Fixes and improvements
- Replaced fragile readline password handling with maintained interactive prompts
- API-key prompt remains visible while entered secrets are masked
- Added one-time provider onboarding for OpenAI, OpenRouter, Groq, Ollama, and custom endpoints
- Added live model discovery, model-family filtering, searchable model selection, and custom model fallback
- Separated model-profile setup from the per-launch assessment wizard
- Added structured scope, exclusions, authorization reference, testing window, and rate-limit capture
- Replaced the slash hint with a searchable arrow-key command launcher
- Passes the declared scope and rules of engagement into the agent run
- Prevents credentials from carrying across provider changes
Verification
- 12 automated tests passed
- Password masking and slash-search terminal regressions covered directly
- Interactive end-to-end suite passed
- Clean npm consumer install passed
- npm audit: 0 vulnerabilities
npm install -g @nullsquare/null-cli@latest