OR Key
drop another .md file to compare - side-by-side diff against box

box

Connects your assistant to your Box files and storage.
description: "Triggers on prompt mention of 'box'."
personal 2 files

What it does for you

Connects your assistant to your Box files and storage.

What it produces

A recent result, so you can see the kind of work it returns.

loading…

How to get it

These run inside the Snappy workspace. Want this working in your business? I set skills like this up with you, in one focused week.

Work with me
For developers how this skill is built, graded, and how it runs

at a glance- the short version

actorExported functions in state/lib/box.ts.
auditorNone wired yet - eval is manual (Robert review).
eval modeshape
categoryIntegrations
stages3
dependssettings

what's inside - the parts that make up a skill 3/4 present

A skill is just a few plain-text files. Only the main one is required. The rest are optional, added as the work needs them. This is what the skill is made of; how it runs is just below.

The skill
state/skills/box/SKILL.md present
the skill itself, in plain text
The main file. It says what the skill is and lays out the steps in plain English.
Code
state/lib/box.ts present
code the skill can run
Reusable code this skill can call when it needs to.
Scripts
state/bin/box/ not present
helper scripts
Optional. Added when a skill has a few commands to run.
Loader
state/skills/box/AGENTS.md present
what the AI loads on the fly
Loaded automatically the moment this skill is needed. Kept short on purpose.

how it's graded - what counts as a good run 4 criteria · 4 deterministic

Each row is one thing a good run has to get right. deterministic means a quick check decides, pass or fail. judge means the AI reads the result and rates it. Grading each piece on its own (instead of one overall score) shows exactly where a run fell short, so the fix is obvious.

name
kind
check
box_result_nonzero
deterministic
Called function returns non-empty/non-null result. listRoutes returns array with length > 0. runSql/callRoute return object with data fields. deploy returns {status, ...}.
http_200_success
deterministic
Box server HTTP response code is 200/201 (success). No timeout, connection refused, or 5xx errors in logs.
result_matches_api
deterministic
Result schema matches Box REST API. Routes array includes {id, path, ...}. SQL result includes rows or affected_count. callRoute returns the endpoint response.
eval_row_persisted
deterministic
state/log/evals.ndjson or state/log/pending-eval.ndjson receives row with skill='box', score, and result summary.

how it runs - the shared frame every skill uses 4/5 present

Every skill runs the same way. One part does the work, a separate part checks it, and a short loader hands the AI exactly what it needs for the job. Anything this skill doesn't use shows a one-line note saying why, on purpose, not by accident.

makes the work The worker
present
Exported functions in state/lib/box.ts. the worker
Does the actual work. Whatever it produces is what gets checked next.
checks the work The reviewer
present
None wired yet - eval is manual (Robert review). the checker
A separate checker grades the work, so the part that made it can't approve its own work.
frame
learns Self-correction
not present

This skill doesn't fix its own gaps yet.

tidies up Background fixes
present
queued for rewrite runs in the background
Bigger fixes that can't be made on the spot get queued and rewritten in the background later.
remembers Run history
present
state/log/pending-eval.ndjson pending runs
Every run is written down here, then reviewed by hand each week.
Critical rules the things this skill must not get wrong
  1. NEVER hardcode the box URL or token - read via env() from state/lib/env.ts
  2. runSql and deploy are write-effect - surface them through a scope/apply gate, never auto-fire

what it has learned - fixes written back in over time sample

When a run hits something this skill didn't handle, the fix gets written back into the skill so it doesn't happen again. FIXED means it was corrected on the spot. LOGGED means it's queued for a bigger rewrite. Either way, the skill gets a little better and never makes the same mistake twice.

  1. Loading feedback rows…

how the work flows- who makes it, who checks it

inputs settings
actor Exported functions in state/lib/box.ts.
1 generator
invoke
actor = Exported functions in state/lib/box.ts.
import { listRoutes, runSql, deploy, callRoute } from "state/lib/box.ts"
auditor None wired yet - eval is manual (Robert review).
2 auditor
inspect
auditor = None wired yet - eval is manual (Robert review).
npx tsx -e 'import("/Users/robertboulos/projects/snappy-os/state/lib/box.ts").then(m => console.log(Object.keys(m)))'
3 data
eval log
`state/log/pending-eval.ndjson` (skill: "box")

SKILL.md- the skill, written out in plain English

box

Box server HTTP API for all snappy-* skills.

Ported from kernel snappy-box in Phase 0.5. See state/lib/box.ts for the full API surface.

Steps

  • listRoutes() - see state/lib/box.ts
  • runSql() - see state/lib/box.ts
  • deploy() - see state/lib/box.ts
  • callRoute() - see state/lib/box.ts

Eval

Actor: the exported functions in state/lib/box.ts. Auditor: none wired yet - eval is manual (Robert review). File a state/log/pending-eval.ndjson row on each run.

Score convention:

OutcomeScore
Pass on first try1.0
Failed first, auto-fix applied, re-check passed0.5
Still failing or unrecoverable0.0

Gotchas

via the Phase 0.5 driver. Only these rewrites were applied: already in state/lib/)

  1. realpathSync(process.argv[1]) CLI guard wrapped in try/catch
  • See the kernel SKILL.md for the original long-form guidance if you need it

(read-only reference at the kernel path above).

Graduation

This skill is prose. Graduate by defining a deterministic auditor and flipping eval: auto.

Rubric

criteria:
  - name: box_result_nonzero
    kind: deterministic
    check: "Called function returns non-empty/non-null result. listRoutes returns array with length > 0. runSql/callRoute return object with data fields. deploy returns {status, ...}."
  - name: http_200_success
    kind: deterministic
    check: "Box server HTTP response code is 200/201 (success). No timeout, connection refused, or 5xx errors in logs."
  - name: result_matches_api
    kind: deterministic
    check: "Result schema matches Box REST API. Routes array includes {id, path, ...}. SQL result includes rows or affected_count. callRoute returns the endpoint response."
  - name: eval_row_persisted
    kind: deterministic
    check: "state/log/evals.ndjson or state/log/pending-eval.ndjson receives row with skill='box', score, and result summary."

AGENTS.md- what the AI loads when this skill comes up

box - loader

Per-turn rules for the box skill. Full reference: state/skills/box/SKILL.md. Do not skip these.

Critical Rules

_(no failures recorded yet - Phase 0.5 mechanical port from kernel snappy-box. Read state/skills/box/SKILL.md and state/lib/box.ts before invoking.)_

  • NEVER hardcode the box URL or token - read via env() from state/lib/env.ts
  • runSql and deploy are write-effect - surface them through a scope/apply gate, never auto-fire

Commands

| ui model | live composition via compose_inline, persisted as artifact lang_body, reopened with OpenArtifact | |invoke: import { listRoutes, runSql, deploy, callRoute } from "state/lib/box.ts" |verify: npx tsx -e 'import("/Users/robertboulos/projects/snappy-os/state/lib/box.ts").then(m => console.log(Object.keys(m)))' |eval log: state/log/pending-eval.ndjson (skill: "box")

Known Pitfalls

  • Phase 0.5 port - only mechanical rewrites applied
  • Kernel SKILL.md at ~/projects/snappy-kernel/skills/snappy-box/ is the long-form reference

Self-Test

An agent reading this should correctly:

  1. [ ] Treat runSql and deploy as write-effect (gate before applying)
  2. [ ] Read URL/token via env(), not bash fallback
  3. [ ] Use state/lib/box.ts, not raw fetch()

<!-- kernel-ok: Phase 0.5 port pointer - kernel SKILL.md reference is a historical long-form link, not an active dependency -->

Found a gap? Edit this file. <!-- footer-injection-point -->

api.ts- the code it can call

#!/usr/bin/env npx tsx
/**
 * snappy-box/api.ts -- Box server HTTP API for all snappy-* skills.
 *
 * Required env vars (set in .env.cache):
 *   SNAPPY_BOX_URL        - Base URL of your box server, e.g. http://192.168.1.10:8080
 *   BOX_API_KEY           - API key for x-api-key auth
 *
 * Optional env vars:
 *   SNAPPY_BOX_SSH_TARGET - SSH target for retrieving BOX_API_KEY, e.g. user@192.168.1.10
 *
 * If SNAPPY_BOX_URL is not set, all box calls return a feature-unavailable message.
 *
 * Boundary: box = the Box self-editing server (routes, SQL, deploy routes).
 *   snappy-deploy = trigger Vercel/Fly deployments.
 *   snappy-infra = health probes + SSH to box.
 *
 * Usage:
 *   npx tsx api.ts routes                  # list deployed routes
 *   npx tsx api.ts sql "SELECT 1"          # run SQL query
 *   npx tsx api.ts call GET /pulse         # call any route
 *
 * Or import as module:
 *   import { listRoutes, runSql, deploy, callRoute } from "./box.ts";
 */

import { env } from "./env.ts";
import { realpathSync } from "fs";

const BOX_URL: string | null = process.env.SNAPPY_BOX_URL ?? null;

function apiKey(): string {
  return env("BOX_API_KEY", false);
}

async function box(
  path: string,
  options?: { method?: string; body?: unknown }
): Promise<unknown> {
  if (!BOX_URL) {
    throw new Error(
      "[snappy-box] feature unavailable: set SNAPPY_BOX_URL=http://your-box:port in .env.cache"
    );
  }

  const key = apiKey();
  if (!key) {
    const sshTarget = process.env.SNAPPY_BOX_SSH_TARGET ?? "<box-host>";
    throw new Error(
      "[snappy-box] BOX_API_KEY not in .env.cache. " +
      `Retrieve via: ssh ${sshTarget} "/usr/local/bin/docker exec box-box-1 printenv BOX_API_KEY". ` +
      "Set SNAPPY_BOX_URL and SNAPPY_BOX_SSH_TARGET to point at your box."
    );
  }

  const res = await fetch(`${BOX_URL}${path}`, {
    method: options?.method || "GET",
    headers: {
      "x-api-key": key,
      ...(options?.body ? { "Content-Type": "application/json" } : {}),
    },
    body: options?.body ? JSON.stringify(options.body) : undefined,
  });

  const text = await res.text();
  try {
    return JSON.parse(text);
  } catch {
    if (!res.ok) throw new Error(`Box ${path} failed (${res.status}): ${text}`);
    return text;
  }
}

// --- Public API ---

/** List all deployed routes. */
export async function listRoutes() {
  return box("/_routes");
}

/** Run a SQL query against Box's internal database. */
export async function runSql(query: string) {
  return box("/system/sql", { method: "POST", body: { query } });
}

/**
 * Deploy a route to Box.
 * routeConfig should include: name, method, path, code, and optionally pack, meta.
 */
export async function deploy(routeConfig: {
  name: string;
  method: string;
  path: string;
  code: string;
  pack?: string;
  meta?: { description?: string; inputs?: unknown[]; outputs?: unknown };
}) {
  return box("/_deploy", { method: "POST", body: routeConfig });
}

/** Generic route caller -- hit any Box endpoint. */
export async function callRoute(method: string, path: string, body?: unknown) {
  return box(path, { method, body: body || undefined });
}

// --- CLI ---

if ((() => { try { return import.meta.url === `file://${realpathSync(process.argv[1])}`; } catch { return false; } })()) {
  (async () => {
    const [, , cmd, ...args] = process.argv;

    switch (cmd) {
      case "routes": {
        const data = await listRoutes() as { deployed?: { name: string; method: string; path: string }[] };
        if (data?.deployed) {
          for (const r of data.deployed) {
            console.log(`${r.method}\t${r.path}\t${r.name}`);
          }
        } else {
          console.log(JSON.stringify(data, null, 2));
        }
        break;
      }
      case "sql": {
        const [query] = args;
        if (!query) { console.error("Usage: api.ts sql <query>"); process.exit(1); }
        const result = await runSql(query);
        console.log(JSON.stringify(result, null, 2));
        break;
      }
      case "call": {
        const [method, path, ...bodyParts] = args;
        if (!method || !path) { console.error("Usage: api.ts call <METHOD> <path> [json-body]"); process.exit(1); }
        const body = bodyParts.length ? JSON.parse(bodyParts.join(" ")) : undefined;
        const result = await callRoute(method, path, body);
        console.log(JSON.stringify(result, null, 2));
        break;
      }
      default:
        console.log("Usage: npx tsx api.ts [routes|sql|call] ...");
    }
  })();
}

scripts- helper scripts it can run

prose-only skill - 1 inline code block live in SKILL.md above (no state/bin/ sidecar yet).

how we check it- the checks, plus the last 10 runs

rubric shape schema-shape check (no inline rubric)
recent no runs actor/auditor: unverifiable
deps settings

no recent runs logged - the eval contract is declared but nothing has been graded yet