---
name: "cedros-site-operator"
description: "Discover and safely operate one Cedros site through its live MCP capability registry."
version: "0.1.91"
updated: "2026-08-23"
canonical_url: "https://cedros.ai/skill.md"
entrypoint: "https://cedros.ai/skill.json"
required_auth: "Bearer token for MCP and protected execution; public discovery requires none"
primary_resources: ["cedros://admin/areas", "cedros://tasks", "cedros://agents"]
safety_skill: "/skills/admin-site-operator.md"
compatible_platform_api_versions: ["1"]
---

# Cedros Agent Entry Point

Cedros is an MCP-first operating and authoring surface. This entrypoint is
documentation release `0.1.91` for platform API `1`. Use
[`skill.json`](/skill.json) for ordered task-mode routing, document hashes,
and provenance. The authenticated MCP registry remains the source of truth for
the exact tools and schemas available on one deployment.

`MUST`, `MUST NOT`, `SHOULD`, `SHOULD NOT`, and `MAY` are normative. Other prose
is rationale. Rules are identified by stable IDs published in
[`reference/rules.json`](/authoring/latest/extension/docs/extension-authoring/reference/rules.json).

## Choose the path first

- **Evaluate Cedros for your user:** read the [product overview](/overview.md)
  for fit, workflows, setup, limitations, and pricing links. No account or MCP
  connection is needed. Research alone does not require the operating or
  authoring procedures below. A [readable page](/overview) is also available.
- **Find an extension or theme:** browse the public directories below. No account
  or MCP connection is needed to compare public listings.
- **Operate a live site:** load [Admin Site Operator](/skills/admin-site-operator.md), connect
  to `/mcp`, and use the live registry. Do not load authoring material
  unless the request changes an extension artifact or platform contract.
- **Author or change an artifact:** classify one of the eight task modes below,
  then load the exact ordered document IDs from [`skill.json`](/skill.json).

## Public extension and theme directories

| Directory | Browse | Agent-readable overview |
|---|---|---|
| Extensions — add site capabilities | [Extensions](https://cedros.ai/marketplace/extensions) | [Extensions Markdown](https://cedros.ai/marketplace/extensions.md) |
| Themes — choose site presentation and style | [Themes](https://cedros.ai/marketplace/themes) | [Themes Markdown](https://cedros.ai/marketplace/themes.md) |

These anonymous directories describe the currently public listings. Their Markdown
versions include names, IDs, versions, descriptions, extension features, and links
to individual detail pages and their `.md` alternates. Use `?q=` to search by name,
description, or extension capability, or omit it for the full public overview.
Machine-readable listings also come from
[extension showcase JSON](https://cedros.ai/extension-marketplace/showcase) and
[theme showcase JSON](https://cedros.ai/extensions/cedros-theme-manager/showcase).

When asked to find one, read the relevant overview, shortlist matches to the user's
needs, and explain the fit using published descriptions and features. Link the
public detail pages. Treat absent functionality, pricing, or compatibility as
unspecified. These are public marketplace listings, not the current site's installed
extensions or available MCP tools. Installation and theme application require the
user's site, the operator workflow, and its live compatibility and permissions checks.

## Agent operating procedure

Apply this procedure to the requested outcome. A question, draft edit, repair,
package, and live publication are different scopes; do not automatically run
later release phases. Reuse established version context and references whose
content is unchanged. Refresh live discovery after a connection, permission,
version, or extension change, and read current target state before writing.
Load only the required and applicable conditional documents for the selected
mode. Batch independent reads where supported and preserve revision ordering
for dependent writes. Internal Cedros repository build and CI policy is not a
client requirement.

1. Determine the Cedros documentation, platform API, SDK, and WIT version context.
2. Inspect an existing repository before changing anything.
3. Classify the task mode and required surfaces through `skill.json`.
4. Resolve every Cedros API and schema against published references.
5. Implement through public contracts only; preserve stable IDs and migrations.
6. Run the canonical verifier and report evidence at its actual level.
7. Report unresolved host-contract dependencies explicitly.

Stop under `CED-AUTH-001` or `CED-AUTH-005`: MUST NOT invent a host API, shim a
platform contract, replace compliant existing architecture because another
pattern is preferred, claim host-dependent behavior without host evidence, or
treat lack of local testability as success. Same-precedence sources that
conflict MUST be surfaced and work on that contract MUST stop.

## Task modes

| Mode | Start | Preservation boundary |
|---|---|---|
| Create a new extension | Extension Authoring | Start from the runnable floor; use only published contracts. |
| Convert an existing application | Extension Authoring | Inventory and preserve product behavior before mapping Cedros surfaces. |
| Audit and repair an extension | Extension Authoring | Inventory first; preserve intent, stable IDs, and migrations. |
| Add a feature to a released extension | Extension Authoring | Preserve compatibility and released identifiers. |
| Complete product/UX without contract changes | Extension Authoring | Skip contract docs only after inventory proves no contract change. |
| Prepare a release | Extension Authoring | Validate the final package and label evidence honestly. |
| Upgrade or roll back | Extension Authoring | Preserve data integrity; do not pretend irreversible changes rolled back. |
| Operate a live site | Admin Site Operator | Use MCP tools and runtime permissions, not authoring assumptions. |

The `modes` object in `skill.json` is normative for ordered documents,
conditional additions, preservation rules, and skip conditions.

## MCP credential decision table

| Credential evidence from `resources/list` | Required URIs | Action |
|---|---|---|
| Personal MCP API key | `cedros://admin/areas`, `cedros://tasks`, `cedros://agents` | Read one admin area and its narrowest section. `cedros://tasks/current` is optional unless the session is task-bound. |
| Task connection token | `cedros://tasks`, `cedros://agents`; `cedros://tasks/current` when task-bound | Use only task/agent resources. Any admin resource is unexpected and MUST be reported (`CED-AUTH-005`). |
| Missing or ambiguous | required URI absent, contradictory admin access, or unknown credential scope | Use the failure protocol; do not guess the session type. |

HTTP `401` means authentication is absent or invalid; repair credentials. HTTP
`403` means the authenticated principal lacks scope; do not retry around it.

## Global source precedence

1. Published machine-readable schemas and WIT contracts.
2. Published SDK exports and signatures.
3. Version-matched canonical references, including this file and kit docs.
4. Surface-specific prompts.
5. Official examples.
6. Existing repository conventions.
7. Agent assumptions, which are never authoritative.

An official example is normative only where marked. Do not infer capabilities
from incidental implementation details.

## Universal failure protocol

When a required reference cannot be fetched, the relevant Cedros version is unknown, canonical
references conflict, an SDK export is missing, repository state contradicts its
manifest, a capability is draft/planned, a host dependency cannot be exercised,
`resources/list` is unexpected, a referenced resource is missing, or a user
decision remains unresolved, stop only the dependent operation and continue safe
authorized work. Reuse a verified version-matched local reference if available.
Do not treat an unavailable runtime check as a pass or an unrelated blocker as
a reason to abandon the task. If it prevents the requested outcome, return:

```json
{
  "status": "blocked",
  "blockingRule": "CED-AUTH-001",
  "reason": "Schema and SDK references disagree",
  "evidence": ["source and hash for each conflicting contract"],
  "workStillCompleted": ["safe work that does not depend on the conflict"],
  "requiredResolution": "Cedros must publish the authoritative contract"
}
```

## Operator connection

Reuse the selected site's configured MCP connection before requesting credentials
or browser sign-in. If tools appear missing, follow the operator guide's connection
diagnosis: client filters, launcher credentials, running-session discovery, and
server permissions are separate layers. Missing visible tools do not establish
that a site feature is unavailable. Cedros Pay catalog actions are discovered as
extension capabilities, not necessarily as top-level payment tools.

1. If no connection exists, connect your MCP client to `/mcp` with a personal MCP API key from **Assistant Settings → MCP**, or with a task connection token for task-only coordination. Send either as an `Authorization: Bearer` credential.
2. Let the client initialize, then inspect `resources/list`.
3. Apply the credential table above; unexpected resources route to the failure protocol.
4. Load [Admin Site Operator](/skills/admin-site-operator.md) for routing, write modes, confirmations, and safety rules.
5. Choose one area, then one section for the narrowest exact-schema view. Standard MCP clients may also materialize the broader permission-filtered `tools/list`. Read current state before changing it.
6. If the request is about how a particular admin page works, read `cedros://admin/page-docs`, choose one `cedros://admin/page-docs/sections/{sectionKey}` summary, then load the closest `cedros://admin/page-docs/{slug}` guide; expand only if the task spans pages.

Do not copy tool schemas from this document. Tool availability and input schemas vary with the Cedros version, enabled features and extensions, authenticated permissions, and token scope.

`write modes` distinguish reversible draft writes from explicit publication;
`confirmations` are exact schema tokens for consequential actions; a
`review-gated handoff` stays pending until a human/operator accepts it; and
`reference-contract feedback` is deterministic static validation against a
published contract, not host execution.

## Authoring surfaces

- [Site migration](/skills/cedros-site-migration-authoring.md) - capture an authorized public URL into private evidence and a review-gated page, theme, or extension handoff.
- [Extensions](/skills/cedros-extension-authoring.md) - plan, implement, validate, test, package, and release installable behavior.
- [Themes](/skills/cedros-theme-authoring.md) - design, validate, review, package, and distribute presentation-only themes.
- [Custom pages](/skills/cedros-custom-page-authoring.md) - create, validate, preview, review, and publish site-owned Page Builder content.
- [Shared page templates](/skills/cedros-custom-page-authoring.md#shared-layouts-with-per-page-content) - reuse a linked layout with per-page content; publish design changes across its linked pages.
- [Full-page forms](/page-docs/add-edit-form.md#design) - design a saved form and confirmation screen with responsive previews and the same settings in admin and MCP.
- [Centralized Forge authoring scan](https://cedros.ai/extensions/cedros-forge/skill.md) - submit an artifact to the Cedros control plane for deterministic reference-contract feedback when no local or MCP-connected test site is available.

These stable public guides remain readable when the main site is gated. They
route versioned contracts to authoring kits and current tool schemas and
permissions to the authenticated MCP registry.

For similar pages, inspect `cedros.page_builder.templates.list` before rebuilding
layouts or duplicating custom code. Use a suitable published shared template and
edit each page's values through `cedros.page_builder.templates.bind`. A starter is
a one-time copy; a shared template stays linked. Template publication changes all
linked live layouts, while page content still has its own draft/publish lifecycle.
Read the linked guide and live schemas before changing either.

## Capability Landscape

| Area | Scope |
|------|-------|
| [Content](/skills/cedros-content-operations.md) | Create, inspect, analyze, and publish site content. |
| [Audience and communication](/skills/cedros-audience-communication.md) | Manage people, messages, support, campaigns, and scheduling. |
| [Growth and planning](/skills/cedros-growth-planning.md) | Coordinate goals, links, agreements, routines, and tasks. |
| [Site operations](/skills/cedros-site-operations.md) | Inspect health and configure, secure, observe, and govern the site. |
| [Data and knowledge](/skills/cedros-data-knowledge.md) | Work with structured data, knowledge workflows, and migrations. |
| [Extensions](/skills/cedros-extension-operations.md) | Operate installed extensions, domains, monetization, builds, and themes. |

## Available Skills

| Skill | Publisher | Description | Visibility | Tags |
|-------|-----------|-------------|------------|------|
| [Admin Site Operator](/skills/admin-site-operator.md) | Cedros | Operate one Cedros site through its live assistant and MCP capability registry. | admin | mcp, admin, site-operations |
| [Audience and communication](/skills/cedros-audience-communication.md) | Cedros | Navigate Cedros audience and communication capabilities through compact MCP sections and load exact tool schemas only when needed. | admin | mcp, admin, audience-communication |
| [Content](/skills/cedros-content-operations.md) | Cedros | Navigate Cedros content capabilities through compact MCP sections and load exact tool schemas only when needed. | admin | mcp, admin, content |
| [Custom Page Authoring](/skills/cedros-custom-page-authoring.md) | Cedros | Create, edit, preview, and publish site-owned pages and shared page templates with per-page content. | public | authoring, pages, page-builder, shared-page-templates |
| [Data and knowledge](/skills/cedros-data-knowledge.md) | Cedros | Navigate Cedros data and knowledge capabilities through compact MCP sections and load exact tool schemas only when needed. | admin | mcp, admin, data-knowledge |
| [Admin](/skills/cedros-data-admin-2e7bbe31.md) | Cedros Data | Site bootstrap, collection admin, page management, and editorial runtime operations. | admin | bootstrap, pages, editorial, collections |
| [Data](/skills/cedros-data-data-bcf1e60b.md) | Cedros Data | Entry upsert, query, and collection management. | authenticated | entries, collections, query |
| [Schema](/skills/cedros-data-schema-961edd8b.md) | Cedros Data | Custom schemas, contract verification, and site import or export workflows. | authenticated | schemas, contracts, import, export |
| [Site](/skills/cedros-data-site-280ee4d0.md) | Cedros Data | Site registration, migration, export, and public runtime configuration. | authenticated | site, config, migration, export |
| [Storage](/skills/cedros-data-storage-892a81c4.md) | Cedros Data | Media upload, asset management, and S3-compatible storage operations. | admin | media, assets, storage, s3 |
| [Extension Authoring](/skills/cedros-extension-authoring.md) | Cedros | Create, validate, package, test, and publish a Cedros extension without guessing host contracts. | public | authoring, extensions, packaging |
| [Extensions](/skills/cedros-extension-operations.md) | Cedros | Navigate Cedros extensions capabilities through compact MCP sections and load exact tool schemas only when needed. | admin | mcp, admin, extensions |
| [Growth and planning](/skills/cedros-growth-planning.md) | Cedros | Navigate Cedros growth and planning capabilities through compact MCP sections and load exact tool schemas only when needed. | admin | mcp, admin, growth-planning |
| [Site Migration Authoring](/skills/cedros-site-migration-authoring.md) | Cedros | Capture an authorized public website into private evidence and route a reviewed handoff into page, theme, or extension authoring. | public | authoring, migration, website-capture |
| [Site operations](/skills/cedros-site-operations.md) | Cedros | Navigate Cedros site operations capabilities through compact MCP sections and load exact tool schemas only when needed. | admin | mcp, admin, site-operations |
| [Theme Authoring](/skills/cedros-theme-authoring.md) | Cedros | Design, validate, review, package, and distribute a Cedros theme. | public | authoring, themes, design |

## Extension Capabilities

The table below is illustrative of the current deployment, not exhaustive of
Cedros platform capabilities. The live `cedros.*` MCP catalog is the exhaustive
permission-filtered operating source and is intentionally not duplicated here.
Registered extensions can additionally publish schema-validated capabilities
through the shared host execution contract below.

| Capability | Publisher | Type | Host Execute | Routes To | Visibility | Auth Hints |
|------------|-----------|------|--------------|-----------|------------|------------|
| Query Entries | Cedros Data | tool | `POST /ai/capabilities/cedros-data:query-entries/execute` | `POST /entries/query` | authenticated | bearer-token |
| Upsert Entry | Cedros Data | action | `POST /ai/capabilities/cedros-data:upsert-entry/execute` | `POST /entries/upsert` | authenticated | bearer-token |

## Discovery Endpoints

| Endpoint | Purpose |
|----------|---------|
| /overview.md | Public product evaluation: fit, workflows, adoption, and limitations |
| /overview | No-JavaScript readable product overview |
| /skill.md | Canonical human-readable entrypoint and table of contents |
| /skill.txt | Plain UTF-8 byte-equivalent fallback |
| /skill | No-JavaScript HTML fallback |
| /skill.json | Machine-readable task router, provenance, document hashes, skills, and capabilities |
| /agent.md | MCP connection and operating guide |
| /authoring/latest/extension/docs/extension-authoring/README.md | Latest complete extension authoring guide; currently `0.1.91` |
| /authoring/latest/extension/kit.zip | Latest checksummed authoring kit alias; currently `0.1.91` |
| /authoring/0.1.91/extension/kit.zip | Immutable `0.1.91` authoring kit |
| /schemas/extension-manifest.schema.json | Canonical extension manifest JSON Schema |
| /schemas/extension-context.schema.json | Canonical shared Extension Context JSON Schema |
| /page-docs/index.json | Compact index of page-guide sections |
| /page-docs/sections/{sectionKey}.json | Page metadata for one section |
| /page-docs/{slug}.md | One exact page-specific guide |
| /.well-known/mcp-lite.json | Compact unauthenticated MCP orientation |
| /.well-known/mcp | Full unauthenticated MCP tool schemas |
| /.well-known/ai-discovery.json | Canonical discovery index with skill and capability pointers |
| /ai/capabilities/{capability-id}/execute | Shared execution endpoint for manifest-owned AI capabilities |
| /.well-known/skills.zip | Downloadable ZIP bundle of all published skills |

These discovery documents remain readable when the public site is gated. Authentication and permissions are still required for MCP and protected API execution.

Visibility levels:

- `public`: safe to advertise without auth requirements
- `authenticated`: discoverable, but execution requires a bearer token
- `admin`: discoverable, but intended for authenticated admin operators only

## Illustrative worked trace

`ILLUSTRATIVE ONLY` · release `0.1.91`: “Update the homepage hero” → connect
with a personal key → confirm `cedros://admin/areas` → read the content area →
load the pages section → read current homepage state → call the exact confirmed
draft or publish tool from that section. The trace does not define tool names or
schemas; the authenticated registry does.
