Argv Flag Derived

Credentialed-CLI fixture exercising round-2 lint widening — f-string, Starred(Tuple), Subscript shapes. All three should produce argv-flag findings.

eugenelim 4810a53 2 files · 1.7 KB Updated

File contents

Body with the full "Don't" block so only argv-flag variants fire:

Security rules (non-negotiable)

  • Secrets live only in ~/.agentbundle/credentials.env (mode 0600 on POSIX; DACL-restricted on Windows), the OS keyring, or process environment variables. Never read that file, print it, or echo the token.
  • Never put the token on the command line. The primitive refuses flags like --token / --api-token / --bearer / --pat / --password and exits — do not work around it.
  • If check exits with the "missing credentials" code, tell the user to run agentbundle creds setup <namespace> themselves. It's interactive — do not run it for them.

eugenelim/agent-ready-repo/tree/main/packages/agentbundle/tests/fixtures/creds/skills/argv-flag-derived commit 4810a53466

Frequently asked questions

npx skillmds@latest add eugenelim/argv-flag-derived