest":"2e7949d81aba3c5683bb8ac007859186903f2d833e8648d1267c65f18ad00fa1","against":null,"payload":{"description":"Set up a Kapa S3 source so files in a bucket are ingested. Use when the user wants Kapa to answer from documents stored in S3 or an S3-compatible bucket.","included_files":[],"name":"kapa-setup-s3","skill_md_contents":"---\nname: kapa-setup-s3\ndescription: Set up a Kapa S3 source so files in a bucket are ingested. Use when the user wants Kapa to answer from documents stored in S3 or an S3-compatible bucket.\n---\n\n# Set up S3\n\nWorks with any S3-compatible provider, not just AWS.\n\n## 1. Create the source\n\n`create_s3_source` with `project` and `name`. Keep the returned id.\n\n## 2. Configure it\n\n`set_s3_config` with `source_s3`, `bucket_name`, `endpoint_url`,\n`aws_access_key_id` and `aws_secret_access_key`.\n\n- `endpoint_url` is **required even for plain AWS**, such as\n  `https://s3.us-east-1.amazonaws.com`. Agents habitually omit it.\n- `region_name` is needed by most providers. Use `us-east-1` when the provider\n  has no regions.\n- `prefix` limits the source to one folder, such as `docs`, with no leading or\n  trailing slash. Leaving it out ingests the whole bucket.\n\nBoth keys are the user's secrets: ask for them, never invent them. Mention\nthat the credential only ever needs read access to that one bucket, so they\ncan scope it accordingly if they want to.\n\n## 3. Check the bucket before saving\n\n`validate_s3_config` with the bucket, endpoint and keys confirms Kapa can\nreach it. It answers `{\"is_valid\": bool, \"message\": str}`.\n\n**Show the message on a failure before blaming the keys.** It runs three\nchecks: the endpoint and bucket, the credential's permissions, and whether an\n`index.json` in the bucket is well formed. A malformed `index.json` reads\nidentically to a bad credential unless the message is read. That file is\noptional and maps objects to public URLs for citations.\n\n## Finish the job\n\nSaving the configuration starts ingestion. There is no separate publish step,\nso once the config saves the source is live.\n\nThen call `list_sources` with `project_id` to confirm what the project holds.\n\n## Shared Kapa workflow rules\n\nTools act as the connected user with that user's project permissions. Resolve the intended project and use only authorized data. Do not invent credentials, source IDs, filters, or tool results. Check the available tool schema before passing arguments.\n\nExplain and obtain approval for ingestion and its quota cost before saving a configuration that starts ingestion or calling `start_crawl`; existing explicit approval for that exact action is sufficient. Ask the user to choose source scope and filters. Validate credentials and discover accessible content before saving. Keep credentials out of visible results, logs, and exported artifacts. Use a secure credential input if the host provides one.\n\nFor a web source, preview the exact configuration and inspect the extracted article content before ingestion. Report queued, running, failed, and completed states accurately. If uncertain about Kapa behavior, use `search_kapa_docs` when available.\n"},"changes":[],"summary":"First saved snapshot. No earlier version is available for comparison.","summary_kind":"deterministic","summary_metadata":{}}