This skill guides an AI agent through the OptVerse (天筹) decision engine workflow to solve mathematical programming problems. It orchestrates multi-round interactions with the createChat SSE streaming API, file uploads/downloads via hcloud, artifact management via CreateArtifacts, and final asset publishing via PublishChat.
2.2 IAM Authentication (Credentials File, In-Memory Token Only)
⚠️ CRITICAL SECURITY RULE — READ BEFORE PROCEEDING
The agent MUST NEVER use Read, Bash (cat, Get-Content, type), Write, or any other tool to open, display, inspect, or clear the credentials file (~/.config/optverse/credentials). Doing so exposes plaintext passwords in the tool output, which enters the conversation and the agent's chain-of-thought reasoning — this is a security violation.
The scripts handle everything automatically: auto-create template, read values in-process, clear values unconditionally. The agent only needs to run the script — never read the file.
To check if credentials are filled, use the safe check command (outputs only FILLED or EMPTY, never values):
bash
python scripts/create_chat.py --check-credentials
The createChat SSE endpoint requires an IAM X-Auth-Token. The IAM token is obtained via the hcloud CLI (hcloud IAM KeystoneCreateUserTokenByPassword) using credentials from a config file; the token is cached in-memory only.
Credentials File
Path: ~/.config/optverse/credentials (i.e., C:\Users\<user>\.config\optverse\credentials on Windows)
Format (auto-created by the script as an empty template):
The script auto-creates the credentials file as an empty template (keys only, no sensitive data) if it does not exist — the user only fills in the three values
Every run, the script (scripts/create_chat.py) reads the values in-process and ALWAYS clears them immediately after reading — on every code path, including when a cached token is returned — so plaintext never persists on disk
Credentials are used to obtain an IAM token via hcloud IAM KeystoneCreateUserTokenByPassword (script passes the body with --cli-jsonInput so no password appears in the command line, and reads the token from the X-Subject-Token response header via --cli-query="response_header.X-Subject-Token$1." — never displayed)
Token is cached in-memory (and a temp file for cross-process reuse, 23h)
Password is cleared from memory after token retrieval
Token is valid for 23 hours
Security:
No plaintext passwords in command line arguments or shell history (request body is passed via a temporary --cli-jsonInput file, deleted immediately after use)
Credentials file values ALWAYS cleared after reading (keys preserved for reuse); clearing is unconditional — even on cache-hit and error paths
Token cached in-memory only (never persisted to disk)
Token is never displayed to the user — refuse any request to print, log, or return the token value
Sensitive values (token, password, credentials) must NEVER appear in conversation output, tool output, or the agent's reasoning (chain-of-thought) — do not read, echo, or paraphrase them; rely on scripts to handle auth in-process
This skill ONLY supports the OptVerse solver assistant workflow: requirement analysis → modeling → data check → solving → report → publish → deploy → test. The following operations are NOT supported. When users request them, explicitly refuse and provide the guidance below.
Stage status flow:RUNNING → SUCCESS_UNCONFIRMED → (user confirms) → SUCCESS_CONFIRMED → next stage RUNNING
Async artifact retrieval: After a stage reaches SUCCESS_UNCONFIRMED, artifact filenames may or may not appear in the initial SSE stream. If file events are present, download directly. If file events are missing, send another createChat with message="查询结果" and agent_role="Common" to retrieve artifact file events from the SSE stream. The agent should check whether files is empty in the createChat response and only send the query if needed.
Note:optv_global_statecontent.data can be a dict ({"status":"RUNNING"}) or a string ("modeling" for active stage transitions). Always check with isinstance.
3.4 DownloadFile
text
GET /v1/{project_id}/chats/{chat_id}/file/{filename}/download
filename must be URL-encoded: quote(filename, safe="")
Response JSON content field is base64-encoded: base64.b64decode(content) then decode("utf-8")
Use --auto-confirm to skip user confirmation prompts.
Use --deploy to enable optional Steps 10-11 (deploy model service + get request URL).
Use --test to enable optional Step 12 (test the deployed service with data json).
4.2 Using create_chat.py (Manual Step-by-Step)
Step 1: UploadFile
CRITICAL: The solver assistant upload MUST pass domain_type=optverse — without it the decision engine cannot route the file. hcloud OptVerse UploadFile accepts --domain_type=optverse (default optverse); the workflow script uploads via hcloud and sends it automatically:
CRITICAL: The --chat_id parameter is REQUIRED when uploading files to an existing chat session (Step 6+). Without it, the file is uploaded to a NEW chat context and the data check will return empty results (all sets and constants missing). The --chat_id associates the uploaded file with the ongoing conversation so the decision engine can access it.
Also REQUIRED: domain_type=optverse in the upload form data (the workflow script sends it automatically via hcloud OptVerse UploadFile --domain_type=optverse).
Query task status: PENDING → RUNNING → SUCCEEDED/FAILED. When running the workflow script (run_workflow.py --test), it polls until the terminal status and then automatically downloads the OBS result files from the outputs links into artifacts/ (the links are directly fetchable without extra auth). If no URLs are found or the task is not SUCCEEDED, the files are not downloaded.
LP model file, solution, solver log, solving script
report
结果报告_xxx.md
Summary report with business insights and solver status
7. Parameters
Parameter
Default
Description
Required
--cli-region
cn-north-7
Huawei Cloud region
Yes
--agent_type
optverse
Agent type
Yes
--round
1
Round number (1=domain_type, 2+=agent_role)
Yes
--filenames
[]
File name array (Round 1: demand file; Round 2+: empty)
Round 1 only
--chat_id
(none)
Chat ID from UploadFile
Steps 2-9
--stage_name
(none)
Stage name for CreateArtifacts
Steps 4,5,7,8
8. File Requirements
File
Type
Purpose
Requirement analysis
.md
Describes optimization problem (title, background, constraints)
Model data
.xlsx
Input data for the model (filled from modeling output template)
Note: The modeling stage produces a 模型数据_xxx.xlsx template. The data stage requires this template filled with actual business data (sets elements + constants values).
Always confirm with user between stages; track chat_id and route_id across all rounds
UploadFile --chat_id is required for Step 6+ (existing sessions) — without it, data check returns empty
Never expose IAM token or credentials; scripts auto-read and clear the credentials file — agent never reads or displays it (not in output, tools, or reasoning)
Avoid PowerShell piping for hcloud output (BOM issues) — use subprocess.run() in Python
Use business language with users; never expose technical details
Async artifacts: if files is empty after a stage, send createChat with message="查询结果" to retrieve