mirror of
https://github.com/mattpocock/skills.git
synced 2026-09-12 10:28:06 +07:00
A Snyk audit (W007, HIGH) flagged the skill for insecure credential handling: it tells the agent to "paste the invocation and its output", builds curl loops, and collects artifacts — three paths by which a live token can end up reproduced in the agent's response. Add a Redact section making redaction the first move on each, and point the two call sites at it. Warn in the HITL template that `capture` prints its value back to the terminal, where the agent reads it. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
45 lines
1.3 KiB
Bash
45 lines
1.3 KiB
Bash
#!/usr/bin/env bash
|
|
# Human-in-the-loop reproduction loop.
|
|
# Copy this file, edit the steps below, and run it.
|
|
# The agent runs the script; the user follows prompts in their terminal.
|
|
#
|
|
# Usage:
|
|
# bash hitl-loop.template.sh
|
|
#
|
|
# Two helpers:
|
|
# step "<instruction>" → show instruction, wait for Enter
|
|
# capture VAR "<question>" → show question, read response into VAR
|
|
#
|
|
# At the end, captured values are printed as KEY=VALUE for the agent to parse.
|
|
#
|
|
# `capture` prints its value back to the terminal, where the agent reads it — so
|
|
# capture observations, and leave signing in to the user as a `step`.
|
|
|
|
set -euo pipefail
|
|
|
|
step() {
|
|
printf '\n>>> %s\n' "$1"
|
|
read -r -p " [Enter when done] " _
|
|
}
|
|
|
|
capture() {
|
|
local var="$1" question="$2" answer
|
|
printf '\n>>> %s\n' "$question"
|
|
read -r -p " > " answer
|
|
printf -v "$var" '%s' "$answer"
|
|
}
|
|
|
|
# --- edit below ---------------------------------------------------------
|
|
|
|
step "Open the app at http://localhost:3000 and sign in."
|
|
|
|
capture ERRORED "Click the 'Export' button. Did it throw an error? (y/n)"
|
|
|
|
capture ERROR_MSG "Paste the error message (or 'none'):"
|
|
|
|
# --- edit above ---------------------------------------------------------
|
|
|
|
printf '\n--- Captured ---\n'
|
|
printf 'ERRORED=%s\n' "$ERRORED"
|
|
printf 'ERROR_MSG=%s\n' "$ERROR_MSG"
|