One command per call — keep commands small, readable, and atomic. Don't chain with &&, ;, or cd dir && command. Use separate calls — first cd, then the command.
No inline env vars — don't use VAR=value command. Set env separately or use proper auth tools.
Git Auth
Use gh auth login / gh auth switch to switch GitHub accounts — never prefix with GH_TOKEN=....
Why
Each chained command is one opaque action to the permission layer; splitting them gives one auditable tool call per intent. Inline env vars hide configuration in the command line and leak secrets into shell history; explicit auth tools (gh auth login) keep credentials in the keyring where they belong.
Prerequisites
A POSIX shell (bash or zsh).
For the Git Auth rule: gh CLI installed and authenticated.
Failure modes
gh auth login fails or token expired. Re-run gh auth login -h github.com interactively, then gh auth status to verify. Don't paste the token into a shell command.
Account switch needed.gh auth switch -u <user>. If that user's token is invalid, re-auth that account before switching.
Command needs elevated privileges. Set up the privilege out-of-band (sudoers entry, group membership) rather than prefixing the command with sudo inline; an unattended agent shouldn't be entering passwords.
Shell aliases that hide what runs. Avoid invoking aliases in agent procedures; spell out the real command so it's auditable.
1---2name: shell-discipline3description: Shell Commands4---56## Shell Commands78- **One command per call** — keep commands small, readable, and atomic. Don't chain with `&&`, `;`, or `cd dir && command`. Use separate calls — first `cd`, then the command.9- **No inline env vars** — don't use `VAR=value command`. Set env separately or use proper auth tools.1011## Git Auth1213- Use `gh auth login` / `gh auth switch` to switch GitHub accounts — never prefix with `GH_TOKEN=...`.1415## Why1617Each chained command is one opaque action to the permission layer; splitting them gives one auditable tool call per intent. Inline env vars hide configuration in the command line and leak secrets into shell history; explicit auth tools (`gh auth login`) keep credentials in the keyring where they belong.1819## Prerequisites2021- A POSIX shell (bash or zsh).22- For the Git Auth rule: `gh` CLI installed and authenticated.2324## Failure modes2526- **`gh auth login` fails or token expired.** Re-run `gh auth login -h github.com` interactively, then `gh auth status` to verify. Don't paste the token into a shell command.27- **Account switch needed.** `gh auth switch -u <user>`. If that user's token is invalid, re-auth that account before switching.28- **Command needs elevated privileges.** Set up the privilege out-of-band (sudoers entry, group membership) rather than prefixing the command with `sudo` inline; an unattended agent shouldn't be entering passwords.29- **Shell aliases that hide what runs.** Avoid invoking aliases in agent procedures; spell out the real command so it's auditable.
Run npx skillmds@latest add aibot88/shell-discipline in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.
Shell Commands It is listed under Coding & Dev Tools on SkillMD.
This skill has not completed SkillMD's automated safety review yet. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.
This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.
Yes. Installing skills from SkillMD is free, and the skill stays under its author's original license.
aibot88 (@aibot88) published this skill. Their other Agent Skills are listed on their SkillMD profile.