> ## Documentation Index
> Fetch the complete documentation index at: https://test-8ad8522e-feat-ai-sre.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# 上传技能

> 上传技能压缩包（.skill/.zip/.tar.gz/.tgz）以创建或覆盖技能。

## 限制说明

| 项目   | 说明                         |
| ---- | -------------------------- |
| 速率限制 | 每个账户 **30 次/分钟**；**3 次/秒** |
| 权限要求 | **Skill 管理**（`ai-sre`）     |

## 使用说明

* 以 `multipart/form-data` 提交，包含 `file` 部分；支持的压缩包类型为 `.skill`、`.zip`、`.tar.gz`、`.tgz`，最大 100MB（超限文件会在读取正文前即被拒绝）。
* `skill_id` + `replace=true` 会定向覆盖该指定技能，且跳过团队归属校验，因为调用者本就拥有该行。
* 仅 `replace=true`（不带 `skill_id`）会按技能名称做 upsert；不设置 `replace` 则始终创建新技能 —— 这两条路径都要求调用者被允许向目标 `team_id` 创建资源。
* 响应始终将 `can_edit` 标记为 `true`。
* 每次调用都会记录到账户审计日志。


## OpenAPI

````yaml /api-reference/safari.openapi.zh.json post /safari/skill/upload
openapi: 3.1.0
info:
  title: Flashduty 开放 API
  description: >-
    Flashduty AI SRE 平台的公开 HTTP API —— 技能、MCP 服务器（连接器）、A2A 智能体与会话。所有接口均使用
    Flashduty 控制台签发的 `app_key` 查询参数进行认证。
  version: 1.0.0
servers:
  - url: https://api.flashcat.cloud
    description: Flashduty Open API
security:
  - AppKeyAuth: []
tags:
  - name: AI SRE/技能
    description: AI SRE 智能体技能管理。
  - name: AI SRE/MCP 服务器
    description: MCP（Model Context Protocol）服务器管理。
  - name: AI SRE/A2A 智能体
    description: A2A（智能体到智能体）远程智能体管理。
  - name: AI SRE/会话
    description: AI SRE 智能体会话历史 —— 查询、查看与导出会话记录。
  - name: AI SRE/自动化
  - name: AI SRE/知识
  - name: AI SRE/产物
    description: AI SRE 产物库 —— 发布、浏览并公开分享智能体生成的文件。
paths:
  /safari/skill/upload:
    post:
      tags:
        - AI SRE/技能
      summary: 上传技能
      description: 上传技能压缩包（.skill/.zip/.tar.gz/.tgz）以创建或覆盖技能。
      operationId: skill-write-upload
      requestBody:
        required: true
        content:
          multipart/form-data:
            schema:
              $ref: '#/components/schemas/SkillUploadRequest'
            example:
              team_id: 0
              replace: false
      responses:
        '200':
          description: 成功
          content:
            application/json:
              schema:
                allOf:
                  - $ref: '#/components/schemas/ResponseEnvelope'
                  - type: object
                    properties:
                      data:
                        $ref: '#/components/schemas/SkillItem'
              example:
                request_id: 01HK8XQE3Z7JM2NTFQ5YJ8P9R4
                data:
                  skill_id: skill_8s7Hn2kLpQ3xYbVc4Wd2m
                  account_id: 10023
                  team_id: 0
                  skill_name: k8s-triage
                  description: >-
                    Diagnose unhealthy Kubernetes workloads from cluster events
                    and pod logs.
                  version: 1.2.0
                  tags:
                    - kubernetes
                    - triage
                  author: sre-team
                  tools:
                    - bash
                    - mcp:prometheus/query
                  status: enabled
                  created_by: 80011
                  created_at: 1716960000000
                  updated_at: 1717046400000
                  can_edit: true
                  update_available: false
                  is_modified: false
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '429':
          $ref: '#/components/responses/TooManyRequests'
        '500':
          $ref: '#/components/responses/ServerError'
      security:
        - AppKeyAuth: []
components:
  schemas:
    SkillUploadRequest:
      type: object
      description: 上传技能压缩包的 multipart 表单。
      properties:
        file:
          type: string
          format: binary
          description: 技能压缩包（.skill / .zip / .tar.gz / .tgz），最大 100MB；超限文件会在读取正文前即被拒绝。
        team_id:
          type: integer
          description: 新建/upsert 技能的团队范围：0 表示账户级。通过 `skill_id` 定向替换时会忽略该字段。
          format: int64
        replace:
          type: boolean
          description: 为 true 时覆盖已有技能而非在名称冲突时报错 —— 若提供 `skill_id` 则按其匹配，否则按技能名称匹配。
        skill_id:
          type: string
          description: 定向替换指定技能时的技能 ID（需配合 `replace=true`）。
      required:
        - file
    ResponseEnvelope:
      type: object
      description: >-
        Standard response envelope used by every Flashduty public API. On
        success `data` contains the endpoint-specific payload and `error` is
        absent. On failure `error` is present and `data` is absent. `request_id`
        is always present and is also mirrored in the `Flashcat-Request-Id`
        response header.
      properties:
        request_id:
          type: string
          description: 本次请求的唯一 ID，与 Flashcat-Request-Id 响应头一致。反馈问题时请携带该 ID。
          example: 01HK8XQE3Z7JM2NTFQ5YJ8P9R4
        error:
          $ref: '#/components/schemas/DutyError'
        data:
          description: 端点专属数据负载，具体结构见各操作 200 响应中的 schema。
      required:
        - request_id
    SkillItem:
      type: object
      description: AI SRE 技能 —— 智能体可加载的 SKILL.md 打包资源。
      properties:
        skill_id:
          type: string
          description: 技能唯一 ID（前缀 `skill_`）。
        account_id:
          type: integer
          description: 所属账户 ID。
          format: int64
        team_id:
          type: integer
          description: 团队范围：0 表示账户级；>0 表示所属团队。
          format: int64
        skill_name:
          type: string
          description: 技能名称，在其作用域内唯一（账户范围或单个团队内）。
        description:
          type: string
          description: 来自 SKILL.md frontmatter 的可读描述。
        description_en:
          type: string
          description: >-
            可选的英文描述。英文语言环境下的界面响应优先使用该字段而非 `description`；当 `description`
            被本地化展示时，技能目录也会用它作为稳定的选型信号。
        content:
          type: string
          description: 完整的 SKILL.md 内容；列表响应中省略。
        version:
          type: string
          description: frontmatter 中的技能版本。
        tags:
          type: array
          items:
            type: string
          description: 从 frontmatter 解析的标签。
        author:
          type: string
          description: 技能作者。
        license:
          type: string
          description: 技能许可证。
        tools:
          type: array
          items:
            type: string
          description: 所需工具（内置或 `mcp:server/tool`）。
        venues:
          type: array
          items:
            type: string
          description: 限定技能可用的执行环境类型（EnvironmentKind 字符串，如 `byoc`）；为空时省略，表示所有环境均可用。
        s3_key:
          type: string
          description: 技能压缩包在对象存储中的 key。
        checksum:
          type: string
          description: 技能压缩包的 SHA-256 校验和。
        status:
          type: string
          description: 技能状态。已删除的技能不会出现在任何 API 响应中，因此只会返回这两种状态。
          enum:
            - enabled
            - disabled
        created_by:
          type: integer
          description: 创建该技能的成员 ID。
          format: int64
        created_at:
          type: integer
          format: int64
          description: 创建时间，Unix 毫秒时间戳。
        updated_at:
          type: integer
          format: int64
          description: 最近更新时间，Unix 毫秒时间戳。
        can_edit:
          type: boolean
          description: 调用者是否可编辑该技能。
        source_template_name:
          type: string
          description: 该技能安装来源的市场模板名称；自建技能为空。
        source_template_version:
          type: string
          description: 安装时的模板版本。
        update_available:
          type: boolean
          description: 当市场存在更新版本时为 true。
        is_modified:
          type: boolean
          description: 当市场来源技能被本地修改时为 true（自动更新将跳过）。
        created:
          type: boolean
          description: 仅在“从会话安装”响应中出现：true 表示新建，false 表示原地更新。
      required:
        - skill_id
        - account_id
        - team_id
        - skill_name
        - description
        - status
        - created_by
        - created_at
        - updated_at
        - can_edit
        - update_available
        - is_modified
    DutyError:
      type: object
      description: 响应结构中的错误 payload，仅在非 2xx 响应时出现。
      properties:
        code:
          $ref: '#/components/schemas/ErrorCode'
        message:
          type: string
          description: 用户可读的错误描述，语言会跟随调用方的 Accept-Language。可能包含字段名、ID 等请求上下文。
          example: The specified parameter template_id is not valid.
      required:
        - code
        - message
    ErrorResponse:
      type: object
      description: 错误响应结构。`error` 必填，`data` 不存在。
      properties:
        request_id:
          type: string
          example: 01HK8XQE3Z7JM2NTFQ5YJ8P9R4
          description: 本次请求的唯一追踪 ID（trace ID），反馈问题时请提供该值以便检索日志。
        error:
          $ref: '#/components/schemas/DutyError'
      required:
        - request_id
        - error
    ErrorCode:
      type: string
      description: >-
        Flashduty 错误码枚举。每个失败响应的 `error.code` 都是下列稳定值之一，HTTP 状态码仅作参考。


        | 错误码 | HTTP | 含义 |

        |---|---|---|

        | `OK` | 200 | 保留值，正常错误响应不会返回。 |

        | `InvalidParameter` | 400 | 必填参数缺失或未通过校验。 |

        | `BadRequest` | 400 | 通用的 400 错误，通常是请求本身不合法。 |

        | `InvalidContentType` | 400 | 请求头 `Content-Type` 不是 `application/json`。
        |

        | `ResourceNotFound` | 400 | 目标资源不存在。注意 HTTP 状态码是 400 而非 404（历史设计）。 |

        | `NoLicense` | 400 | 功能需要有效授权，但未找到可用的 license。 |

        | `ReferenceExist` | 400 | 该资源仍被其他实体引用，无法删除。 |

        | `Unauthorized` | 401 | `app_key` 缺失、无效或已过期。 |

        | `BalanceNotEnough` | 402 | 账户余额不足，无法执行需要计费的操作。 |

        | `AccessDenied` | 403 | 身份认证通过，但 RBAC 权限不足以执行该操作。 |

        | `RouteNotFound` | 404 | 请求的 URL 路径不是已知路由。 |

        | `MethodNotAllowed` | 405 | 当前路径不接受所使用的 HTTP 方法。 |

        | `UndonedOrderExist` | 409 | 账户存在未完成的订单，请稍后重试。 |

        | `RequestLocked` | 423 | 因连续失败被临时锁定。 |

        | `EntityTooLarge` | 413 | 请求体超过允许的最大长度。 |

        | `RequestTooFrequently` | 429 | 命中限流（全局、账户级或集成级）。 |

        | `RequestVerifyRequired` | 428 | 操作需要二次验证码，但未提供。 |

        | `DangerousOperation` | 428 | 危险操作，需要进行 MFA 验证。 |

        | `InternalError` | 500 | 服务端未预期错误。反馈问题请附上 `request_id`。 |

        | `ServiceUnavailable` | 503 | 后端依赖不可用，请稍后重试。 |
      enum:
        - OK
        - InvalidParameter
        - BadRequest
        - InvalidContentType
        - ResourceNotFound
        - NoLicense
        - ReferenceExist
        - Unauthorized
        - BalanceNotEnough
        - AccessDenied
        - RouteNotFound
        - MethodNotAllowed
        - UndonedOrderExist
        - RequestLocked
        - EntityTooLarge
        - RequestTooFrequently
        - RequestVerifyRequired
        - DangerousOperation
        - InternalError
        - ServiceUnavailable
      x-enumDescriptions:
        OK: 保留值，正常错误响应不会返回。
        InvalidParameter: 必填参数缺失或未通过校验。
        BadRequest: 通用的 400 错误，通常是请求本身不合法。
        InvalidContentType: 请求头 `Content-Type` 不是 `application/json`。
        ResourceNotFound: 目标资源不存在。注意 HTTP 状态码是 400 而非 404（历史设计）。
        NoLicense: 功能需要有效授权，但未找到可用的 license。
        ReferenceExist: 该资源仍被其他实体引用，无法删除。
        Unauthorized: '`app_key` 缺失、无效或已过期。'
        BalanceNotEnough: 账户余额不足，无法执行需要计费的操作。
        AccessDenied: 身份认证通过，但 RBAC 权限不足以执行该操作。
        RouteNotFound: 请求的 URL 路径不是已知路由。
        MethodNotAllowed: 当前路径不接受所使用的 HTTP 方法。
        UndonedOrderExist: 账户存在未完成的订单，请稍后重试。
        RequestLocked: 因连续失败被临时锁定。
        EntityTooLarge: 请求体超过允许的最大长度。
        RequestTooFrequently: 命中限流（全局、账户级或集成级）。
        RequestVerifyRequired: 操作需要二次验证码，但未提供。
        DangerousOperation: 危险操作，需要进行 MFA 验证。
        InternalError: 服务端未预期错误。反馈问题请附上 `request_id`。
        ServiceUnavailable: 后端依赖不可用，请稍后重试。
      example: InvalidParameter
  responses:
    BadRequest:
      description: Invalid request — usually a missing or malformed parameter.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            missingParameter:
              summary: Missing required parameter
              value:
                request_id: 01HK8XQE3Z7JM2NTFQ5YJ8P9R4
                error:
                  code: InvalidParameter
                  message: The specified parameter skill_id is not valid.
    Unauthorized:
      description: Missing or invalid app_key.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            missingAppKey:
              value:
                request_id: 01HK8XQE3Z7JM2NTFQ5YJ8P9R4
                error:
                  code: Unauthorized
                  message: You are unauthorized.
    Forbidden:
      description: The app_key is valid but lacks permission for this operation.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            accessDenied:
              value:
                request_id: 01HK8XQE3Z7JM2NTFQ5YJ8P9R4
                error:
                  code: AccessDenied
                  message: Access Denied.
    TooManyRequests:
      description: Rate limit hit. Either the global API limit or a per-account limit.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            rateLimited:
              value:
                request_id: 01HK8XQE3Z7JM2NTFQ5YJ8P9R4
                error:
                  code: RequestTooFrequently
                  message: Request too frequently.
    ServerError:
      description: Unexpected server-side error. Include the request_id when reporting.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            internal:
              value:
                request_id: 01HK8XQE3Z7JM2NTFQ5YJ8P9R4
                error:
                  code: InternalError
                  message: >-
                    We encountered an internal error, and it has been reported.
                    Please try again later.
  securitySchemes:
    AppKeyAuth:
      type: apiKey
      in: query
      name: app_key
      description: >-
        App key issued from the Flashduty console. Required on every public API
        call. Keep it secret — it grants the same access as the owning account.

````