v0.19.1
What's New in v0.19.1
Bug Fix
request_secret now supports token rotation via force: true (#271)
When an agent called request_secret for a secret that was already registered in secretEnvKeys, the tool returned alreadyExisted: true and skipped prompting — even if the actual keychain value had been deleted or rotated. Agents had no way to ask the user for an updated token without manually clearing stale entries from data.json.
A new force?: boolean parameter bypasses this early-return. When force: true:
- The user is always prompted, regardless of whether the secret already exists
- The modal heading changes to "Agent is replacing a secret" and shows a note that the existing value will be replaced
- The keychain entry is updated on save
Usage:
request_secret({ secretName: "MY_API_KEY", reason: "token was rotated", force: true })
Tests
- 10 new unit tests covering the
forcebypass logic, cancellation behaviour, and argument normalisation - 2 new screenshot tests for the normal and force modal variants