SKILL.md
Full skill instructions
CloudBase Development Guidelines
Workflow
1. Exploration → Read the matching skill completely before writing any code.
Search with searchKnowledgeBase(mode="skill"), then Read full SKILL.md.
2. Implementation
├── 2a. Resource preparation → Prefer MCP; if MCP tools are missing in THIS session,
│ configure MCP for next session and use `tcb` CLI now (see tooling-fallback.md)
└── 2b. Frontend implementation → Write code, install deps, start server, test
3. Close-out → Run cloudbase-code-review, fix errors, declare done
Key constraints: Stage 2a must precede frontend code. Stage 3 is mandatory.
Activation Contract
Routing uses stable skill ids (auth-tool-cloudbase, auth-web-cloudbase, http-api-cloudbase, …) across source, generated artifacts, and installs.
Standalone skill fallback
If only one published skill is exposed:
- Prefer local relative paths (
references/<skill-id>/SKILL.mdor sibling skill directories) when those files exist in the workspace. - Do not fetch sibling skill markdown from remote raw URLs into the agent context.
- If a required sibling skill is missing locally, ask the user to install the full CloudBase skills pack or IDE plugin (
npx skills add tencentcloudbase/cloudbase-skills), then continue using local files only.
Follow relative references/... paths from the current skill. If MCP is unavailable in this session, follow references/tooling-fallback.md: configure MCP via references/mcp-setup.md for the next session, and use tcb CLI via the cloudbase-cli skill (read core.md + the matching domain reference — not tcb deploy) to finish login/manage now. If npm/npx are missing, follow the “No npm/npx” section in tooling-fallback.md.
Global rules before action
- Identify the scenario, then read the matching skill before writing code or calling CloudBase APIs.
- Prefer semantic sources for toolkit maintenance; express runtime routing in stable skill ids.
- Prefer MCP or mcporter for management tasks when those tools are available in this session; inspect tool schemas before execution. If they are not available yet, do not stall — use the CLI fallback in
references/tooling-fallback.md. - UI tasks: read
ui-designfirst and output the design spec before interface code. - Auth tasks: read
auth-tool-cloudbasefirst and enable providers before frontend implementation. - Keep auth domains separate: management login uses
auth(ortcb loginwhen MCP auth is unavailable); app-side auth usesqueryAppAuth/manageAppAuth.
Universal guardrails
- After 2–3 failed attempts on the same path, stop and reroute (platform skill, runtime, auth domain, permission model, SDK boundary).
- Always specify
EnvIdexplicitly; do not rely on CLI-selected or implicit env state. - When the environment identifier is an alias, nickname, or other short form, do not pass it directly to
auth.set_env, SDK init, console URLs, or generated config. First resolve it to the canonical fullEnvIdwithenvQuery(action=list, alias=..., aliasExact=true). If multiple environments match or no exact alias exists, stop and clarify with the user. - When writing MCP/tool results to a file, pass serialized text (
JSON.stringify(result, null, 2)), not raw objects. If a write tool sayscontentexpected a string but received an object, do not retry with the same raw object. Serialize the object first, then retry once with the serialized text, and make sure the retried call actually passes the serialized string rather than the original object. - Keep scenario-specific pitfalls in child skills — do not expand this entry file.
- First frontend deploy must use
manageApps(action="createApp", ...).manageHostingis only for incremental updates of projects originally deployed via hosting.
Engineering constitution (applies to every scenario)
These rules override convenience. Full rationale lives in web-development.
- Prepare backend resources before writing frontend code. Prefer MCP for auth providers, tables, storage domains, and security rules; if MCP tools are missing in this session, use
tcbCLI after configuring MCP for the next session (references/tooling-fallback.md). - Do NOT use
anyto bypass type errors. Preferunknown+ type guards / precise interfaces. - Self-verify before claiming done. Static (
tsc/ lint / build / tests) and runtime (agent-browserfor user-visible flows). Name gaps explicitly if a layer cannot run. - Do not paper over failures. No empty
try/catch, no deleting failing tests to go green. ai.createModel(...)/wx.cloud.extend.AI.createModel(provider)takes a GroupName, not a vendor/model id. Legal:"cloudbase","hunyuan-exp", or"custom-<name>". Model ids go ingenerateText/streamTextmodelfield. Seeai-model-web/ai-model-nodejs/ai-model-wechat.- Low-capability STOP card: For PostgreSQL / CloudBase PG /
app.rdb()/queryPgDatabase/managePgDatabase, route topostgresql-development-cloudbase— do not use NoSQL/manageMysqlDatabasefor that path. For Web auth guards, useauth.getSession()and requiredata.session; do not use deprecatedgetLoginState()/auth.getUser()as login proof.
High-priority routing
<!-- DO NOT EDIT: auto-generated from references/activation-map.yaml -->| Scenario | Read first | Then read | Do NOT route to first | Must check before action |
|---|---|---|---|---|
| Minimal Web BaaS demo (fast path) | minimal-web-baas-demo | web-development, no-sql-web-sdk, postgresql-development | cloud-functions, cloudrun, spec-workflow, ui-design | BaaS-first Web SDK CRUD, MCP schema only, zero cloud functions unless secrets/cron/rules-cannot-express |
| Web login / registration / auth UI | auth-tool-cloudbase | auth-web, web-development | cloud-functions, http-api | Provider status and publishable key |
| WeChat mini program + CloudBase | miniprogram-development | auth-wechat, no-sql-wx-mp-sdk | auth-web, web-development | Whether the project really uses CloudBase / wx.cloud |
| Native App / Flutter / React Native | http-api-cloudbase | auth-tool, relational-database-tool | auth-web, cloudbase-document-database-web-sdk, web-development | SDK boundary, OpenAPI, auth method |
| Web projects + NoSQL Database | web-development | no-sql-web-sdk, auth-web | relational-database-tool, http-api | Login state and database access permission model |
| CloudBase PostgreSQL / PG | postgresql-development-cloudbase | auth-tool, auth-web-cloudbase, web-development, miniprogram-development, cloud-storage-web, http-api | relational-database-tool, no-sql-web-sdk | PG schema, usernamePassword login, backend/RLS permission model |
| MySQL Database (relational) | relational-database-mcp-cloudbase | relational-database-web, http-api | no-sql-web-sdk, web-development | Distinguish MCP management vs app code access |
| Cloud Functions | cloud-functions | auth-tool, ai-model-nodejs | cloudrun-development, auth-web | Event vs HTTP function, runtime, scf_bootstrap |
| CloudRun backend | cloudrun-development | auth-tool, relational-database-tool | cloud-functions | Container boundary, Dockerfile, CORS |
| AI Agent (智能体开发) | cloudbase-agent | cloud-functions, cloudrun-development | cloud-functions, cloudrun-development | AG-UI protocol, scf_bootstrap, SSE streaming |
| AI model call (大模型调用 / 文本生成 / 图片生成 / 流式对话) | ai-model-web | ai-model-nodejs, ai-model-wechat | cloudbase-agent, cloud-functions, cloudrun-development | 先跑「调用前必须的资格检查」:DescribeActivityInfo(小程序成长计划) + DescribeEnvPostpayPackage(Token Credits 资源包) |
| UI generation | ui-design | web-development, miniprogram-development | cloud-functions | Design specification first |
| AI Model (Web) | web-development | ai-model-web, ui-design | ai-model-wechat, http-api | Platform and streaming interaction mode |
| Resource health inspection / troubleshooting | ops-inspector | cloud-functions, cloudrun-development | ui-design, spec-workflow | CLS enabled; use queryEnv(action=metrics) for QPS/CPU (never callCloudApi); time range for logs |
| Spec workflow / architecture design | spec-workflow | cloudbase | web-development, cloud-functions | Requirements, design, tasks confirmed |
Routing reminders
- Web auth failures: usually skipped provider config, not missing frontend snippets.
- Native App failures: usually Web SDK paths, not missing HTTP API knowledge.
- Mini program failures: treating
wx.cloudlike Web auth/SDK. - CloudBase PG failures: falling back to MySQL/NoSQL, skipping username-password readiness, or guessing raw HTTP instead of
app.rdb()/ documented OpenAPI. - AI model failures: usually missing Token Credits / Growth Plan — run
DescribeEnvPostpayPackage/DescribeActivityInfobefore changing code.
MCP + CLI prerequisite
Prefer CloudBase MCP for management/deploy when tools are loaded in the current session. Setup: references/mcp-setup.md. First-session / unavailable path: references/tooling-fallback.md.
- Preferred install:
npx plugins add TencentCloudBase/cloudbase-plugin -y --scope user. Supported--targetIDs:claude-code,cursor,codex,grok,kimi,github-copilot,vscode. Seereferences/mcp-setup.md. - Verify with
npx mcporter list | grep cloudbaseor the IDE MCP panel. Ifnpm/npxare missing, seereferences/tooling-fallback.md(install Node LTS or use IDE marketplace MCP). If MCP is missing or not yet visible after config, still proceed: finish install/config, tell the user a restart unlocks MCP next time, and usetcbCLI now viacloudbase-clidomain skills — do not recommendtcb deploy. - Prefer device-code login via MCP
authwhen available; otherwisetcb login. Do not hard-code secrets.
On-demand references
Load only when needed (do not expand this entry):
references/tooling-fallback.md— MCP vstcbCLI decision tree for first session / missing toolsreferences/deployment-workflow.md— deploy backend/frontend,manageAppsvs hosting, URL/docs updatesreferences/console-links.md— console hash paths after creating resourcesreferences/scenarios.md— user-need → CloudBase capability mappingreferences/mcp-setup.md— Plugin install (global default + targets), IDE MCP / mcporter config and auth examplesreferences/activation-map.yaml— canonical routing contract source
Reference index
All packaged reference files (required for skill lint reachability):
