Fork-Safe Flexport Contract CI
SkillDev toolsGate Flexport integrations in CI with credential-free contract tests and an optional protected read-only smoke lane. Use when adding REST, MCP, webhook, version, or mutation safety checks. Trigger with: "test Flexport in CI", "Flexport contract tests", "secure Flexport CI".
Use Fork-Safe Flexport Contract CI in Claude, ChatGPT or Ahel Desktop
Free. Sign in, add Fork-Safe Flexport Contract CI and connect your AI. About a minute.
Also: Claude Code · Cursor · Codex
Then ask your AI: use the Fork-Safe Flexport Contract CI skill
Details
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; Ahel provides instructions and does not run this skill.
No other account needed.
Add Ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
What this skill tells your AI
The instructions your AI receives, as published by jeremylongshore/tons-of-skills-marketplace in skills/.curated/flexport-ci-integration/SKILL.md and read by Ahel’s review.
Overview
The required CI lane must run without Flexport secrets and remain safe for forks. Live verification belongs in a protected, non-fork, read-only lane with explicit environment approval.
Prerequisites
- Sanitized REST, MCP, OAuth-error, and webhook fixtures
- CI permissions model and fork-event policy
- Optional test credential approved through Flexport/account ownership
Instructions
Step 1: Build the required lane
Validate schemas, tolerant additive fields, pagination, error classification, webhook raw-body signatures, and mutation guards entirely from fixtures.
Step 2: Test secret absence
Assert default tests cannot resolve Flexport credentials or reach live mutation adapters.
Step 3: Protect fork execution
Never expose repository/environment secrets to untrusted pull-request code; keep required fork checks credential-free.
Step 4: Define an optional live lane
Run only from trusted refs after environment approval, inject a scoped credential, and permit one documented read-only proof.
Step 5: Block mutations
Enforce an adapter-level CI policy that rejects booking, document, invoice, or purchase-order writes even when a credential exists.
Step 6: Publish receipts
Attach test counts, fixture/source dates, release SHA, and redacted live outcome; never upload tokens or provider payloads.
Authentication
REST calls authenticate with a cached OAuth 2.0 client-credentials Bearer token using audience https://api.flexport.com, or an explicitly accepted broad API key. Use distinct credentials per workload and never log credentials or tokens. MCP calls use the authenticated connection to https://mcp.flexport.com/mcp and remain subject to each tool's documented account permissions.
Tool Discipline
Use Read and Grep for discovery and evidence. Use Write or Edit only for the approved artifact, code, configuration, test, or receipt described by this workflow; do not make an unapproved Flexport-side change.
Output
- Scoped decision or implementation artifact
- Redacted operation and validation receipt
- Failure, rollback, and follow-up ownership record
Return a machine-reviewable receipt in this shape; adapt the operation values, but never place credentials or provider payloads in it:
surface: rest-v3
operation: shipment-read
decision: approved
outcome: verified
evidence:
release_sha: recorded-out-of-band
provider_reference: redacted
rollback_owner: logistics-platform
Examples
Every pull request tests v3 shipment envelopes, MCP cursor handling, malformed webhook signatures, and ambiguous booking guards. A protected main-branch job may perform one shipment list read with a test credential.
Error Handling
| Failure | Response |
|---|---|
| Fork can read a secret | Disable the lane and repair event/environment permissions immediately. |
| Fixture contains production data | Replace and purge it before rerunning. |
| Live job can mutate | Fail the policy gate and remove write-capable paths. |
| Schema drift appears | Update from current first-party docs and add a regression fixture. |
Resources
Signals
- GitHub stars
- 3k
- Forks
- 415
- Last commit
- Oct 2026
Advanced
- Item type
- skill
- Key
flexport-ci-integration- Source
- github.com/jeremylongshore/tons-of-skills-marketplace
github.com/jeremylongshore/tons-of-skills-marketplace