From 87a50a926a7256201ce1771aad7764898f24ff60 Mon Sep 17 00:00:00 2001 From: Jarvis Jr Hermes Date: Thu, 27 Aug 2026 20:50:36 +0000 Subject: [PATCH] feat: add safe shared SSO login guidance (central kanban) --- SKILL.md | 13 ++++++++++++- 1 file changed, 12 insertions(+), 1 deletion(-) diff --git a/SKILL.md b/SKILL.md index 6256626..9ab9845 100644 --- a/SKILL.md +++ b/SKILL.md @@ -1,7 +1,7 @@ --- name: corp-v1-channel-kanban description: "Use when operating or synchronizing a Corp v1 project's Kanban channel. Maintains Board and Focus across Epic, Feature, and task state; correlates all seven same-project channels; and records human approval before tasks enter Delivery's executable InBacklog queue." -version: 1.4.1 +version: 1.4.2 author: Hermes Agent license: MIT metadata: @@ -22,6 +22,17 @@ Load the global `documentation-docusaurus` skill from `https://gitea.lego-cloud. Load the global `corp-v1--glossary` skill from `https://gitea.lego-cloud.eu/home-v1-skills-code-agent/corp-v1--glossary` whenever project documentation needs to define or explain a reusable term. Maintain one canonical definition in the project's final top-level **Glossary** area and link to it from the owning domain page; do not duplicate glossary-style explanations across channel documentation. +## Shared Corp v1 System Login + +When an authorized task requires login to a Corp v1 system being built or operated, follow the shared policy in `corp-v1--main` and use only the Bitwarden-injected runtime secrets named: + +```text +HL_V1_SSO_EMAIL +HL_V1_SSO_PASSWORD +``` + +Secret availability is capability, not authorization. Verify the destination origin and task purpose before login. Never print, inspect, log, hash, serialize, paste, screenshot, or persist either value; never place a value in a command line, URL, file, repository, prompt, Discord message, browser console, test fixture, CI output, or generated artifact. Never ask a human to paste a value into chat. If a variable is unavailable, report only its missing name and request Bitwarden/gateway injection. Login does not authorize account recovery, MFA or credential changes, permission changes, billing, spending, destructive operations, or access outside the approved project task. + ## When to Use Use this skill when: