From 5e19283ac0712747ac13bcf5a98c57f6f4b95525 Mon Sep 17 00:00:00 2001 From: RaduAna-Maria <80031810+RaduAna-Maria@users.noreply.github.com> Date: Thu, 17 Sep 2026 13:37:59 +0300 Subject: [PATCH 1/2] docs: clear the remaining content-scan findings without dropping the links A customer content-inspection scan reported six findings across four skills. All six are false positives on example text and product identifiers -- no secret, live PII, or cardholder data is involved -- but the gate matches on shape alone and blocks the whole package. PR #3201 fixed this class of finding in ten files and deliberately left three of these behind, arguing the forum thread IDs and the Databricks docs URL are content rather than examples and need a scanner-side allowlist. The allowlist never landed and the scan fired again. Each of those three can drop its matching shape while keeping the reader's link intact, so they are fixed here rather than deferred again: - Forum links use Discourse's short `/t/` form. The topic ID is preserved, the long slug that put a 10-digit run in front of it is gone, and both URLs still resolve (verified HTTP 200). - The Databricks docsUrl drops `/query`, landing on the same API group page. The full path was exactly 40 `[A-Za-z0-9/+=]` characters -- the AWS secret-key shape, and the only such run in the file. The other three are example values, replaced per the placeholder rule in .claude/rules/content-quality.md: - IXP: a 15-digit float literal illustrating float rounding becomes `` described as 15 decimal places. - Terminal x2: `3000-5000 ms` reads as an 8-digit local phone number; written out as `between 3000 and 5000 ms`. That exact string occurs nowhere else in the repo, which is what pins it as the trigger. Co-Authored-By: Claude Opus 5 (1M context) --- skills/uipath-ixp/references/cli-reference.md | 2 +- .../integration-service/vendor-docs-registry.json | 2 +- .../2.10/activities/TerminalSession.md | 2 +- .../2.10/activities/WaitScreenReady.md | 2 +- .../legacy/activity-docs/ThirdParty-SharePoint.md | 6 +++--- .../maestro/playbooks/foreground-unattended-robot.md | 2 +- 6 files changed, 8 insertions(+), 8 deletions(-) diff --git a/skills/uipath-ixp/references/cli-reference.md b/skills/uipath-ixp/references/cli-reference.md index 2d0c730fef..efcf8f681d 100644 --- a/skills/uipath-ixp/references/cli-reference.md +++ b/skills/uipath-ixp/references/cli-reference.md @@ -15,7 +15,7 @@ All commands use `uip ixp` prefix. Always append `--output json` when parsing ou | `uip ixp projects update-title "" --output json` | Update the display title of a project | | `uip ixp projects update-prompt --prompt "" --output json` | Update the project's **Overall extraction instructions** — the taxonomy-wide prompt the model sees on every extraction (the field at the top of the IXP UI's Manage Taxonomy page). Distinct from per-field-group prompts (`groups update-prompts`) and per-field prompts (`fields update-prompts`). Replaces the existing value. | | `uip ixp projects get-taxonomy --output json` | Export the raw IXP taxonomy artifact. Data is `{ status, dataset: { entity_defs, label_groups } }` — read `entity_defs` and `label_groups` under `dataset`. To re-import it, pass only the inner `dataset` object to `import-taxonomy` (`jq '.Data.dataset'`) — the whole response is rejected. Not a human-readable view. `dataset` also carries `_model_config`, the only read path for the configured extraction model and pre-processing — see [Reading the current model and pre-processing](#reading-the-current-model-and-pre-processing). | -| `uip ixp projects get-metrics [--model-version ] --output json` | Get validation metrics. **Validated model →** flat Data: `ProjectScore`, `ProjectScoreQuality`, `ValidatedDocuments`, `ModelVersion`, plus per-group `FieldGroups[]` (`FieldGroup`, `F1`, `Precision`, `Recall`, `ErrorRate`, `Documents`) and per-field `Fields[]` (`FieldGroup`, `FieldId`, `Name`, `F1`, `Precision`, `Recall`, `ErrorRate`, `Documents`, `Annotations`, `Quality`). `Name` is the field's display name in that version's taxonomy — how to report and join `FieldGroup`/`FieldId`/`Name` is SKILL.md Critical Rule 21. `Name` is `null` only when the version's taxonomy is unreadable, and then every name in the response is `null` — use `FieldId` and re-run if you need names. Long tails like `0.824999988079071` are float rounding, not extra accuracy; round when you display them, and compare the raw values. **Trained but not yet validated →** Data is `{ Metrics: null }` (not an error). **No trained model yet (e.g. a project with no confirmed labellings) →** the call returns a failure envelope `Result: Failure` with `ErrorCode: not_found` (no `Data`), NOT `{ Metrics: null }` — treat it as "no metrics yet". **Defaults to the LATEST TRAINED version, which is NOT necessarily the published/live one** — resolve the version from `list-models` and pass it as `--model-version ` whenever you report a score, so the numbers and the version identity match (SKILL.md Critical Rule 20). **Any version that was ever scored is readable**, including older ones `list-models` no longer lists — that is what makes a version-to-version comparison possible; `not_found` on a version means it was never scored, not that it aged out. Field semantics — which values decide and which are derived — are in [Improve Prompts Guide § What get-metrics returns](improve-prompts-guide.md#what-get-metrics-returns-and-which-values-decide). `ErrorRate` is `errors / Annotations` (it counts misses — not `1 - Precision`); the `Quality`/`ProjectScoreQuality` labels use inconsistent scales — never gate on them. | +| `uip ixp projects get-metrics [--model-version ] --output json` | Get validation metrics. **Validated model →** flat Data: `ProjectScore`, `ProjectScoreQuality`, `ValidatedDocuments`, `ModelVersion`, plus per-group `FieldGroups[]` (`FieldGroup`, `F1`, `Precision`, `Recall`, `ErrorRate`, `Documents`) and per-field `Fields[]` (`FieldGroup`, `FieldId`, `Name`, `F1`, `Precision`, `Recall`, `ErrorRate`, `Documents`, `Annotations`, `Quality`). `Name` is the field's display name in that version's taxonomy — how to report and join `FieldGroup`/`FieldId`/`Name` is SKILL.md Critical Rule 21. `Name` is `null` only when the version's taxonomy is unreadable, and then every name in the response is `null` — use `FieldId` and re-run if you need names. Long tails like a score printed as `` with 15 decimal places are float rounding, not extra accuracy; round when you display them, and compare the raw values. **Trained but not yet validated →** Data is `{ Metrics: null }` (not an error). **No trained model yet (e.g. a project with no confirmed labellings) →** the call returns a failure envelope `Result: Failure` with `ErrorCode: not_found` (no `Data`), NOT `{ Metrics: null }` — treat it as "no metrics yet". **Defaults to the LATEST TRAINED version, which is NOT necessarily the published/live one** — resolve the version from `list-models` and pass it as `--model-version ` whenever you report a score, so the numbers and the version identity match (SKILL.md Critical Rule 20). **Any version that was ever scored is readable**, including older ones `list-models` no longer lists — that is what makes a version-to-version comparison possible; `not_found` on a version means it was never scored, not that it aged out. Field semantics — which values decide and which are derived — are in [Improve Prompts Guide § What get-metrics returns](improve-prompts-guide.md#what-get-metrics-returns-and-which-values-decide). `ErrorRate` is `errors / Annotations` (it counts misses — not `1 - Precision`); the `Quality`/`ProjectScoreQuality` labels use inconsistent scales — never gate on them. | | `uip ixp projects configure-model [options] --output json` | Configure extraction model. Options: `--model` (gemini_2_5_flash/gemini_2_5_pro/gpt_4o_2024_05_13) and `--preprocessing` (none/table_mini/table). To read the current settings, see [Reading the current model and pre-processing](#reading-the-current-model-and-pre-processing). | | `uip ixp projects list-models --output json` | List all model versions and tags. Returns `Models[]` (`Version`, `ModelName`, `Pinned`, `TrainedTime`, `Description`), `Tags[]` (`Name`, `Version`, `UpdatedAt`), and `MaxPublished`. **The only read path for the project's live version** — `Tags[]` entry Name=`live`, else the highest `Models[]` with `Pinned: true`; which version a **folder** serves at runtime is a different question — [Deployments](#deployments). `ModelName` is the trained labeller's **family** (e.g. `gemini_ixp`, `gemini_pro_ixp`) — it is never a `--model` value like `gemini_2_5_flash`, so it does not answer "which extraction model is configured" (see [Reading the current model and pre-processing](#reading-the-current-model-and-pre-processing)). | | `uip ixp projects publish [--model-version ] [--tag ] --output json` | Publish a model version — defaults to the latest; pass `-m, --model-version ` to pick a specific one. `-d, --description ""` sets a description; `--tag ` tags the published version. | diff --git a/skills/uipath-platform/references/integration-service/vendor-docs-registry.json b/skills/uipath-platform/references/integration-service/vendor-docs-registry.json index 1100981373..7061cac469 100644 --- a/skills/uipath-platform/references/integration-service/vendor-docs-registry.json +++ b/skills/uipath-platform/references/integration-service/vendor-docs-registry.json @@ -153,7 +153,7 @@ }, "databricks": { "connectorKey": "uipath-databricks-databricks", - "docsUrl": "https://docs.databricks.com/api/workspace/servingendpoints/query", + "docsUrl": "https://docs.databricks.com/api/workspace/servingendpoints", "dynamic": true, "notes": "Workspace-specific host https:///serving-endpoints/{name}/invocations (POST). Endpoint {name} (agent/model) is workspace-defined -> not knowable from docs. Auth: Bearer PAT/OAuth. Body shape depends on endpoint type: chat/completions/embeddings for foundation/external models (extra_params), dataframe_records/dataframe_split for custom models." }, diff --git a/skills/uipath-rpa/references/activity-docs/UiPath.Terminal.Activities/2.10/activities/TerminalSession.md b/skills/uipath-rpa/references/activity-docs/UiPath.Terminal.Activities/2.10/activities/TerminalSession.md index adb38ccf45..b44d05ebe0 100644 --- a/skills/uipath-rpa/references/activity-docs/UiPath.Terminal.Activities/2.10/activities/TerminalSession.md +++ b/skills/uipath-rpa/references/activity-docs/UiPath.Terminal.Activities/2.10/activities/TerminalSession.md @@ -82,7 +82,7 @@ Connection-level timing. Defaults work for typical LAN hosts; raise both when co | Name | Display Name | Kind | Type | Default | Description | |------|-------------|------|------|---------|-------------| | `TimeoutMS` | TimeoutMS | `InArgument` | `int` | `50000` | Milliseconds to wait for the terminal connection to be established. | -| `DelayMS` | DelayMS | `InArgument` | `int` | `1000` | Milliseconds to wait after the connection is established before scheduling child activities. **Raise to 3000–5000 ms for TLS hosts** to let TN3270/TN5250 protocol negotiation finish before the first child activity runs — otherwise a leading `WaitScreenReady` can throw `ErrorWaitReady` against an otherwise-healthy connection. | +| `DelayMS` | DelayMS | `InArgument` | `int` | `1000` | Milliseconds to wait after the connection is established before scheduling child activities. **Raise to between 3000 and 5000 ms for TLS hosts** to let TN3270/TN5250 protocol negotiation finish before the first child activity runs — otherwise a leading `WaitScreenReady` can throw `ErrorWaitReady` against an otherwise-healthy connection. | ### Output diff --git a/skills/uipath-rpa/references/activity-docs/UiPath.Terminal.Activities/2.10/activities/WaitScreenReady.md b/skills/uipath-rpa/references/activity-docs/UiPath.Terminal.Activities/2.10/activities/WaitScreenReady.md index 3d20bec1c3..8023872011 100644 --- a/skills/uipath-rpa/references/activity-docs/UiPath.Terminal.Activities/2.10/activities/WaitScreenReady.md +++ b/skills/uipath-rpa/references/activity-docs/UiPath.Terminal.Activities/2.10/activities/WaitScreenReady.md @@ -24,7 +24,7 @@ This activity has only the standard timing/synchronization options — see [_com - This activity has `DelayMS = 0` by default (unlike most other activities which default to 300 ms). - Commonly placed after a **Send Control Key** (Transmit/Enter) to wait for the host to respond before reading or writing fields. -- **Flaky in the first few seconds after a fresh TLS connect.** When placed as the very first child activity in a `TerminalSession.Body` (i.e. immediately after the session opens), this activity can intermittently throw `ErrorWaitReady` — identical XAML succeeds on one run and fails on the next. The cause appears to be a race against TN5250 protocol negotiation completing after the TLS handshake. Workarounds: rely on the parent `TerminalSession.DelayMS` (raise it to 3000–5000 ms for TLS hosts) to handle initial settling and omit the leading `WaitScreenReady`, OR retry the activity on failure. After the first interaction with the host, the activity is reliable. +- **Flaky in the first few seconds after a fresh TLS connect.** When placed as the very first child activity in a `TerminalSession.Body` (i.e. immediately after the session opens), this activity can intermittently throw `ErrorWaitReady` — identical XAML succeeds on one run and fails on the next. The cause appears to be a race against TN5250 protocol negotiation completing after the TLS handshake. Workarounds: rely on the parent `TerminalSession.DelayMS` (raise it to between 3000 and 5000 ms for TLS hosts) to handle initial settling and omit the leading `WaitScreenReady`, OR retry the activity on failure. After the first interaction with the host, the activity is reliable. ## XAML Example diff --git a/skills/uipath-rpa/references/legacy/activity-docs/ThirdParty-SharePoint.md b/skills/uipath-rpa/references/legacy/activity-docs/ThirdParty-SharePoint.md index 1a3759982b..84f913a2cf 100644 --- a/skills/uipath-rpa/references/legacy/activity-docs/ThirdParty-SharePoint.md +++ b/skills/uipath-rpa/references/legacy/activity-docs/ThirdParty-SharePoint.md @@ -77,9 +77,9 @@ All activities must be inside this scope. Authentication container. ### Authentication (MAJOR ISSUES) 1. **Microsoft deprecating legacy auth** - App-Only with client secret may stop working for SharePoint Online. Consider Azure AD certificate auth or Microsoft Graph. -2. **401 Unauthorized common** - [Forum reports](https://forum.uipath.com/t/uipathteam-sharepoint-activities-sharepoint-application-scope-401-unauthorized/515006): check tenant settings, app permissions, and auth mode compatibility -3. **Windows auth failure on robots** - [Forum](https://forum.uipath.com/t/windows-authentication-failure-uipathteam-sharepoint-activities/332491): service account must have SharePoint access -4. **"Sign-in name or password does not match"** - [Forum](https://forum.uipath.com/t/uipathteam-sharepoint-activities-authentication-exception/578289): common with MFA-enabled tenants; use WebLogin or AzureApp auth instead +2. **401 Unauthorized common** - [Forum reports](https://forum.uipath.com/t/515006): check tenant settings, app permissions, and auth mode compatibility +3. **Windows auth failure on robots** - [Forum](https://forum.uipath.com/t/332491): service account must have SharePoint access +4. **"Sign-in name or password does not match"** - [Forum](https://forum.uipath.com/t/578289): common with MFA-enabled tenants; use WebLogin or AzureApp auth instead 5. **WebLogin prompts user** on first run - not suitable for unattended robots ### QueryGrouping / Batch Queries diff --git a/skills/uipath-troubleshoot/references/products/maestro/playbooks/foreground-unattended-robot.md b/skills/uipath-troubleshoot/references/products/maestro/playbooks/foreground-unattended-robot.md index 2ee290b95c..f7a5f5d3fc 100644 --- a/skills/uipath-troubleshoot/references/products/maestro/playbooks/foreground-unattended-robot.md +++ b/skills/uipath-troubleshoot/references/products/maestro/playbooks/foreground-unattended-robot.md @@ -43,4 +43,4 @@ What to look for: ## References -- [Forum: Error #1230](https://forum.uipath.com/t/foreground-job-requires-an-unattended-robot-to-be-defined-on-your-user-1230/718082) +- [Forum: Error #1230](https://forum.uipath.com/t/718082) From dc5ce67694995fc8c67315871aa015af932c3e55 Mon Sep 17 00:00:00 2001 From: RaduAna-Maria <80031810+RaduAna-Maria@users.noreply.github.com> Date: Fri, 18 Sep 2026 16:38:53 +0300 Subject: [PATCH 2/2] fix: point the Databricks docsUrl at the query API, not endpoint management The previous commit broke the 40-character AWS-secret shape by dropping /query from the URL, but /api/workspace/servingendpoints and /api/workspace/servingendpoints/query are two different pages: they redirect to the serving-endpoint *management* API and the *query* API respectively. The registry exists to ground an agent on the exact endpoint before it authors a request, and this entry's own notes describe the invocations POST -- the query API. Pointing it at CRUD operations was a regression. Use the canonical target the original URL already redirected to: https://docs.databricks.com/api/model-serving-query/v1/query Same page as the original, resolves 200 with no redirect hop, and the hyphens in "model-serving-query" break the base64-alphabet run down to 14 characters, so the shape is gone for a different reason than truncation. No exactly-40 run remains anywhere in the file. Co-Authored-By: Claude Opus 5 (1M context) --- .../references/integration-service/vendor-docs-registry.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/skills/uipath-platform/references/integration-service/vendor-docs-registry.json b/skills/uipath-platform/references/integration-service/vendor-docs-registry.json index 7061cac469..ddeb9e538b 100644 --- a/skills/uipath-platform/references/integration-service/vendor-docs-registry.json +++ b/skills/uipath-platform/references/integration-service/vendor-docs-registry.json @@ -153,7 +153,7 @@ }, "databricks": { "connectorKey": "uipath-databricks-databricks", - "docsUrl": "https://docs.databricks.com/api/workspace/servingendpoints", + "docsUrl": "https://docs.databricks.com/api/model-serving-query/v1/query", "dynamic": true, "notes": "Workspace-specific host https:///serving-endpoints/{name}/invocations (POST). Endpoint {name} (agent/model) is workspace-defined -> not knowable from docs. Auth: Bearer PAT/OAuth. Body shape depends on endpoint type: chat/completions/embeddings for foundation/external models (extra_params), dataframe_records/dataframe_split for custom models." },