stage-launch
Phase 2 of building a Claude Managed Agent — turn a validated build sheet into exact API payloads and a resumable BYOK curl launch script, then laun…
它会碰到什么
这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。
技能内容
Phase 2 — Stage → Launch
Turn the build sheet into runnable artifacts, then let the founder launch with
their own key. No script here touches the network or the key — the user runs
launch.sh.
Workflow
- Generate payloads.
python3 scripts/payload_generator.py \
--sheet ./my-agent/build-sheet.json --out-dir ./my-agent
# -> ./my-agent/payloads/{01-environment,02-agent,03-session,04-kickoff}.json
Agent toolset → always_allow; every MCP toolset → always_ask (baked into
the agent payload's permission_policies).
- Write the launch script.
python3 scripts/launch_script_writer.py --out-dir ./my-agent
launch.sh creates environment → agent → session → kickoff in order,
chaining IDs, and resumes on re-run (each step skips if its *.id file
exists). It reads $ANTHROPIC_API_KEY at runtime.
- Validate before launch.
python3 scripts/payload_validator.py --dir ./my-agent
FAIL blocks — especially a key_leak finding. Fix and re-run.
- Minimal key step (never in chat). Check the shell first:
[ -n "$ANTHROPIC_API_KEY" ] && echo "key present" || echo "export ANTHROPIC_API_KEY=... first"
Point the founder to platform.claude.com → API keys. **Never print the key to
chat, never write it to a file.**
- Launch + watch the first poll.
export ANTHROPIC_API_KEY=... # in their shell, not in chat
./my-agent/launch.sh
Mark checkpoints with Console deep links. Then `goal_state.py set --phase
grade-iterate` and advance.
Hard rules (API-key safety)
- The key never enters chat, a file, a payload, or a log.
launch.shreads it
from the environment; payload_validator.py scans for sk-ant-… leaks and FAILs.
- Sequential launch. environment → agent → session → kickoff. Watch the first
poll foreground before declaring success.
- Resumable. Re-running
launch.shcontinues from the last created ID.
Forcing-question library (recommend + cite)
- "Is the key in your shell env already?" Recommend: check
$ANTHROPIC_API_KEY
before anything. Cite: this SKILL, key-safety rules.
- "Cloud or self-hosted environment?" Recommend: cloud for v0. Cite:
cma-primitives.md (environment).
- "Any MCP server in the payload?" Recommend: keep it
always_ask. Cite:
cma-primitives.md (permissions).
- "Did the first poll return idle/running cleanly?" Recommend: watch it
foreground before moving on. Cite: cma-primitives.md (session lifecycle).
Tools
scripts/payload_generator.py— build sheet → 4 ordered API payloads.scripts/launch_script_writer.py— resumable BYOK curl launcher (no key handling).scripts/payload_validator.py— pre-launch check + API-key-leak scan.
想直接用这个技能?
本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。
它属于哪个仓库
agent-launcher/skills/stage-launch/SKILL.md