workhuman-ci-integration

v2026.09.24

Build fork-safe CI gates for a Workhuman adapter using pinned customer contracts, synthetic fixtures, and an optional protected tenant smoke test. Use when automating integration verification. Trigger with "add Workhuman CI".

GitHub
安装命令
npx skhub add jeremylongshore/workhuman-ci-integration
Markdown
SKILL.md

Workhuman Contract and Fixture CI

Overview

Turn customer-authorized Workhuman behavior into deterministic, secret-free merge gates and isolate any live tenant probe behind trusted approval.

Prerequisites

  • A pinned contract or mapping digest, typed adapter, and sanitized synthetic fixtures
  • CI threat model covering forks, artifacts, logs, caches, and secret exposure
  • Named owners for tenant access, contract updates, failures, and live-test approval

Tool Discipline

Use Read, Glob, and Grep to inspect workflows and test assets, WebFetch to re-check authoritative context, and Write or Edit for CI, tests, fixtures, and redacted receipts.

Current Contract

Workhuman publicly confirms open-API and managed-integration capabilities without publishing universal routes or schemas. CI must pin the customer's authorized artifacts and fail on drift rather than embedding assumptions from the former pack.

Authentication

Default pull-request jobs receive no Workhuman secrets. A live check may use only an approved non-production principal in a protected environment with host allowlisting and no untrusted code execution.

Instructions

  1. Pin contract, mapping, fixture, and adapter digests and document their owners and review dates.
  2. Add secretless gates for schema validity, generated-code drift, type checks, unit tests, contract tests, Unicode, and secret scanning.
  3. Cover read, valid-empty, invalid, duplicate, timeout, throttling, partial, drift, and ambiguous-write behavior with synthetic fixtures.
  4. Assert that tests deny network by default and that fixtures contain no workforce, recognition, reward, financial, or credential data.
  5. Separate required deterministic checks from an optional trusted live lane.
  6. Gate the live lane on explicit approval, non-production tenant, synthetic identity, allowlisted host, bounded read-only operation, and cleanup.
  7. Redact logs and artifacts; retain only version, digest, safe status, timing, counts, and correlation evidence.
  8. Make contract or fixture drift fail with an owner and regeneration instruction.

Approval Boundaries

Do not expose secrets to forks, run customer writes, upload private contracts as public artifacts, or make provider-dependent live tests required without a governed exception.

Output

Return the gate graph, pinned digests, fixture safety proof, required test result, live-lane controls, redaction evidence, failure ownership, and CI receipt.

Error Handling

ConditionResponse
Fork job requests a secretDeny it and keep the required lane fixture-only.
Contract digest changesFail closed until reviewed artifacts and fixtures regenerate together.
Live smoke is unavailableReport it separately; do not weaken deterministic required gates.

Example

A redacted completion receipt might look like this:

contract=sha256:...; required=12-pass; network=denied; secrets=0; live=protected-read-only; artifacts=redacted

Resources

Next Steps

Require these gates before deployment and review the protected live lane after any CI trust-boundary change.

发现
标签

此技能尚未发布标签。

版本
最新版本元数据

版本

v2026.09.24

发布时间

2026年9月24日

分类

未分类

许可证

MIT

源路径

skills/.curated/workhuman-ci-integration

默认分支

main

最新提交

e5a6c3b

Tree SHA

c2dc8e8