Structured candidate
- Company
- Example Meridian
- Fit rationale
- Selected attributes align; trigger remains unconfirmed.
- Contact context
- Role evidence available; channel freshness unresolved.
- Review state
- Investigate further
Agent integrations
Treat every input source, research action, credential, and output destination as a governed connection. The canvas shows a reference architecture, not a claim of verified support for a named third-party platform.

Runtime matrix
Do not mistake a decorative logo wall for an integration contract. Confirm each connection in the environment where the skill runs, and label unverified routes honestly.
A connection is named in configuration, but no successful request has been observed in the current environment.
A dated, read-only test records the runtime version, provider, permission scope, request ID, latency, returned fields, and failure state.
The same fixture passes after a package, runtime, provider API, permission, or schema change. Any one of those changes invalidates the earlier status until retested.
Inspectable handoff
This SAMPLE illustrates the fields a team may use to understand an agent result. It does not represent a real company, person, source provider, or integration.
observed_at_utc
os_version
node_version
agent_runtime
runtime_versionpackage_name
resolved_version
installer_exit_code
install_seconds
configuration_hashprovider_name
endpoint_or_tool
permission_scope
request_id
latency_msfixture_id
source_checked_at
review_state
reviewer_reason
failure_codeNever place API keys, access tokens, personal email addresses, or raw customer records in this manifest. Hash the non-secret configuration, keep secrets in the runtime store, and preserve the denominator behind every measured rate.
Connection boundaries
Security posture cannot be inferred from a page design. Use published documentation, package inspection, runtime configuration, provider terms, and your own technical review to confirm actual behavior.
Use the secret mechanism supported by your chosen runtime. Scope, rotate, and revoke credentials through the provider process.
Review package output, requested access, network behavior, update path, and uninstall procedure before allowing sensitive workflows.
Account for agent history, logs, provider retention, generated files, exports, and downstream destinations. Assign deletion ownership.
Rate limits, authentication errors, conflicting fields, and missing evidence should produce visible failure states instead of plausible guesses.
Install reference
Copying does not execute the package or authorize a connection.