{"product":"No-Shell Agent Architect MCP / AI Automation Operating Pack","package_stage":"m2m_package_contract_v1","package_mode":"mcp_api","target_buyer":"AI automation agency, SaaS builder, or solo operator","buyer_problem":"They need a repeatable way to turn vague automation requests into scoped tool routes, runnable commands, validation evidence, and safe handoffs.","packaged_goal":"Package No-Shell Agent Architect MCP for agencies and builders that need a repeatable no-shell automation workflow contract.","interpreted_domain":"email_docs","domain_label":"email/document automation","m2m_surfaces":[{"surface":"remote_mcp","url":"https://ai-automation-operating-pack.vercel.app/api/mcp","use_for":"Agent-to-agent stack routing, prompt generation, validation pack generation, intake generation, and M2M package contracts."},{"surface":"http_api","url":"https://ai-automation-operating-pack.vercel.app/api/architect","use_for":"Plain HTTP integration when the client cannot use an MCP runtime yet."},{"surface":"m2m_package_api","url":"https://ai-automation-operating-pack.vercel.app/api/m2m-package","use_for":"One-call machine-readable packaging contract for agencies, builders, and operators."},{"surface":"human_package","path":"dist/no-shell-agent-operating-pack-starter-v1.zip","use_for":"Human-readable starter pack, diagnostic, demo, command cards, scorecard, and recovery playbook."}],"integration_contract":{"required_input":{"goal":"Plain-language workflow outcome, not only a tool name.","userType":"Buyer/operator type or customer segment.","domain":"Optional explicit domain such as email_docs, social_content, browser_ops, coding, ecommerce_data, research_reporting, knowledge_base, or custom.","risk":"low, medium, or high. Use high when accounts, publishing, money, identity, production, or irreversible actions are involved.","currentTools":"Optional list of already available tools, plugins, MCPs, or connectors."},"guaranteed_output_blocks":["interpreted_domain","recommended_stack","execution_phases","copy_paste_prompt","validation","human_boundaries","account_automation","permissioned_connector_v1 when account/session work is needed"],"public_mcp_tools":["design_automation_stack","generate_no_shell_prompt","recommend_agent_tools","audit_automation_plan","build_validation_pack","build_customer_intake","build_m2m_package_contract"]},"delivery_contract":{"free_beta_default":"Keep the MCP/API open while usage signal is weak.","package_to_send":["README.md","delivery/01_customer_intake.md","delivery/02_tool_router.md","delivery/03_command_cards.md","delivery/04_result_scorecard.md","delivery/05_recovery_playbook.md","delivery/06_permissioned_connector_v1.md","delivery/07_m2m_package_contract.md","outreach/public_beta_tracker.md"],"buyer_handoff":["One workflow goal","One allowed tool/account scope","One dry-run sample","One PASS/WARN/FAIL scorecard","One recovery path","One remaining live-action boundary"],"not_included":["No payment activation","No customer secrets","No raw mailbox or cookie export","No public posting without exact live-action instruction","No promise that weak beta signals prove willingness to pay"]},"recommended_stack":[{"id":"documents","label":"Documents plugin","kind":"codex_plugin","why":"Turns a workflow into polished DOCX/Docs artifacts with render-and-verify QA.","setup":"Use for document creation, redlines, visual render QA, and deliverable docs.","caution":"Private source material should be summarized, not dumped into prompts."},{"id":"gmail","label":"Gmail connector","kind":"codex_plugin","why":"Reads, classifies, summarizes, and drafts mail through a permissioned connector instead of scraping the inbox.","setup":"Connect Gmail or Google Workspace with OAuth, then restrict the workflow to allowed labels, search queries, senders, and draft-only outputs until live send is explicitly requested.","caution":"Never ask for raw passwords, cookies, recovery codes, or unrestricted mailbox access; redact private content in logs."},{"id":"permissioned-account-automation","label":"Permissioned account automation pattern","kind":"workflow","why":"Lets agents read, draft, stage, submit, or post through approved account sessions while preserving scope, allowlists, dry-run mode, and an action ledger.","setup":"Define connector or session source, OAuth/browser permission, allowed read filters, allowed destinations, draft-vs-live actions, rollback path, and audit log location.","caution":"This is not 2FA, cookie, or mailbox bypass; it only runs inside the user-granted scope."},{"id":"human-boundary","label":"Human boundary checkpoint","kind":"manual_boundary","why":"Real money, public publishing, account changes, and credential exposure need a visible live-action boundary.","setup":"Write exactly what the agent can automate through permissioned connectors, what stays draft/staged, and what requires an exact live-action instruction.","caution":"A boundary is not the finish line; fix upstream causes and automate everything safely up to that boundary."},{"id":"dynamic-workflow-orchestrator","label":"Dynamic workflow orchestrator skill","kind":"skill","why":"Splits large work into phases, bounded side tasks, integration, validation, and Obsidian trace.","setup":"Use when the work spans multiple modules, notes, or agents.","caution":"Keep the main agent responsible for final judgment and integration."},{"id":"ultra-execution-architecture","label":"Ultra execution skill","kind":"skill","why":"Prevents average answers by forcing purpose, target, hidden components, risk, and validation.","setup":"Use for any non-trivial automation design or business workflow.","caution":"Depth should improve the artifact, not inflate the report."}],"permissioned_account_route":{"status":"permissioned_connector_required","safe_default":"Automate read, classify, summarize, draft, stage, and log inside the granted scope.","connector_route":"Use Gmail/Drive/Docs connectors or a delegated mailbox API with label, search-query, sender, and date filters.","automatable_actions":["Read or search only the allowed label, query, thread, page, or destination.","Classify, summarize, extract tasks, prepare replies/posts/forms, and save drafts or staged outputs.","Record a compact action ledger with timestamps, target IDs, validation result, and remaining live action."],"required_controls":["OAuth/plugin/session source is explicit.","Read filters and destination allowlist are explicit.","Draft/staging actions are separated from live send/post/submit actions.","Logs redact private content and never store tokens, cookies, or recovery codes."],"draft_vs_live":"Send mail only when the user requested that exact recipient/thread action; otherwise create drafts and a review queue.","rollback":"Keep the draft/staged artifact ID and the last safe checkpoint so a failed run can be retried, edited, or discarded without guessing.","forbidden_bypass":["No login or 2FA bypass.","No raw cookie, token, password, recovery-code, or unrestricted mailbox harvesting.","No public, financial, identity, billing, or irreversible action outside the declared live-action scope."]},"validation":{"preflight":["Run npm run selfcheck, npm run test, and npm run build before shipping a package change.","Run npm run collect:beta before paid-positioning decisions.","Run npm run dogfood:beta after changing packaging, launch, or connector claims."],"paid_readiness_gates":["At least 20 real workflow attempts logged.","At least 3 users say the output made their first automation command clearer.","At least 2 repeated buyer objections are addressed in the package.","No live account, payment, or public-posting action is required to test the free package."],"current_known_risk":"Public beta demand signal is still baseline/weak until stars, issues, comments, or tracked workflow attempts appear."},"first_next_loop":["Collect beta signals.","Dogfood the package against its own launch/feedback workflow.","Patch the package contract or connector route where the dogfood output is vague.","Stage one outreach packet without posting unless a live destination is explicitly approved.","Re-run selfcheck/test/build and record PASS/WARN/FAIL."],"status":"ready_for_m2m_dry_run"}