account-rotation
Switch coding-agent accounts and verify runtime identity. Use when: the caller requests an account change; never rotate automatically to evade a quo…
它会碰到什么
这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。
技能内容
Account rotation — credential adapter
Choose the credential tool from both host and agent family, perform only the
explicit account switch, and report the identity observed by the matching
runtime.
Verifying identity through the target runtime works because the runtime is the
only party whose opinion matters: credential files can be swapped perfectly
and still authenticate as the old account in an already-running process.
Named failure mode — stale-process identity: declaring the rotation done
while every live session still holds the previous account's tokens in memory.
Anti-pattern: confirming a switch by diffing credential file bytes.
Corrective: ask the matching runtime who it is now, and report whether a new
process is required for the answer to hold.
Boundary
- Perform only the account switch the caller explicitly authorized; rotation
mutates host credential state and is never implied by repository access.
- The credential tool is caller- or operator-selected per host and agent family;
the names below are this operator's routes, not a universal prescription. On
macOS with Claude credentials the route is claude-acct (Keychain-backed);
file-backed Codex, Gemini, Linux, or WSL credentials use caam. Never use
caam for macOS Claude account operations.
- Verify account identity through the target runtime; token bytes are not account
identity.
- If neither the selected credential tool nor a runtime identity probe is
available, report that absence as a disclosed fact and stop. Never fall back to
diffing credential-file bytes to declare a switch done.
- Existing processes retain credentials already loaded in memory. Rotation
affects a new process.
- This skill does not restart work, resume a task, select a pane, move repository
state, or decide what happens after the switch.
Return the host, agent family, selected tool, requested account/profile, the
identity observed before and after the switch, whether any live runtime still
holds the previous account (a partial rotation), the command exit code, and
whether a new process is required for the new identity to hold.
想直接用这个技能?
本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。
它属于哪个仓库
plugins/boshu2/agentops/skills-codex/account-rotation/SKILL.md