An autonomous skill worker needs to upload new skills and publish new versions on skills it owns or has an explicit write grant for, without receiving package/version deletion or skill-management authority. Today ornn:skill:update also authorizes permissions, ownership, visibility, bindings, source changes, deprecation, and dist-tag management for an owner; dist-tag DELETE also uses that permission.
Add ornn:skill:publish as a narrow, additive permission for ZIP upload and content updates. Reuse existing object write grants for the skill boundary. Allow explicit public visibility only at creation so a worker can create usable recommendations without a separate human publishing step; preserve the private default and existing callers. A publish-only caller must not change an existing skill's visibility, including through multipart update.
The dedicated worker role contains ornn:skill:read and ornn:skill:publish only. Package/version/tag deletion, ACL/ownership/visibility changes, service binding, skillsets, generation and playground execution remain unavailable to that role. NyxID separately confines the credential to Ornn and recommendation changes on exact granted admin services.
Validation must exercise the actual routes with a service-account subject and explicit object grants, verify all management/deletion denials even on owned skills, and preserve existing create/update behavior. Update the permission catalog and OpenAPI contract. No general per-key permission ceiling or proxy wrapper is needed.
Related to #1123 and #1127.
An autonomous skill worker needs to upload new skills and publish new versions on skills it owns or has an explicit write grant for, without receiving package/version deletion or skill-management authority. Today
ornn:skill:updatealso authorizes permissions, ownership, visibility, bindings, source changes, deprecation, and dist-tag management for an owner; dist-tag DELETE also uses that permission.Add
ornn:skill:publishas a narrow, additive permission for ZIP upload and content updates. Reuse existing object write grants for the skill boundary. Allow explicit public visibility only at creation so a worker can create usable recommendations without a separate human publishing step; preserve the private default and existing callers. A publish-only caller must not change an existing skill's visibility, including through multipart update.The dedicated worker role contains
ornn:skill:readandornn:skill:publishonly. Package/version/tag deletion, ACL/ownership/visibility changes, service binding, skillsets, generation and playground execution remain unavailable to that role. NyxID separately confines the credential to Ornn and recommendation changes on exact granted admin services.Validation must exercise the actual routes with a service-account subject and explicit object grants, verify all management/deletion denials even on owned skills, and preserve existing create/update behavior. Update the permission catalog and OpenAPI contract. No general per-key permission ceiling or proxy wrapper is needed.
Related to #1123 and #1127.