SKILL DELTA — API compatibility repair (2026-10-01)
Status: DRAFT — NOT applied. Skill semantic content changes only through
the Boss's skill process (rule 03, "Skill parity same-day"); this file is the
delta it applies. Source of the facts: production/provider-api-lifecycle.json
and docs/audits/api-compatibility/2026-10-01/ (ISSUES.json, EVIDENCE.md).
Raised by the lane's independent review (finding 16).
Apply order: 1) edit canonical skills/adwords-virtuoso/SKILL.md; 2) let
python3 scripts/skills_sync.py --fix carry it to .claude/skills/ and the
Boss copies (.claude/skills/BOSS_AGENT_SKILLS.md,
.claude/skills/boss_specialist_skills.lock.json); 3) verify with
python3 scripts/skills_sync.py --check and the specialist-skills gate.
skills/adwords-virtuoso/SKILL.md — "Google Ads API Versions and Sunsets"
The table row "Connectors gateway, GAQL cell, measurement-rails … | v23" is
stale. Replace the table and the bullet list with these facts:
- One version policy, dated. Every Google Ads caller selects its version
through a dated lifecycle table. The gateway, action runner, Boss and gemini
worker share one byte-identical
provider_versions.py; the GAQL cell (gaql_cell/config.py), the action runner (execution_adapters/google_ads.py) and the measurement rails carry copies that a governance test pins to the inventory. Default v25 everywhere;GOOGLE_ADS_API_VERSIONoverrides; a retired or unknown value is refused before any request. - Sunsets: v21 and earlier are gone (v21 on 2026-08-05); v22 on 2026-10-07 (day published); v23 February 2027, v24 May 2027, v25 August 2027 (Google publishes only the month, "any time in that month", so the code uses the first day of the month).
- SDK: the GAQL cell runs
google-ads33.0.0, which ships v25/v24/v23 and binds the version at construction and on every service. API v25 is not package version 25. - No developer token. Google sunset developer tokens on 2026-09-09 (sent
headers are "optional and ignored"). Access belongs to the Google Cloud
project that owns the OAuth client: a production account needs that project
to have Explorer or Basic access (Cloud Console → Google Ads API Overview).
Access errors such as
CLOUD_PROJECT_NOT_APPROVED_FOR_PRODUCTIONname that remedy. Never ask a tenant for a developer token. - The guards:
tests/governance/test_google_ads_api_version_sunset.py(every pin it can see, 14 days before sunset) andscripts/api_lifecycle_check.pyoverproduction/provider-api-lifecycle.json(every deployed selection — live, dark or credential-gated — fails 14 days before retirement and warns from 90; dormant rows only warn). Both use the same dates. Boss's credential-gated modules still pin v23 and fail both checks from 2027-01-18 unless re-pinned or retired (ISSUES.json API-G13). - Synthetic GAQL data is never live data. Without credentials the GAQL
cell serves a labelled synthetic stream; its
/channels/google/*routes answer 503google_ads_not_liveunless the caller passesallow_synthetic=true, and synthetic rows are never persisted, enveloped or proposed to the Decision Control Plane. - Upgrading: move a version in one change across the inventory, the code copies and the evidence; run both guards and the GAQL version-resilience tests.