feat: add safe shared SSO login guidance (central ui-ux)

This commit is contained in:
2026-08-27 20:50:35 +00:00
parent 82659d10ec
commit 132406f061
+12 -1
View File
@@ -1,7 +1,7 @@
--- ---
name: corp-v1-channel-ui-ux name: corp-v1-channel-ui-ux
description: "Use when operating or synchronizing a Corp v1 project's UI/UX channel. Maintains project frontend design work, Penpot artifacts, design-system decisions, accessibility evidence, and implementation handoffs while correlating verified activity across the project's seven channels." description: "Use when operating or synchronizing a Corp v1 project's UI/UX channel. Maintains project frontend design work, Penpot artifacts, design-system decisions, accessibility evidence, and implementation handoffs while correlating verified activity across the project's seven channels."
version: 1.2.0 version: 1.2.1
author: Hermes Agent author: Hermes Agent
license: MIT license: MIT
metadata: metadata:
@@ -26,6 +26,17 @@ This skill does not own product scope, system architecture, task admission, fron
Load the project's adopted `documentation-docusaurus--<code>` skill before changing project documentation. Load global `corp-v1--glossary` when defining reusable terminology. Use the project's development and delivery skills when design work reaches implementation. Load the project's adopted `documentation-docusaurus--<code>` skill before changing project documentation. Load global `corp-v1--glossary` when defining reusable terminology. Use the project's development and delivery skills when design work reaches implementation.
## Shared Corp v1 System Login
When an authorized task requires login to a Corp v1 system being built or operated, follow the shared policy in `corp-v1--main` and use only the Bitwarden-injected runtime secrets named:
```text
HL_V1_SSO_EMAIL
HL_V1_SSO_PASSWORD
```
Secret availability is capability, not authorization. Verify the destination origin and task purpose before login. Never print, inspect, log, hash, serialize, paste, screenshot, or persist either value; never place a value in a command line, URL, file, repository, prompt, Discord message, browser console, test fixture, CI output, or generated artifact. Never ask a human to paste a value into chat. If a variable is unavailable, report only its missing name and request Bitwarden/gateway injection. Login does not authorize account recovery, MFA or credential changes, permission changes, billing, spending, destructive operations, or access outside the approved project task.
## When to Use ## When to Use
Use this skill when: Use this skill when: