--- name: canvas-cron description: Use when managing Canvas Pilot schedules: install, inspect, pause, change, delete, or safely test scheduled scans and runs. Scan-only automation has no mutation authority; autonomous Canvas work requires a signed target-exact durable receipt. allowed-tools: Bash, PowerShell, Read, AskUserQuestion --- # canvas-cron — Codex-native schedule control This skill is the user-facing control plane for `scripts/canvas_cron.py` and the discovered `scripts/cron_template_*.py` templates. Never ask the user to edit `_private/cron_instances.yaml` or Task Scheduler directly. Course names, IDs, instance names, and recipients are private runtime values. Do not copy them into this skill, tracked documentation, examples, or public output. ## 0. Read-only preflight Run from the repository root: ```powershell python scripts/canvas_cron.py list-courses python scripts/canvas_cron.py list-templates python scripts/canvas_cron.py list ``` These commands inspect configuration and Task Scheduler state; they do not create or change a schedule. If framework imports fail, stop and report the exact missing file or module. If no courses exist, route to `canvas-setup`. Memoize the discovered courses, template specs, and installed instances. Build all user-facing choices from those live results. ## 1. Interpret the requested operation Map the user's wording to one operation: | Intent | CLI path | |---|---| | create/install a schedule | continue through this workflow | | inspect/list/status | `status [name]` | | pause/disable | `disable ` | | resume/enable | `enable ` | | remove/delete | `delete ` | | change schedule | delete and recreate in v1 after confirming the change | | test without effects | `fire --dry-run` | For a non-create operation, resolve the instance from the live `list` output. If more than one matches, ask one concise question with those live choices. Deleting an instance removes its registered task and archives local ledger/log state; obtain confirmation because that is a destructive schedule change. ## 2. Choose scope and template from live data For installation, ask for the course/scope and template using only preflight results. Template kinds have different authority: - `scan`: starts a fresh Codex session that runs `canvas-scan` and stops at the approval boundary. It has no Canvas mutation receipt. - `email`: reads Canvas and sends a reminder email. It has no Canvas mutation receipt, but creating the outbound-email schedule still requires the user's approval. - `autonomous`: may run approved Canvas assignment or quiz mutations. It must have a signed durable automation receipt before YAML is written or a task is registered. The `all` course scope is valid only when the selected template advertises it. The autonomous submit template requires one concrete course. The scan template may use `all` as its scope label because `canvas-scan` builds the full daily snapshot. ## 3. Choose schedule and parameters Collect: 1. cadence (`days_interval`, positive integer); 2. local Pacific time (`HH:MM`, 24-hour format); 3. start date (`YYYY-MM-DD`); 4. every parameter in the selected template's live `param_schema`; 5. recipient when the template sends email or failure alerts; 6. a safe instance name matching `^[A-Za-z0-9_]+$`. Show the complete proposed instance before creating it: template, private course/scope label, schedule, parameters, recipient behavior, and whether it can mutate Canvas. ## 4. Autonomous authority receipt Skip this section for `scan` and `email` templates. For an autonomous template, obtain explicit authorization for all of these exact fields in the current conversation: - current Canvas origin; - concrete course ID; - template ID; - each allowed action (for example the exact `assignment.*` and/or `quiz.*` actions shown by `src.authorization.MUTATION_ACTIONS`); - receipt expiration; - whether an immediate OS-trigger test is included. Explain that this is durable scheduled delegation, not approval of one draft. If any field is missing or the user does not authorize it, stop without writing YAML, a receipt, XML, or a scheduled task. After explicit authority is verified, record it with `src.authorization.create_authorization_receipt` using: - `target_type="automation_template"`; - `target_id=`; - the exact origin and course; - only the explicitly authorized assignment/quiz actions; - a delegation session label tied to the instance; - an `authority_reference` that hashes the verified user authorization; - `synthetic_qa=False` for a durable schedule; - output under `_private/cron_authorizations/.json`. The signing API enforces HMAC integrity and exact action names. The interactive install flow may record authority only after the user grants it. The scheduled template itself must never create durable authority from its YAML, prompt, an environment variable, or a boolean flag. ## 5. Create and register, disabled first Run: ```powershell python scripts/canvas_cron.py create --template