You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Derive authenticated Gitea asset verification routes from the configured API origin and exact
repository/tag/file identity. Check uploaded names and sizes, keep corrupt uploads in draft, and
strip authentication on foreign redirects; UI and attachment aliases cannot select request targets.
Clarify that the executing agent performs routine review, verification and acceptance. Authorized
Full Access execution needs no additional confirmation; required native and independent approvals
remain enforced. Ship the updated Skill payload and matching manifest pins.
Support explicitly verified GitHub + Gitea mirrors in release records, require mirrored tags on
both hosts, and document recovery of the same verified Gitea draft without changing published tags.