feat(skills): discover service recommendations in the backend - #3683
Open
AbigailDeng wants to merge 3 commits into
Open
AbigailDeng wants to merge 3 commits into
AbigailDeng wants to merge 3 commits into
Conversation
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Selecting a Skill should proactively identify services the caller may need. This backend change adds authenticated
GET /api/skills/service-recommendations?skillName=..., returning advisory evidence and exact personal/organization UserService instances. It never selects services or changes grants.Targets
feature/integrate. Only backend contracts, implementation, tests and API documentation are included. The Channels consumer is delivered separately in #3679 againstfeat/2026-08-04_workflow-activity-vnext. Related issue: #3678. Deploy this endpoint before the complete console experience is available; the console keeps manual selection usable if discovery is unavailable.Ownership and behavior
AI.Abstractions.Skillsowns protobuf contracts;AI.Core.Skillsowns recommendation policy behindISkillServiceDiscoverySource.recommended_skillsassociation, or a whole service name/slug mention in the description/root instructions. Skill content is treated as data and never executed. All recommendations are advisory; existing APIs do not declare exhaustive mandatory dependencies. Literal matching may miss aliases or include incidental mentions.Cache-Control: no-store.docs/contracts/skill-service-recommendations.mddocuments the endpoint, layering, caller isolation, evidence limits and separate integration paths.Local verification
Validated on backend base
7f6a24572(origin/feature/integrate):All passed: 34 provider/client tests (6 new discovery cases and 28 existing Ornn client cases), 3 new endpoint tests, architecture guards including docs lint (95 files), test stability guards including 9 meta-tests, and whitespace checks. The test commands compiled affected backend projects, including Mainnet Host.
The nine new backend cases cover evidence precedence and exact instance identity, mismatched Skill identity, missing root instructions, unavailable catalog, cancellation, caller isolation, HTTP mapping, authentication/input rejection and retryable errors. Existing repository compiler/analyzer warnings remain outside this change. No live deployment or authenticated end-to-end smoke test was performed.
NyxID conformance
The endpoint registration changes digest-pinned Mainnet Host source, so the Aevatar manifest is mechanically refreshed to source commit
3da66b8813c03a7b1d87616889dd3ff343dcde1a. Assistant behavior, evaluation evidence and its fixed external source pins are unchanged.The independent current-main wire baseline is reviewed against NyxID
301fbe732a0f20a3c674184e7ea3408ab62968ab. The six changed upstream files preserve Aevatar's consumed authorization/route contracts. The renamedvalidate_catalog_credentialstill parses token-exchange credentials against declared fields; its new call and retained body are checked. Direct/node bearer forwarding moved intoproxy_service::forwarded_caller_token, whose owner file and both call sites are now covered. API-key scoped inventory and read-only key listing are also explicitly checked. No production adapter change is needed, and the workflow continues to check current upstreammain.docs/contracts/nyxid-code-execution-conformance/v1/README.mdrecords each reviewed surface and consumer impact. The service-recommendation contract clarifies that restricted Agent Keys see scoped inventory, so an absent instance does not prove the account lacks a connection.Additional local verification (all passed): 114 API/route-admission cases, 88 code-execution/durable-transport cases, 23 conformance/semantic guard cases, both local conformance modes, docs lint (95 files), and whitespace checks.
The wire checkout is pinned to the reviewed upstream commit for local reproduction; GitHub continues to fetch
main. Both conformance modes were rerun after committing. The earlier source-pin correction also passed the architecture guard after commit in CI's PR range mode:GITHUB_EVENT_NAME=pull_request GITHUB_BASE_REF=feature/integrate PATH="/opt/homebrew/opt/python@3.12/libexec/bin:/Users/abigaildeng/.dotnet:$PATH" bash tools/ci/architecture_guards.shGitHub verified the updated head
2c31b0bc2: current-main-wire-drift and pinned-source-drift both passed. The original conformance failure is resolved.