boxfetch-original-kit
Neon Postgres Bootstrap
Packaged by Verified seller
UnverifiedStandard discoveryAgent-ready
# Neon Postgres Bootstrap — public fit preview
This public sample is for fit selection only and is not executable. It contains
no package manifest, input payload, runner command, SQL, or connection value.
## Job solved
Create one approved Neon project or one branch in an approved existing project,
obtain pooled and direct connection references for the exact selected branch,
prove fixed read-only connectivity, and optionally run one bounded SQL asset
owned by the entitled package. Provider resource ids may enter a redacted
receipt; API keys, passwords, and connection strings do not.
## Good fit
- The job is exactly `create_project` or
`create_branch_in_existing_project`.
- The database, role, branch, and mutation gates can be declared before apply.
- A human will approve the exact plan digest.
- Verification is fixed `SELECT 1` plus an optional parameterized marker-table
existence check.
## Not a fit
General/production migrations, arbitrary or remote SQL, target-repository SQL,
data cloning, organization administration, or deletion of unowned resources. A
separate branch must receive its exact ready read-write endpoint before any
connection or SQL work.
## Verification state
Deterministic offline coverage is complete. `provider_verified = false`; no live
Neon account or provider resource was used.
Agent access. Agents can preview this box and request fetch on your behalf, within your spending limits.
Markdown content / neon-postgres-bootstrap-1.0.1.kit.md / 63.9 KB
boxfetch-original-kit
Cloudflare R2 Prefix-Scoped Bucket
Packaged by Verified seller
UnverifiedStandard discoveryAgent-ready
# Cloudflare R2 prefix-scoped bucket — public sample
This public sample is for fit selection only and is not executable. It contains
no manifest, input payload, command, credential, provider response, or full
implementation.
This Original is for an agent that needs one new disposable private R2 bucket
and one short-lived object credential restricted to one non-root prefix.
Before purchase, expect:
- strict new-bucket-only behavior;
- fixed Standard class and default jurisdiction;
- fixed one-hour `object-read-write` permission;
- one mandatory prefix;
- an AWS CLI v2 proof that writes and reads inside the prefix and attempts a
real denied write outside it;
- secret-reference-only credential outputs;
- authenticated, empty-only teardown.
It does not adopt existing buckets, configure public access, attach domains,
create parent tokens, force-remove unknown objects, or perform live verification
without the explicit live gate.
Agent access. Agents can preview this box and request fetch on your behalf, within your spending limits.
Markdown content / cloudflare-r2-scoped-bucket-1.0.1.kit.md / 65.3 KB
boxfetch-original-kit
Vercel Environment Synchronization
Packaged by Verified seller
UnverifiedStandard discoveryAgent-ready
# Vercel Environment Synchronization — public fit preview
This public sample is for fit selection only and is not executable. The entitled
package, manifest, runner guidance, and implementation are not included here.
## Job solved
Synchronize declared secret-backed variable names into one existing linked
Vercel project across development, preview, production, and optional
branch-preview scopes. The kit can create missing variables, update existing
variables through Vercel's supported in-place operation, verify name presence,
and optionally run one bounded command with Vercel-managed environment
injection. Values never belong in arguments, plans, or receipts.
## Good fit
- The project is already linked and its exact identity is known.
- Every variable has an explicit secret label, target name, and target scope.
- A human will review create, update, and production gates before mutation.
- Name-presence verification, plus an optional exit-status check, is sufficient.
## Not a fit
Project creation/linking, deployments, DNS/domains, team-wide administration,
previous-value backup, value-equality claims, or bulk deletion. Environment
changes affect future deployments only, and teardown can remove only variables
created by the approved run.
## Verification state
Deterministic offline coverage is complete. `provider_verified = false`; no live
Vercel account or production mutation was used.
Agent access. Agents can preview this box and request fetch on your behalf, within your spending limits.
Markdown content / vercel-env-sync-1.1.1.kit.md / 43.8 KB
boxfetch-original-kit
GitHub Actions Exact AWS OIDC Trust
Packaged by Verified seller
UnverifiedStandard discoveryAgent-ready
# Public sample
This public sample is for fit selection only and is not executable. It contains
no manifest, input payload, command, credential, trust policy, or role-creation
implementation.
This kit prepares one GitHub OIDC claim probe and, only after human observation
and approval, can create one zero-permission AWS IAM role with exact trust.
The public sample contains no AWS credential, role-creation command, trust
policy implementation, wildcard, static key, deployment workflow, provider
mutation, or executable lifecycle. It cannot create, update, or delete a role
or account OIDC provider.
Supported buyers use the entitled package, exact version/hash, protected
environment, observed non-secret claims, explicit production gates, and
authenticated evidence.
Agent access. Agents can preview this box and request fetch on your behalf, within your spending limits.
Markdown content / github-actions-aws-oidc-role-1.0.1.kit.md / 66.4 KB
boxfetch-original-kit
Auth.js v5 Google OAuth Setup
Packaged by Verified seller
UnverifiedStandard discoveryAgent-ready
# Auth.js v5 Google OAuth Setup — public fit preview
This public sample is for fit selection only and is not executable. It contains
no package manifest, input payload, runner command, templates, or credentials.
## Job solved
Configure Google sign-in for one clean Next.js 16.2.6 App Router + TypeScript +
pnpm 10 target using exact `next-auth@5.0.0-beta.31`. The entitled kit can
install that pinned dependency when approved, generate a bounded no-overwrite
file set, compute exact local/deployed callback URIs, and stop at the human
Google Cloud client checkpoint.
## Good fit
- The repository is clean, uses root `app/`, and has no auth conflicts.
- Google is the only provider and explicit route protection is sufficient.
- A human can create the OAuth client and inject `AUTH_SECRET`,
`AUTH_GOOGLE_ID`, and `AUTH_GOOGLE_SECRET`.
## Not a fit
Existing-auth merge, Auth.js v4 migration, other versions, `src/app`, Pages
Router, npm/yarn, multiple providers, adapters/SSO, or automated Google
password, MFA, CAPTCHA, login, or consent. A live OAuth round trip is not part of
the kit.
## Verification state
The generated exact fixture typechecks and builds offline.
`provider_verified = false`; no live Google OAuth flow was run.
Agent access. Agents can preview this box and request fetch on your behalf, within your spending limits.
Markdown content / authjs-google-oauth-1.0.1.kit.md / 63.3 KB
boxfetch-original-kit
Stripe Signed Webhook Receiver
Packaged by Verified seller
UnverifiedStandard discoveryAgent-ready
# Stripe Signed Webhook Receiver — Fit Preview
This public sample is for fit selection only and is not executable.
## Job solved
Generate a bounded raw-body signature-verification boundary for one exact clean
Next.js App Router target. The receiver has a fixed path, size limit, timestamp
tolerance, three-event Checkout allowlist, typed application seam, and a safe
non-2xx default until business handling is configured.
## Fit
Choose this kit only for Next.js 16.2.6, root App Router, TypeScript, Node 22,
stable pnpm 10.x, and exact Stripe 22.3.2. It refuses existing receiver files,
alternate routers/layouts, conflicting body frameworks, package ranges, and
unapproved dependency or file mutation.
The human still owns Stripe Dashboard destination setup, endpoint signing-secret
injection, deployment, persistent idempotency, and payment-side business logic.
Signature verification proves origin and byte integrity within tolerance; it
does not prove settlement, uniqueness, ordering, or completed side effects.
The paid package contains the exact templates, lifecycle, refusal matrix,
fixtures, offline proof, acceptance contract, and evidence-bound teardown rules.
This preview intentionally omits the complete route, handler, verifier, secret
shape, package manifest, and runner commands.
Agent access. Agents can preview this box and request fetch on your behalf, within your spending limits.
Markdown content / stripe-signed-webhook-1.0.1.kit.md / 55.2 KB
smoke
Native purchase route smoke (27576673850-1)
Packaged by Verified seller
UnverifiedStandard discoveryAgent-ready
Smoke fixture preview — not a real marketplace listing.
Agent access. Agents can preview this box and request fetch on your behalf, within your spending limits.
resale
Marketplace Listing Audit
Packaged by Verified seller
UnverifiedStandard discoveryAgent-ready
Preview of "Marketplace Listing Audit". Demo fixture content for the Alexa account.
Agent access. Agents can preview this box and request fetch on your behalf, within your spending limits.
finance
Invoice Categorization Template
Packaged by Verified seller
UnverifiedStandard discoveryAgent-ready
Preview of "Invoice Categorization Template". Demo fixture content for the Alexa account.
Agent access. Agents can preview this box and request fetch on your behalf, within your spending limits.
agents
Agent Prompt Pack: Buyer Outreach
Packaged by Verified seller
UnverifiedStandard discoveryAgent-ready
Preview of "Agent Prompt Pack: Buyer Outreach". Demo fixture content for the Alexa account.
Agent access. Agents can preview this box and request fetch on your behalf, within your spending limits.
research
Micro-SaaS Competitor Scan
Packaged by Verified seller
UnverifiedStandard discoveryAgent-ready
Preview of "Micro-SaaS Competitor Scan". Demo fixture content for the Alexa account.
Agent access. Agents can cite this brief while assembling a structured answer.
local
Wedding Vendor Shortlist
Packaged by Verified seller
UnverifiedStandard discoveryAgent-ready
Preview of "Wedding Vendor Shortlist". Demo fixture content for the Alexa account.
Agent access. Agents can preview this box and request fetch on your behalf, within your spending limits.
Boxes are ordered by most recently updated. Spend uses BoxFetch credits only; larger agent purchases can pause for human approval. Credit price labels reflect the in-product unit — not USD or cash.