recover-credentials
Help the user recover lost AxonFlow tenant credentials via the email magic-link flow, or apply a paid Pro-tier license token. Use when the user says…
它会碰到什么
这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。
技能内容
The AxonFlow agent exposes two recovery flows users sometimes need to reach from inside Codex:
- Email-magic-link recovery (free, applies to any tenant). The user lost their
AXONFLOW_AUTH/ tenant secret and needs new credentials. They request a magic link, click it, copy the hex token, and the plugin persists the new credentials atomically into~/.codex/axonflow.toml. - Pro-tier license-token install. The user just paid for the Pro tier through Stripe Checkout and received an
AXON--prefixed license token by email. They paste it through the same recovery surface and the plugin persists it for the next Codex session to pick up.
Use the exec_command tool to invoke the recovery script that ships with the plugin:
| User intent | Command |
|---|---|
| Lost credentials, request new magic link | bash $PLUGIN_DIR/scripts/recover.sh request |
| Click magic link, paste hex token | bash $PLUGIN_DIR/scripts/recover.sh verify |
| Install paid Pro license token | bash $PLUGIN_DIR/scripts/recover.sh apply-token |
| Check current tier / config | bash $PLUGIN_DIR/scripts/recover.sh status |
$PLUGIN_DIR resolves to the plugin checkout the user installed.
For non-interactive use (test harnesses, CI, automation), the script also reads:
AXONFLOW_RECOVER_EMAILforrequestAXONFLOW_RECOVER_TOKENforverifyAXONFLOW_LICENSE_TOKENforapply-token
In each case, after the script runs, advise the user that the new credentials live in ~/.codex/axonflow.toml (mode 0600) and that they should restart Codex (or re-export AXONFLOW_AUTH / AXONFLOW_LICENSE_TOKEN from the file) for the change to take effect.
Never paste the token or secret into chat. The script reads from stdin or env so the value never enters the model context.
想直接用这个技能?
本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。
它属于哪个仓库
plugins/getaxonflow/axonflow-codex-plugin/skills/recover-credentials/SKILL.md