Skip to content

docs: machine B is agent-driven too — with a triple guard against team forgery - #574

Open
fujibee wants to merge 3 commits into
integration/remotefrom
docs/agent-pull-setup
Open

docs: machine B is agent-driven too — with a triple guard against team forgery#574
fujibee wants to merge 3 commits into
integration/remotefrom
docs/agent-pull-setup

Conversation

@fujibee

@fujibee fujibee commented Jul 31, 2026

Copy link
Copy Markdown
Owner

The CLI-first doctrine for machine B came from a real fear: an agent asked to "join team X" might create a fresh local team named X instead of pulling the remote one. Tonight's live cross-account test showed the other side of the trade: the CLI-only path was painful enough that the operator gave up on it, while the B-side agent — once taught — executed pull → digest check → unlock → join flawlessly, refused to let the identity into chat, and flagged a leftover world-readable secret unprompted.

So machine B's main path becomes agent-driven, matching machine A, and the fear is answered with an explicit triple guard in SKILL.md and all nine templates: joining a server-side team must NEVER go through join/create; it always goes through remote pull; and if an unconnected local team with the same name already exists, stop and ask the user. The raw CLI walkthrough stays as Reference.

Template slices hash-identical across nine types; registry/template suites 19/19 green.

PR opened on the author's behalf — their sandbox blocks GitHub access.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant