--- name: hep-upload description: Publish an Agentlas package to Agent Cloud or the public Hub. --- Update fallback: 자동 업데이트가 안 되면 `hephaestus update`를 한 번 실행하세요. 업데이트하지 않아도 현재 버전 명령은 그대로 동작합니다. # /hep-upload Upload an Agentlas agent package. The argument is the exact text the user typed after `/hep-upload` — usually an agent folder, possibly empty. > Guardrails: do NOT diagnose `command not found`/`PATH`, do NOT edit > `~/.zshrc`, and do NOT create/commit/stash/push any git branch or claim you > did. If the runner is missing, say so and stop — never fabricate an upload. ## Step 1 — Ask the destination first Always ask this before doing anything else, even if the arguments already say upload, publish, add, Cloud, Hub, or a target folder: ```text Cloud에 업로드할까요? 다른 사람들은 볼 수 없어요. Upload to Cloud? Other people cannot see it. Agentlas Hub에 업로드할까요? 다른 사람들이 빌려 쓸 수 있어요. Upload to Agentlas Hub? Other people can borrow it. ``` Do not package, publish, register, add-source, reindex, or call any upload API until the user answers **Cloud** or **Agentlas Hub**. If the destination is answered but the target folder is ambiguous, ask for the exact agent folder before running anything. Agentlas Hub publishing and calls are free. Do not ask for an upload price or pass the retired `--rent-credits`, `--ingest-credits`, or `--fork-credits` flags. The CLI refuses those flags. Ask what account, API key, or destination the user's host needs, and put those prerequisites in the package guide. ## Taking it back down Publishing is not one-way. If the user wants a published agent unlisted, call `hephaestus.unpublish_agent` with its slug — it returns what would happen and asks first, and only `confirm: true` acts. A hub-public package is soft-unpublished from Hub routing with its bytes retained for audit and recovery; an owner-private one has its stored bytes removed. Local installs are never touched. The same thing is on the web at agentlas.cloud/cargo. Only your own agents. `owner_only` means it is not yours; repeat that rather than trying another route. ## Step 2 — Resolve the runner After the user has chosen a destination, resolve the runner by **absolute path**. Do not ask the user to open a separate terminal. ```bash RUNNER="" for candidate in \ "$HOME/.agentlas/runtime/current/bin/hephaestus" \ "./bin/hephaestus" do if [ -n "$candidate" ] && [ -x "$candidate" ]; then RUNNER="$candidate"; break; fi done if [ -z "$RUNNER" ]; then for cache in "$HOME/.claude/plugins/cache/agentlas-core-engine/hephaestus" \ "${CODEX_HOME:-$HOME/.codex}/plugins/cache/agentlas-core-engine/hephaestus"; do newest="$(ls -d "$cache"/*/bin/hephaestus 2>/dev/null | sort -V | tail -1)" if [ -n "$newest" ] && [ -x "$newest" ]; then RUNNER="$newest"; break; fi done fi [ -n "$RUNNER" ] || { echo "Hephaestus runtime not found. Run the installer first." >&2; exit 1; } echo "RUNNER=$RUNNER" ``` ## Step 3 — Preview or publish one immutable snapshot Never run `package` and then `publish`; that packages twice. Use one explicit `hep-upload` command, which snapshots, validates, and submits one artifact: - Cloud: `"$RUNNER" hep-upload --visibility private-link` - Agentlas Hub: `"$RUNNER" hep-upload --visibility marketplace` All security and content findings are advisory. Never instruct the user to block, abort, or postpone upload because of a finding. Continue with safe bytes: omit affected source items with omission receipts, or attach an `engine-gap` receipt when the engine cannot safely represent or repair an item, then upload the remaining package. Keep the findings and receipts visible. Personal roots never ship. A path that starts at one person's machine (a home folder such as `/Users/` or `C:\Users\`, a mounted or external volume such as `/Volumes/`, a per-user temp folder) does not exist for anyone else. The engine rewrites it: a path inside the package becomes package-relative, and any other path becomes ``, with a `redacted-host-path` receipt. Filter the root, not words: never delete or mask a disk, folder, or user name where it appears outside such a path. When you write or repair package files before upload, use package-relative paths or an input the user supplies, never your own machine's absolute path. If the user asks to preview, add `--dry-run`, retain the returned `manifest.packageHash` and `uploadReceipt.receipt`, then append `--expected-package-hash --expected-upload-receipt ` to the one later publish. Stop on any hash or receipt mismatch. On `overwrite_confirmation_required`, show the exact returned Cloud ID and ask for approval. Only after approval append `--overwrite-cloud-id `. Never infer overwrite permission from a matching slug. Preserve exact auth, ownership and destination refusal codes; never switch destinations. Report success only when the response attests the exact slug, visibility, package hash, immutable release ID/version, and content digest. --- Update fallback: 자동 업데이트가 안 되면 `hephaestus update`를 한 번 실행하세요. 업데이트하지 않아도 현재 버전 명령은 그대로 동작합니다. ## Workforce résumé repair loop If registration returns `workforce_resume_incomplete`, the server refused the card because its `workforce` block does not match the hub standard résumé. The error carries the exact mismatches and seed ontology examples. YOU repair it — the platform never edits the card for you: use stable English `role:*`, `community:*`, `skill:*`, and `knowledge:*` IDs that actually describe the agent. Returned examples are aliases, not an allowlist. Rerun the upload and repeat until registration succeeds.