Dotfile With Optout

Credentialed primitive that legitimately reads the dotfile, with the opt-out marker on the same line; lint must NOT flag it.

eugenelim 251faaf 2 files · 1.3 KB Updated

File contents

The credentialed-primitive itself (not a skill) legitimately reads the dotfile. The opt-out comment names the relaxation explicitly so PR review can see and approve.

Security rules (non-negotiable)

  • Secrets live only in ~/.agentbundle/credentials.env (mode 0600 on POSIX; DACL-restricted on Windows), the OS keyring, or process environment variables. Never read that file, print it, or echo the token.
  • Never put the token on the command line. The primitive refuses flags like --token / --api-token / --bearer / --pat / --password and exits — do not work around it.
  • If check exits with the "missing credentials" code, tell the user to run agentbundle creds setup <namespace> themselves. It's interactive — do not run it for them.

eugenelim/agent-ready-repo/tree/main/packages/agentbundle/tests/fixtures/creds/skills/dotfile-with-optout commit 251faaf309

Frequently asked questions

npx skillmds@latest add eugenelim/dotfile-with-optout