96 Commits

Author SHA1 Message Date
Elisabeth Rulke 95c744e7de [vercel-sandbox] rewrite skill as a comprehensive general Sandbox guide (#180)
* [vercel-sandbox] rewrite skill as a comprehensive general Sandbox guide

The published skill was a stale browser-automation recipe: it installed
packages with dnf on Amazon Linux (the default image is Ubuntu/apt) and
omitted persistence, regions, images, drives, network policy, credential
brokering, multi-agent, the CLI, and limits. Agents loading it were steered
wrong on the basics.

Rewrite skills/vercel-sandbox/upstream/SKILL.md into a full general Sandbox
skill covering the create/run/stop loop, auth, all create options, commands
(no shell, exit-code semantics), files, apt packages, ports and preview URLs,
persistence/sessions/hooks, snapshots, images, drives, network policy and
credential brokering, running AI agents via the AI Gateway, multi-agent
isolation, the CLI, limits, and a best-practice checklist. Add a summary
field to overlay.yaml as the injection-budget fallback.

Every claim is mapped to a vercel.com/docs/sandbox source or a live probe;
key runtime behaviors (non-zero exit does not throw, timeout rejects in
flight, default user is ubuntu) are BEHAVIOR_CONFIRMED against @vercel/sandbox
3.1.0. Regenerated skill build output and manifest.

* [vercel-sandbox] bump plugin version to 0.49.2

Skill content ships to users via a version bump (per #171). Bump the source
version in package.json and .claude-plugin/plugin.json, sync the per-harness
manifests (.cursor-plugin, .kimi-plugin, .plugin) and the telemetry hook
fallback, and regenerate build outputs. Addresses review feedback.
2026-09-13 13:44:56 -07:00
Vincent Derks df0f55213f Sync flags skill updates; bump to 0.49.1 (#171)
* Sync flags skill updates; bump to 0.49.1 (EXP-3444)

* Sync flags entities CLI guidance
2026-09-10 09:18:43 -04:00
MelkeyDev 358400ace0 adding skill invocation for plugin (#166)
* adding skill invocation for plugin

* Address review: namespace allowlist, skill:injected, harness tagging

- Only accept skills under the plugin's own namespaces (vercel, vercel-plugin);
  other-plugin:deploy, netlify:deploy, and bare slugs are dropped
- Emit skill:injected from the opt-in inject hooks via the same detached sender
- Persist the detected harness per session and attach plugin:agent_harness to
  every skill event batch
- Fix normalizeDetectedAgentHarness for AI_AGENT-style names
  (claude-code_<version>_agent was reporting as "other")
- Accept Cursor-shaped payloads (conversation_id) through compat normalizeInput
- Disable telemetry for the whole test suite via bunfig preload so hook tests
  never phone home

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-09-05 11:23:35 -07:00
Jerilyn Zheng 7b0a6f61b2 [skills] Refresh the AI Gateway skill (#162)
* [skills] Refresh the AI Gateway skill

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* [skills] Add AI Gateway CLI inventory, fixtures, and coding-agent validation

- Add a Vercel CLI inventory table to the ai-gateway skill covering
  api-keys, budgets, budget defaults, models, routing rules,
  coding-agents setup, and leaderboard
- Add a validate rule for the Claude Code footgun: ANTHROPIC_BASE_URL
  pointed at AI Gateway requires ANTHROPIC_API_KEY empty with the
  gateway key in ANTHROPIC_AUTH_TOKEN
- Add pattern fixtures for vercel ai-gateway commands and
  @ai-sdk/gateway installs
- Bump plugin version to 0.48.2

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* [skills] Cover AI Gateway dashboard and API surfaces added since refresh

- Model discovery documents the live /v1/models fields (type,
  modalities, tags, pricing, zdr/no_training) and the per-endpoint
  response (has_zdr, has_no_training, full and regional pricing,
  live uptime/latency/throughput), with a tested jq filter example
- Add service tiers, fast mode, model filtering (has), safety
  identifiers, and virtual model configs to the routing reference
- Add Usage & Billing endpoints (GET /v1/credits, GET /v1/generation)
  and generation ID capture to the spend reference
- Correct the pricing claim: some models price below provider list
  for every team, and volume discounts exist
- Correct spend alert recipients (owners and Billing role for team
  and project budgets) and document spend attribution plus the
  AI Gateway Budget Manager permission
- Note project-scoped Logs and CSV/JSON export, per-agent setup
  pages for coding agents, and the rules REST endpoints

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* [skills] Document reasoning across providers and API formats

- Add a reasoning section to the routing reference: discovery through
  the model's reasoning_options field, per-format parameters (AI SDK
  top-level reasoning, Chat Completions/Responses reasoning object,
  Anthropic thinking), cross-format effort and budget mapping, and
  per-provider usage reporting differences
- Call out the precedence footgun: providerOptions reasoning entries
  fully override the top-level reasoning option and are never merged
- Add the invariant to SKILL.md plus retrieval intent and prompt
  signal coverage

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* [skills] Document tool calling across API formats

- Add a tools section to the routing reference: discovery through the
  tool-use tag and supported_parameters, cross-format translation of
  tool schemas to the serving provider, per-format entry points, and
  web search as a built-in tool
- Add retrieval intent and prompt signal coverage

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* [skills] Document structured outputs and file attachments

- Structured outputs: json_schema response_format across formats,
  legacy json form, streaming accumulation, per-format pages
- File attachments: content-part arrays, image_url and file parts,
  discovery through modalities.input and vision/file-input tags
- Retrieval intents and prompt signals for both

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* [skills] Link the AI Gateway rate limits page from the 429 row

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* [skills] Link the AI Gateway FAQ page

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* [skills] Drop transcript capture from the observability reference

Content capture is not public yet.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* [skills] Address R-Taneja's review nits

- Single-quote the chainTo pattern scalar so spec-strict YAML parsers
  accept it
- Make the BYOK skip case-insensitive and let other keys precede
  gateway in providerOptions
- Use exact-match index() instead of array contains() in the jq
  example; verified it returns the same 76 models against the live
  catalog
- Separate CLI-configured agents from first-party-provider agents in
  the coding-agents reference so OpenCode and Pi no longer appear on
  both sides

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* [hooks] Unpin the telemetry test's plugin version and rebuild

The test asserted the literal 0.48.1 while the built hook inlines the
version from package.json at build time, so any version bump fails CI
with a green local run (the local build goes stale silently). The test
now reads .plugin/plugin.json, and hooks/telemetry.mjs is rebuilt for
0.48.2.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-01 10:58:42 -07:00
Ricardo Gonzalez 7f60d3237d [create-a-backend-skill] creating a skill for backends on vercel (#147)
* Add create-a-backend skill

* Refine create-a-backend metadata

* feedback

* db and ws

* Update skills/create-a-backend/SKILL.md

Co-authored-by: Yury Selivanov <yury@vercel.com>

* fixes

* front + back pair

* minor uptick

* docker and queues

* Sync telemetry with plugin version

* combinations

* combinations v2

* + flask

---------

Co-authored-by: Yury Selivanov <yury@vercel.com>
2026-08-20 12:47:45 -07:00
MelkeyDev 11c3258878 [Plugin] adding harness detection and install session ID (#136)
* adding plugin telemetry

* adding kimi and grok detection logic

* upticking version

* fixing headers

* adding harness calls

* fixing installing-id

* fixing detect agent logic to include more

* fixing await to not block other calls
2026-08-12 14:43:51 -07:00
Ricardo Gonzalez 12d077072a [services] Add Vercel Services skill (#134)
* Add Vercel Services skill

* Prepare Services skill release; bump to 0.47.0

* Reframe Services skill around coupled-components use case

Lead with when Services is the right call (tightly coupled frontend +
backend in one project) and its concrete benefits: skew protection,
synced previews, atomic deploys and rollbacks, private bindings. The
separate-projects escape hatch is now about independent deploy cadence.

Drop framework pinning from examples, add /api namespace-split guidance
(SPA vs frameworks with their own API routes), prefix stripping via
service-scoped rewrite, SPA catch-all to /index.html, and a subdomain
section with the preview-environment caveat.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Make :path prefix capture optional so bare /api matches

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Warn against destination.path instead of teaching it

The proxy only reads destination.service when dispatching into a
service; the path field is compiled and validated but never consumed
at request time.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Spell out the private-by-default rule for services

No top-level rewrite means a service is unreachable from the public
internet and only accessible through bindings; adding a rewrite makes
it public regardless of bindings.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Drop frontend from the backend+vercel prompt signal group

Review feedback: the frontend term made the group miss backend-led
phrasings. The wider [backend, vercel] group can reach the threshold
with anyOf hits, which we accept for now.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Rework retrieval intents and examples

Intents: one line per job the skill teaches, anchored by domain
vocabulary (services, binding, rewrites, vercel.json) rather than
product-name prefixes, and covering the private-by-default, subdomain,
and prefix-stripping content added in this PR.

Examples: verbatim-style prompts carrying stack names (FastAPI, Vite,
Express, Go) and symptom phrasings, which is what the lowest-weight
retrieval field is for.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Remove 'frontend' option from skill manifest

Removed 'frontend' from the 'anyOf' array in skill manifest.

* Drop frontend from anyOf in skill source, not just the manifest

The manifest is generated from SKILL.md, so removing the term only
from generated/skill-manifest.json left the two out of sync and
failed the manifest check.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-08-07 11:19:15 -07:00
MelkeyDev 1e821f3087 [Plugin] Adds a new skill for deployment protection (#130)
* Adding new deployment protection skill

* bumping plugin versoin

* fixing token access preview

* fixing skill to have header and request header
2026-07-31 15:18:55 -07:00
Jathin Pranav Singaraju c9b1d8ff93 [marketplace] fix skill shadowed by command + discover-first routing (#107)
* feat(marketplace): discover-first commerce routing + provisioning guidance

Make the model reliably reach for the Marketplace when an app needs an
external service, instead of hardcoding a provider from memory.

- knowledge-update (always-injected at session start): add a discover-first
  directive — load the `marketplace` skill, then discover + provision a real
  integration BEFORE planning/writing code/asking.
- marketplace SKILL.md: broaden the description (commerce/payments/etc. as the
  catch-all for capabilities without a dedicated skill); restructure into
  discover -> install -> build with an anti-mock/anti-punt rule; add a
  Recommendations section keyed on the product-catalog test (commerce vs
  payments), with no hardcoded providers (discover names them).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(marketplace): remove command that shadowed the skill; tighten routing

The `marketplace` skill and `/marketplace` command shared a name, so the
command shadowed the skill — Skill(vercel:marketplace) loaded the command's
runbook instead, and the skill's routing guidance never reached the model.

Remove the command (marketplace is skill-only, like the other capabilities)
so the skill loads, and tighten routing: discover-first flow, a preferred-
provider table (commerce -> Shopify, payments -> Stripe), and a slimmer
knowledge-update that points at the skill.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* chore(release): patch-bump plugin manifests to 0.45.1

Backwards-compatible fix (marketplace skill routing); bump the version in
all three shipped manifests (.claude-plugin, .cursor-plugin, .plugin).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-01 12:18:42 -07:00
MelkeyDev 375ea4c515 Adding Eve Skill (#104)
* adding eve skill

* fixing generated skills
2026-06-29 09:53:03 -07:00
Tim White b73bc95636 feat: add microfrontends skill (#97)
* feat: add microfrontends skill

Adds the `microfrontends` skill (SKILL.md + 6 reference docs covering
configuration, path-routing, local development, management, security,
and troubleshooting) for building, configuring, and deploying
microfrontends on Vercel.

Triggering covers the common entry points:
- pathPatterns: microfrontends.json / apps/*/microfrontends.json
- bashPatterns: `vercel microfrontends` / `vercel mf`, and
  npm/pnpm/bun/yarn install of @vercel/microfrontends
- importPatterns: @vercel/microfrontends

Regenerates generated/skill-manifest.json and generated/skill-catalog.md
(now 27 skills) and updates the vercel.md ecosystem graph.

Rebased onto current main as a single signed commit (supersedes #35).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* docs(microfrontends): trim reference boilerplate

Lowest-risk size reduction with no loss of factual content:
- Remove Table-of-Contents blocks from local-development, managing-
  microfrontends, and troubleshooting references. No other skill's
  reference files use a ToC (0 of 51 repo-wide) — these were the only
  outliers; removal aligns with house convention. Section anchors are
  unaffected, so in-doc links still resolve.
- Tighten security.md: dedupe repeated "verified only by…" prose and
  collapse repeated full URLs. All 13 original links preserved.

Net: -64 lines across 4 reference files. References are loaded on demand
(grep), not part of the injected SKILL.md budget, so this is a read-cost
and maintainability win, not an injection-size change.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* chore: bump version for all providers; bump to 0.44.0

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* test: update telemetry version assertions to 0.44.0

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-09 08:21:42 +01:00
MelkeyDev 1edb125d13 Adding new active session telemetry (#83) 2026-05-15 20:51:00 -07:00
Julia Shi e6cbaf4d1d Add Vercel metrics CLI guidance 2026-05-07 00:19:10 +01:00
melkeydev 16aaf2d68d upticking version number 2026-04-30 11:14:18 -07:00
melkeydev a2c094f036 Adding back telemetry for vercel plugin 2026-04-28 11:34:42 -07:00
melkeydev aa13859ab0 uptick version 2026-04-10 12:39:14 -07:00
MelkeyDev e30174330a Merge branch 'main' into uptick-version-0.32.5 2026-04-10 07:49:54 -07:00
melkeydev 0b19919486 finishing uptick merge conflict 2026-04-10 07:49:17 -07:00
melkeydev 1e254b83ea upticking the version 2026-04-10 07:47:23 -07:00
melkeydev 6f4e7dc177 uptick version 2026-04-09 16:31:00 -07:00
melkeydev d8b5e5d770 one more change 2026-04-09 16:25:35 -07:00
melkeydev 83e958a07a removing vercel labs to vercel 2026-04-09 16:17:47 -07:00
melkeydev 86b6ad8155 Adding .claude-code 2026-04-09 15:39:30 -07:00
melkeydev 850f891dd0 uptick versions 2026-04-09 12:33:17 -07:00
melkeydev 969eae3f41 removing telemetry 2026-04-09 11:26:28 -07:00
melkeydev 92e501ec0c uptick version numbers 2026-04-06 11:03:51 -07:00
melkeydev 4d4ed0d15b uptick version 2026-04-02 09:46:03 -07:00
melkeydev 44417d3786 uptick CC version 2026-04-01 11:32:34 -07:00
melkeydev a8aef0120f fixing generated and uptick version 2026-03-30 12:27:42 -07:00
melkeydev 63a1008b4b uptick versions 2026-03-23 11:14:30 -07:00
melkeydev eab4da0aba fixing readme and CI 2026-03-22 15:51:45 -07:00
melkeydev 3fe23669ec version bump 2026-03-18 22:08:17 -07:00
melkeydev 3c50276108 fixing telemetry to be base tracking and anonymous 2026-03-18 10:46:28 -07:00
melkeydev 87b8d0f6bb updating prompt telemetry 2026-03-16 12:33:36 -07:00
melkeydev c649033060 removing vercel-lab references 2026-03-16 11:14:28 -07:00
melkeydev fbc2cb7e86 Bump version to 0.20.0 2026-03-15 21:26:40 -07:00
melkeydev 61b2838afb updating cursor plugin requirements 2026-03-12 14:10:55 -07:00
John Lindquist 8e3350454c feat: prompt scoring improvements, compaction re-injection, validation dedup, strip droppedByCap from context; bump to 0.18.0
- Add dominant-topic suppression (top score >= 600 filters scores < 50)
- Add project-context boost (+3 for VERCEL_PLUGIN_LIKELY_SKILLS skills)
- Add lexical fallback floor (reject raw score < 20)
- Add compaction re-injection for priority >= 7 skills (VERCEL_PLUGIN_CONTEXT_COMPACTED)
- Add validation rule dedup tracking (ruleId + filePath on violations)
- Strip droppedByCap from injected HTML comments (kept in debug logs)
- Fix ncc/SKILL.md and next-forge/SKILL.md YAML frontmatter
- Add startup diagnostic for broken skill frontmatter
2026-03-11 19:01:59 -06:00
John Lindquist b7e9b1b053 feat: merge upstream telemetry + Cursor compat, fix tests and dedup migration; bump to 0.17.0 2026-03-11 16:12:55 -06:00
John Lindquist 7a124e6561 Add sitemap field to skill metadata: parse metadata.sitemap in skill-map-frontmatter.mts, add sitemap to SkillConfig interface and KNOWN_KEYS, render sitemap URLs in buildDocsBlock() alongside doc links, include sitemap in generated manifest, and add sitemap URLs to 35 SKILL.md files for domains that have sitemap.xml. Also fix 15 broken doc URLs across 14 skills (vercel.com/docs path changes, anthropic docs, stripe, descope, flags-sdk, ai-sdk). Bump to 0.16.1. 2026-03-10 14:31:40 -06:00
John Lindquist 5dffded3d5 Replace skill body injection with Skill tool invocation; bump to 0.16.0
Instead of injecting full SKILL.md bodies as additionalContext, hooks now
inject "You must run the Skill(<name>) tool." — leveraging the conventional
Skill tool mechanism for context loading.
2026-03-10 12:46:54 -06:00
John Lindquist 5948eb1497 Scan every skills/*/SKILL.md file for documentation URLs, HTTP-check each one for 404s, and replace broken links with verified live alternatives. Broken URLs found: vercel.com/docs/marketplace → /docs/integrations, vercel.com/docs/marketplace/sign-in-with-vercel → /docs/sign-in-with-vercel, vercel.com/docs/functions/middleware → /docs/routing-middleware, vercel.com/docs/getting-started → /docs/getting-started-with-vercel, vercel.com/docs/infrastructure/runtime-cache → /docs/runtime-cache, vercel.com/docs/content → /docs/solutions/cms, vercel.com/docs/queues/api-reference → /docs/queues/api, vercel.com/docs/security/secure-backend-access/oidc-federation → /docs/oidc, vercel.com/docs/workflow/flags → /docs/feature-flags, flags-sdk.dev/docs/upgrade-guide → github.com/vercel/flags upgrade-to-v4.md, ai-sdk.dev/docs/reference/types/ui-message → /docs/reference/ai-sdk-core/ui-message, docs.anthropic.com/en/docs/claude-code/agent-tool-use → /sub-agents, docs.descope.com/sdks/nextjs → /getting-started/nextjs, docs.stripe.com/libraries/node → /sdks, vercel.com/blog/ncc → github.com/vercel/ncc. Rebuild manifest. Bump to 0.15.1. 2026-03-10 12:32:09 -06:00
John Lindquist b8b233995c feat(skills): broaden trigger patterns for 7 under-injected skills based on eval findings; add next-forge skill; bump to 0.15.0
Eval analysis of 9 real sessions showed 10 skills never triggering despite being
requested. Root causes: pathPatterns too narrow (agents write to lib/email-template.tsx
not emails/), promptSignals containing regex instead of plain text (vercel-sandbox),
and missing promptSignals entirely (v0-dev, vercel-firewall).

Skills updated: email, vercel-queues, edge-runtime, vercel-firewall, chat-sdk,
v0-dev, vercel-sandbox. New skill: next-forge (bootstrap detection).
2026-03-09 17:56:23 -06:00
John Lindquist 0c49abc547 fix(skills): quote YAML validate patterns ending with colon to fix js-yaml parse errors; bump to 0.14.1 2026-03-09 16:38:11 -06:00
John Lindquist 92dbe3ae02 feat(hooks): add SubagentStart/SubagentStop hooks for subagent skill injection; bump to 0.14.0
- SubagentStart bootstrap hook injects project context (likely skills, summaries) into spawned subagents
  with budget scaling by agent type (minimal for Explore/Plan, standard for general-purpose)
- SubagentStop sync hook writes agent metadata to a session-scoped JSONL ledger for observability
- SessionEnd cleanup extended to remove subagent ledger files
- Updated ai-elements/nextjs skills, benchmark-agents and eval skill definitions
2026-03-09 15:52:56 -06:00
John Lindquist f15a7d6889 feat(eval): ai-elements validate rules, broader workflow promptSignals, wider chat pathPatterns; bump to 0.13.0
- ai-elements: add PostToolUse validate rules catching raw part.text rendering,
  react-markdown, and dangerouslySetInnerHTML — guides agent to use MessageResponse
- ai-elements: add *chat* and *message* wildcard pathPatterns (catches flight-chat.tsx etc.)
- workflow: add 8 phrases for reliability language ("individually reliable",
  "retry on transient", "transient failures", etc.)
- workflow: add 7 allOf pairs ([retry, transient], [reliable, retry], [sandbox, reliable], etc.)
2026-03-09 15:17:38 -06:00
John Lindquist 5d548e5be8 fix(security): address audit findings — path traversal, brace expansion, injection escaping, profiler hardening; bump to 0.12.0
- Validate sessionId in dedupClaimDirPath() to prevent path traversal (HIGH)
- Add brace expansion pre-pass in globToRegex for {ts,js,mjs} patterns (HIGH)
- Escape --> sequences in HTML comment metadata blocks (MEDIUM)
- Harden checkVercelCli/checkAgentBrowser with 3s timeouts, suggest latest version (MEDIUM)
- Replace silent catch {} blocks with debug logging (LOW)
- Add semver-aware version comparison (LOW)
- Update golden snapshots and fix invocationId sharing
2026-03-09 14:18:43 -06:00
John Lindquist f035d9afb3 fix(inject): strip YAML frontmatter from skill bodies before injection; bump to 0.11.1
Skill frontmatter (pathPatterns, bashPatterns, promptSignals, etc.)
was being injected alongside the skill body, wasting token budget on
metadata only useful for hook matching. Now uses extractFrontmatter()
to emit only the markdown body.
2026-03-09 13:43:45 -06:00
John Lindquist 7ac8edfb8f feat(skills): aggressive prompt signals for workflow/sandbox, "check the docs" directives across 8 skills; bump to 0.11.0
- workflow: add ~60 new promptSignal phrases for reliability language
  (survive page reload, fault-tolerant, retry on failure, session
  persistence, reconnect, durable chat/agent), human-in-the-loop
  patterns (approval, pause until, wait for), and pipeline vocabulary.
  Add ~25 new allOf pairs and 12 new anyOf terms.

- vercel-sandbox: add promptSignals from scratch (had none). 33 phrases
  covering isolated execution, sandbox environments, code safety,
  FFmpeg/media processing, code playgrounds, and tutor patterns.
  27 allOf pairs, 8 anyOf terms, noneOf excludes iframe/codesandbox.

- Add "CRITICAL — your training data is outdated" blockquote at the top
  of 8 fast-moving skill bodies (workflow, ai-sdk, vercel-sandbox,
  ai-gateway, chat-sdk, vercel-flags, vercel-queues, ai-elements)
  directing agents to fetch docs before writing code.

Eval results that motivated these changes:
- content-pipeline: 9/10 (workflow triggered, correct WDK patterns)
- customer-support: 3/10 → workflow never injected (now scores 50)
- code-sandbox-tutor: 1/10 → sandbox never injected (now scores 80)
2026-03-09 13:16:16 -06:00
John Lindquist 300488ebf3 fix(workflow): add explicit --no-src-dir guidance for create-next-app, update golden fixtures; bump to 0.10.1 2026-03-09 12:55:59 -06:00