Skip to content

scaffold + agent new: mirror agents#1513's OpenShell 0.1 credential declarations for github-ro #7883

Description

@waynesun09

Current shape

fullsend agent new copies providers and profiles from the scaffold embed (internal/scaffold/fullsend-repo/{providers,profiles}/, last changed in #7229). These are also the files per-repo CI layers in. For github-ro:

  • providers/github-ro.yaml: only name and type, with no credentials:
  • profiles/fullsend-github-ro.yaml: no credentials: block and no graphql endpoint
  • internal/agentnew/render.go buildHarness() puts GH_TOKEN: ${GH_TOKEN} in env.sandbox

Shape in fullsend-ai/agents (since fullsend-ai/agents#1513)

  • providers/github-ro.yaml: credentials: { GH_TOKEN: "${GH_TOKEN}" }
  • profiles/fullsend-github-ro.yaml: credentials: [{ name: api_token, env_vars: [GH_TOKEN], required: true }], plus an api.github.com graphql endpoint (path: /graphql, read-only)

Impact

This affects every per-repo install, plus everything agent new generates.

It is unproven either way whether the current scaffold shape is invalid on OpenShell 0.1.2: main pins 0.1.2 and ships it. So for now this is consistency and hardening: a declared credential, which the sandbox sees as a placeholder, versus a raw token in the sandbox environment.

Ask

Decide whether the scaffold should adopt the declared-credential shape. If yes, mirror it in the generator (drop GH_TOKEN from the generated env.sandbox if the provider supplies it) and update the internal/agentnew golden files.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    component/harnessAgent harness, config, and skills loadingcomponent/sandboxOpenShell sandbox environmentpriority/mediumNormal priority, plan for next cyclesecuritySecurity threat model and related concernstriagedTriaged but awaiting human prioritization

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions