* [vercel-sandbox] rewrite skill as a comprehensive general Sandbox guide
The published skill was a stale browser-automation recipe: it installed
packages with dnf on Amazon Linux (the default image is Ubuntu/apt) and
omitted persistence, regions, images, drives, network policy, credential
brokering, multi-agent, the CLI, and limits. Agents loading it were steered
wrong on the basics.
Rewrite skills/vercel-sandbox/upstream/SKILL.md into a full general Sandbox
skill covering the create/run/stop loop, auth, all create options, commands
(no shell, exit-code semantics), files, apt packages, ports and preview URLs,
persistence/sessions/hooks, snapshots, images, drives, network policy and
credential brokering, running AI agents via the AI Gateway, multi-agent
isolation, the CLI, limits, and a best-practice checklist. Add a summary
field to overlay.yaml as the injection-budget fallback.
Every claim is mapped to a vercel.com/docs/sandbox source or a live probe;
key runtime behaviors (non-zero exit does not throw, timeout rejects in
flight, default user is ubuntu) are BEHAVIOR_CONFIRMED against @vercel/sandbox
3.1.0. Regenerated skill build output and manifest.
* [vercel-sandbox] bump plugin version to 0.49.2
Skill content ships to users via a version bump (per #171). Bump the source
version in package.json and .claude-plugin/plugin.json, sync the per-harness
manifests (.cursor-plugin, .kimi-plugin, .plugin) and the telemetry hook
fallback, and regenerate build outputs. Addresses review feedback.
* adding skill invocation for plugin
* Address review: namespace allowlist, skill:injected, harness tagging
- Only accept skills under the plugin's own namespaces (vercel, vercel-plugin);
other-plugin:deploy, netlify:deploy, and bare slugs are dropped
- Emit skill:injected from the opt-in inject hooks via the same detached sender
- Persist the detected harness per session and attach plugin:agent_harness to
every skill event batch
- Fix normalizeDetectedAgentHarness for AI_AGENT-style names
(claude-code_<version>_agent was reporting as "other")
- Accept Cursor-shaped payloads (conversation_id) through compat normalizeInput
- Disable telemetry for the whole test suite via bunfig preload so hook tests
never phone home
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* [skills] Refresh the AI Gateway skill
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* [skills] Add AI Gateway CLI inventory, fixtures, and coding-agent validation
- Add a Vercel CLI inventory table to the ai-gateway skill covering
api-keys, budgets, budget defaults, models, routing rules,
coding-agents setup, and leaderboard
- Add a validate rule for the Claude Code footgun: ANTHROPIC_BASE_URL
pointed at AI Gateway requires ANTHROPIC_API_KEY empty with the
gateway key in ANTHROPIC_AUTH_TOKEN
- Add pattern fixtures for vercel ai-gateway commands and
@ai-sdk/gateway installs
- Bump plugin version to 0.48.2
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* [skills] Cover AI Gateway dashboard and API surfaces added since refresh
- Model discovery documents the live /v1/models fields (type,
modalities, tags, pricing, zdr/no_training) and the per-endpoint
response (has_zdr, has_no_training, full and regional pricing,
live uptime/latency/throughput), with a tested jq filter example
- Add service tiers, fast mode, model filtering (has), safety
identifiers, and virtual model configs to the routing reference
- Add Usage & Billing endpoints (GET /v1/credits, GET /v1/generation)
and generation ID capture to the spend reference
- Correct the pricing claim: some models price below provider list
for every team, and volume discounts exist
- Correct spend alert recipients (owners and Billing role for team
and project budgets) and document spend attribution plus the
AI Gateway Budget Manager permission
- Note project-scoped Logs and CSV/JSON export, per-agent setup
pages for coding agents, and the rules REST endpoints
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* [skills] Document reasoning across providers and API formats
- Add a reasoning section to the routing reference: discovery through
the model's reasoning_options field, per-format parameters (AI SDK
top-level reasoning, Chat Completions/Responses reasoning object,
Anthropic thinking), cross-format effort and budget mapping, and
per-provider usage reporting differences
- Call out the precedence footgun: providerOptions reasoning entries
fully override the top-level reasoning option and are never merged
- Add the invariant to SKILL.md plus retrieval intent and prompt
signal coverage
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* [skills] Document tool calling across API formats
- Add a tools section to the routing reference: discovery through the
tool-use tag and supported_parameters, cross-format translation of
tool schemas to the serving provider, per-format entry points, and
web search as a built-in tool
- Add retrieval intent and prompt signal coverage
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* [skills] Document structured outputs and file attachments
- Structured outputs: json_schema response_format across formats,
legacy json form, streaming accumulation, per-format pages
- File attachments: content-part arrays, image_url and file parts,
discovery through modalities.input and vision/file-input tags
- Retrieval intents and prompt signals for both
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* [skills] Link the AI Gateway rate limits page from the 429 row
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* [skills] Link the AI Gateway FAQ page
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* [skills] Drop transcript capture from the observability reference
Content capture is not public yet.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* [skills] Address R-Taneja's review nits
- Single-quote the chainTo pattern scalar so spec-strict YAML parsers
accept it
- Make the BYOK skip case-insensitive and let other keys precede
gateway in providerOptions
- Use exact-match index() instead of array contains() in the jq
example; verified it returns the same 76 models against the live
catalog
- Separate CLI-configured agents from first-party-provider agents in
the coding-agents reference so OpenCode and Pi no longer appear on
both sides
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* [hooks] Unpin the telemetry test's plugin version and rebuild
The test asserted the literal 0.48.1 while the built hook inlines the
version from package.json at build time, so any version bump fails CI
with a green local run (the local build goes stale silently). The test
now reads .plugin/plugin.json, and hooks/telemetry.mjs is rebuilt for
0.48.2.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
* adding plugin telemetry
* adding kimi and grok detection logic
* upticking version
* fixing headers
* adding harness calls
* fixing installing-id
* fixing detect agent logic to include more
* fixing await to not block other calls
* Add Vercel Services skill
* Prepare Services skill release; bump to 0.47.0
* Reframe Services skill around coupled-components use case
Lead with when Services is the right call (tightly coupled frontend +
backend in one project) and its concrete benefits: skew protection,
synced previews, atomic deploys and rollbacks, private bindings. The
separate-projects escape hatch is now about independent deploy cadence.
Drop framework pinning from examples, add /api namespace-split guidance
(SPA vs frameworks with their own API routes), prefix stripping via
service-scoped rewrite, SPA catch-all to /index.html, and a subdomain
section with the preview-environment caveat.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* Make :path prefix capture optional so bare /api matches
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* Warn against destination.path instead of teaching it
The proxy only reads destination.service when dispatching into a
service; the path field is compiled and validated but never consumed
at request time.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* Spell out the private-by-default rule for services
No top-level rewrite means a service is unreachable from the public
internet and only accessible through bindings; adding a rewrite makes
it public regardless of bindings.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* Drop frontend from the backend+vercel prompt signal group
Review feedback: the frontend term made the group miss backend-led
phrasings. The wider [backend, vercel] group can reach the threshold
with anyOf hits, which we accept for now.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* Rework retrieval intents and examples
Intents: one line per job the skill teaches, anchored by domain
vocabulary (services, binding, rewrites, vercel.json) rather than
product-name prefixes, and covering the private-by-default, subdomain,
and prefix-stripping content added in this PR.
Examples: verbatim-style prompts carrying stack names (FastAPI, Vite,
Express, Go) and symptom phrasings, which is what the lowest-weight
retrieval field is for.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* Remove 'frontend' option from skill manifest
Removed 'frontend' from the 'anyOf' array in skill manifest.
* Drop frontend from anyOf in skill source, not just the manifest
The manifest is generated from SKILL.md, so removing the term only
from generated/skill-manifest.json left the two out of sync and
failed the manifest check.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* feat(marketplace): discover-first commerce routing + provisioning guidance
Make the model reliably reach for the Marketplace when an app needs an
external service, instead of hardcoding a provider from memory.
- knowledge-update (always-injected at session start): add a discover-first
directive — load the `marketplace` skill, then discover + provision a real
integration BEFORE planning/writing code/asking.
- marketplace SKILL.md: broaden the description (commerce/payments/etc. as the
catch-all for capabilities without a dedicated skill); restructure into
discover -> install -> build with an anti-mock/anti-punt rule; add a
Recommendations section keyed on the product-catalog test (commerce vs
payments), with no hardcoded providers (discover names them).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
* fix(marketplace): remove command that shadowed the skill; tighten routing
The `marketplace` skill and `/marketplace` command shared a name, so the
command shadowed the skill — Skill(vercel:marketplace) loaded the command's
runbook instead, and the skill's routing guidance never reached the model.
Remove the command (marketplace is skill-only, like the other capabilities)
so the skill loads, and tighten routing: discover-first flow, a preferred-
provider table (commerce -> Shopify, payments -> Stripe), and a slimmer
knowledge-update that points at the skill.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
* chore(release): patch-bump plugin manifests to 0.45.1
Backwards-compatible fix (marketplace skill routing); bump the version in
all three shipped manifests (.claude-plugin, .cursor-plugin, .plugin).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
* feat: add microfrontends skill
Adds the `microfrontends` skill (SKILL.md + 6 reference docs covering
configuration, path-routing, local development, management, security,
and troubleshooting) for building, configuring, and deploying
microfrontends on Vercel.
Triggering covers the common entry points:
- pathPatterns: microfrontends.json / apps/*/microfrontends.json
- bashPatterns: `vercel microfrontends` / `vercel mf`, and
npm/pnpm/bun/yarn install of @vercel/microfrontends
- importPatterns: @vercel/microfrontends
Regenerates generated/skill-manifest.json and generated/skill-catalog.md
(now 27 skills) and updates the vercel.md ecosystem graph.
Rebased onto current main as a single signed commit (supersedes #35).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* docs(microfrontends): trim reference boilerplate
Lowest-risk size reduction with no loss of factual content:
- Remove Table-of-Contents blocks from local-development, managing-
microfrontends, and troubleshooting references. No other skill's
reference files use a ToC (0 of 51 repo-wide) — these were the only
outliers; removal aligns with house convention. Section anchors are
unaffected, so in-doc links still resolve.
- Tighten security.md: dedupe repeated "verified only by…" prose and
collapse repeated full URLs. All 13 original links preserved.
Net: -64 lines across 4 reference files. References are loaded on demand
(grep), not part of the injected SKILL.md budget, so this is a read-cost
and maintainability win, not an injection-size change.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* chore: bump version for all providers; bump to 0.44.0
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* test: update telemetry version assertions to 0.44.0
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Instead of injecting full SKILL.md bodies as additionalContext, hooks now
inject "You must run the Skill(<name>) tool." — leveraging the conventional
Skill tool mechanism for context loading.
Eval analysis of 9 real sessions showed 10 skills never triggering despite being
requested. Root causes: pathPatterns too narrow (agents write to lib/email-template.tsx
not emails/), promptSignals containing regex instead of plain text (vercel-sandbox),
and missing promptSignals entirely (v0-dev, vercel-firewall).
Skills updated: email, vercel-queues, edge-runtime, vercel-firewall, chat-sdk,
v0-dev, vercel-sandbox. New skill: next-forge (bootstrap detection).
- SubagentStart bootstrap hook injects project context (likely skills, summaries) into spawned subagents
with budget scaling by agent type (minimal for Explore/Plan, standard for general-purpose)
- SubagentStop sync hook writes agent metadata to a session-scoped JSONL ledger for observability
- SessionEnd cleanup extended to remove subagent ledger files
- Updated ai-elements/nextjs skills, benchmark-agents and eval skill definitions
Skill frontmatter (pathPatterns, bashPatterns, promptSignals, etc.)
was being injected alongside the skill body, wasting token budget on
metadata only useful for hook matching. Now uses extractFrontmatter()
to emit only the markdown body.