salesloft-ci-integration

v2026.09.24

Gate Salesloft integration changes with offline contract fixtures and an optional fork-safe read-only smoke lane. Use when wiring CI for auth, pagination, errors, rate limits, or webhooks. Trigger with "Salesloft CI", "Salesloft contract tests", or "Salesloft GitHub Actions".

GitHub
安装命令
npx skhub add jeremylongshore/salesloft-ci-integration
Markdown
SKILL.md

Salesloft Contract CI

Overview

This skill keeps pull-request validation deterministic and secretless while retaining a separately authorized live smoke check. It prevents CI from creating people or cadence memberships as a connectivity test.

Prerequisites

  • A repository with a test runner and identified HTTP adapter
  • Sanitized success and failure fixtures
  • Protected CI environment for any live credential
  • Named owner for contract drift and smoke failures

Tool Discipline

Use Read, Glob, and Grep to inspect workflows, test commands, adapters, and secret references. Use WebFetch only for official Salesloft contracts. Use Write or Edit after confirming the CI file and repository conventions.

Current Contract

  • Offline fixtures cover data, list metadata, singular error, field-keyed errors, and rate headers.
  • Webhook tests sign exact raw bytes with SHA-1 HMAC and the fixture callback token.
  • Untrusted fork workflows receive no Salesloft secret.
  • The optional live lane performs one bounded read such as GET /v2/me and logs no response body.

Authentication

Store a least-privilege read credential only in a protected environment. Pin it to a non-production or explicitly approved team and rotate it through the owning Salesloft flow.

Instructions

  1. Map required unit, contract, security, and static checks to CI jobs.
  2. Run sanitized fixture tests on every pull request with no external dependency.
  3. Assert secret redaction, tenant binding, pagination termination, bounded retries, and raw-body signature behavior.
  4. Disable live jobs for fork-originated and untrusted events.
  5. Run the live read-only smoke only after protected-environment authorization.
  6. Make contract drift and live failures visible without leaking body or credential data.

Approval Boundaries

Do not expose repository secrets to fork code, print API responses, or perform Salesloft writes from the default CI lane. A new live environment or scope needs owner approval.

Output

Return workflow paths, trigger matrix, fixture coverage, secret boundary, live-lane guard, commands, results, and unresolved failures.

Error Handling

ConditionResponse
Fork requests secretSkip the live lane and run fixtures only.
Live 401/403Fail clearly and rotate or correct scope outside the log.
Live 429Stop; do not turn CI into a retry storm.
Fixture driftUpdate contract and consumer together with an official-source receipt.

Examples

The example below shows the minimum redacted evidence expected from a successful invocation of this operator workflow.

pr-fixtures=pass; fork-secrets=0; live-smoke=protected; writes=0

Resources

发现
标签

此技能尚未发布标签。

版本
最新版本元数据

版本

v2026.09.24

发布时间

2026年9月24日

分类

未分类

许可证

MIT

源路径

skills/.curated/salesloft-ci-integration

默认分支

main

最新提交

e5a6c3b

Tree SHA

c2dc8e8