Argv Flag

Credentialed-CLI fixture whose script accepts `--token` on argv; an argv-flag finding is expected.

eugenelim 4bc43e8 2 files · 1.2 KB Updated

File contents

Body content with the full "Don't" block (so the missing-block check is silent and the argv finding is the only one fired):

Security rules (non-negotiable)

  • Secrets live only in ~/.agentbundle/credentials.env (mode 0600 on POSIX; DACL-restricted on Windows), the OS keyring, or process environment variables. Never read that file, print it, or echo the token.
  • Never put the token on the command line. The primitive refuses flags like --token / --api-token / --bearer / --pat / --password and exits — do not work around it.
  • If check exits with the "missing credentials" code, tell the user to run agentbundle creds setup <namespace> themselves. It's interactive — do not run it for them.

eugenelim/agent-ready-repo/tree/main/packages/agentbundle/tests/fixtures/creds/skills/argv-flag commit 4bc43e80fb

Frequently asked questions

npx skillmds@latest add eugenelim/argv-flag