Current shape
fullsend agent new copies providers and profiles from the scaffold embed (internal/scaffold/fullsend-repo/{providers,profiles}/, last changed in #7229). These are also the files per-repo CI layers in. For github-ro:
providers/github-ro.yaml: only name and type, with no credentials:
profiles/fullsend-github-ro.yaml: no credentials: block and no graphql endpoint
internal/agentnew/render.go buildHarness() puts GH_TOKEN: ${GH_TOKEN} in env.sandbox
providers/github-ro.yaml: credentials: { GH_TOKEN: "${GH_TOKEN}" }
profiles/fullsend-github-ro.yaml: credentials: [{ name: api_token, env_vars: [GH_TOKEN], required: true }], plus an api.github.com graphql endpoint (path: /graphql, read-only)
Impact
This affects every per-repo install, plus everything agent new generates.
It is unproven either way whether the current scaffold shape is invalid on OpenShell 0.1.2: main pins 0.1.2 and ships it. So for now this is consistency and hardening: a declared credential, which the sandbox sees as a placeholder, versus a raw token in the sandbox environment.
Ask
Decide whether the scaffold should adopt the declared-credential shape. If yes, mirror it in the generator (drop GH_TOKEN from the generated env.sandbox if the provider supplies it) and update the internal/agentnew golden files.
Current shape
fullsend agent newcopies providers and profiles from the scaffold embed (internal/scaffold/fullsend-repo/{providers,profiles}/, last changed in #7229). These are also the files per-repo CI layers in. Forgithub-ro:providers/github-ro.yaml: onlynameandtype, with nocredentials:profiles/fullsend-github-ro.yaml: nocredentials:block and no graphql endpointinternal/agentnew/render.gobuildHarness()putsGH_TOKEN: ${GH_TOKEN}inenv.sandboxShape in fullsend-ai/agents (since fullsend-ai/agents#1513)
providers/github-ro.yaml:credentials: { GH_TOKEN: "${GH_TOKEN}" }profiles/fullsend-github-ro.yaml:credentials: [{ name: api_token, env_vars: [GH_TOKEN], required: true }], plus anapi.github.comgraphql endpoint (path: /graphql, read-only)Impact
This affects every per-repo install, plus everything
agent newgenerates.It is unproven either way whether the current scaffold shape is invalid on OpenShell 0.1.2: main pins 0.1.2 and ships it. So for now this is consistency and hardening: a declared credential, which the sandbox sees as a placeholder, versus a raw token in the sandbox environment.
Ask
Decide whether the scaffold should adopt the declared-credential shape. If yes, mirror it in the generator (drop
GH_TOKENfrom the generatedenv.sandboxif the provider supplies it) and update theinternal/agentnewgolden files.