leak-publish
Overview
This skill operates publish workflows only:
- Publish a local file behind an x402 gate.
- Optionally expose with
--publicafter explicit consent. - Keep process alive using detached supervisors.
Safety policy (required)
- Require explicit user confirmation of the file path.
- Require explicit user consent before
--publicexposure. - Reject symlink paths.
- Reject directories and non-regular files.
- Block sensitive paths:
~/.ssh~/.aws~/.gnupg~/.config/gcloud/etc/private/etc/proc/sys/var/run/secrets/private/var/run/secrets
Dependency policy (required)
- Require
leakbinary on PATH. - Do not execute
npxor dynamic package install at runtime.
Runtime policy (required)
- Treat publish as persistent-by-default for all sale windows.
- Use
--run-mode autounless user explicitly asks for foreground. - Detached supervisor order:
systemd --user(Linux)launchd(macOS)tmuxscreennohupfallback
- After background launch, report control details:
- supervisor/session or PID
- log file
- stop command
Required inputs
- File path.
- Price in USDC.
- Sale window.
- Seller payout address (
--pay-to). - Public exposure choice (
--publicor local only).
Local publish
bash skills/leak-publish/scripts/publish.sh \
--run-mode auto \
--file ./protected/asset.bin \
--price 0.01 \
--window 15m \
--pay-to 0xSELLER_ADDRESS \
--network eip155:84532
Public publish
bash skills/leak-publish/scripts/publish.sh \
--run-mode auto \
--file ./protected/asset.bin \
--price 0.01 \
--window 15m \
--pay-to 0xSELLER_ADDRESS \
--public
Runtime smoke check
bash skills/leak-publish/scripts/smoke_persistent_runner.sh --mode auto --sleep-seconds 8
Expected result: PASS and selected backend.
Troubleshooting
leakmissing:- install:
npm i -g leak-cli
- install:
- public confirmation failed:
- rerun with exact confirmation phrase when prompted