affaan-m/ECC · error · ValueError

remote instinct imports require https URLs

Error message

remote instinct imports require https URLs

What it means

Raised by _validate_import_url when a remote instinct import URL does not use the https scheme. Because the CLI will fetch and parse the remote content, it refuses plaintext http to prevent tampered or downgraded downloads. Only https:// URLs pass this first validation gate.

Solutions

  1. Change the URL to use https:// and retry.
  2. If the host does not support https, download the file over a trusted channel and import it from a local path instead.
  3. Verify the scheme programmatically before calling: urllib.parse.urlparse(source).scheme == 'https'.
  4. Fix upstream links/config that emit http URLs.

Example fix

# before
url = "http://example.com/instincts.yaml"
# after
url = "https://example.com/instincts.yaml"
Defensive patterns

Strategy: validation

Validate before calling

from urllib.parse import urlparse
if urlparse(source).scheme != "https":
    raise ValueError("import source must be an https URL")

Try / catch

try:
    cli_import(url=source)
except ValueError as e:
    if "https" in str(e):
        print("upgrade the URL to https://")

Prevention

When it happens

Trigger: Calling the import command with a source like http://example.com/instincts.yaml, ftp://..., or a bare host with no scheme so urlparse yields scheme ''.

Common situations: Copying an http link from an old README or internal server; a URL built from a config variable that defaults to http; pasting a URL without its scheme.

Understand the failure class

Background: "Invalid URL" / "URL cannot be empty": fix the malformed or missing URL behind request-construction failures — this error's family across 50 libraries.

Related errors


AI-assisted analysis of affaan-m/ECC@8321021c54 (2026-09-16). Data as JSON: /api/errors/6c3f5a2d730819fa. Report an issue: GitHub.

Appendix: source

Thrown at skills/continuous-learning-v2/scripts/instinct-cli.py:193

def _validate_instinct_id(instinct_id: str) -> bool:
    """Validate instinct IDs before using them in filenames."""
    if not instinct_id or len(instinct_id) > 128:
        return False
    if "/" in instinct_id or "\\" in instinct_id:
        return False
    if ".." in instinct_id:
        return False
    if instinct_id.startswith("."):
        return False
    return bool(re.match(r"^[A-Za-z0-9][A-Za-z0-9._-]*$", instinct_id))


def _validate_import_url(source: str) -> str:
    """Validate remote instinct imports before opening a network connection."""
    parsed = urllib.parse.urlparse(source)
    if parsed.scheme != "https":
        raise ValueError("remote instinct imports require https URLs")
    if not parsed.hostname:
        raise ValueError("remote import URL is missing a hostname")

    try:
        addr_infos = socket.getaddrinfo(parsed.hostname, parsed.port or 443, type=socket.SOCK_STREAM)
    except socket.gaierror as exc:
        raise ValueError(f"remote import host could not be resolved: {parsed.hostname}") from exc

    for family, _, _, _, sockaddr in addr_infos:
        host = sockaddr[0]
        try:
            ip = ipaddress.ip_address(host)
        except ValueError:
            continue
        if (
            ip.is_private
            or ip.is_loopback
            or ip.is_link_local

View on GitHub (pinned to 8321021c54)