{
"query": "Smart Print estimate preview",
"dryRunOnly": true
}
Smart Shikka Core Control Center
Overview
Core Structure Map
Static architecture view of the preview-only layers. No live execution or external call.
Route Explorer
54 routes in the preview contract index.
{}
{
"limit": 10
}
{
"lines": [
"{\"event\":\"test\"}"
],
"dryRunOnly": true
}
{
"alertType": "suspicious_token",
"severity": "high"
}
{
"toolId": "calculator",
"intent": "add",
"userMessage": "2 + 2"
}
{
"eventType": "test_event",
"dryRunOnly": true
}
{
"query": "customer order summary",
"dryRunOnly": true
}
{
"action": "catalog_preview"
}
{
"action": "request_preview",
"requestedAction": "deploy"
}
{
"action": "plan_preview",
"userMessage": "What is the workflow?"
}
{
"action": "context_envelope",
"appId": "smart_print"
}
{
"action": "dashboard_preview",
"appId": "smart_print"
}
{
"action": "policy_check"
}
{}
{}
{
"action": "policy_check"
}
{}
{}
{
"action": "policy_check"
}
{}
{}
{
"action": "policy_check"
}
{}
{}
{
"action": "policy_check"
}
{}
{}
{
"action": "policy_check"
}
{}
{}
{
"action": "policy_check"
}
{}
{}
{}
{
"action": "policy_check"
}
{}
{}
{
"action": "status_preview"
}
{}
{}
{
"action": "status_preview"
}
{}
{}
{
"action": "status_preview"
}
{}
{}
{
"action": "status_preview"
}
{}
{}
{
"action": "status_preview"
}
{}
{}
{
"action": "status_preview"
}
Module Explorer
26 modules available.
- Gateway preview does not route real traffic.
- Observability is in-memory only; no external export.
- No real remediation or security rule update.
- No real WhatsApp/GitHub/create/deploy gate change.
- Read-only tools preview only; no live MCP execution.
- Audit store preview is in-memory only; no real persistence.
- Memory retrieval preview is in-memory only; no vector/embedding write.
- No provider SDK, no key exposure, no outbound call.
- Real execution is always blocked; approval is preview-only.
- No real AI/provider call or action execution.
- No real app execution, mutation, payment, or send.
- Aggregates only safe metadata; no external call or real execution.
- Central metadata-only index; no real execution or external call.
- No provider call or key validation in preview.
- No secret storage, env write, or key exposure.
- All provider settings are owner-only and blocked until explicit future unlock.
- No real file upload, document parsing, or OCR in preview.
- No external URL fetch, website crawling, or embedding generation.
- No vector DB call, vector write, memory write, or secret exposure.
- No real memory write, persistence, or customer record update in preview.
- No vector DB call, embedding generation, or file/database/audit write.
- No provider call, external network, send, payment, or approved execution.
- No real Goose execution, shell, or process execution in preview.
- No file read/write, workspace mutation, or git mutation in preview.
- No browser automation, MCP live tool execution, provider call, or external network.
- No real browser extension build, installable manifest, content script, or background worker in preview.
- No browser automation, DOM access, page scraping, cookies/history access, or scripting in preview.
- No local storage / session storage / indexed DB, service worker, provider call, external network, or real execution.
- No real WhatsApp or Telegram API call, no webhook registration, no real inbound webhook processing in preview.
- No message send, no email/SMS send, no message persistence, no contact/customer update in preview.
- No provider call, external network, local storage / session storage / indexed DB, service worker, or real execution.
- No real execution, no provider call, no external network, no WhatsApp/Telegram API call, no Goose execution.
- No database/file/audit/memory write, no mutation, no embedding generation, no vector write, no payment, no send.
- No local storage / session storage / indexed DB / service worker, no key material exposure, no live HTTP check.
- No real API call, no provider SDK, no key configuration, no external network.
- No send, no upload, no screenshot, no PDF, no mutation, no write, no payment.
- All candidate APIs require owner approval. No production provider selected.
- No Python execution, no subprocess, no internet fetch, no source fetch.
- No report write, no key/secret, no provider call, no mutation.
- Owner approval required for live research run.
- No real approval persistence, no execution unlock, no send, no write, no payment.
- No external API call, no Python execution, no screenshot, no PDF, no file upload.
- All unsafe capabilities disabled. Owner approval required for all live actions.
- No real execution, no adapter execution, no provider call, no send, no write, no payment.
- No Python execution, no rollback execution, no approval persistence, no audit persistence.
- All unsafe capabilities disabled. Planning layer only.
- No adapter execution, no adapter SDK, no provider SDK, no external API, no send, no write, no payment.
- No Python execution, no subprocess, no research execution, no file/PDF/screenshot.
- All unsafe capabilities disabled. Registry and capability routing only.
- No policy decision persistence, no receipt signing, no real execution.
- No adapter execution, no external API, no Python, no send, no write, no payment.
- Decision engine preview only. All unsafe capabilities disabled.
API Explorer
27 API groups; all endpoints are preview-only and read-only.
{"query":"Smart Print estimate preview","dryRunOnly":true}
{ previewOnly, mode, requestedMode, provider, model, blocked, requiresApproval, mutationExecuted, providerCallExecuted, realExecutionPerformed }
Unauthenticated preview-only route; always returns safe metadata and never routes real traffic.
{}
{ ok, previewOnly, eventCount, maxEventCount, recentEvents, redactionApplied, storage, persistentStoreEnabled, externalNetworkEnabled, mutationExecuted, providerCallExecuted, realExecutionPerformed }
Token-protected read-only route; returns in-memory safe observability summary.
{"limit":10}
{ previewOnly, events, redactionApplied, eventCount, capped }
Token-protected read-only route; returns redacted and capped in-memory events.
{"lines":["{\"event\":\"test\"}"],"dryRunOnly":true}
{ previewOnly, accepted, redacted, parsedRows, errors, policyFlags }
Preview-only security inventory ingest; no real rule update or remediation.
{"alertType":"suspicious_token","severity":"high"}
{ previewOnly, alertPreview, workflowSteps, blocked, policyFlags }
Preview-only alert workflow; no real WhatsApp/GitHub/create/deploy gate change.
{"toolId":"calculator","intent":"add","userMessage":"2 + 2"}
{ previewOnly, toolId, result, redactedInput, policyFlags }
Read-only preview tools; no live MCP/tool execution or network call.
{"eventType":"test_event","dryRunOnly":true}
{ previewOnly, auditEventId, redactedSummary, persisted, policyFlags }
Preview-only audit store; persisted is always false and no real storage write.
{"query":"customer order summary","dryRunOnly":true}
{ previewOnly, matches, queryPreview, memoryWriteEnabled, vectorDatabaseEnabled, embeddingGenerationEnabled, policyFlags }
Preview-only memory retrieval; no memory/vector/embedding write or network call.
{"action":"catalog_preview"}
{ previewOnly, catalog, diagnostics, selectedAdapter, providerCallsEnabled, policyFlags }
Preview-only provider registry; no provider SDK, no key exposure, no outbound call.
{"action":"request_preview","requestedAction":"deploy"}
{ superseded, canonicalRoute, realExecutionPerformed }
Superseded compatibility tombstone; canonical approval authority is POST /api/ceo/approve.
{"action":"plan_preview","userMessage":"What is the workflow?"}
{ superseded, canonicalRoute, realExecutionPerformed }
Superseded compatibility tombstone; canonical orchestration authority is POST /api/ceo/turn.
{"action":"context_envelope","appId":"smart_print"}
{ superseded, canonicalRoute, canonicalManifest, realExecutionPerformed }
Superseded compatibility tombstone; canonical app dispatch uses POST /api/ceo/turn and the seven-app manifest.
{"action":"dashboard_preview","appId":"smart_print"}
{ previewOnly, action, dashboard, modules, readiness, blockers, nextActions, health, policyFlags }
Preview-only owner/ops dashboard aggregator; no real execution or external call.
{"action":"policy_check"}
{ previewOnly, action, routeCatalog?, moduleCatalog?, smokePack?, safetyExpectations?, summary?, policyFlags }
Token-protected preview-only route; returns the central contract index catalog and policy checks.
{}
{ superseded, canonicalReadRoute, canonicalWriteRoute, realExecutionPerformed }
Superseded compatibility tombstone; canonical settings authority is /api/settings/control-plane.
{}
{ superseded, canonicalReadRoute, canonicalWriteRoute, realExecutionPerformed }
Superseded compatibility tombstone; canonical settings authority is /api/settings/control-plane.
{"action":"policy_check"}
{ superseded, canonicalReadRoute, canonicalWriteRoute, realExecutionPerformed }
Superseded compatibility tombstone; canonical settings authority is /api/settings/control-plane.
{}
text/html; previewOnly, uploadEnabled=false, documentParsingEnabled=false, embeddingGenerationEnabled=false, vectorWriteExecuted=false, memoryWriteExecuted=false
Public static HTML page with no file upload, no parser, no URL fetch, no crawling, no embedding, no secret.
{}
{ previewOnly, status, policyFlags, sourceCatalog, uploadEnabled, documentParsingEnabled, embeddingGenerationEnabled, vectorWriteExecuted }
Token-protected safe JSON status; no file upload, no parser, no URL fetch, no embedding, no vector write.
{"action":"policy_check"}
{ action, status, html, summary, schema, chunking, redaction, retrieval, sourceCatalog, policyFlags, policyCompliant }
Preview actions for knowledge / RAG uploads; requires local auth token; no real upload, parser, fetch, embedding, or vector DB call.
{}
text/html; previewOnly, memoryWriteEnabled=false, memoryPersistenceEnabled=false, vectorDatabaseEnabled=false, embeddingGenerationEnabled=false, customerRecordUpdated=false
Public static HTML page with no memory write, no persistence, no secret, no input/button/form/script.
{}
{ previewOnly, status, policyFlags, categoryCatalog, memoryWriteEnabled, memoryPersistenceEnabled, vectorDatabaseEnabled, embeddingGenerationEnabled, customerRecordUpdated }
Token-protected safe JSON status; no memory write, no persistence, no vector DB, no embedding, no customer update.
{"action":"policy_check"}
{ action, status, html, summary, suggestion, approvalFlow, redaction, retention, forgetFlow, policyFlags, policyCompliant }
Preview actions for memory write approval; requires local auth token; no real memory write, persistence, vector DB, or embedding.
{}
text/html; previewOnly, gooseExecutionEnabled=false, shellExecutionEnabled=false, fileWriteExecuted=false, workspaceMutationEnabled=false
Public static HTML page with no Goose execution, no shell/process, no file/workspace/git mutation, no script, no secret.
{}
{ previewOnly, status, policyFlags, commandCatalog, gooseExecutionEnabled, shellExecutionEnabled, commandExecutionPerformed }
Token-protected safe JSON status; no Goose execution, shell, process, file/workspace/git mutation, or provider call.
{"action":"policy_check"}
{ action, status, html, summary, commandCatalog, executionPlan, approvalFlow, sandboxPolicy, rollbackPlan, policyFlags, policyCompliant }
Preview actions for Goose connector; requires local auth token; no real Goose execution, shell, process, file/workspace/git mutation, or provider call.
{}
text/html; previewOnly, extensionBuildEnabled=false, installableManifestEnabled=false, contentScriptEnabled=false, browserAutomationEnabled=false, pageScrapingEnabled=false
Public static HTML page with no real extension build, no installable manifest, no content script, no background worker, no browser automation, no DOM access, no page scraping, no script, no secret.
{}
{ previewOnly, status, policyFlags, permissionCatalog, extensionBuildEnabled, installableManifestEnabled, contentScriptEnabled, browserAutomationEnabled, pageScrapingEnabled }
Token-protected safe JSON status; no real extension build, no installable manifest, no content script, no background worker, no browser automation, no DOM access, no page scraping, no provider call.
{"action":"policy_check"}
{ action, status, html, summary, permissionCatalog, pageContext, redaction, actionDraft, manifest, policyFlags, policyCompliant }
Preview actions for browser extension; requires local auth token; no real extension build, no installable manifest, no content script, no background worker, no browser automation, no DOM access, no page scraping, no provider call.
{}
text/html; previewOnly, whatsappEnabled=false, telegramEnabled=false, whatsappApiCallExecuted=false, telegramApiCallExecuted=false, sendEnabled=false, webhookRegistrationEnabled=false
Public static HTML page with no real WhatsApp/Telegram API call, no webhook registration, no real inbound processing, no message send, no message persistence, no script, no secret.
{}
{ previewOnly, status, policyFlags, channelCatalog, whatsappEnabled, telegramEnabled, sendEnabled, webhookRegistrationEnabled }
Token-protected safe JSON status; no real WhatsApp/Telegram API call, no webhook registration, no real inbound processing, no message send, no provider call.
{"action":"policy_check"}
{ action, status, html, summary, channelCatalog, inboundMessage, redaction, replyDraft, sendPolicy, webhookSchema, policyFlags, policyCompliant }
Preview actions for WhatsApp / Telegram connector; requires local auth token; no real API call, no webhook registration, no real inbound processing, no message send, no provider call.
{}
text/html; previewOnly, static app catalog, route index, safety summary, next safe actions
Public read-only home HTML page with no real execution, no provider call, no external network, no secret, no mutation, no storage, no service worker.
{}
text/html; previewOnly, compact app catalog and route index
Public read-only /apps HTML page with no real execution, no provider call, no secret, no mutation, no storage.
{}
{ previewOnly, status, appCatalog, routeIndex, navigation, policyFlags, policyCompliant }
Token-protected safe JSON status; no real execution, no provider call, no external network, no secret exposure.
{"action":"policy_check"}
{ action, status, html, summary, appCatalog, routeIndex, navigation, policyFlags, policyCompliant }
Preview actions for the home dashboard; requires local auth token; no real execution, no provider call, no external network, no mutation, no secret exposure.
{}
text/html; previewOnly, external service toolkit catalog and policy preview
Public read-only external service toolkit HTML page; no real API call, no provider SDK, no key, no send, no upload, no screenshot, no PDF.
{}
{ status, policyFlags, previewOnly }
Token-protected external service toolkit status; no real API call, no provider SDK, no key, no mutation.
{"action":"status_preview"}
{ action, result|catalog|permissions|policy|status|summary, policyFlags, previewOnly }
Preview actions for external service toolkit; requires local auth token; no real API call, no provider SDK, no key, no send, no upload, no screenshot, no PDF.
{}
text/html; previewOnly, research engine preview page with research types and source catalog
Public read-only research engine HTML page; no Python execution, no subprocess, no internet fetch, no report write.
{}
{ status, policyFlags, previewOnly }
Token-protected research engine status; no Python execution, no subprocess, no internet fetch, no report write.
{"action":"status_preview"}
{ action, result|catalog|plan|schema|policy|flow|safety, policyFlags, previewOnly }
Preview actions for research engine; requires local auth token; no Python execution, no subprocess, no internet fetch, no report write.
{}
{ contentType, html, previewOnly }
Public HTML preview of tool approval workflow; no real persistence, no execution, no send, no write, no payment.
{}
{ previewOnly, status, policyFlags }
Token-protected tool approval workflow status; no real persistence, no execution, no send, no write, no payment.
{"action":"status_preview"}
{ action, result|status|summary, policyFlags, previewOnly }
Preview actions for tool approval workflow; requires local auth token; no real persistence, no execution, no send, no write, no payment.
{}
{ contentType, html, previewOnly }
Public HTML preview of safe tool execution plan; no real execution, no adapter, no send, no write, no payment.
{}
{ previewOnly, status, policyFlags }
Token-protected safe tool execution plan status; no real execution, no adapter, no send, no write, no payment.
{"action":"status_preview"}
{ action, result|status|summary, policyFlags, previewOnly }
Preview actions for safe tool execution plan; requires local auth token; no real execution, no adapter, no send, no write, no payment.
{}
HTML page (no script, no form, no button)
Public HTML tool adapter registry preview; no token, no adapter execution, no SDK, no send, no write, no payment.
{}
{ previewOnly, status, policyFlags }
Token-protected tool adapter registry status; no adapter execution, no SDK, no send, no write, no payment.
{"action":"status_preview"}
{ action, result|status|summary, policyFlags, previewOnly }
Preview actions for tool adapter registry; requires local auth token; no adapter execution, no SDK, no send, no write, no payment.
{}
{ html }
Public policy decision API HTML preview; no token; safe static read-only page.
{}
{ status, policyFlags, previewOnly }
Protected policy decision API JSON status; requires local auth token; no persistence, no execution.
{"action":"status_preview"}
{ action, result|status|summary, policyFlags, previewOnly }
Preview actions for policy decision API; requires local auth token; no persistence, no execution, no send, no write, no payment.
{}
text/html; previewOnly, realExecutionPerformed=false, providerCallExecuted=false, mutationExecuted=false
Public static HTML page with no secret and no live env read.
{}
{ status, routeCount, moduleCount, apiExplorerGroups, mcpExplorerTools, policyFlags, previewOnly }
Safe JSON status; requires x-smart-shikka-local-token header if local auth is configured.
{"action":"status_preview"}
{ action, status, html, summary, policyFlags, policyCompliant, previewOnly }
Preview actions for control center; requires x-smart-shikka-local-token header if local auth is configured.
MCP Read-only Tools
4 read-only preview tools; no live execution or provider call.
{
"toolId": "calculator_preview",
"intent": "<INTENT>",
"userMessage": "<USER_MESSAGE>",
"pageContext": {},
"knowledgeContext": {},
"maxResults": 10
}
{
"previewOnly": true,
"readOnly": true,
"toolId": "calculator_preview",
"toolStatus": "preview_only",
"policy": {
"allowed": true,
"riskLevel": "safe"
},
"result": {},
"mutationExecuted": false,
"providerCallExecuted": false,
"realExecutionPerformed": false,
"externalNetworkEnabled": false,
"approvedExecutionEnabled": false,
"saveExecuted": false,
"sendExecuted": false,
"paymentExecuted": false,
"customerRecordUpdated": false
}
Safe numeric/formula preview only. No real calculation backend, no payment math.
{
"toolId": "knowledge_search_preview",
"intent": "<INTENT>",
"userMessage": "<USER_MESSAGE>",
"pageContext": {},
"knowledgeContext": {},
"maxResults": 10
}
{
"previewOnly": true,
"readOnly": true,
"toolId": "knowledge_search_preview",
"toolStatus": "preview_only",
"policy": {
"allowed": true,
"riskLevel": "safe"
},
"result": {},
"mutationExecuted": false,
"providerCallExecuted": false,
"realExecutionPerformed": false,
"externalNetworkEnabled": false,
"approvedExecutionEnabled": false,
"saveExecuted": false,
"sendExecuted": false,
"paymentExecuted": false,
"customerRecordUpdated": false
}
Searches only provided sanitized context. No DB, no network, no raw private data echo.
{
"toolId": "report_draft_preview",
"intent": "<INTENT>",
"userMessage": "<USER_MESSAGE>",
"pageContext": {},
"knowledgeContext": {},
"maxResults": 10
}
{
"previewOnly": true,
"readOnly": true,
"toolId": "report_draft_preview",
"toolStatus": "preview_only",
"policy": {
"allowed": true,
"riskLevel": "safe"
},
"result": {},
"mutationExecuted": false,
"providerCallExecuted": false,
"realExecutionPerformed": false,
"externalNetworkEnabled": false,
"approvedExecutionEnabled": false,
"saveExecuted": false,
"sendExecuted": false,
"paymentExecuted": false,
"customerRecordUpdated": false
}
Draft outline/text preview only. No save, no send, no export, no PDF generation.
{
"toolId": "status_read_preview",
"intent": "<INTENT>",
"userMessage": "<USER_MESSAGE>",
"pageContext": {},
"knowledgeContext": {},
"maxResults": 10
}
{
"previewOnly": true,
"readOnly": true,
"toolId": "status_read_preview",
"toolStatus": "preview_only",
"policy": {
"allowed": true,
"riskLevel": "safe"
},
"result": {},
"mutationExecuted": false,
"providerCallExecuted": false,
"realExecutionPerformed": false,
"externalNetworkEnabled": false,
"approvedExecutionEnabled": false,
"saveExecuted": false,
"sendExecuted": false,
"paymentExecuted": false,
"customerRecordUpdated": false
}
Read-only metadata summary. No live route call, no Core DB read.
Safety Flags
Safety Matrix
All unsafe capabilities are blocked by policy; no live execution or network call.
| Capability | Status | Expected | Evidence |
|---|---|---|---|
| Provider Call | blocked | off | providerCallExecuted=false; capability is blocked by control center policy. |
| External Network | blocked | off | externalNetworkEnabled=false; capability is blocked by control center policy. |
| Real Execution | blocked | off | realExecutionPerformed=false; capability is blocked by control center policy. |
| Approved Execution | blocked | off | approvedExecutionEnabled=false; capability is blocked by control center policy. |
| Mutation | blocked | off | mutationExecuted=false; capability is blocked by control center policy. |
| Database Write | blocked | off | databaseWriteExecuted=false; capability is blocked by control center policy. |
| File Write | blocked | off | fileWriteExecuted=false; capability is blocked by control center policy. |
| Audit Write | blocked | off | auditWriteExecuted=false; capability is blocked by control center policy. |
| Memory Write | blocked | off | memoryWriteExecuted=false; capability is blocked by control center policy. |
| Payment | blocked | off | paymentExecuted=false; capability is blocked by control center policy. |
| Send | blocked | off | sendExecuted=false; capability is blocked by control center policy. |
| Customer Record Update | blocked | off | customerRecordUpdated=false; capability is blocked by control center policy. |
| Embedding Generation | blocked | off | embeddingGenerationEnabled=false; capability is blocked by control center policy. |
| Key Material Exposure | blocked | off | keyMaterialExposed=false; capability is blocked by control center policy. |
| Smoke Execution | blocked | off | smokeExecuted=false; capability is blocked by control center policy. |
Route Risk Matrix
Risk posture for every preview route from the contract catalog.
| Route | Risk Level | Risk Factors | Mitigation |
|---|---|---|---|
POST POST /v1/gateway/preview |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
GET GET /v1/gateway/observability/preview-status |
auth_required_preview |
|
Protect with local token; do not expose the token in browser or logs. |
GET GET /v1/gateway/observability/recent-events |
auth_required_preview |
|
Protect with local token; do not expose the token in browser or logs. |
POST POST /v1/security/bumblebee/preview-ingest |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
POST POST /v1/security/bumblebee/preview-alert |
safe_preview |
|
Public preview route; no auth or live execution required. |
POST POST /v1/mcp/read-only-tools/preview |
safe_preview |
|
Public preview route; no auth or live execution required. |
POST POST /v1/audit-store/preview |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
POST POST /v1/memory-retrieval/preview |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
POST POST /v1/provider-registry/preview |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
POST POST /v1/approval-execution/preview |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
POST POST /v1/assistant/orchestrator/preview |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
POST POST /v1/app-integration/preview |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
POST POST /v1/owner-ops-dashboard/preview |
owner_ops_preview |
|
Owner/ops route; verify role and intent before any real ops enablement. |
POST POST /v1/core/preview-contracts |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
GET GET /settings/providers |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
GET GET /v1/core/provider-settings |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
POST POST /v1/core/provider-settings/preview |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
GET GET /knowledge |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
GET GET /v1/core/knowledge |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
POST POST /v1/core/knowledge/preview |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
GET GET /memory |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
GET GET /v1/core/memory |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
POST POST /v1/core/memory/preview |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
GET GET /goose |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
GET GET /v1/core/goose |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
POST POST /v1/core/goose/preview |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
GET GET /browser-extension |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
GET GET /v1/core/browser-extension |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
POST POST /v1/core/browser-extension/preview |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
GET GET /messaging |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
GET GET /v1/core/messaging |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
POST POST /v1/core/messaging/preview |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
GET GET / |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
GET GET /apps |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
GET GET /v1/core/apps |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
POST POST /v1/core/apps/preview |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
GET GET /external-services |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
GET GET /v1/core/external-services |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
POST POST /v1/core/external-services/preview |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
GET GET /research-engine |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
GET GET /v1/core/research-engine |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
POST POST /v1/core/research-engine/preview |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
GET GET /approvals |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
GET GET /v1/core/approvals |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
POST POST /v1/core/approvals/preview |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
GET GET /execution-plans |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
GET GET /v1/core/execution-plans |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
POST POST /v1/core/execution-plans/preview |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
GET GET /adapters |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
GET GET /v1/core/adapters |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
POST POST /v1/core/adapters/preview |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
GET GET /policy-decisions |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
GET GET /v1/core/policy-decisions |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
POST POST /v1/core/policy-decisions/preview |
blocked_execution_preview |
|
Forbidden capabilities are blocked by contract; real execution remains disabled. |
Module Risk Matrix
Risk posture for every preview module from the module catalog.
| Module | Risk Level | Risk Factors | Mitigation |
|---|---|---|---|
| Gateway Preview (gateway_preview) | safe_preview |
|
All execution, provider, and write flags are disabled; safe to preview. |
| Gateway Observability (gateway_observability) | safe_preview |
|
All execution, provider, and write flags are disabled; safe to preview. |
| Security Inventory Preview (security_inventory_preview) | safe_preview |
|
All execution, provider, and write flags are disabled; safe to preview. |
| Security Alert Preview (security_alert_preview) | safe_preview |
|
All execution, provider, and write flags are disabled; safe to preview. |
| MCP Read-only Tools Preview (mcp_readonly_tools_preview) | safe_preview |
|
All execution, provider, and write flags are disabled; safe to preview. |
| Audit Store Preview (audit_store_preview) | safe_preview |
|
All execution, provider, and write flags are disabled; safe to preview. |
| Memory + Retrieval Preview (memory_retrieval_preview) | safe_preview |
|
All execution, provider, and write flags are disabled; safe to preview. |
| Provider Registry Preview (provider_registry_preview) | safe_preview |
|
All execution, provider, and write flags are disabled; safe to preview. |
| Approval Execution Preview (approval_execution_preview) | safe_preview |
|
All execution, provider, and write flags are disabled; safe to preview. |
| Assistant Orchestrator Preview (assistant_orchestrator_preview) | safe_preview |
|
All execution, provider, and write flags are disabled; safe to preview. |
| App Integration Preview (app_integration_preview) | app_integration_preview |
|
App integration module; verify per-app policy and consent before real handoff. |
| Owner/Ops Dashboard Preview (owner_ops_dashboard_preview) | owner_ops_preview |
|
Owner/ops module; restrict to authorized operators and audit before enabling. |
| Core Preview Contract Index (core_preview_contract_index) | safe_preview |
|
All execution, provider, and write flags are disabled; safe to preview. |
| Owner API Key Settings Preview (provider_settings_preview) | safe_preview |
|
All execution, provider, and write flags are disabled; safe to preview. |
| Knowledge / RAG Upload Preview (knowledge_rag_preview) | safe_preview |
|
All execution, provider, and write flags are disabled; safe to preview. |
| Memory Write Approval Preview (memory_approval_preview) | safe_preview |
|
All execution, provider, and write flags are disabled; safe to preview. |
| Goose Connector Preview (goose_connector_preview) | safe_preview |
|
All execution, provider, and write flags are disabled; safe to preview. |
| Browser Extension Preview (browser_extension_preview) | safe_preview |
|
All execution, provider, and write flags are disabled; safe to preview. |
| WhatsApp / Telegram Connector Preview (messaging_connector_preview) | safe_preview |
|
All execution, provider, and write flags are disabled; safe to preview. |
| Preview Apps Home Dashboard (preview_apps_home_dashboard) | safe_preview |
|
All execution, provider, and write flags are disabled; safe to preview. |
| External Service Toolkit Preview (external_service_toolkit_preview) | safe_preview |
|
All execution, provider, and write flags are disabled; safe to preview. |
| Research Engine Preview (research_engine_preview) | safe_preview |
|
All execution, provider, and write flags are disabled; safe to preview. |
| Tool Approval Workflow Preview (tool_approval_workflow_preview) | safe_preview |
|
All execution, provider, and write flags are disabled; safe to preview. |
| Safe Tool Execution Plan Preview (safe_tool_execution_plan_preview) | safe_preview |
|
All execution, provider, and write flags are disabled; safe to preview. |
| Tool Adapter Registry Preview (tool_adapter_registry_preview) | safe_preview |
|
All execution, provider, and write flags are disabled; safe to preview. |
| Policy Decision API Preview (policy_decision_api_preview) | safe_preview |
|
All execution, provider, and write flags are disabled; safe to preview. |
Diagnostics Preview
Static, preview-only diagnostics with no live checks, no env read, and no network call.
Deployment
API Route Availability
Auth Boundary
Control Center HTML Safety
Provider Safety
Execution Safety
App Integration Readiness
Owner/Ops Readiness
Documentation
Section Completion
Current completion status of the Web/Desktop control center sections.
Print/Export Safe View
Browser print and export are safe for this read-only preview page.
- Browser print is safe; only static preview text is shown.
- No token, API key, Mongo URI, or provider key appears in the page.
- No live data is fetched when printing or exporting.
- No hidden environment variables are exposed.
- No execution, payment, send, or provider call is triggered.
- Printed copy remains preview-only and non-binding.
Use your browser print dialog to save a read-only copy. Do not use this copy for production operations.
Completion Summary
Final web/desktop section status. Live deploy and Smart Print/Drishti consumption are handled separately.
Copy-Safe cURL Examples
Replace <LOCAL_AUTH_TOKEN> with your local token only when running locally. Never commit a real token.
curl -X POST "https://shikka.anoopampress.com/api/v1/gateway/preview" \
-H "Content-Type: application/json" \
-d '{"query":"Smart Print estimate preview","dryRunOnly":true}'
curl -X GET "https://shikka.anoopampress.com/api/v1/gateway/observability/preview-status" \
-H "Content-Type: application/json" \
-H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>"
curl -X GET "https://shikka.anoopampress.com/api/v1/gateway/observability/recent-events" \
-H "Content-Type: application/json" \
-H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>"
curl -X POST "https://shikka.anoopampress.com/api/v1/security/bumblebee/preview-ingest" \
-H "Content-Type: application/json" \
-d '{"lines":["{\"event\":\"test\"}"],"dryRunOnly":true}'
curl -X POST "https://shikka.anoopampress.com/api/v1/security/bumblebee/preview-alert" \
-H "Content-Type: application/json" \
-d '{"alertType":"suspicious_token","severity":"high"}'
curl -X POST "https://shikka.anoopampress.com/api/v1/mcp/read-only-tools/preview" \
-H "Content-Type: application/json" \
-d '{"toolId":"calculator","intent":"add","userMessage":"2 + 2"}'
curl -X POST "https://shikka.anoopampress.com/api/v1/audit-store/preview" \
-H "Content-Type: application/json" \
-d '{"eventType":"test_event","dryRunOnly":true}'
curl -X POST "https://shikka.anoopampress.com/api/v1/memory-retrieval/preview" \
-H "Content-Type: application/json" \
-d '{"query":"customer order summary","dryRunOnly":true}'
curl -X POST "https://shikka.anoopampress.com/api/v1/provider-registry/preview" \
-H "Content-Type: application/json" \
-d '{"action":"catalog_preview"}'
curl -X POST "https://shikka.anoopampress.com/api/v1/approval-execution/preview" \
-H "Content-Type: application/json" \
-d '{"action":"request_preview","requestedAction":"deploy"}'
curl -X POST "https://shikka.anoopampress.com/api/v1/assistant/orchestrator/preview" \
-H "Content-Type: application/json" \
-d '{"action":"plan_preview","userMessage":"What is the workflow?"}'
curl -X POST "https://shikka.anoopampress.com/api/v1/app-integration/preview" \
-H "Content-Type: application/json" \
-d '{"action":"context_envelope","appId":"smart_print"}'
curl -X POST "https://shikka.anoopampress.com/api/v1/owner-ops-dashboard/preview" \
-H "Content-Type: application/json" \
-d '{"action":"dashboard_preview","appId":"smart_print"}'
curl -X POST "https://shikka.anoopampress.com/api/v1/core/preview-contracts" \
-H "Content-Type: application/json" \
-H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>" \
-d '{"action":"policy_check"}'
curl -X GET "https://shikka.anoopampress.com/api/settings/providers" \
-H "Content-Type: application/json"
curl -X GET "https://shikka.anoopampress.com/api/v1/core/provider-settings" \
-H "Content-Type: application/json"
curl -X POST "https://shikka.anoopampress.com/api/v1/core/provider-settings/preview" \
-H "Content-Type: application/json" \
-d '{"action":"policy_check"}'
curl -X GET "https://shikka.anoopampress.com/api/knowledge" \
-H "Content-Type: application/json"
curl -X GET "https://shikka.anoopampress.com/api/v1/core/knowledge" \
-H "Content-Type: application/json" \
-H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>"
curl -X POST "https://shikka.anoopampress.com/api/v1/core/knowledge/preview" \
-H "Content-Type: application/json" \
-H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>" \
-d '{"action":"policy_check"}'
curl -X GET "https://shikka.anoopampress.com/api/memory" \
-H "Content-Type: application/json"
curl -X GET "https://shikka.anoopampress.com/api/v1/core/memory" \
-H "Content-Type: application/json" \
-H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>"
curl -X POST "https://shikka.anoopampress.com/api/v1/core/memory/preview" \
-H "Content-Type: application/json" \
-H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>" \
-d '{"action":"policy_check"}'
curl -X GET "https://shikka.anoopampress.com/api/goose" \
-H "Content-Type: application/json"
curl -X GET "https://shikka.anoopampress.com/api/v1/core/goose" \
-H "Content-Type: application/json" \
-H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>"
curl -X POST "https://shikka.anoopampress.com/api/v1/core/goose/preview" \
-H "Content-Type: application/json" \
-H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>" \
-d '{"action":"policy_check"}'
curl -X GET "https://shikka.anoopampress.com/api/browser-extension" \
-H "Content-Type: application/json"
curl -X GET "https://shikka.anoopampress.com/api/v1/core/browser-extension" \
-H "Content-Type: application/json" \
-H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>"
curl -X POST "https://shikka.anoopampress.com/api/v1/core/browser-extension/preview" \
-H "Content-Type: application/json" \
-H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>" \
-d '{"action":"policy_check"}'
curl -X GET "https://shikka.anoopampress.com/api/messaging" \
-H "Content-Type: application/json"
curl -X GET "https://shikka.anoopampress.com/api/v1/core/messaging" \
-H "Content-Type: application/json" \
-H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>"
curl -X POST "https://shikka.anoopampress.com/api/v1/core/messaging/preview" \
-H "Content-Type: application/json" \
-H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>" \
-d '{"action":"policy_check"}'
curl -X GET "https://shikka.anoopampress.com/api/" \
-H "Content-Type: application/json"
curl -X GET "https://shikka.anoopampress.com/api/apps" \
-H "Content-Type: application/json"
curl -X GET "https://shikka.anoopampress.com/api/v1/core/apps" \
-H "Content-Type: application/json" \
-H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>"
curl -X POST "https://shikka.anoopampress.com/api/v1/core/apps/preview" \
-H "Content-Type: application/json" \
-H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>" \
-d '{"action":"policy_check"}'
curl -X GET "https://shikka.anoopampress.com/api/external-services" \
-H "Content-Type: application/json"
curl -X GET "https://shikka.anoopampress.com/api/v1/core/external-services" \
-H "Content-Type: application/json" \
-H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>"
curl -X POST "https://shikka.anoopampress.com/api/v1/core/external-services/preview" \
-H "Content-Type: application/json" \
-H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>" \
-d '{"action":"status_preview"}'
curl -X GET "https://shikka.anoopampress.com/api/research-engine" \
-H "Content-Type: application/json"
curl -X GET "https://shikka.anoopampress.com/api/v1/core/research-engine" \
-H "Content-Type: application/json" \
-H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>"
curl -X POST "https://shikka.anoopampress.com/api/v1/core/research-engine/preview" \
-H "Content-Type: application/json" \
-H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>" \
-d '{"action":"status_preview"}'
curl -X GET "https://shikka.anoopampress.com/api/approvals" \
-H "Content-Type: application/json"
curl -X GET "https://shikka.anoopampress.com/api/v1/core/approvals" \
-H "Content-Type: application/json" \
-H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>"
curl -X POST "https://shikka.anoopampress.com/api/v1/core/approvals/preview" \
-H "Content-Type: application/json" \
-H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>" \
-d '{"action":"status_preview"}'
curl -X GET "https://shikka.anoopampress.com/api/execution-plans" \
-H "Content-Type: application/json"
curl -X GET "https://shikka.anoopampress.com/api/v1/core/execution-plans" \
-H "Content-Type: application/json" \
-H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>"
curl -X POST "https://shikka.anoopampress.com/api/v1/core/execution-plans/preview" \
-H "Content-Type: application/json" \
-H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>" \
-d '{"action":"status_preview"}'
curl -X GET "https://shikka.anoopampress.com/api/adapters" \
-H "Content-Type: application/json"
curl -X GET "https://shikka.anoopampress.com/api/v1/core/adapters" \
-H "Content-Type: application/json" \
-H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>"
curl -X POST "https://shikka.anoopampress.com/api/v1/core/adapters/preview" \
-H "Content-Type: application/json" \
-H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>" \
-d '{"action":"status_preview"}'
curl -X GET "https://shikka.anoopampress.com/api/policy-decisions" \
-H "Content-Type: application/json"
curl -X GET "https://shikka.anoopampress.com/api/v1/core/policy-decisions" \
-H "Content-Type: application/json" \
-H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>"
curl -X POST "https://shikka.anoopampress.com/api/v1/core/policy-decisions/preview" \
-H "Content-Type: application/json" \
-H "x-smart-shikka-local-token: <LOCAL_AUTH_TOKEN>" \
-d '{"action":"status_preview"}'
Smoke Checklist
Leak Checks
- no_api_key
- no_password
- no_secret
- no_private_key
- no_access_token
- no_provider_key
- no_database_uri
- no_mongo_url
- no_whatsapp_token
- no_customer_pii
No route is invoked; no network call; no real token required for preview catalog.