App-store audit: fixed submissions for kinetic, rentahuman, dial, deadsimple, docker, aegis - #126
Closed
Alexgodoroja wants to merge 13 commits into
Closed
Alexgodoroja wants to merge 13 commits into
Alexgodoroja wants to merge 13 commits into
Conversation
A byo app whose users create their key on the provider's site had no way to hand that key to the adapter short of editing $APP/secrets.json by hand and restarting the app. The new set_key step generates a local <ns>.set_key method that caches a caller-supplied key (overwriting, so a revoked key can be replaced) and is read per request like any minted key. Calls made before a key exists soft-fail with a hint naming set_key and where to get a key. The activation hint is now step-aware: it previously told agents to call the signup method with no arguments even for register flows that need an email. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Apps whose key comes from a signup route wrap every http method in requireKey, so endpoints the provider serves without credentials (method catalogues, recommendations, the signup handshake itself) were unreachable until a key existed. A route marked public: true is forwarded as-is. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ed broker 1.0.0 shipped as a managed app, but the broker never had a Kinetic master key or registration, so every call failed with "unknown app". Kinetic submitted it as a bring-your-own-token app and issues self-serve kp_live_ tokens, so 1.0.1 goes direct to api.kineticpricing.com: - kinetic.set_key saves the account holder's token; calls made before it return a hint naming set_key instead of a 401 - kinetic.signup_start/status/complete drive Kinetic's agent-assisted signup - method_list, method_recommend, offer_list and research stay keyless - method_recommend takes the decision enum the API now requires; the old demo passed free text and failed validation - demo and next steps drop the Pilot $5 budget and kinetic.balance, which only exist for managed apps Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Docker shipped Linux bundles only, so every macOS install was refused. macOS can't run dockerd, so the darwin assets carry the official static docker CLI and a dockerctl that finds the running engine (Docker Desktop, OrbStack, colima, Rancher Desktop or /var/run/docker.sock). engine_start reports what it found or how to start one; engine_stop is a no-op. The Linux bundles are unchanged, and the version stays 29.6.1 to match upstream Docker. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
deadsimple.signup answered "address": "" because it read the default data.address; agent-signup returns the inbox at data.inbox.email. Agents had to call list_inboxes to learn the address they had just been given. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The app shipped AEGIS 0.1.3 for darwin/arm64 and linux only, so Intel Macs could not install it, and upstream has since released 0.1.4 (adversarial hardening). 0.1.4's official release binaries cover all four platforms; they are repackaged unmodified (Linux builds are static) on the artifact registry. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Upstream Docker 29.8.1, all four platforms. engine_start used to go straight to the bundled dockerd, which needs root, while the standard installer runs the pilot daemon as a normal user, so it failed on ordinary Linux hosts even when Docker was already running. It now uses a running engine first (system or rootless Docker, DOCKER_HOST, or on macOS Docker Desktop, OrbStack or colima), starts the bundled dockerd only as root, and otherwise says how to get an engine. engine_stop leaves engines it didn't start alone. The help text no longer embeds the builder's home directory, and the tarballs carry no macOS extended attributes. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
0.2.0 was built on Rent A Human's partner API through a managed broker entry that was never registered (no master key; partner access is enterprise-gated), so every call failed with "unknown app". 0.3.0 goes back to the surface the vendor submitted: the public REST API at rentahuman.ai/api with a self-serve X-API-Key. - rentahuman.set_key saves the user's rah_ key; calls made before it return a hint naming set_key instead of a 401 - search_humans, get_human, get_reviews, browse_services, availability and the new list_bounties are keyless - hiring, booking, escrow and QA methods are the vendor's, unchanged - new demo and next-steps graph (the vendor spec had neither) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… endpoint
Some providers issue the API key in the body of an ordinary call rather than
through a signup flow the generator knows: Dial returns it once from
/auth/verify (existing account) or /auth/verify-number (new account). Those
apps forwarded the key to the agent in plain JSON and never stored it, so
every later call was unauthenticated.
A route with save_key: {path, secret_key, start} now caches the string at
path into $APP/secrets.json on a 2xx answer, replaces it in the reply, and
counts as the app's key-minting route: other calls soft-fail with a hint that
points at start until a key exists, and send the key once it does.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Dial now requires new accounts to verify a phone number a human owns before it issues an API key, so 0.1.0's signup -> verify stopped at a registrationId and every call stayed 401. 0.1.0 also returned keys to the agent in plain JSON and never stored them. - new dial.register_number and dial.verify_number complete new-account signup - dial.verify (sign-in to an existing account) and dial.verify_number save the key they issue on this host via http.save_key and redact it - dial.set_key saves an existing sk_live_ key - signup methods are public; other calls made before a key return a hint naming dial.signup - next steps route verify -> register_number -> verify_number -> status Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… the key Dial issues its key from /auth/verify (existing account) or /auth/verify-number (new account); naming only the first sent new users to the wrong step. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Collaborator
Author
|
Duplicate of #125 (same branch, opened from a parallel session). Closing. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Submission updates from the app-store audit. Builds on #124 (the
set_key,public, andsave_keygenerator features); merge that first and this diff shrinks to the six submissions.unknown appset_keyforkp_live_tokens, Kinetic's agent-assisted signup, keyless catalogue/recommend/research. Also fixes themethod_recommendenum the old demo got wrongunknown appX-API-Key;set_key; keyless search, browse and bounties; new demo and next-stepsregister_numberandverify_number;save_keystores the key and redacts it from the reply;set_keyfor existing keyssignupreturned"address": ""address_path: data.inbox.emailengine_startfailed on any host where the daemon isn't root, even with Docker runningVerified
verify-submissionand the demo/next-steps gates are green; demo scores are 95–100.bundles/<id>/<ver>/, and native assets under<id>/<ver>/, each fetched back and sha-checked.Not verifiable without accounts
The catalogue entries are in the matching pilotprotocol PR.
🤖 Generated with Claude Code