Claude enrollment handoff
Load ops-rules before acting. Public repo (no personal data). Outbound: one draft → one approval → one send. If AskUserQuestion / Workflow are missing, follow Rule 10 in ops-rules (Hermes: numbered options / two-turn Telegram card; delegate_task).
Direct Claude browser, OAuth, magic-link, setup, and unattended authentication
are disabled. Do not launch a browser, poll email, invoke rotate.mjs --setup,
invoke rotate-magic.mjs, modify auth inventory, or suggest an environment
bypass.
Tell the operator to use scripts/account-rotation/staged-enrollment.mjs with:
- An owner-only deployment config that pins every trust root and the canonical operation lock.
- A short-lived, separately signed
stageapproval for an externally captured CLIProxyAPI Claude auth candidate. - External containment of all writers.
- A distinct
activateapproval bound to the staged digest and attestingwritersQuiesced: true.
The attestation records operator confirmation; it does not stop services or contain writers itself. This skill does not sign approvals or perform either operation on the operator's behalf.