# Argv Flag Derived

> Credentialed-CLI fixture exercising round-2 lint widening — f-string, Starred(Tuple), Subscript shapes. All three should produce argv-flag findings.

- Skill: `eugenelim/argv-flag-derived` (Agent Skill, multi-file: 2 files)
- Install (CLI): `npx skillmds@latest add eugenelim/argv-flag-derived`
- Raw SKILL.md: https://api.skillmd.com/api/skills/eugenelim/argv-flag-derived/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- Author: eugenelim (https://skillmd.com/u/eugenelim)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/eugenelim/argv-flag-derived

---


Body with the full "Don't" block so only argv-flag variants fire:

### Security rules (non-negotiable)

- Secrets live only in `~/.agentbundle/credentials.env`
  (mode 0600 on POSIX; DACL-restricted on Windows), the OS keyring,
  or process environment variables.
  **Never** read that file, print it, or echo the token.
- **Never** put the token on the command line. The primitive
  refuses flags like `--token` / `--api-token` / `--bearer` /
  `--pat` / `--password` and exits — do not work around it.
- If `check` exits with the "missing credentials" code, tell the
  user to run `agentbundle creds setup <namespace>` themselves.
  It's interactive — do not run it for them.

